CVEs
776 CVEs referenced across all briefs. Click an ID for the full appearance trail.
Total CVEs
776
2008 – 2026
Recent (30 d)
303
entities with new coverage in window
Distinct sources
217
hosts cited at least once
Total appearances
770
brief-section attributions
Co-occurrence links
1892
entity ↔ entity in same item
Recent coverage
Aggregate mentions per ISO week, last 14 weeks.
By year
| CVE | Title | First seen | Last seen | Latest coverage |
|---|---|---|---|---|
| CVE-2026-58047 | cPanel & WHM — HTTP request smuggling in cpsrvd allowing an unauthenticated attacker to manipulate responses delivered to other users on the same server (CVSS v4.0 5.6); interim mitigation disables cpsrvd backend connection reuse | 2026-08-06 | 2026-08-06 | — |
| CVE-2026-58048 | cPanel & WHM — SQL mode not preserved when renaming a database, so an authenticated account holder with the MySQL/MariaDB feature executes SQL in root context (CVSS v4.0 9.4, HackerOne CNA); fixed across the 11.110–11.136 build lines and WP Squared 138.1.6 | 2026-08-06 | 2026-08-06 | — |
| CVE-2026-58067 | Veeam Service Provider Console — unauthenticated host-memory exhaustion denial of service (CVSS v4.0 8.7); fixed in 9.3.0.35057 | 2026-08-06 | 2026-08-06 | — |
| CVE-2026-58071 | Veeam Service Provider Console — unauthenticated access to the proxied appliance API as Portal Administrator during a window after an admin session begins (CVSS v4.0 8.2); fixed in 9.3.0.35057 | 2026-08-06 | 2026-08-06 | — |
| CVE-2026-58072 | Veeam Service Provider Console — arbitrary file write on the management server leading to remote code execution (CVSS v4.0 9.0); fixed in 9.3.0.35057 | 2026-08-06 | 2026-08-06 | — |
| CVE-2026-58073 | Veeam Service Provider Console — unauthenticated attacker impersonates a managed agent and obtains its credentials (CVSS v4.0 9.5, high attack complexity); fixed in SPC 9.3.0.35057 | 2026-08-06 | 2026-08-06 | — |
| CVE-2026-58074 | Veeam ONE — arbitrary code execution on the server by a high-privileged user (CVSS v4.0 8.6); fixed in 13.1.0.7034 | 2026-08-06 | 2026-08-06 | — |
| CVE-2026-58075 | Veeam ONE — unauthenticated arbitrary file read from the host, leveragable to local privilege escalation (CVSS v4.0 8.7); fixed in 13.1.0.7034 | 2026-08-06 | 2026-08-06 | — |
| CVE-2026-63077 | JetBrains TeamCity On-Premises — unauthenticated deserialization RCE via the agent-polling protocol (CVSS 9.8); added to the CISA KEV catalog 2026-08-05 on evidence of active exploitation, reversing the vendor's no-known-exploitation position at disclosure | 2026-07-29 | 2026-08-06 | 2026-07-29 |
| CVE-2026-63455 | HPE Aruba Networking SD-WAN Orchestrator — REST API authentication bypass via spoofed HTTP headers (CVSS v3.1 9.8), 9.6.x branch only; fixed in 9.6.2.40210 / 9.6.3.40140 / 9.7.0.43264 | 2026-08-06 | 2026-08-06 | — |
| CVE-2026-63456 | HPE Aruba Networking SD-WAN Orchestrator — second REST API authentication bypass via spoofed HTTP headers (CVSS v3.1 9.8), 9.6.x branch only; fixed in 9.6.2.40210 / 9.6.3.40140 / 9.7.0.43264 | 2026-08-06 | 2026-08-06 | — |
| CVE-2026-64630 | Veeam ONE — low-privileged retrieval of report data outside a shared link's scope (CVSS v4.0 5.3); fixed in 13.1.0.7034 | 2026-08-06 | 2026-08-06 | — |
| CVE-2026-64631 | Veeam ONE — SQL injection by a low-privileged user extracting database contents (CVSS v4.0 8.6); fixed in 13.1.0.7034 | 2026-08-06 | 2026-08-06 | — |
| CVE-2026-64633 | Veeam ONE — unauthenticated remote code execution on the agent host (CVSS v4.0 10.0); fixed in Veeam ONE 13.1.0.7034 | 2026-08-06 | 2026-08-06 | — |
| CVE-2026-64634 | Veeam ONE — local privilege escalation into the Reporter service context (CVSS v4.0 8.4); fixed in 13.1.0.7034 | 2026-08-06 | 2026-08-06 | — |
| CVE-2026-66747 | Zbtlink routers/CPE — ENDLESSDOORS, a factory-installed unauthenticated root-command backdoor started by the vendor's own init script across 20+ models; no fix, VulnCheck advises device replacement | 2026-08-06 | 2026-08-06 | — |
| CVE-2026-17583 | Thermo Fisher Applied Biosystems genetic analyzers — missing integrity checking on .fsa/.hid output files allows post-run tampering with DNA results (CVSS 3.1 8.4, local); no vendor fix stated in ICSMA-26-216-01 | 2026-08-05 | 2026-08-05 | 2026-08-05 |
| CVE-2026-18556 | N-able N-central — authentication bypass using an alternate path or channel (CWE-288), affects through 2026.1, fixed in 2026.2 (CVSS 8.2) | CISA KEV 2026-08-04. | 2026-08-03 | 2026-08-05 | 2026-08-05 +1 more |
| CVE-2026-18574 | Check Point Security Management / Multi-Domain Security Management — unauthenticated bypass of management authentication to arbitrary command execution; fixed in Jumbo HFA R81.20 Take 161 / R82 Take 122 / R82.10 Take 40, no fix for the R80.x / R81 / R81.10 end-of-support trains | 2026-08-05 | 2026-08-05 | 2026-08-05 |
| CVE-2026-18577 | N-able N-central — incomplete patch for CVE-2026-18556; unauthenticated admin auth bypass exploited in the wild, fixed in build 2026.3.1.7 (CVSS 8.2) | 2026-08-03 | 2026-08-05 | 2026-08-03 |
| CVE-2026-29146 | Apache Tomcat — EncryptInterceptor defaulted to CBC and was exploitable as a padding oracle; its fix introduced the fail-open regression tracked as CVE-2026-34486 | 2026-08-05 | 2026-08-05 | — |
| CVE-2026-34486 | Apache Tomcat Tribes/EncryptInterceptor fail-open — the fix for CVE-2026-29146 let messages that fail decryption reach the Java deserialization path; CISA KEV 2026-08-04 (previously recorded only as reverse-shell attempts observed by Unit 42); fixed in 9.0.117 / 10.1.54 / 11.0.21 | 2026-08-02 | 2026-08-05 | 2026-08-05 |
| CVE-2026-9198 | IBM Langflow — unauthenticated auto_login endpoint mints a superuser token, chained with the code-validation endpoint for pre-auth code execution (CVSS 9.8); CISA KEV 2026-08-04; affects Langflow OSS 1.0.0-1.10.0 | 2026-08-05 | 2026-08-05 | 2026-08-05 |
| CVE-2026-15409 | SonicWall SMA1000 Work Place unauthenticated SSRF (CVSS 10.0, actively exploited) | 2026-07-14 | 2026-08-04 | 2026-08-04 +2 more |
| CVE-2026-15410 | SonicWall SMA1000 AMC post-auth code injection (actively exploited) | 2026-07-14 | 2026-08-04 | 2026-08-04 +2 more |
| CVE-2026-20079 | CVE-2026-20079 — Cisco Secure Firewall Management Center web interface: unauthenticated authentication bypass to root via a boot-time csm_processes session (CVSS 10.0, CWE-288); disclosed 2026-03-04 with no fix, per-train hot fixes added to the advisory 2026-07-31; Cisco reports no known malicious use, VulnCheck built a working exploit | 2026-08-04 | 2026-08-04 | 2026-08-04 |
| CVE-2026-51294 | FABRICATED / NOT A REAL VULNERABILITY — a use-after-free claim against SQLite 3.41 from the LLM-generated advisory batch published via the programmervuln/cveadvisory- GitHub repository. NOT among the six ids JFrog Security Research reproduction-tested; JFrog assessed 54 of the 55 advisories from that account as completely fabricated, and SQLite's maintainer reported the wave independently on 2026-07-29. Still live as an unreviewed record in the GitHub Advisory Database (GHSA-4r76-5xh9-qj36) on 2026-08-04, after BSI CERT-Bund and NCSC-NL had withdrawn their SQLite advisories. Recorded here so a scanner or triage lookup resolves to the retraction — do NOT open remediation work from this id. | 2026-08-04 | 2026-08-04 | — |
| CVE-2026-51296 | FABRICATED / NOT A REAL VULNERABILITY — one of the LLM-generated SQLite advisories published via the programmervuln/cveadvisory- GitHub repository. JFrog Security Research reproduction-tested it under AddressSanitizer against the claimed SQLite release and it did not reproduce; it cited lines 3555 and 3575 of src/json.c in a file that is 2706 lines long in the claimed version 3.41.0. NCSC-NL withdrew NCSC-2026-0268 on 2026-08-03 stating the CVE was hallucinated by an LLM, and BSI CERT-Bund withdrew WID-SEC-2026-2581 and WID-SEC-2026-2604 the same day. Recorded here so a scanner or triage lookup resolves to the retraction — do NOT open remediation work from this id. | 2026-08-04 | 2026-08-04 | — |
| CVE-2026-51297 | FABRICATED / NOT A REAL VULNERABILITY — one of the LLM-generated SQLite advisories published via the programmervuln/cveadvisory- GitHub repository. JFrog Security Research reproduction-tested it under AddressSanitizer against the claimed SQLite release and it did not reproduce; it referenced jsonBlobEdit(), a function absent from the claimed version 3.41.0. NCSC-NL withdrew NCSC-2026-0268 on 2026-08-03 stating the CVE was hallucinated by an LLM, and BSI CERT-Bund withdrew WID-SEC-2026-2581 and WID-SEC-2026-2604 the same day. Recorded here so a scanner or triage lookup resolves to the retraction — do NOT open remediation work from this id. | 2026-08-04 | 2026-08-04 | — |
| CVE-2026-51300 | FABRICATED / NOT A REAL VULNERABILITY — one of the LLM-generated SQLite advisories published via the programmervuln/cveadvisory- GitHub repository. JFrog Security Research reproduction-tested it under AddressSanitizer against the claimed SQLite release and it did not reproduce; the cited line numbers are a comment and a memory allocation, unrelated to the deletion logic it describes. NCSC-NL withdrew NCSC-2026-0268 on 2026-08-03 stating the CVE was hallucinated by an LLM, and BSI CERT-Bund withdrew WID-SEC-2026-2581 and WID-SEC-2026-2604 the same day. Recorded here so a scanner or triage lookup resolves to the retraction — do NOT open remediation work from this id. | 2026-08-04 | 2026-08-04 | — |
| CVE-2026-51302 | FABRICATED / NOT A REAL VULNERABILITY — one of the LLM-generated SQLite advisories published via the programmervuln/cveadvisory- GitHub repository. JFrog Security Research reproduction-tested it under AddressSanitizer against the claimed SQLite release and it did not reproduce; the named function exprComputeOperands() did not exist in SQLite 3.41 and sqlite3ReleaseTempReg() performs no heap deallocation, making the claimed bug class impossible; Red Hat initially scored it 10.0 before downgrading to 7.6. NCSC-NL withdrew NCSC-2026-0268 on 2026-08-03 stating the CVE was hallucinated by an LLM, and BSI CERT-Bund withdrew WID-SEC-2026-2581 and WID-SEC-2026-2604 the same day. Recorded here so a scanner or triage lookup resolves to the retraction — do NOT open remediation work from this id. | 2026-08-04 | 2026-08-04 | — |
