UpdateStar Vulnerability Index · July 2026

Monthly severity snapshot for widely-installed consumer software

74
Overall Score

SEVERE

July 2026 delivered the largest Patch Tuesday in Microsoft's history — 569 CVEs, more than 2.5× June's already-record 208. Two of those flaws (SharePoint, AD FS) were exploited as zero-days and landed on CISA KEV within days. Separately, Mozilla shipped an emergency Firefox release after confirming public exploit code for two critical flaws, and the WinRAR path-traversal bug from July 2025 is still being actively exploited by nation-state groups a full year later.

2 × KEV Listed Ongoing Nation-State Exploitation 2 × Public PoC 569 MS CVEs

Top 5 — Consumer App Severity

#1
WinRAR CVE-2025-8088
Path traversal → Startup folder · Nation-state exploitation still widespread a year later (RomCom, Gamaredon, Paper Werewolf) · No auto-update, ~500M users exposed
CISA KEV APT Active Patched 7.13
8.4
CVSS HIGH
#2
Adobe Acrobat Reader CVE-2026-48373
Heap-based buffer overflow → arbitrary code execution · Requires opening a malicious file · Patched same day as disclosure
Patched 26.001.21662 (APSB26-63)
7.8
CVSS HIGH
#3
Mozilla Firefox CVE-2026-15718 / -15719
Invalid-pointer JS/WebAssembly bug + Fission site-isolation bypass · Mozilla confirmed public exploit code for both, no ITW attacks observed yet · Auto-update reliable but needs a restart
Public PoC (both CVEs) Patched Firefox 152.0.6
Critical
CVSS PENDING (NVD)
#4
Google Chrome CVE-2026-15764 / -15765
Two critical use-after-free flaws in the Ozone display layer · Sits at the OS trust boundary, closer path to sandbox escape · No confirmed exploitation at disclosure, gradual rollout leaves an exposure window
Patched 150.0.7871.124/.125
Critical
CVSS PENDING (NVD)
#5
Heap overflow in XZ archive decoder · No auto-update · ZDI advisory made details public Jul 15, ~3 weeks after the silent fix
Patched 26.02
7.0
CVSS HIGH

CVSS Score Comparison

WinRAR 8.4
Adobe Acrobat Reader 7.8
Firefox Critical (pending)
Chrome Critical (pending)
7-Zip 7.0

Key Stats — July 2026

569
Microsoft CVEs patched in a single Patch Tuesday (record)
2
MS zero-days exploited ITW & added to CISA KEV (AD FS, SharePoint)
2
Firefox CVEs with confirmed public exploit code
365+
Days WinRAR CVE-2025-8088 under continuous nation-state exploitation
−7
Days mean time-to-exploit (Mandiant M-Trends 2026)
43
Days median KEV remediation time (Verizon DBIR 2026)

Patch Lag — Days Since Disclosure vs. Update Status

WinRAR (CVE-2025-8088) 365+ d
Patched Jul 2025 · still under active nation-state exploitation a year later, no auto-update
Adobe Acrobat Reader (CVE-2026-48373) ~7 d
Fixed Jul 17 · newly disclosed, no confirmed exploitation yet
Firefox (CVE-2026-15718 / -15719) <10 d
Fixed Jul 14 · exploit code public, auto-update reliable but requires restart
Chrome (CVE-2026-15764 / -15765) <10 d
Fixed Jul 15 · staged gradual rollout, no confirmed ITW yet
7-Zip (CVE-2026-14266) ~30 d
Silently fixed Jun 25 · ZDI advisory public Jul 15 · no auto-update, no confirmed PoC/ITW
Data sources: NVD · CISA KEV · Mandiant M-Trends 2026 · Verizon DBIR 2026 · vendor advisories (Mozilla, Google, Adobe, RARLAB, 7-Zip/ZDI, Microsoft MSRC)
Check and update all software at updatestar.com · Download the UpdateStar Client for Windows

July 2026 Highlights

  • KEV3 CVEs on CISA Known Exploited Vulnerabilities list (2 new — AD FS & SharePoint, 1 carryover — WinRAR)
  • APTWinRAR still under active nation-state exploitation a year after patch
  • PoC2 CVEs (Firefox) with public proof-of-concept / exploit code
  • MS569 Microsoft CVEs in a single Patch Tuesday — a new record

Overall Severity Score

Index Score 74 / 100
Rating SEVERE

App Quick Reference

  • CRIT WinRAR 8.4
  • HIGH Acrobat Reader 7.8
  • HIGH Firefox Critical*
  • HIGH Chrome Critical*
  • MED 7-Zip 7.0

Patch Status

  • WinRAR — patched but no auto-update, still actively exploited
  • Acrobat Reader — patched (Jul 17)
  • Firefox — patched (auto-update, restart required); exploit code circulating
  • Chrome — patched (staged/gradual rollout)
  • 7-Zip — patched but no auto-update

Data Sources

  • NVD (National Vulnerability Database)
  • CISA Known Exploited Vulnerabilities
  • Mandiant M-Trends 2026
  • Verizon DBIR 2026
  • Vendor security advisories