July 2026 brought 22 open-source device CVEs worth reviewing across the packages commonly shipped inside device images, not counting the Linux kernel. For the eight priority packages in the table below, an upstream fix or a patched update path was available when this review was compiled. None of these eight was in the CISA Known Exploited Vulnerabilities catalog at that time, and the action is the same in each case: update the affected package to the fixed version and rebuild your image. The eight packages are U-Boot, OpenSSH, curl, FFmpeg, GStreamer, Chromium, containerd, and Node.js.

This is the device stack beyond the kernel. It is the bootloader, the C library, the TLS and networking code, the media pipeline, and the container runtime that sit inside a shipped image. Which of these open-source device CVEs matter to you depends on what is actually in your image and your software bill of materials (SBOM). The EU Cyber Resilience Act creates software-inventory and vulnerability-handling duties that make SBOM-style tracking operationally necessary, so the SBOM is the list you check this report against. This month the crypto libraries were quiet: no CVE in OpenSSL, wolfSSL, Mbed TLS, or GnuTLS met this report's inclusion criteria in July. The pressure was on the bootloader, the remote-access tools, the media stack, and the container runtime.