| CVE-2026-51303 | FABRICATED / NOT A REAL VULNERABILITY — one of the LLM-generated SQLite advisories published via the programmervuln/cveadvisory- GitHub repository. JFrog Security Research reproduction-tested it under AddressSanitizer against the claimed SQLite release and it did not reproduce; it claimed a fix in 3.51.3 although a 3.51.2-to-3.51.3 diff shows no changes to src/expr.c at all. NCSC-NL withdrew NCSC-2026-0268 on 2026-08-03 stating the CVE was hallucinated by an LLM, and BSI CERT-Bund withdrew WID-SEC-2026-2581 and WID-SEC-2026-2604 the same day. Recorded here so a scanner or triage lookup resolves to the retraction — do NOT open remediation work from this id. | 2026-08-04 | 2026-08-04 | — |
| CVE-2026-51304 | FABRICATED / NOT A REAL VULNERABILITY — one of the LLM-generated SQLite advisories published via the programmervuln/cveadvisory- GitHub repository. JFrog Security Research reproduction-tested it under AddressSanitizer against the claimed SQLite release and it did not reproduce; it gave a single-argument signature for a function that requires a database-handle argument. NCSC-NL withdrew NCSC-2026-0268 on 2026-08-03 stating the CVE was hallucinated by an LLM, and BSI CERT-Bund withdrew WID-SEC-2026-2581 and WID-SEC-2026-2604 the same day. Recorded here so a scanner or triage lookup resolves to the retraction — do NOT open remediation work from this id. | 2026-08-04 | 2026-08-04 | — |
| CVE-2025-11371 | Gladinet CentreStack and Triofox — files or directories accessible to external parties; added to the CISA Known Exploited Vulnerabilities catalog 2025-11-04. Referenced as historical exploitation context by the 2026-08-03 CentreStack entry. | 2025-11-04 | 2026-08-03 | — |
| CVE-2025-14611 | Gladinet CentreStack and Triofox — hard-coded cryptographic key vulnerability; added to the CISA Known Exploited Vulnerabilities catalog 2025-12-15. Referenced as historical exploitation context by the 2026-08-03 CentreStack entry. | 2025-12-15 | 2026-08-03 | — |
| CVE-2025-30406 | Gladinet CentreStack — use of a hard-coded cryptographic key; added to the CISA Known Exploited Vulnerabilities catalog 2025-04-08. Referenced as historical exploitation context by the 2026-08-03 CentreStack entry. | 2025-04-08 | 2026-08-03 | — |
| CVE-2026-12185 | Bouncy Castle for Java (< 1.85) — BKS/UBER keystore allocates from untrusted lengths before integrity check (CVSS 7.1) | 2026-08-03 | 2026-08-03 | 2026-08-03 |
| CVE-2026-12802 | Bouncy Castle for Java (< 1.85) — CMS AuthEnvelopedData fails to enforce tag-length on decryption (CVSS 8.7) | 2026-08-03 | 2026-08-03 | 2026-08-03 |
| CVE-2026-12803 | Bouncy Castle for Java (< 1.85) — KCCMBlockCipher MAC does not bind nonce when AAD is absent (cross-nonce AEAD forgery) (CVSS 8.7) | 2026-08-03 | 2026-08-03 | 2026-08-03 |
| CVE-2026-12816 | Bouncy Castle for Java (< 1.85) — IESEngine stream-mode MAC forgery via length-dependent KDF split (CVSS 8.7) | 2026-08-03 | 2026-08-03 | 2026-08-03 |
| CVE-2026-12817 | Bouncy Castle for Java (< 1.85) — OpenPGP AEAD decryption skips final tag on chunk-aligned data (CVSS 8.7) | 2026-08-03 | 2026-08-03 | 2026-08-03 |
| CVE-2026-12852 | Bouncy Castle for Java (< 1.85) — MLS wire decoder allocates attacker-declared opaque length before bounds check (CVSS 8.7) | 2026-08-03 | 2026-08-03 | 2026-08-03 |
| CVE-2026-12860 | Bouncy Castle for Java (< 1.85) — RSA PKCS#1 verification skips last two hash bytes in NULL-omitted path (CVSS 8.7) | 2026-08-03 | 2026-08-03 | 2026-08-03 |
| CVE-2026-13506 | Bouncy Castle for Java (< 1.85) — Lazy ASN.1 sequence forcing resets nesting-depth guard (CVSS 8.7) | 2026-08-03 | 2026-08-03 | 2026-08-03 |
| CVE-2026-13586 | Bouncy Castle for Java (< 1.85) — PKCS#12 MAC and bag-decryption KDF iteration-count bound (DoS) (CVSS 5.3) | 2026-08-03 | 2026-08-03 | 2026-08-03 |
| CVE-2026-14682 | Bouncy Castle for Java (< 1.85) — Possible OOM from unbounded up-front allocation on a definite-length read (CVSS 8.7) | 2026-08-03 | 2026-08-03 | 2026-08-03 |
| CVE-2026-15055 | Bouncy Castle for Java (< 1.85) — PKCS#8 / PBES2 decryptors honour unbounded KDF cost from input (CVSS 5.3) | 2026-08-03 | 2026-08-03 | 2026-08-03 |
| CVE-2026-54363 | Gladinet CentreStack < 17.5 — hardcoded cryptographic key (static SysNumber) forges AccessTickets and x-glad-auth headers, reaching a domain-administrator IdentityTicket and unauthenticated RCE (CVSS 9.3) | 2026-08-03 | 2026-08-03 | 2026-08-03 |
| CVE-2026-54364 | Gladinet CentreStack < 17.4 — session-variable injection at SelectProvider.aspx bypasses the IsValidRSession check (CVSS 6.9) | 2026-08-03 | 2026-08-03 | 2026-08-03 |
| CVE-2026-54365 | Gladinet CentreStack < 17.3 — unauthenticated deserialization in GSNamespace.dll reaches NetUserAdd, creating arbitrary local OS accounts (CVSS 8.7) | 2026-08-03 | 2026-08-03 | 2026-08-03 |
| CVE-2026-54366 | Gladinet CentreStack < 17.4 — XXE at the unauthenticated SharePoint StorageConfig endpoint exfiltrates files including Web.config (CVSS 8.7) | 2026-08-03 | 2026-08-03 | 2026-08-03 |
| CVE-2026-54367 | Gladinet CentreStack < 17.2 — unauthenticated authorization bypass via forged EntAcctId values reaches any account's settings (CVSS 8.8) | 2026-08-03 | 2026-08-03 | 2026-08-03 |
| CVE-2026-54368 | Gladinet CentreStack < 17.4 — authenticated SQL injection via the x-glad-filter header writes files through PostgreSQL large-object functions (CVSS 8.7) | 2026-08-03 | 2026-08-03 | 2026-08-03 |
| CVE-2026-58059 | Bouncy Castle for Java (< 1.85) — Quadratic-time escaping when stringifying X.500 distinguished names (CVSS 8.7) | 2026-08-03 | 2026-08-03 | 2026-08-03 |
| CVE-2026-58060 | Bouncy Castle for Java (< 1.85) — HSS public-key level count unbounded, enabling huge allocation on verify (CVSS 8.7) | 2026-08-03 | 2026-08-03 | 2026-08-03 |
| CVE-2026-58061 | Bouncy Castle for Java (< 1.85) — CCM-family modes write plaintext to caller buffer before tag check (CVSS 8.7) | 2026-08-03 | 2026-08-03 | 2026-08-03 |
| CVE-2026-58062 | Bouncy Castle for Java (< 1.85) — Stapled OCSP response accepted without binding to the checked certificate (CVSS 9.3) | 2026-08-03 | 2026-08-03 | 2026-08-03 |
| CVE-2026-58063 | Bouncy Castle for Java (< 1.85) — BCFKS keystore load honours unbounded KDF cost from untrusted file (CVSS 5.3) | 2026-08-03 | 2026-08-03 | 2026-08-03 |
| CVE-2026-59638 | Bouncy Castle for Java (< 1.85) — JSSE hostname verifier CN-fallback enabled by default despite documented opt-in (CVSS 9.3) | 2026-08-03 | 2026-08-03 | 2026-08-03 |
| CVE-2026-59639 | Bouncy Castle for Java (< 1.85) — CMS verifySignatures returns true for SignedData with zero signers (CVSS 8.7) | 2026-08-03 | 2026-08-03 | 2026-08-03 |
| CVE-2026-59640 | Bouncy Castle for Java (< 1.85) — OpenPGP CFB quick-check oracle active on symmetric/session-key paths (CVSS 8.7) | 2026-08-03 | 2026-08-03 | 2026-08-03 |
| CVE-2026-59641 | Bouncy Castle for Java (< 1.85) — S/MIME validator trusts signer-asserted signingTime for path validation (CVSS 8.7) | 2026-08-03 | 2026-08-03 | 2026-08-03 |
| CVE-2026-59642 | Bouncy Castle for Java (< 1.85) — CMS AuthenticatedData content not bound to MAC when authAttrs present (CVSS 8.7) | 2026-08-03 | 2026-08-03 | 2026-08-03 |
| CVE-2026-59643 | Bouncy Castle for Java (< 1.85) — OpenPGP inline-signature policy failures silently ignored (CVSS 8.7) | 2026-08-03 | 2026-08-03 | 2026-08-03 |
| CVE-2026-59644 | Bouncy Castle for Java (< 1.85) — MLS hash-ratchet honours arbitrary 32-bit generation counter from sender (CVSS 8.7) | 2026-08-03 | 2026-08-03 | 2026-08-03 |
| CVE-2026-59645 | Bouncy Castle for Java (< 1.85) — OER parser recurses without depth limit on self-referential IEEE 1609.2 schema (CVSS 8.7) | 2026-08-03 | 2026-08-03 | 2026-08-03 |
| CVE-2026-59646 | Bouncy Castle for Java (< 1.85) — DTLS handshake reassembler allocates buffer from unchecked 24-bit length (CVSS 8.7) | 2026-08-03 | 2026-08-03 | 2026-08-03 |
| CVE-2026-59647 | Bouncy Castle for Java (< 1.85) — CRMF/CMP password-MAC honours unbounded iteration count (CVSS 6.9) | 2026-08-03 | 2026-08-03 | 2026-08-03 |
| CVE-2026-59648 | Bouncy Castle for Java (< 1.85) — OpenPGP Argon2 S2K honours attacker-chosen memory and passes (CVSS 6.9) | 2026-08-03 | 2026-08-03 | 2026-08-03 |
| CVE-2026-59649 | Bouncy Castle for Java (< 1.85) — OpenPGP user-attribute subpacket length bounded only by JVM max memory (CVSS 8.7) | 2026-08-03 | 2026-08-03 | 2026-08-03 |
| CVE-2026-59650 | Bouncy Castle for Java (< 1.85) — MTI/A0 DH agreement exponentiates unvalidated peer value (CVSS 9.3) | 2026-08-03 | 2026-08-03 | 2026-08-03 |
| CVE-2026-59651 | Bouncy Castle for Java (< 1.85) — BKS keystore accepts legacy version with 16-bit integrity MAC key (CVSS 7.1) | 2026-08-03 | 2026-08-03 | 2026-08-03 |
| CVE-2026-59652 | Bouncy Castle for Java (< 1.85) — LDAP filter injection in legacy jdk1.4 LDAPStoreHelper (CVSS 6.9) | 2026-08-03 | 2026-08-03 | 2026-08-03 |
| CVE-2026-8763 | Bouncy Castle for Java (< 1.85) — Name Constraints bypass via trailing dot in rfc822Name and URI (CVSS 9.3) | 2026-08-03 | 2026-08-03 | 2026-08-03 |
| CVE-2013-4786 | CVE-2013-4786 — 24,650 internet-exposed BMCs hand a crackable password hash to any unauthenticated caller, and Lava found ransom notes on live management interfaces | 2026-07-30 | 2026-08-02 | 2026-07-30 |
| CVE-2025-15467 | OpenSSL CMS AuthEnvelopedData parsing stack buffer overflow (CVSS 9.8 per Siemens ProductCERT; OpenSSL rates it High) — pre-auth, fires before AEAD tag verification; vendored in Siemens Desigo CC, where family V7 has no fix available, V8 is fixed by patch V8.0 QU2.0021 and V9 by 9.0.1; public command-execution PoC | 2026-07-29 | 2026-08-02 | 2026-07-29 |
| CVE-2025-68686 | FortiOS SSL-VPN symlink-persistence patch bypass (exploited, KEV) | 2026-07-28 | 2026-08-02 | 2026-07-28 |
| CVE-2026-0769 | Langflow eval_custom_component_code eval injection (CVSS 9.8, CWE-95) — unauthenticated RCE, published by ZDI as a 0-day advisory with no fixed version documented anywhere and "restrict interaction with the product" as the only stated mitigation; VulnCheck reports observed exploitation for credential harvesting, cryptomining and lateral movement; NOT in CISA KEV (distinct from the KEV-listed CVE-2026-0770) | 2026-07-29 | 2026-08-02 | 2026-07-29 |
| CVE-2026-12569 | PTC Windchill / FlexPLM — pre-auth deserialization RCE, CISA KEV-listed, now driving a Cl0p-attributed mass data-theft extortion campaign | 2026-06-20 | 2026-08-02 | 2026-07-27 +4 more |
