Multiple critical vulnerabilities disclosed in software July 27-29

Between July 27-29, 2026, security exploits were publicly disclosed for five software products: nginx 1.30.3 (heap buffer overflow/RCE), GitLab Community Edition 18.11.3 (notebook diff RCE), MouseHero 1.2.0+1 (remote power control), OpenWrt odhcpd (RCE), and vBulletin 6.2.1 (pre-auth RCE). All were listed on Packet Storm with exploit code available.

12 reportsother

Claim audit

No BS check run yet — press ⚖ to extract this story's claims and verify them against independent sources.

All coverage