| CVE-2026-14446 | IBM WebSphere Application Server traditional — missing authentication for critical function in the administrative console (CWE-306), CVSS 9.8; interim fix APAR DT496500, Fix Pack targeted 3Q2026 | 2026-08-01 | 2026-08-02 | 2026-08-01 |
| CVE-2026-14512 | IBM WebSphere Application Server traditional — pre-authentication unsafe deserialization (CWE-502), CVSS 9.8; interim fix APAR PH72166, Fix Pack targeted 3Q2026 | 2026-08-01 | 2026-08-02 | 2026-08-01 |
| CVE-2026-16232 | Check Point SmartConsole authentication bypass to full admin (exploited) | 2026-07-23 | 2026-08-02 | 2026-07-29 +1 more |
| CVE-2026-16723 | Alibaba fastjson 1.2.68–1.2.83 — remote code execution under stock defaults in Spring Boot fat-JAR deployments; no patched 1.x release, exploited in the wild | 2026-07-27 | 2026-08-02 | 2026-07-27 |
| CVE-2026-16812 | Arista VeloCloud Orchestrator on-prem unauthenticated OS command injection (exploited, KEV) | 2026-07-28 | 2026-08-02 | 2026-07-28 |
| CVE-2026-20316 | CVE-2026-20316 — Cisco Secure Firewall Management Center ships a static low-privilege account in its web interface, and Cisco confirms exploitation has been ongoing | 2026-07-30 | 2026-08-02 | 2026-07-30 |
| CVE-2026-28323 | SolarWinds Web Help Desk — unauthenticated SAML 2.0 authentication bypass, CVSS 9.8; fixed in 2026.2.1 | 2026-08-01 | 2026-08-02 | 2026-08-01 |
| CVE-2026-3055 | Citrix NetScaler ADC/Gateway out-of-bounds memory read when configured as a SAML Identity Provider (CWE-125, CVSS 9.8) — CISA KEV-listed and exploited by multiple unrelated clusters, including manual exfiltration of appliance memory searched for session cookies (Unit 42, 2026-07-30); fixed in 13.1-62.24 / 14.1-66.60 / 13.1-FIPS-NDcPP 13.1-37.263 | 2026-07-01 | 2026-08-02 | 2026-07-31 |
| CVE-2026-33824 | Windows IKE Extensions (IKE VPN) — Unit 42 records reverse-shell callbacks from three endpoints in the autonomous-AI intrusion campaign | 2026-08-02 | 2026-08-02 | — |
| CVE-2026-39987 | marimo notebook — pre-auth RCE via the unauthenticated /terminal/ws endpoint (CWE-306), CVSS 4.0 9.3, fixed in 0.23.0, CISA KEV-listed; Unit 42 records command execution confirmed on 11 endpoints during the 2026-07 autonomous-agent campaign | 2026-05-30 | 2026-08-02 | 2026-08-02 |
| CVE-2026-42897 | Microsoft Exchange Server Outlook Web Access stored XSS (CWE-79, CVSS 3.1 8.1, Microsoft CNA) — exploited in the wild by TA488/LAUNDRY BEAR to deliver the OWAReaper browser implant; CISA KEV 2026-05-15; permanent fix is the July 2026 Exchange SU (SE RTM; 2019 CU14/CU15 and 2016 CU23 via ESU Period 2), which does not remove earlier mitigations | 2026-05-11 | 2026-08-02 | 2026-07-31 +4 more |
| CVE-2026-44090 | Phoenix Contact CHARX SEC-3xxx — MQTT broker reachable without authentication, protected from external access only by the device firewall (CWE-306); CVSS 3.1 9.8 | 2026-08-02 | 2026-08-02 | 2026-08-02 |
| CVE-2026-44101 | Phoenix Contact CHARX SEC-3xxx — missing authentication on the CHARX OCPP Agent lets a remote attacker reconfigure the backend connection (CWE-306); CVSS 3.1 9.8 | 2026-08-02 | 2026-08-02 | 2026-08-02 |
| CVE-2026-44104 | Phoenix Contact CHARX SEC-3xxx — basemodule firmware update validates only a CRC32 checksum with no cryptographic signature verification (CWE-347), allowing unauthenticated installation of modified firmware; CVSS 3.1 9.8 | 2026-08-02 | 2026-08-02 | 2026-08-02 |
| CVE-2026-44108 | Phoenix Contact CHARX SEC-3xxx — firewall terminates prematurely during shutdown because of script execution order (CWE-696), exposing internal services in the window; CVSS 3.1 9.8 | 2026-08-02 | 2026-08-02 | 2026-08-02 |
| CVE-2026-48448 | Adobe Campaign Classic — unauthenticated SQL injection giving arbitrary file-system read; CVSS 3.1 8.6, fixed in ACC v7 7.4.3 build 9398 (APSB26-114) | 2026-08-02 | 2026-08-02 | 2026-08-02 |
| CVE-2026-48449 | Adobe Campaign Classic — Incorrect Authorization (CWE-863) giving unauthenticated arbitrary code execution; CVSS 3.1 10.0, on-premise and hybrid on-premise components only, fixed in ACC v7 7.4.3 build 9398 (APSB26-114) | 2026-08-02 | 2026-08-02 | 2026-08-02 |
| CVE-2026-59243 | Apache Airflow FAB provider — Azure AD OAuth login decoded ID tokens with verify_signature defaulted to False, allowing login as any user incl. Admin; no CVSS published by any party; fixed in apache-airflow-providers-fab 3.7.3 | 2026-07-29 | 2026-08-02 | 2026-07-29 |
| CVE-2026-59726 | CVE-2026-59726 (RufRoot) — Ruflo's MCP bridge took unauthenticated tool calls on all interfaces, and the memory it poisons is not cleaned up by the patch (CVSS 10.0) | 2026-07-30 | 2026-08-02 | 2026-07-30 |
| CVE-2026-61511 | vBulletin {vb:math} runMaths eval injection, unauthenticated RCE (public exploit) | 2026-07-28 | 2026-08-02 | 2026-07-28 |
| CVE-2026-65766 | JoomShaper SP Page Builder for Joomla — pre-authentication SQL injection in the Dynamic Content endpoint's ORDER BY clause, guarded only by a CSRF token Joomla issues to anonymous visitors; Joomla CNA CVSS 4.0 9.2 (discloser self-scored 8.7), fixed in 6.7.1 | 2026-08-02 | 2026-08-02 | 2026-08-02 |
| CVE-2026-65876 | JoomShaper SP Page Builder for Joomla — unauthenticated SQL injection through the catid parameter of the loadMoreArticles endpoint; Joomla CNA CVSS 4.0 9.2, fixed in 6.7.1. Not among the four flaws mySites.guru reported and not tested by it | 2026-08-02 | 2026-08-02 | 2026-08-02 |
| CVE-2026-65877 | JoomShaper SP Page Builder for Joomla — authenticated SQL injection in the media manager's search and date filters, reachable by a low-privilege author; Joomla CNA CVSS 4.0 8.2, fixed in 6.7.1 | 2026-08-02 | 2026-08-02 | 2026-08-02 |
| CVE-2026-65878 | JoomShaper SP Page Builder for Joomla — authenticated arbitrary file delete via an unguarded request-supplied path in the media-delete action; Joomla CNA CVSS 4.0 8.3, fixed in 6.7.1 | 2026-08-02 | 2026-08-02 | 2026-08-02 |
| CVE-2026-65879 | JoomShaper SP Page Builder for Joomla — unauthenticated mail relay via a shared secret hardcoded identically into every shipped copy (CWE-798); the Joomla CNA assigned no metrics, so the 9.8 is a CISA-ADP CVSS 3.1 score and is not on the CVSS 4.0 scale its siblings use. Fixed in 6.7.1 | 2026-08-02 | 2026-08-02 | 2026-08-02 |
| CVE-2026-65883 | Aimy Captcha-Less Form Guard (Joomla plugin) — unauthenticated PHP object injection to RCE, CVSS 9.8; fixed in 20.1 | 2026-08-01 | 2026-08-02 | 2026-08-01 |
| CVE-2026-65884 | Balbooa Gridbox for Joomla — registration handler adds caller-supplied usergroup IDs, letting an unauthenticated visitor register an account directly into an administrator group; CVSS 4.0 10.0 (CWE-284, Joomla CNA), exploit maturity Attacked; affected 1.0.0-2.20.1, fixed 2.20.2 | 2026-07-31 | 2026-08-02 | 2026-07-31 |
| CVE-2026-65885 | Balbooa Gridbox for Joomla — authenticated arbitrary file upload; becomes unauthenticated RCE chained with CVE-2026-65884 because the attacker can create the required account; CVSS 4.0 9.4 (CWE-434, Joomla CNA), exploit maturity Attacked; affected 1.0.0-2.20.1, fixed 2.20.2 | 2026-07-31 | 2026-08-02 | 2026-07-31 |
| CVE-2026-66066 | Ruby on Rails Active Storage variant processing on libvips — unauthenticated arbitrary file read (and possible RCE via exposed application secrets) from an untrusted image upload; CVSS 4.0 9.5 assigned by GitHub Security Advisories as the Rails CNA; fixed in activestorage 7.2.3.2 / 8.0.5.1 / 8.1.3.1 and requires libvips >= 8.13 to be effective | 2026-07-31 | 2026-08-02 | 2026-08-02 +1 more |
| CVE-2026-7849 | Phoenix Contact CHARX SEC-3xxx EV charging controllers — unauthenticated command injection into the system configuration executed as root (CWE-77); CVSS 3.1 9.8, firmware below 1.9.1, fix unreleased at disclosure (CERT@VDE VDE-2026-008) | 2026-08-02 | 2026-08-02 | 2026-08-02 |
| CVE-2026-14528 | IBM WebSphere Application Server traditional — sensitive information written to log files (CWE-532), CVSS 7.4 | 2026-08-01 | 2026-08-01 | 2026-08-01 |
| CVE-2026-28299 | SolarWinds Web Help Desk — denial of service, server crash due to insufficient memory; 8.2 High per the vendor's 2026.2.1 release-notes CVE table; fixed in 2026.2.1 | 2026-08-01 | 2026-08-01 | 2026-08-01 |
| CVE-2026-14869 | HCSEC-2026-23 — HashiCorp Terraform MCP Server leaks its own bearer token to an attacker-supplied address, and its credential cache crosses sessions and tenants (CVE-2026-14869, CVE-2026-16496, CVE-2026-16498) | 2026-07-30 | 2026-07-30 | 2026-07-30 |
| CVE-2026-16496 | HCSEC-2026-23 — HashiCorp Terraform MCP Server leaks its own bearer token to an attacker-supplied address, and its credential cache crosses sessions and tenants (CVE-2026-14869, CVE-2026-16496, CVE-2026-16498) | 2026-07-30 | 2026-07-30 | 2026-07-30 |
| CVE-2026-16498 | HCSEC-2026-23 — HashiCorp Terraform MCP Server leaks its own bearer token to an attacker-supplied address, and its credential cache crosses sessions and tenants (CVE-2026-14869, CVE-2026-16496, CVE-2026-16498) | 2026-07-30 | 2026-07-30 | 2026-07-30 |
| CVE-2026-41703 | VMSA-2026-0006 — VMware vCenter: unauthenticated Directory Service auth bypass and Syslog traversal RCE (both CVSS 9.8), plus a VMXNET3 guest-to-host escape | 2026-07-30 | 2026-07-30 | 2026-07-30 |
| CVE-2026-41709 | VMSA-2026-0006 — VMware vCenter: unauthenticated Directory Service auth bypass and Syslog traversal RCE (both CVSS 9.8), plus a VMXNET3 guest-to-host escape | 2026-07-30 | 2026-07-30 | 2026-07-30 |
| CVE-2026-47876 | VMSA-2026-0006 — VMware vCenter: unauthenticated Directory Service auth bypass and Syslog traversal RCE (both CVSS 9.8), plus a VMXNET3 guest-to-host escape | 2026-07-30 | 2026-07-30 | 2026-07-30 |
| CVE-2026-59309 | VMSA-2026-0006 — VMware vCenter: unauthenticated Directory Service auth bypass and Syslog traversal RCE (both CVSS 9.8), plus a VMXNET3 guest-to-host escape | 2026-07-30 | 2026-07-30 | 2026-07-30 |
| CVE-2026-59310 | VMSA-2026-0006 — VMware vCenter: unauthenticated Directory Service auth bypass and Syslog traversal RCE (both CVSS 9.8), plus a VMXNET3 guest-to-host escape | 2026-07-30 | 2026-07-30 | 2026-07-30 |
| CVE-2026-65617 | Hugging Face intrusion update — the sandbox escape was a chain of previously unknown JFrog Artifactory flaws, now patched, and the models also used publicly exposed credentials on four third-party services | 2026-07-30 | 2026-07-30 | 2026-07-30 |
| CVE-2026-65921 | Hugging Face intrusion update — the sandbox escape was a chain of previously unknown JFrog Artifactory flaws, now patched, and the models also used publicly exposed credentials on four third-party services | 2026-07-30 | 2026-07-30 | 2026-07-30 |
| CVE-2026-65922 | Hugging Face intrusion update — the sandbox escape was a chain of previously unknown JFrog Artifactory flaws, now patched, and the models also used publicly exposed credentials on four third-party services | 2026-07-30 | 2026-07-30 | 2026-07-30 |
| CVE-2026-65923 | Hugging Face intrusion update — the sandbox escape was a chain of previously unknown JFrog Artifactory flaws, now patched, and the models also used publicly exposed credentials on four third-party services | 2026-07-30 | 2026-07-30 | 2026-07-30 |
| CVE-2026-65924 | Hugging Face intrusion update — the sandbox escape was a chain of previously unknown JFrog Artifactory flaws, now patched, and the models also used publicly exposed credentials on four third-party services | 2026-07-30 | 2026-07-30 | 2026-07-30 |
| CVE-2026-65925 | Hugging Face intrusion update — the sandbox escape was a chain of previously unknown JFrog Artifactory flaws, now patched, and the models also used publicly exposed credentials on four third-party services | 2026-07-30 | 2026-07-30 | 2026-07-30 |
| CVE-2026-66014 | Hugging Face intrusion update — the sandbox escape was a chain of previously unknown JFrog Artifactory flaws, now patched, and the models also used publicly exposed credentials on four third-party services | 2026-07-30 | 2026-07-30 | 2026-07-30 |
| CVE-2026-66015 | Hugging Face intrusion update — the sandbox escape was a chain of previously unknown JFrog Artifactory flaws, now patched, and the models also used publicly exposed credentials on four third-party services | 2026-07-30 | 2026-07-30 | 2026-07-30 |
| CVE-2026-66018 | Hugging Face intrusion update — the sandbox escape was a chain of previously unknown JFrog Artifactory flaws, now patched, and the models also used publicly exposed credentials on four third-party services | 2026-07-30 | 2026-07-30 | 2026-07-30 |
| CVE-2026-7891 | Siemens Mendix Runtime (all versions, CVSS 9.1) — platform-enforced access rules on the System.User entity cannot be overridden by access rules on a specialization, so the anonymous role commonly reaches all stored user records; no code fix, mitigation is App Security role-management reconfiguration | 2026-07-29 | 2026-07-29 | 2026-07-29 |
| CVE-2025-33053 | Windows shortcut working-directory resolution flaw abused for remote WebDAV execution | 2026-07-26 | 2026-07-26 | 2026-07-26 |
| CVE-2026-0770 | CVE-2026-0770 — Langflow: unauthenticated exec_globals RCE (actively exploited, CISA KEV 2026-07-21) | 2026-07-22 | 2026-07-26 | 2026-07-22 |
| CVE-2026-14499 | IBM Langflow OSS Python Interpreter authenticated command injection (CVSS 8.8) — fixed in 1.10.2, not 1.10.1 | 2026-07-26 | 2026-07-26 | 2026-07-26 |
| CVE-2026-47056 | Oracle Data Integrator REST Service — unauthenticated takeover (CVSS 10.0, July 2026 CPU) | 2026-07-26 | 2026-07-26 | 2026-07-26 |
| CVE-2026-60137 | WordPress core WP_Query author__not_in SQL injection (WP2Shell chain component) | 2026-07-18 | 2026-07-26 | 2026-07-26 +1 more |
| CVE-2026-60217 | Oracle Coherence Core — unauthenticated takeover over TCP (CVSS 10.0, July 2026 CPU) | 2026-07-26 | 2026-07-26 | 2026-07-26 |
| CVE-2026-60365 | Oracle Fusion Middleware CVSS 10.0 unauthenticated flaw — listed twice in Oracle's July 2026 risk matrix (Oracle HTTP Server and WebLogic Server Proxy Plug-in), which is why the ten-row / nine-CVE counts diverge | 2026-07-26 | 2026-07-26 | — |
| CVE-2026-61211 | Oracle Database Server — DBMS_CLOUD privilege abuse to full server control (CVSS 9.9) | 2026-07-26 | 2026-07-26 | 2026-07-26 |
| CVE-2026-61425 | Balbooa Gridbox for Joomla — unauthenticated cookie-forgery authentication bypass to Super User | 2026-07-26 | 2026-07-26 | 2026-07-26 |
| CVE-2026-62415 | Membership Pro for Joomla — unauthenticated file upload (CVSS 9.1, Joomla CNA); fixed in 4.6.2 | 2026-07-26 | 2026-07-26 | 2026-07-26 |
| CVE-2026-63030 | WP2Shell: WordPress core REST batch route confusion to pre-auth RCE chain | 2026-07-18 | 2026-07-26 | 2026-07-26 +1 more |
| CVE-2026-63047 | Events Booking for Joomla — unauthenticated invoice IDOR exposing personal and financial data | 2026-07-26 | 2026-07-26 | 2026-07-26 |
| CVE-2026-65759 | JoomShaper EasyStore for Joomla — unauthenticated order/payment forgery on the repayment endpoint (CVSS 4.0 8.7, Joomla CNA) | 2026-07-26 | 2026-07-26 | 2026-07-26 |
| CVE-2026-65760 | JoomShaper EasyStore for Joomla — cross-customer order/invoice IDOR reachable by any logged-in customer (CVSS 4.0 9.2, Joomla CNA) | 2026-07-26 | 2026-07-26 | 2026-07-26 |
| CVE-2026-65761 | JoomShaper EasyStore for Joomla — unauthenticated SQL injection, full site-database read (CVSS 4.0 9.3, Joomla CNA) | 2026-07-26 | 2026-07-26 | 2026-07-26 |
| CVE-2023-43770 | Roundcube webmail persistent XSS (n-day exploited by TA458/Operation RoundPress) | 2026-07-25 | 2026-07-25 | — |
| CVE-2025-27915 | Zimbra Collaboration half-click webmail flaw (TA458/Operation RoundPress) | 2026-07-25 | 2026-07-25 | — |
| CVE-2025-3929 | mDaemon webmail half-click flaw (TA458/Operation RoundPress) | 2026-07-25 | 2026-07-25 | — |
| CVE-2026-54121 | Certighost — Windows Server AD CS elevation of privilege (DC impersonation to DCSync) | 2026-07-25 | 2026-07-25 | 2026-07-25 |
| CVE-2026-62144 | Check Point Security Management / MDS unauthenticated command execution | 2026-07-25 | 2026-07-25 | 2026-07-25 |
| CVE-2026-62145 | Check Point Gaia Portal read-only to root command execution | 2026-07-25 | 2026-07-25 | 2026-07-25 |
| CVE-2026-8496 | SOGo webmail half-click XSS zero-day (Operation RoundPress / TA458) | 2026-07-25 | 2026-07-25 | 2026-07-25 |
| CVE-2025-66376 | Zimbra Collaboration Suite Classic Web Client stored XSS (view-based/zero-click) exploited by Russian actor LAUNDRY BEAR; CVSS 7.2 (MITRE)/6.1 (NVD); CISA KEV; patched ZCS 10.0.18/10.1.13 | 2026-07-24 | 2026-07-24 | 2026-07-24 |
| CVE-2026-16002 | MZ Automation lib60870 out-of-bounds read parser-crash DoS (IEC 60870-5-104); lib60870 <= 2.4.0 (CVSS 3.1 8.2 / 4.0 8.8) | 2026-07-24 | 2026-07-24 | 2026-07-24 |
| CVE-2026-49035 | MZ Automation libIEC61850 unauthenticated heap-overflow RCE via crafted MMS Initiate request (CVSS 3.1 8.1 / 4.0 9.2); libIEC61850 1.0.0-1.6.1 | 2026-07-24 | 2026-07-24 | 2026-07-24 |
| CVE-2026-50032 | MZ Automation libIEC61850 NULL-pointer dereference DoS in MMS Write Named Variable List handler (CVSS 3.1 7.5 / 4.0 8.7) | 2026-07-24 | 2026-07-24 | 2026-07-24 |
| CVE-2026-50039 | MZ Automation libIEC61850 stack-based buffer overflow via crafted ReadRequest (CVSS 3.1 7.5 / 4.0 8.7) | 2026-07-24 | 2026-07-24 | 2026-07-24 |
| CVE-2026-50103 | MZ Automation libIEC61850 NULL-pointer dereference DoS in L2 GOOSE/R-GOOSE parser via malformed TLV (CVSS 3.1 6.5 / 4.0 7.1) | 2026-07-24 | 2026-07-24 | 2026-07-24 |
| CVE-2026-28302 | SolarWinds Serv-U 2026.3 IDOR/broken-access-control (priv-esc to root RCE) | 2026-07-23 | 2026-07-23 | 2026-07-23 |
| CVE-2026-28304 | SolarWinds Serv-U 2026.3 IDOR/broken-access-control (priv-esc to root RCE) | 2026-07-23 | 2026-07-23 | 2026-07-23 |
| CVE-2026-28305 | SolarWinds Serv-U 2026.3 IDOR/broken-access-control (priv-esc to root RCE) | 2026-07-23 | 2026-07-23 | 2026-07-23 |
| CVE-2026-28306 | SolarWinds Serv-U 2026.3 IDOR/broken-access-control (priv-esc to root RCE) | 2026-07-23 | 2026-07-23 | 2026-07-23 |
| CVE-2026-28307 | SolarWinds Serv-U 2026.3 IDOR/broken-access-control (priv-esc to root RCE) | 2026-07-23 | 2026-07-23 | 2026-07-23 |
| CVE-2026-28308 | SolarWinds Serv-U 2026.3 IDOR/broken-access-control (priv-esc to root RCE) | 2026-07-23 | 2026-07-23 | 2026-07-23 |
| CVE-2026-28309 | SolarWinds Serv-U 2026.3 IDOR/broken-access-control (priv-esc to root RCE) | 2026-07-23 | 2026-07-23 | 2026-07-23 |
| CVE-2026-28310 | SolarWinds Serv-U 2026.3 IDOR/broken-access-control (priv-esc to root RCE) | 2026-07-23 | 2026-07-23 | 2026-07-23 |
| CVE-2026-28311 | SolarWinds Serv-U 2026.3 IDOR/broken-access-control (priv-esc to root RCE) | 2026-07-23 | 2026-07-23 | 2026-07-23 |
| CVE-2026-28312 | SolarWinds Serv-U 2026.3 IDOR/broken-access-control (priv-esc to root RCE) | 2026-07-23 | 2026-07-23 | 2026-07-23 |
| CVE-2026-28313 | SolarWinds Serv-U 2026.3 IDOR/broken-access-control (priv-esc to root RCE) | 2026-07-23 | 2026-07-23 | 2026-07-23 |
| CVE-2026-28314 | SolarWinds Serv-U 2026.3 IDOR/broken-access-control (priv-esc to root RCE) | 2026-07-23 | 2026-07-23 | 2026-07-23 |
| CVE-2026-28315 | SolarWinds Serv-U 2026.3 IDOR/broken-access-control (priv-esc to root RCE) | 2026-07-23 | 2026-07-23 | 2026-07-23 |
| CVE-2026-28316 | SolarWinds Serv-U 2026.3 IDOR/broken-access-control (priv-esc to root RCE) | 2026-07-23 | 2026-07-23 | 2026-07-23 |
| CVE-2026-28317 | SolarWinds Serv-U 2026.3 IDOR/broken-access-control (priv-esc to root RCE) | 2026-07-23 | 2026-07-23 | 2026-07-23 |
| CVE-2026-28321 | SolarWinds Serv-U 2026.3 IDOR/broken-access-control (priv-esc to root RCE) | 2026-07-23 | 2026-07-23 | 2026-07-23 |
| CVE-2026-47678 | GLPI 11.0.8/10.0.26 security release (critical RCE via form import; MFA bypass) | 2026-07-23 | 2026-07-23 | 2026-07-23 |
| CVE-2026-47679 | GLPI 11.0.8/10.0.26 security release (critical RCE via form import; MFA bypass) | 2026-07-23 | 2026-07-23 | 2026-07-23 |
| CVE-2026-48482 | GLPI 11.0.8/10.0.26 security release (critical RCE via form import; MFA bypass) | 2026-07-23 | 2026-07-23 | 2026-07-23 |
| CVE-2026-49470 | GLPI 11.0.8/10.0.26 security release (critical RCE via form import; MFA bypass) | 2026-07-23 | 2026-07-23 | 2026-07-23 |
| CVE-2026-52848 | GLPI 11.0.8/10.0.26 security release (critical RCE via form import; MFA bypass) | 2026-07-23 | 2026-07-23 | 2026-07-23 |
| CVE-2026-53610 | GLPI 11.0.8/10.0.26 security release (critical RCE via form import; MFA bypass) | 2026-07-23 | 2026-07-23 | 2026-07-23 |
| CVE-2026-53625 | GLPI 11.0.8/10.0.26 security release (critical RCE via form import; MFA bypass) | 2026-07-23 | 2026-07-23 | 2026-07-23 |
| CVE-2026-53626 | GLPI 11.0.8/10.0.26 security release (critical RCE via form import; MFA bypass) | 2026-07-23 | 2026-07-23 | 2026-07-23 |
| CVE-2026-53629 | GLPI 11.0.8/10.0.26 security release (critical RCE via form import; MFA bypass) | 2026-07-23 | 2026-07-23 | 2026-07-23 |
| CVE-2026-55214 | GLPI 11.0.8/10.0.26 security release (critical RCE via form import; MFA bypass) | 2026-07-23 | 2026-07-23 | 2026-07-23 |
| CVE-2026-10631 | CVE-2026-10631 — Zimbra: EWS extension access-control issue (fixed 10.1.20; RESERVED on NVD) | 2026-07-22 | 2026-07-22 | 2026-07-22 |
| CVE-2026-50054 | CVE-2026-50054 — Zimbra: mailbox delegation authorization flaw (fixed 10.1.20; RESERVED on NVD) | 2026-07-22 | 2026-07-22 | 2026-07-22 |
| CVE-2026-50055 | CVE-2026-50055 — Zimbra: mail-forwarding restriction bypass (fixed 10.1.20; RESERVED on NVD) | 2026-07-22 | 2026-07-22 | 2026-07-22 |
| CVE-2026-50522 | CVE-2026-50522 — Microsoft SharePoint Server: Site-Owner deserialization RCE (CVSS 9.8) | 2026-07-15 | 2026-07-22 | 2026-07-22 +1 more |
| CVE-2026-7754 | CVE-2026-7754 — Langflow OSS: SSRF from insecure default configuration (fixed 1.10.1) | 2026-07-22 | 2026-07-22 | — |
| CVE-2026-7755 | CVE-2026-7755 — Langflow OSS: RCE via insufficient validation of MCP server config files (fixed 1.10.1) | 2026-07-22 | 2026-07-22 | — |
| CVE-2026-8476 | CVE-2026-8476 — Langflow OSS: unsafe deserialization in AsyncDiskCache via apply_tweaks() (fixed 1.10.1) | 2026-07-22 | 2026-07-22 | — |
| CVE-2026-8859 | CVE-2026-8859 — Langflow OSS: path-traversal arbitrary file write (fixed 1.10.1) | 2026-07-22 | 2026-07-22 | 2026-07-22 |
| CVE-2026-9135 | CVE-2026-9135 — Langflow OSS: code injection in Policies/ToolGuard component (fixed 1.10.1) | 2026-07-22 | 2026-07-22 | 2026-07-22 |
| CVE-2026-9202 | CVE-2026-9202 — Langflow OSS: unauthenticated account creation reaching RCE (fixed 1.10.1) | 2026-07-22 | 2026-07-22 | 2026-07-22 |
| CVE-2026-2291 | dnsmasq really_insert() DNS-cache heap buffer overflow (RCE per Exodus; NVD frames as DoS/cache-poisoning) | 2026-07-21 | 2026-07-21 | 2026-07-21 |
| CVE-2026-6875 | ServiceNow AI Platform sandbox escape — unauthenticated code execution within the platform (CVSS 9.5); hosted fixed server-side, self-hosted/partner patch listed family releases | 2026-07-13 | 2026-07-21 | 2026-07-21 +1 more |
| CVE-2026-42533 | nginx / NGINX Plus PCRE capture-clobber pre-auth heap overflow (CVSS 9.2); F5 out-of-band patch 2026-07-15/16, credited researcher demonstrates RCE beyond F5's DoS-only framing (no public PoC, no ITW as of 2026-07-20); fixed nginx 1.30.4/1.31.3, NGINX Plus R36 P7/37.0.3.1 | 2026-07-20 | 2026-07-20 | 2026-07-20 |
| CVE-2025-40947 | Siemens RUGGEDCOM ROX II feature-key gpgv command injection to root (CVSS 7.5); Unit 42 chain | 2026-07-18 | 2026-07-18 | 2026-07-18 |
| CVE-2025-40948 | Siemens RUGGEDCOM ROX II arbitrary file disclosure via root-privileged xz misuse (CVSS 6.8); Unit 42 chain | 2026-07-18 | 2026-07-18 | 2026-07-18 |
| CVE-2025-40949 | Siemens RUGGEDCOM ROX II task-scheduler command injection, persistent root (CVSS 9.1); Siemens SSA-081142 | 2026-07-18 | 2026-07-18 | 2026-07-18 |
| CVE-2026-47865 | VMware Avi Load Balancer control-plane unauthenticated authentication bypass (CVSS 9.8), VMSA-2026-0005 | 2026-07-18 | 2026-07-18 | 2026-07-18 |
| CVE-2026-47866 | VMware Avi Load Balancer authorization bypass (CVSS 8.3), VMSA-2026-0005 | 2026-07-18 | 2026-07-18 | 2026-07-18 |
| CVE-2026-47867 | VMware Avi Load Balancer high-privilege RCE (CVSS 8.7), VMSA-2026-0005 | 2026-07-18 | 2026-07-18 | 2026-07-18 |
| CVE-2026-47868 | VMware Avi Load Balancer local privilege escalation to root (CVSS 7.8), VMSA-2026-0005 | 2026-07-18 | 2026-07-18 | 2026-07-18 |
| CVE-2026-47869 | VMware Avi Load Balancer authenticated RCE (CVSS 8.7), VMSA-2026-0005 | 2026-07-18 | 2026-07-18 | 2026-07-18 |
| CVE-2026-47870 | VMware Avi Load Balancer privilege escalation (CVSS 7.1), VMSA-2026-0005 | 2026-07-18 | 2026-07-18 | 2026-07-18 |
| CVE-2026-47871 | VMware Avi Load Balancer authenticated directory traversal (CVSS 8.8), VMSA-2026-0005 | 2026-07-18 | 2026-07-18 | 2026-07-18 |
| CVE-2026-54733 | Moodle local_o365 plugin JWT-signature-not-verified SSO auth bypass | 2026-07-18 | 2026-07-18 | 2026-07-18 |
| CVE-2026-15718 | Mozilla Firefox WebAssembly engine invalid-pointer memory-safety flaw (public exploit code, no confirmed ITW); fixed 152.0.6 | 2026-07-17 | 2026-07-17 | 2026-07-17 |
| CVE-2026-15719 | Mozilla Firefox DOM Navigation site-isolation bypass (public exploit code, no confirmed ITW); fixed 152.0.6 | 2026-07-17 | 2026-07-17 | 2026-07-17 |
| CVE-2026-32201 | Microsoft SharePoint Server on-prem RCE — part of the actively-exploited SharePoint cluster (CISA KEV 2026-04-14), referenced as context in the CVE-2026-58644 exploitation update | 2026-07-17 | 2026-07-17 | — |
| CVE-2026-58644 | CVE-2026-58644 — Microsoft SharePoint Server deserialization RCE (CVSS 9.8); confirmed exploited + CISA KEV 2026-07-16 | 2026-07-15 | 2026-07-17 | 2026-07-17 +1 more |
| CVE-2023-4346 | KNX Connection Authorization Option 1 overly-restrictive account-lockout DoS (CVSS 7.5, CWE-645); CISA KEV 2026-07-15, no software patch (procedural mitigation) | 2026-07-16 | 2026-07-16 | 2026-07-16 |
| CVE-2026-46817 | Oracle E-Business Suite / Oracle Payments File Transmission unauthenticated RCE/takeover (CVSS 9.8); CISA KEV 2026-07-15, exploited ITW since 2026-06-27; fixed Oracle May 2026 CPU (12.2.3-12.2.15) | 2026-06-01 | 2026-07-16 | 2026-07-16 +1 more |
| CVE-2025-13162 | CVE-2025-13162 — ABB 800xA for Advant Master / Control Builder A: DLL search-path element (CVSS 4.4) | 2026-07-15 | 2026-07-15 | — |
| CVE-2025-14771 | CVE-2025-14771 — ABB T-MAC Plus: authenticated file disclosure (CVSS 9.9) | 2026-07-15 | 2026-07-15 | 2026-07-15 |
| CVE-2025-14772 | CVE-2025-14772 — ABB T-MAC Plus: broken access control / authz bypass (CVSS 8.8) | 2026-07-15 | 2026-07-15 | 2026-07-15 |
| CVE-2025-14773 | CVE-2025-14773 — ABB T-MAC Plus: stored XSS (CVSS 8.0) | 2026-07-15 | 2026-07-15 | 2026-07-15 |
| CVE-2025-14774 | CVE-2025-14774 — ABB T-MAC Plus: Card Reader service DoS (CVSS 7.4) | 2026-07-15 | 2026-07-15 | 2026-07-15 |
| CVE-2026-10577 | CVE-2026-10577 — Rockwell 1715-AENTR EtherNet/IP Adapter: unauthenticated debug-port takeover (CVSS 10.0) | 2026-07-15 | 2026-07-15 | 2026-07-15 |
| CVE-2026-55040 | CVE-2026-55040 — Microsoft SharePoint Server: JWT authentication bypass, Pwn2Own chain (CVSS 9.1) | 2026-07-15 | 2026-07-15 | 2026-07-15 |
| CVE-2026-55944 | CVE-2026-55944 — Microsoft Dynamics NAV / Dynamics 365 Business Central (On-Prem): pre-auth deserialization RCE (CVSS 9.8) | 2026-07-15 | 2026-07-15 | 2026-07-15 |
| CVE-2015-5281 | GRUB 2 Secure Boot bypass (historical) — cited by ESET/CERT/CC as an old bug reopened by pre-15.3 UEFI shims lacking SBAT (context in CVE-2026-8863/10797 entry) | 2026-07-14 | 2026-07-14 | — |
| CVE-2026-10797 | Forgotten pre-0.9 UEFI shim signature-length validation mismatch (revocation-check vs signature-verification size divergence) — Secure Boot bypass; revoked via Microsoft dbx 2026-06-09 (ESET Research) | 2026-07-14 | 2026-07-14 | 2026-07-14 |
| CVE-2026-2699 | Progress ShareFile Storage Zone Controller pre-auth authentication bypass (CVSS 9.8) — Shadowserver confirmed active in-the-wild exploitation 2026-07-10; fixed 5.12.4 | 2026-07-13 | 2026-07-14 | 2026-07-14 +1 more |
| CVE-2026-27690 | SAP Approuter unauthenticated HTTP request smuggling (CVSS 9.1) | 2026-07-14 | 2026-07-14 | 2026-07-14 |
| CVE-2026-44747 | SAP NetWeaver AS ABAP kernel memory corruption (CVSS 9.9) | 2026-07-14 | 2026-07-14 | 2026-07-14 |
| CVE-2026-44761 | SAP Commerce Cloud hardcoded sample OAuth2 credential (CVSS 9.1) | 2026-07-14 | 2026-07-14 | 2026-07-14 |
| CVE-2026-56155 | Microsoft AD FS local elevation of privilege (exploited zero-day) | 2026-07-14 | 2026-07-14 | 2026-07-14 |
| CVE-2026-56164 | Microsoft SharePoint Server unauthenticated elevation of privilege (exploited zero-day) | 2026-07-14 | 2026-07-14 | 2026-07-14 |
| CVE-2026-8863 | Forgotten pre-0.9 UEFI shim trust-validation weakness (Secure Boot bypass on machines trusting the Microsoft third-party UEFI CA); revoked via Microsoft dbx 2026-06-09 (ESET Research) | 2026-07-14 | 2026-07-14 | 2026-07-14 |
| CVE-2008-4128 | Cisco IOS (end-of-life devices) — named by the 2026-07-13 FSB Centre 16 joint advisory as an exploited legacy CVE; no patch (EOL) | 2026-07-13 | 2026-07-13 | — |
| CVE-2018-0171 | Cisco IOS/IOS XE Smart Install pre-auth RCE — actively exploited by FSB Centre 16 / Static Tundra | 2026-07-13 | 2026-07-13 | 2026-07-13 |
| CVE-2026-2701 | Progress ShareFile Storage Zone Controller — storage-repository web-shell RCE chained from CVE-2026-2699 | 2026-07-13 | 2026-07-13 | 2026-07-13 |
| CVE-2026-4769 | WAGO I/O System Field — undocumented early-boot diagnostic interface, unauthenticated full compromise (CWE-912) | 2026-07-13 | 2026-07-13 | 2026-07-13 |
| CVE-2026-61500 | Rejetto HFS < 3.2.1 predictable session-signing PRNG (Math.random) enables pre-auth admin session forgery to RCE via server_code (CVSS 9.3); fixed 3.2.1 | 2026-07-13 | 2026-07-13 | 2026-07-13 |
| CVE-2026-61501 | Rejetto HFS 3.0.0–3.2.0 stored XSS in admin log via crafted failed-login username; fixed 3.2.1 | 2026-07-13 | 2026-07-13 | 2026-07-13 |
| CVE-2026-61502 | Rejetto HFS 3.0.0–3.2.0 state-changing admin actions accepted over GET with no anti-CSRF check; fixed 3.2.1 | 2026-07-13 | 2026-07-13 | 2026-07-13 |
| CVE-2026-61503 | Rejetto HFS 3.0.0–3.2.0 unauthenticated username enumeration (incl. default admin) via login-endpoint response differences; fixed 3.2.1 | 2026-07-13 | 2026-07-13 | 2026-07-13 |
| CVE-2026-61504 | Rejetto HFS 3.0.0–3.2.0 stored XSS via unescaped filenames in fallback 'basic' listing; fixed 3.2.1 | 2026-07-13 | 2026-07-13 | 2026-07-13 |
| CVE-2026-61505 | Rejetto HFS 3.0.0–3.2.0 path traversal via lang query parameter (limited JSON file read); fixed 3.2.1 | 2026-07-13 | 2026-07-13 | 2026-07-13 |
| CVE-2026-10698 | Progress MOVEit Transfer Custom Reports table-scope bypass, admin-privileged (CVSS 7.2; CERT-FR AVI-0856) | 2026-07-11 | 2026-07-11 | 2026-07-11 |
| CVE-2026-10699 | Progress MOVEit Transfer SFTP-service memory-leak pre-auth denial of service (CVSS 7.5; CERT-FR AVI-0856) | 2026-07-11 | 2026-07-11 | 2026-07-11 |
| CVE-2026-11903 | Progress MOVEit Transfer Ad Hoc module stored XSS, low-priv authenticated (CVSS 8.0; CERT-FR AVI-0856) | 2026-07-11 | 2026-07-11 | 2026-07-11 |
| CVE-2026-47291 | Windows HTTP.sys pre-auth kernel RCE (CVSS 9.8); ZDI published full exploitation mechanics + detection signature 2026-07-10 | 2026-06-10 | 2026-07-11 | 2026-07-11 +1 more |
| CVE-2026-57827 | Joomla RSFiles! (com_rsfiles) unauthenticated file-upload RCE (CVSS 4.0 10.0); part of the mySites.guru Joomla-extension CWE-434 wave | 2026-07-11 | 2026-07-11 | 2026-07-11 |
| CVE-2026-57828 | Joomla Phoca Download (com_phocadownload) authenticated file-upload RCE via member-upload allow-list bypass (CVSS 4.0 9.0) | 2026-07-11 | 2026-07-11 | 2026-07-11 |
| CVE-2026-60090 | PraisonAI PGVector/Cassandra knowledge store — SQL/CQL injection via unvalidated vector dimension (CVSS 9.3) | 2026-07-11 | 2026-07-11 | 2026-07-11 |
| CVE-2026-61445 | PraisonAI AICoder — arbitrary file write / command execution via LLM tool calls (CVSS 9.4) | 2026-07-11 | 2026-07-11 | 2026-07-11 |
| CVE-2026-61447 | PraisonAI CodeAgent — unsandboxed LLM-generated Python execution with full env-secret leak (CVSS 10.0) | 2026-07-11 | 2026-07-11 | 2026-07-11 |
| CVE-2021-29441 | Apache Nacos authentication bypass (Nacos-Server User-Agent header) abused by WP-SHELLSTORM for Java-stack credential theft | 2026-07-10 | 2026-07-10 | — |
| CVE-2025-5777 | CitrixBleed 2 (NetScaler ADC/Gateway pre-auth memory over-read) — weaponised in the STAC3725 IAB-to-DragonForce kill chain (Huntress) | 2026-07-01 | 2026-07-10 | 2026-07-10 |
| CVE-2025-63681 | Open WebUI /api/tasks/stop/ IDOR — unauthorized task cancellation (unpatched) | 2026-07-10 | 2026-07-10 | 2026-07-10 |
| CVE-2025-64496 | Open WebUI Direct Connections XSS chained to unsandboxed Python exec() → RCE | 2026-07-10 | 2026-07-10 | 2026-07-10 |
| CVE-2026-1969 | WordPress ThemeREX Addons plugin vulnerability weaponized by the WP-SHELLSTORM crew | 2026-07-10 | 2026-07-10 | — |
| CVE-2026-20896 | Gitea Docker reverse-proxy trust-all auth bypass (X-WEBAUTH-USER impersonation) — NCSC-CH escalated status to actively-exploited 2026-07-10 | 2026-06-23 | 2026-07-10 | 2026-07-10 +1 more |
| CVE-2026-3844 | WordPress Breeze Cache Cleaner plugin flaw — highest-yield exploit in the WP-SHELLSTORM webshell-brokerage campaign | 2026-07-10 | 2026-07-10 | — |
| CVE-2026-44556 | Open WebUI /api/openai/responses proxy reaches any model without per-model authz | 2026-07-10 | 2026-07-10 | 2026-07-10 |
| CVE-2026-44557 | Open WebUI incomplete collection allowlist exposes knowledge-base metadata to any user | 2026-07-10 | 2026-07-10 | 2026-07-10 |
| CVE-2026-44564 | Open WebUI Socket.IO ydoc:document:update checks room membership not write permission | 2026-07-10 | 2026-07-10 | 2026-07-10 |
| CVE-2026-48939 | iCagenda for Joomla — unauthenticated file-upload-to-RCE, exploited zero-day, CISA KEV | 2026-07-10 | 2026-07-10 | 2026-07-10 |
| CVE-2026-54015 | Open WebUI prompt version-history IDOR (caller-supplied history-ID unauthorized) | 2026-07-10 | 2026-07-10 | 2026-07-10 |
| CVE-2026-54798 | Siemens SICAM 8 HTTP-reachable debug interface → authenticated DoS | 2026-07-10 | 2026-07-10 | 2026-07-10 |
| CVE-2026-54799 | Siemens SICAM 8 firmware-update signature-validation bypass → persistent malicious firmware | 2026-07-10 | 2026-07-10 | 2026-07-10 |
| CVE-2026-54800 | Siemens SICAM 8 ships with OPC UA security disabled by default | 2026-07-10 | 2026-07-10 | 2026-07-10 |
| CVE-2026-54801 | Siemens SICAM 8 web-API admin-account credential-validation bypass → privilege escalation | 2026-07-10 | 2026-07-10 | 2026-07-10 |
| CVE-2024-42009 | Roundcube XSS — exploited by FrostyNeighbor / Ghostwriter (UNC1151) for Polish-targeting credential harvesting | 2026-05-17 | 2026-07-09 | 2026-07-09 |
| CVE-2025-49113 | Roundcube Crypt_GPG_Engine PHP deserialization RCE - chained by UNK_MassTraction after CVE-2024-42009 XSS (Proofpoint) | 2026-07-09 | 2026-07-09 | 2026-07-09 |
| CVE-2026-12486 | GeoVision GV-I/O Box 4E unauthenticated OS command injection (Talos, CVSS 9.1) | 2026-07-09 | 2026-07-09 | 2026-07-09 |
| CVE-2026-12958 | AWS Language Servers / Amazon Q Developer symlink trust-boundary write outside workspace (GhostApproval, CWE-61); fixed language-servers 1.69.0 / @aws/lsp-codewhisperer 0.0.117 | 2026-07-09 | 2026-07-09 | 2026-07-09 |
| CVE-2026-13125 | GeoVision GeoWebPlayer unauthenticated localhost WebSocket screen-capture (Talos, CVSS 8.8) | 2026-07-09 | 2026-07-09 | 2026-07-09 |
| CVE-2026-14480 | OpenPLC v3 Runtime authenticated arbitrary file-write to native RCE (CVSS 9.9; CISA ICSA-26-190-01, no fix) | 2026-07-09 | 2026-07-09 | 2026-07-09 |
| CVE-2026-22879 | VTK-DICOM heap overflow on crafted DICOM file (Talos, CVSS 8.1) | 2026-07-09 | 2026-07-09 | 2026-07-09 |
| CVE-2026-48614 | Plesk XML API code injection (CWE-94) — authenticated low-priv to arbitrary root file write / LPE (CVSS 9.9); CCB Belgium; affected <18.0.30, fixed 18.0.30-18.0.78.4 (18.0.79+ unaffected) | 2026-07-09 | 2026-07-09 | 2026-07-09 |
| CVE-2026-50549 | Cursor IDE sandbox escape via symlink + failed path canonicalization (GhostApproval); fixed Cursor 3.0 | 2026-07-09 | 2026-07-09 | 2026-07-09 |
| CVE-2026-50656 | Microsoft Defender Malware Protection Engine 'RoguePlanet' link-following LPE to SYSTEM - now fixed (engine >=1.1.26060.3008); NCSC-CH Nightmare Eclipse tracker | 2026-06-19 | 2026-07-09 | 2026-07-09 +2 more |
| CVE-2026-5263 | wolfSSL registeredID SAN name-constraint bypass (Talos, CVSS 7.4) | 2026-07-09 | 2026-07-09 | 2026-07-09 |
| CVE-2026-53359 | Linux KVM/x86 'Januscape' shadow-MMU use-after-free — guest-to-host VM escape on Intel and AMD (public PoC host-DoS; RCE withheld); fixed 6.1.177/6.6.144/6.12.95/6.18.38/7.1.3 | 2026-07-09 | 2026-07-09 | 2026-07-09 |
| CVE-2026-56291 | Balbooa Forms for Joomla (com_baforms) unauthenticated file-upload RCE (CWE-434, CVSS 4.0 10.0) — zero-day exploited pre-patch; 3rd Joomla-extension file-upload RCE in the 2026-06/07 wave | 2026-07-09 | 2026-07-09 | 2026-07-09 |
| CVE-2026-6678 | wolfSSL PKCS#7 OtherRecipientInfo integer underflow -> heap overflow (Talos, CVSS 7.5) | 2026-07-09 | 2026-07-09 | 2026-07-09 |
| CVE-2026-7532 | wolfSSL iPAddress SAN name-constraint bypass (Talos coordinated disclosure, CVSS 9.1) | 2026-07-09 | 2026-07-09 | 2026-07-09 |
| CVE-2020-22653 | Ruckus wireless router flaw exploited by UAT-7810 for ORB initial access (context; Cisco Talos) | 2026-07-08 | 2026-07-08 | — |
| CVE-2020-22658 | Ruckus wireless router flaw exploited by UAT-7810 for ORB initial access (context; Cisco Talos) | 2026-07-08 | 2026-07-08 | — |
| CVE-2023-25717 | Ruckus wireless router flaw exploited by UAT-7810 for ORB initial access (context; Cisco Talos) | 2026-07-08 | 2026-07-08 | — |
| CVE-2025-2492 | ASUS AiCloud router flaw exploited by UAT-7810 for ORB initial access (context; Cisco Talos) | 2026-07-08 | 2026-07-08 | — |
| CVE-2026-20744 | Hydro-Quebec EV-charging OCPP WebSocket unauthenticated access -> privilege escalation (CVSS 9.8), CISA ICSA-26-188-01 | 2026-07-08 | 2026-07-08 | 2026-07-08 |
| CVE-2026-33017 | Langflow unauthenticated RCE (build_public_tmp), CISA KEV, exploited in the Langflow IDOR chain | 2026-07-08 | 2026-07-08 | 2026-07-08 |
| CVE-2026-40138 | BeyondTrust RS/PRA pre-auth authentication bypass (CVSS4 9.2), NCSC-CH BT26-03 | 2026-07-08 | 2026-07-08 | 2026-07-08 |
| CVE-2026-40139 | BeyondTrust RS/PRA pre-auth authentication bypass (CVSS4 9.2), NCSC-CH BT26-03 | 2026-07-08 | 2026-07-08 | 2026-07-08 |
| CVE-2026-40140 | BeyondTrust RS/PRA unauthenticated DoS (network-communication subsystem), BT26-03 | 2026-07-08 | 2026-07-08 | 2026-07-08 |
| CVE-2026-40141 | BeyondTrust RS/PRA authenticated broken-access-control (resource access beyond scope), BT26-03 | 2026-07-08 | 2026-07-08 | 2026-07-08 |
| CVE-2026-42952 | Hydro-Quebec EV-charging: no auth-attempt throttling -> DoS (CVSS 7.5), ICSA-26-188-01 | 2026-07-08 | 2026-07-08 | 2026-07-08 |
| CVE-2026-43499 | GhostLock — Linux kernel rtmutex use-after-free LPE + container escape, public exploit | 2026-07-08 | 2026-07-08 | 2026-07-08 |
| CVE-2026-44383 | Hydro-Quebec EV-charging: duplicate concurrent sessions per charge-point ID -> DoS (CVSS 7.5), ICSA-26-188-01 | 2026-07-08 | 2026-07-08 | 2026-07-08 |
| CVE-2026-48282 | Adobe ColdFusion CWE-22 path-traversal RCE (CVSS 10.0), APSB26-68 — actively exploited, CISA KEV 2026-07-07 | 2026-07-02 | 2026-07-08 | 2026-07-08 +1 more |
| CVE-2026-48908 | JoomShaper SP Page Builder unauth file-upload RCE (CVSS 10.0), CISA KEV zero-day | 2026-07-08 | 2026-07-08 | 2026-07-08 |
| CVE-2026-50746 | Ubiquiti UniFi Connect unauthenticated command-injection RCE (CVSS 10.0), SAB-066 | 2026-07-08 | 2026-07-08 | 2026-07-08 |
| CVE-2026-50747 | Ubiquiti UniFi Talk authenticated SQL injection (CVSS 9.9), SAB-066 | 2026-07-08 | 2026-07-08 | 2026-07-08 |
| CVE-2026-50748 | Ubiquiti UniFi Access command injection (CVSS 9.9), SAB-066 | 2026-07-08 | 2026-07-08 | 2026-07-08 |
| CVE-2026-54402 | Ubiquiti UniFi OS command injection (CVSS 9.9), SAB-066 | 2026-07-08 | 2026-07-08 | 2026-07-08 |
| CVE-2026-54403 | Ubiquiti UniFi OS path-traversal auth-bypass (CVSS 8.6), chainable, SAB-066 | 2026-07-08 | 2026-07-08 | 2026-07-08 |
| CVE-2026-55115 | Ubiquiti UniFi Protect SSRF privilege escalation (CVSS 9.9), SAB-066 | 2026-07-08 | 2026-07-08 | 2026-07-08 |
| CVE-2026-55255 | Langflow cross-tenant IDOR (CWE-639), actively exploited, CISA KEV — chained with RCE CVE-2026-33017 | 2026-07-08 | 2026-07-08 | 2026-07-08 |
| CVE-2026-56290 | Joomlack Page Builder CK unauth file-upload RCE (CVSS 10.0), CISA KEV zero-day | 2026-07-08 | 2026-07-08 | 2026-07-08 |
| CVE-2026-59509 | cve-search unauthenticated /fetch_cve_data parameter manipulation exposes admin credential hashes | 2026-07-05 | 2026-07-05 | 2026-07-05 |
| CVE-2025-3248 | Langflow /api/v1/validate/code missing-auth RCE — initial access for the JADEPUFFER agentic ransomware operation | 2026-07-04 | 2026-07-04 | 2026-07-04 |
| CVE-2026-13368 | WatchGuard Fireware OS iked pre-auth use-after-free RCE (IKEv2/LDAP path, CVSS 9.2) | 2026-07-03 | 2026-07-03 | 2026-07-03 |
| CVE-2026-20191 | Cisco Catalyst Center unauthenticated path-traversal arbitrary file read (CVSS 7.5; dropped from §2, awareness only) | 2026-07-03 | 2026-07-03 | — |
| CVE-2026-34038 | Coolify authenticated OS command injection to RCE + secrets exfil (CVSS 9.9) | 2026-07-03 | 2026-07-03 | 2026-07-03 |
| CVE-2026-57517 | Control Web Panel pre-auth blind SQLi to web-shell RCE via INTO DUMPFILE (CVSS 9.8) | 2026-07-03 | 2026-07-03 | 2026-07-03 |
| CVE-2026-14439 | Altium Enterprise Server / Altium 365 Git Service CWE-22 path-traversal to RCE (CVSS 9.4) | 2026-07-02 | 2026-07-02 | 2026-07-02 |
| CVE-2026-45659 | Microsoft SharePoint Server CWE-502 deserialization RCE — authenticated Site Member (PR:L) can execute code over network; CVSS 8.8; NCSC.ch flagged 2026-05-26; § 7 drop (did not clear § 2 gates) | 2026-05-27 | 2026-07-02 | 2026-07-02 |
| CVE-2026-48276 | Adobe ColdFusion CWE-434 unrestricted file-upload RCE (CVSS 10.0), APSB26-68 | 2026-07-02 | 2026-07-02 | 2026-07-02 |
| CVE-2026-48277 | Adobe ColdFusion CWE-20 improper-input-validation RCE (CVSS 10.0), APSB26-68 | 2026-07-02 | 2026-07-02 | 2026-07-02 |
| CVE-2026-48281 | Adobe ColdFusion CWE-20 improper-input-validation RCE (CVSS 10.0), APSB26-68 | 2026-07-02 | 2026-07-02 | 2026-07-02 |
| CVE-2026-48283 | Adobe ColdFusion CWE-434 unrestricted file-upload RCE (CVSS 10.0), APSB26-68 | 2026-07-02 | 2026-07-02 | 2026-07-02 |
| CVE-2026-48286 | Adobe Campaign Classic CWE-863 incorrect-authorization code execution (CVSS 10.0), APSB26-69 | 2026-07-02 | 2026-07-02 | — |
| CVE-2026-48316 | Adobe ColdFusion CWE-20 improper-input-validation RCE (CVSS 10.0), APSB26-68 | 2026-07-02 | 2026-07-02 | 2026-07-02 |
| CVE-2026-8037 | Progress Kemp LoadMaster pre-auth RCE — uninitialized malloc heap corruption in escape_quotes()/ /accessv2 to root (CVSS 9.8); fixed 7.2.63.2 | 2026-06-09 | 2026-07-02 | 2026-07-02 +1 more |
| CVE-2023-4966 | Citrix NetScaler ADC/Gateway 'CitrixBleed' session-token memory overread — cited as CVE-2026-8451 lineage context | 2026-07-01 | 2026-07-01 | — |
| CVE-2025-12101 | Citrix NetScaler ADC/Gateway memory-leak (CitrixBleed variant) — cited as CVE-2026-8451 lineage context | 2026-07-01 | 2026-07-01 | — |
| CVE-2026-10816 | Citrix NetScaler ADC/Gateway — Management Interface unauthenticated arbitrary file read (CTX696604) | 2026-07-01 | 2026-07-01 | — |
| CVE-2026-10817 | Citrix NetScaler ADC/Gateway — memory overread when TCP TimeStamp enabled on LB/CS/VPN vserver (CTX696604) | 2026-07-01 | 2026-07-01 | — |
| CVE-2026-13474 | Citrix NetScaler ADC/Gateway — CTX696604 companion CVE | 2026-07-01 | 2026-07-01 | — |
| CVE-2026-35273 | Oracle PeopleSoft PeopleTools PSEMHUB pre-auth RCE (CVSS 9.8), zero-day exploited by UNC6240/ShinyHunters | 2026-06-12 | 2026-07-01 | 2026-07-01 +3 more |
| CVE-2026-8451 | Citrix NetScaler ADC/Gateway — pre-auth SAML AuthnRequest XML-parser memory overread (CitrixBleed lineage, CVSS 8.8), public PoC | 2026-07-01 | 2026-07-01 | 2026-07-01 |
| CVE-2026-8452 | Citrix NetScaler ADC/Gateway — memory-management flaw (Gateway/DNS-proxy/AAA vserver), DoS/undefined control flow (CTX696604) | 2026-07-01 | 2026-07-01 | — |
| CVE-2026-8655 | Citrix NetScaler ADC/Gateway — memory-management flaw (Gateway/DNS-proxy/AAA vserver), DoS/undefined control flow (CTX696604) | 2026-07-01 | 2026-07-01 | — |
| CVE-2026-13165 | SzafirHost (KIR e-signature client) JAR parser confusion (JarFile vs JarInputStream, CWE-434) → native-library RCE past signature check; fixed v1.2.2 | 2026-06-30 | 2026-06-30 | 2026-06-30 |
| CVE-2026-33691 | Progress Kemp LoadMaster — OWASP CRS whitespace-padding file-upload extension-check bypass (high); same bulletin as CVE-2026-8037 | 2026-06-09 | 2026-06-30 | — |
| CVE-2026-43503 | Linux kernel 'DirtyClone' LPE — SKBFL_SHARED_FRAG drop in __pskb_copy_fclone() + IPsec in-place decrypt; JFrog working exploit on Debian/Ubuntu/Fedora (CVSS 8.8) | 2026-06-27 | 2026-06-30 | 2026-06-30 +2 more |
| CVE-2026-48558 | SimpleHelp RMM OIDC SSO auth bypass — forged-token full Technician session + MFA bypass; now actively exploited (CISA KEV 2026-06-29), Djinn infostealer via TaskWeaver loader (CVSS 10.0) | 2026-06-13 | 2026-06-30 | 2026-06-30 +1 more |
| CVE-2026-54305 | n8n Dynamic Credentials EE — missing ownership/scope checks enable cross-tenant OAuth credential hijack/revoke (CVSS 8.9, GHSA-2j5h-858j-5mpf); NCSC-2026-0212 | 2026-06-30 | 2026-06-30 | — |
| CVE-2026-54307 | n8n public API — editor-level users read other users' credentials in shared instances (CVSS 8.5); NCSC-2026-0212 | 2026-06-30 | 2026-06-30 | — |
| CVE-2026-55200 | libssh2 pre-auth heap OOB write in ssh2_transport_read() (CVSS 9.2) — public PoC released 2026-06-29; no fixed release tagged yet | 2026-06-28 | 2026-06-30 | 2026-06-30 +2 more |
| CVE-2025-67038 | Lantronix EDS5000 OS command injection to root (BRIDGE:BREAK; CISA KEV 2026-06-23) | 2026-06-24 | 2026-06-29 | 2026-06-29 +1 more |
| CVE-2026-10735 | ShapedPlugin WordPress Pro supply-chain backdoor (build/EDD pipeline compromise) | 2026-06-23 | 2026-06-29 | 2026-06-29 +1 more |
| CVE-2026-11800 | Keycloak JWT algorithm confusion -> federated-user impersonation (CVSS 8.1) | 2026-06-28 | 2026-06-29 | 2026-06-29 +1 more |
| CVE-2026-20230 | Cisco Unified Communications Manager WebDialer unauthenticated SSRF → OS-root file write (SIR Critical); fix 14SU6 / Release 15 COP | 2026-06-04 | 2026-06-29 | 2026-06-29 +2 more |
| CVE-2026-20245 | Cisco Catalyst SD-WAN Manager command-injection to root — Mandiant confirms pre-disclosure zero-day exploitation; patched (chains CVE-2026-20127/-20182) | 2026-06-01 | 2026-06-29 | 2026-06-29 +4 more |
| CVE-2026-34908 | Ubiquiti UniFi OS improper access control (chain step 1 to unauth root; CISA KEV 2026-06-23) | 2026-06-24 | 2026-06-29 | 2026-06-29 +1 more |
| CVE-2026-34909 | Ubiquiti UniFi OS path traversal (chain step 2 to unauth root; CISA KEV 2026-06-23) | 2026-06-24 | 2026-06-29 | 2026-06-29 +1 more |
| CVE-2026-34910 | Ubiquiti UniFi OS improper input validation/command injection to root (CISA KEV 2026-06-23, actively exploited) | 2026-06-24 | 2026-06-29 | 2026-06-29 +1 more |
| CVE-2026-46331 | Linux kernel 'pedit COW' LPE — tc act_pedit out-of-bounds write poisons setuid-binary page cache; public weaponised PoC | 2026-06-27 | 2026-06-29 | 2026-06-29 +1 more |
| CVE-2026-52806 | Gogs argument-injection RCE (CVE-2026-52806); now actively exploited in K8s cryptojacking campaign (Wiz) | 2026-06-14 | 2026-06-29 | 2026-06-29 +1 more |
| CVE-2026-55199 | libssh2 infinite-loop pre-auth DoS via crafted SSH_MSG_EXT_INFO (CVSS 8.2) | 2026-06-28 | 2026-06-29 | 2026-06-29 +1 more |
| CVE-2026-58053 | Gitea act_runner Docker container-hardening bypass to host escape (CVSS 9.4, public PoC) | 2026-06-28 | 2026-06-29 | 2026-06-29 +1 more |
| CVE-2026-9800 | Keycloak policy-enforcer authorization bypass via access-denied-page path (CVSS 8.1) | 2026-06-28 | 2026-06-29 | 2026-06-29 +1 more |
| CVE-2025-8088 | WinRAR path-traversal (referenced as initial-access exploit in Gamaredon GammaPhish/GammaWorm campaign, Sekoia 2026-06-01) | 2026-06-02 | 2026-06-28 | 2026-06-27 +3 more |
| CVE-2026-12789 | ILIAS 11.0 SQL injection in ilTrQuery learning-progress subsystem (no patch, PoC public) | 2026-06-23 | 2026-06-28 | 2026-06-23 |
| CVE-2026-20262 | Cisco Catalyst SD-WAN Manager web UI authenticated path traversal — arbitrary file write to root RCE; CISA KEV 2026-06-15 | 2026-06-16 | 2026-06-28 | 2026-06-22 +1 more |
| CVE-2026-9099 | Keycloak group-admin to realm-admin privilege escalation | 2026-06-28 | 2026-06-28 | — |
| CVE-2021-26855 | Microsoft Exchange Server SSRF (ProxyLogon) — cited in 2026-05-16 § 5 deep dive Background as precedent for on-prem Exchange exploitation pattern | 2026-05-16 | 2026-06-27 | — |
| CVE-2023-32315 | Openfire admin-console path-traversal auth bypass — StrikeShark/SharkLoader initial-access vector | 2026-06-27 | 2026-06-27 | — |
| CVE-2023-46747 | F5 BIG-IP TMUI unauthenticated RCE — StrikeShark/SharkLoader initial-access vector | 2026-06-27 | 2026-06-27 | — |
| CVE-2024-21762 | Fortinet FortiOS SSL-VPN out-of-bounds write RCE — StrikeShark/SharkLoader initial-access vector | 2026-06-27 | 2026-06-27 | — |
| CVE-2024-36401 | OSGeo GeoServer OGC-filter RCE — StrikeShark/SharkLoader initial-access vector | 2026-06-27 | 2026-06-27 | — |
| CVE-2026-10712 | GitLab Web IDE workbench stored XSS (CVSS 8.0) — patched 19.1.1/19.0.3/18.11.6; assessed, did not clear §2 gate | 2026-06-26 | 2026-06-27 | — |
| CVE-2026-12957 | Amazon Q Developer (VS Code) auto-loads workspace .amazonq/mcp.json without consent — repo-planted code execution + AWS credential theft | 2026-06-27 | 2026-06-27 | 2026-06-27 |
| CVE-2026-20127 | Cisco Catalyst SD-WAN Manager pre-auth RCE (UAT-8616 prior exploitation, Feb 2026) | 2026-05-15 | 2026-06-27 | 2026-06-27 +1 more |
| CVE-2026-20182 | Cisco Catalyst SD-WAN Controller/Manager pre-auth authentication bypass (CVSS 10.0, actively exploited by UAT-8616) | 2026-05-11 | 2026-06-27 | 2026-06-27 +3 more |
| CVE-2026-43284 | Dirty Frag — Linux kernel xfrm-ESP page-cache write primitive, LPE (ITW, PoC public) | 2026-05-04 | 2026-06-27 | 2026-05-11 +1 more |
| CVE-2026-43500 | Dirty Frag — Linux kernel RxRPC page-cache write primitive, LPE chain (ITW, patch pending) | 2026-05-04 | 2026-06-27 | 2026-05-11 +1 more |
| CVE-2026-46300 | Fragnesia — Linux kernel xfrm ESP-in-TCP LPE (PoC public) | 2026-05-11 | 2026-06-27 | 2026-05-15 +1 more |
| CVE-2026-50751 | Check Point Security Gateway IKEv1 Remote Access/Mobile Access certificate-validation authentication bypass (CVSS 9.3) — actively exploited by Qilin affiliate since 2026-05-07, CISA KEV | 2026-06-09 | 2026-06-27 | 2026-06-22 +2 more |
| CVE-2026-10086 | GitLab EE Analytics Dashboard stored XSS (CVSS 8.7) — patched 19.1.1/19.0.3/18.11.6; assessed, did not clear §2 gate | 2026-06-26 | 2026-06-26 | — |
| CVE-2026-12635 | GitLab repository-mirroring SSRF (CVSS 3.1) — patched 19.1.1/19.0.3/18.11.6; low severity, did not clear §2 gate | 2026-06-26 | 2026-06-26 | — |
| CVE-2026-8461 | FFmpeg MagicYUV decoder heap OOB write (PixelSmash, CVSS 8.8) — fixed FFmpeg 8.1.2; out-of-window this run | 2026-06-26 | 2026-06-26 | — |
| CVE-2026-39893 | Cacti <1.2.31 — pre-auth SQLi in graph_view.php (rfilter); evaluated, dropped to § 7 (out-of-window, single GHSA) | 2026-06-25 | 2026-06-25 | — |
| CVE-2026-56422 | MISP <2.5.42 — broken access control | 2026-06-25 | 2026-06-25 | 2026-06-25 |
| CVE-2026-56423 | MISP <2.5.42 — cross-org IDOR overwrite | 2026-06-25 | 2026-06-25 | 2026-06-25 |
| CVE-2026-56424 | MISP <2.5.42 — broken access control, cross-org hard-delete | 2026-06-25 | 2026-06-25 | 2026-06-25 |
| CVE-2026-56425 | MISP <2.5.42 — Azure-AD OAuth state-reuse session hijack | 2026-06-25 | 2026-06-25 | 2026-06-25 |
| CVE-2026-56446 | MISP <2.5.42 — NDJSON log-injection PHP RCE (site-admin) | 2026-06-25 | 2026-06-25 | 2026-06-25 |
| CVE-2026-56447 | MISP <2.5.42 — rdkafka plugin-load RCE (site-admin) | 2026-06-25 | 2026-06-25 | 2026-06-25 |
| CVE-2026-7473 | Arista EOS tunnel-decapsulation logic flaw (CWE-1023) bypasses VXLAN segmentation; CISA KEV, exploited | 2026-06-10 | 2026-06-25 | 2026-06-10 |
| CVE-2024-40766 | SonicWall SonicOS improper access control (mgmt + SSLVPN, Gen 5/6/7) — Akira/Fog ransomware on-ramp | 2026-06-23 | 2026-06-23 | 2026-06-23 |
| CVE-2025-59718 | FortiGate credential-reuse vector referenced in FortiBleed campaign | 2026-06-23 | 2026-06-23 | — |
| CVE-2025-59719 | FortiGate credential-reuse vector referenced in FortiBleed campaign | 2026-06-23 | 2026-06-23 | — |
| CVE-2026-20779 | Gitea TOTP 2FA bypass (web TOCTOU + X-Gitea-OTP replay) | 2026-06-23 | 2026-06-23 | — |
| CVE-2026-22874 | Gitea SSRF in webhook / repo-migration subsystems | 2026-06-23 | 2026-06-23 | — |
| CVE-2026-24858 | FortiGate credential-reuse vector referenced in FortiBleed campaign | 2026-06-23 | 2026-06-23 | — |
| CVE-2026-27775 | Gitea protected-branch enforcement race (single-push batch) | 2026-06-23 | 2026-06-23 | — |
| CVE-2026-41947 | DifyTap — Dify AI platform cross-tenant authorization bypass (evaluated, dropped § 7: authenticated, no ITW, aggregator-only primary) | 2026-06-23 | 2026-06-23 | — |
| CVE-2026-47645 | Microsoft 365 Copilot Business Chat open redirect (BSI WID-SEC-2026-2020; server-side mitigated, dropped § 7) | 2026-06-23 | 2026-06-23 | — |
| CVE-2026-47729 | Squidbleed — 29-year-old heap over-read in Squid FTP gateway leaks cross-user HTTP credentials | 2026-06-23 | 2026-06-23 | 2026-06-23 |
| CVE-2026-49777 | ShapedPlugin supply-chain backdoor — duplicate CVE submission for CVE-2026-10735 (noted § 7) | 2026-06-23 | 2026-06-23 | — |
| CVE-2026-54130 | Microsoft 365 Copilot missing-authentication info disclosure (BSI WID-SEC-2026-2020; server-side mitigated, dropped § 7) | 2026-06-23 | 2026-06-23 | — |
| CVE-2013-3307 | Linksys/D-Link RTL819X command-injection RCE — initial-access vector for the AryStinger botnet | 2026-06-22 | 2026-06-22 | 2026-06-22 |
| CVE-2016-5681 | D-Link DIR-850L HTTP-service stack buffer overflow RCE — AryStinger botnet access vector | 2026-06-22 | 2026-06-22 | 2026-06-22 |
| CVE-2025-11837 | QNAP Malware Remover code injection (fixed 6.6.8.20251023) — AryStinger NAS access vector | 2026-06-22 | 2026-06-22 | 2026-06-22 |
| CVE-2025-13036 | Rockwell FactoryTalk Historian Site Edition — authentication bypass (CVSS 7.7) | 2026-06-18 | 2026-06-22 | 2026-06-22 +1 more |
| CVE-2026-0257 | PAN-OS GlobalProtect pre-auth authentication bypass | 2026-05-25 | 2026-06-22 | 2026-06-22 +4 more |
| CVE-2026-0646 | Rockwell 1794-AENTR/AENTRXT FLEX I/O — CIP-handling denial-of-service (CVSS 7.5) | 2026-06-18 | 2026-06-22 | 2026-06-22 +1 more |
| CVE-2026-0647 | Rockwell 1794-AENTR/AENTRXT FLEX I/O — unauthenticated web-interface password reset (CVSS 9.4) | 2026-06-18 | 2026-06-22 | 2026-06-22 +1 more |
| CVE-2026-11317 | Rockwell CompactLogix/ControlLogix 5370/5570 — CIP message major non-recoverable fault DoS (CVSS 7.5) | 2026-06-18 | 2026-06-22 | 2026-06-22 +1 more |
| CVE-2026-20181 | Cisco ISE / ISE-PIC — authenticated path-traversal OS command execution to root (CVSS 9.1) | 2026-06-19 | 2026-06-22 | 2026-06-22 +1 more |
| CVE-2026-20190 | Cisco ISE / ISE-PIC — unauthenticated read of sensitive data incl. hashed admin credentials (CVSS 7.5) | 2026-06-19 | 2026-06-22 | 2026-06-22 +1 more |
| CVE-2026-20253 | Splunk Enterprise pre-auth RCE via unauthenticated PostgreSQL sidecar REST API proxied by web tier, CVSS 9.8 | 2026-06-14 | 2026-06-22 | 2026-06-22 +2 more |
| CVE-2026-25089 | FortiSandbox unauthenticated OS command injection in VNC handler (CVSS 9.8); dropped from brief - no inclusion gate cleared | 2026-06-11 | 2026-06-22 | 2026-06-22 +2 more |
| CVE-2026-35278 | Oracle PeopleSoft PeopleTools 8.61/8.62 Performance Monitor — missing-auth RCE (CVSS 9.8) | 2026-06-18 | 2026-06-22 | 2026-06-22 +1 more |
| CVE-2026-39808 | Fortinet FortiSandbox — JRPC API OS command injection (CVSS 9.8); actively exploited | 2026-06-17 | 2026-06-22 | 2026-06-22 +1 more |
| CVE-2026-39813 | Fortinet FortiSandbox — JRPC API path traversal / auth bypass (CVSS 9.1); actively exploited | 2026-06-17 | 2026-06-22 | 2026-06-22 +1 more |
| CVE-2026-4020 | Gravity SMTP WordPress plugin unauthenticated info-disclosure (email-connector credential dump), mass-exploited | 2026-06-21 | 2026-06-22 | 2026-06-22 +1 more |
| CVE-2026-46978 | Oracle Solaris 11.4 Remote Administration Daemon — unauthenticated flaw (CVSS 10.0), Oracle June 2026 CSPU | 2026-06-18 | 2026-06-22 | 2026-06-22 +1 more |
| CVE-2026-48907 | Widget Factory Joomla Content Editor (JCE) <2.9.99.5 — unauthenticated profile-import to PHP RCE (CVSS v4 10.0); CISA KEV | 2026-06-17 | 2026-06-22 | 2026-06-22 +1 more |
| CVE-2026-54420 | LiteSpeed cPanel/WHM plugin symlink-following on CloudLinux/CageFS shared hosting; exploited ITW May 2026; CISA KEV | 2026-06-16 | 2026-06-22 | 2026-06-22 +1 more |
| CVE-2026-55803 | Drupal core — JSON:API PHP object injection (SA-CORE-2026-005, critical) | 2026-06-19 | 2026-06-22 | 2026-06-22 +1 more |
| CVE-2026-55804 | Drupal core — deserialization gadget chain (SA-CORE-2026-006) | 2026-06-19 | 2026-06-22 | 2026-06-22 +1 more |
| CVE-2023-24932 | Windows Boot Manager Secure Boot bypass (BlackLotus-class) — possible FishMonger SprySOCKS UEFI component (unconfirmed) | 2026-06-17 | 2026-06-21 | — |
| CVE-2026-10795 | UpdraftPlus WordPress plugin unauthenticated auth-bypass to RCE (all-zero AES key on failed RSA decrypt), CVSS 8.1; actively exploited | 2026-06-14 | 2026-06-21 | 2026-06-14 |
| CVE-2026-12046 | pgAdmin 4 — unauthenticated pickle.loads RCE primitive in SQL Editor (server mode, CVSS v4 9.5) | 2026-06-19 | 2026-06-21 | 2026-06-19 |
| CVE-2026-2473 | Google Cloud Vertex AI SDK — predictable staging-bucket cross-tenant pickle RCE ('Pickle in the Middle'); patched 1.148.0 | 2026-06-17 | 2026-06-21 | — |
| CVE-2026-40624 | AVer PTC500S/PTC115/PTC500+/PTC115+ cameras — unauthenticated RCE via management web interface (CVSS 9.8), CISA ICSA-26-169-01 | 2026-06-20 | 2026-06-21 | 2026-06-20 |
| CVE-2026-42055 | NGINX — heap overflow in ngx_http_proxy_v2_module/ngx_http_grpc_module (CVSS v4 9.2) | 2026-06-19 | 2026-06-21 | 2026-06-19 |
| CVE-2026-42530 | NGINX — HTTP/3 QUIC use-after-free in ngx_http_v3_module (CVSS v4 9.2) | 2026-06-19 | 2026-06-21 | 2026-06-19 |
| CVE-2026-42824 | Microsoft 365 Copilot Enterprise Search 'SearchLeak' command-injection/info-disclosure; one-click exfil; patched server-side | 2026-06-16 | 2026-06-21 | 2026-06-16 |
| CVE-2026-48611 | phpBB OAuth improper-authentication account hijack (admin) even when OAuth disabled; CVSS 9.8; fixed 3.3.17 | 2026-06-16 | 2026-06-21 | 2026-06-16 |
| CVE-2026-12045 | pgAdmin 4 — AI Assistant read-only-transaction bypass to RCE via COPY TO PROGRAM (CVSS v4 9.4) | 2026-06-19 | 2026-06-19 | 2026-06-19 |
| CVE-2026-12048 | pgAdmin 4 — stored XSS via unsanitised PostgreSQL error/EXPLAIN content (CVSS v4 9.3) | 2026-06-19 | 2026-06-19 | 2026-06-19 |
| CVE-2026-55806 | Drupal core — rebuild.php trusted-host bypass (SA-CORE-2026-007) | 2026-06-19 | 2026-06-19 | — |
| CVE-2026-55807 | Drupal core — Media module oEmbed SSRF (SA-CORE-2026-008) | 2026-06-19 | 2026-06-19 | — |
| CVE-2026-55808 | Drupal core — JSON:API/REST image-upload MIME-validation gap (SA-CORE-2026-009) | 2026-06-19 | 2026-06-19 | — |
| CVE-2020-25213 | WP File Manager pre-auth RCE — used as fallback vector in the ErrTraffic ClickFix framework | 2026-06-17 | 2026-06-17 | — |
| CVE-2023-52271 | Topaz Antifraud wsftprm.sys vulnerable kernel driver — DragonForce BYOVD chain | 2026-06-17 | 2026-06-17 | — |
| CVE-2025-1055 | K7 Security K7RKScan.sys vulnerable kernel driver — DragonForce BYOVD chain | 2026-06-17 | 2026-06-17 | — |
| CVE-2025-55182 | React/Next.js Server Actions deserialisation ("React2Shell") — weaponised by PCPJack worm | 2026-05-10 | 2026-06-17 | — |
| CVE-2025-61155 | Tower of Fantasy GameDriverx64.sys vulnerable kernel driver — DragonForce BYOVD chain | 2026-06-17 | 2026-06-17 | — |
| CVE-2026-20251 | Splunk Secure Gateway jsonpickle deserialization RCE (CVSS 8.8) — assessed, no §2 gate (no ITW, post-auth); NCSC-NL advisory | 2026-06-16 | 2026-06-16 | — |
| CVE-2026-40217 | LiteLLM Custom Code Guardrails sandbox escape to RCE via exec()/bytecode; CVSS 8.8; fixed v1.83.14 | 2026-06-16 | 2026-06-16 | 2026-06-16 |
| CVE-2026-47101 | LiteLLM authorization bypass via unvalidated allowed_routes in key-generation; CVSS 8.8; fixed v1.83.14 | 2026-06-16 | 2026-06-16 | 2026-06-16 |
| CVE-2026-47102 | LiteLLM privilege escalation — self-promote to proxy_admin via /user/update; CVSS 8.8; fixed v1.83.14 | 2026-06-16 | 2026-06-16 | 2026-06-16 |
| CVE-2026-48612 | phpBB OAuth improper state verification + CSRF session hijack; CVSS 8.0; fixed 3.3.17 | 2026-06-16 | 2026-06-16 | 2026-06-16 |
| CVE-2026-10087 | GitLab EE Analytics Dashboard stored XSS (CVSS 8.7) — assessed, no §2 gate | 2026-06-15 | 2026-06-15 | — |
| CVE-2026-34182 | OpenSSL CMS AuthEnvelopedData integrity bypass (moderate) — assessed, out-of-window, not promoted | 2026-06-15 | 2026-06-15 | — |
| CVE-2026-47124 | Traefik v3.x security-policy bypass (GHSA-3g6v-2r68-prfc) — assessed, no §2 gate, out-of-window | 2026-06-15 | 2026-06-15 | — |
| CVE-2026-47928 | Adobe ColdFusion unauthenticated no-interaction RCE (CVSS 9.6, APSB26-64; scope change S:C; fixed 2023 Update 20 / 2025 Update 9) | 2026-06-15 | 2026-06-15 | — |
| CVE-2026-47932 | Adobe ColdFusion path-traversal security-feature bypass (CVSS 8.8, APSB26-64) — co-disclosed; assessed, not promoted | 2026-06-15 | 2026-06-15 | — |
| CVE-2026-7250 | GitLab CE/EE Grape API unauthenticated DoS (CVSS 7.5) — assessed, no §2 gate | 2026-06-15 | 2026-06-15 | — |
| CVE-2026-9204 | GitLab CE/EE Gitaly repository-import SSRF (CVSS 5.3) — assessed, no §2 gate | 2026-06-15 | 2026-06-15 | — |
| CVE-2020-17103 | Windows Cloud Filter driver cldflt.sys privilege escalation (MiniPlasma PoC) | 2026-05-18 | 2026-06-14 | 2026-05-25 +2 more |
| CVE-2022-38028 | Windows Print Spooler privilege escalation weaponised by APT28 GooseEgg (cited as historical context in Sekoia APT28 retrospective) | 2026-06-14 | 2026-06-14 | — |
| CVE-2025-67644 | LangGraph SQLite checkpointer SQL injection in get_state_history() (CVSS 7.3; fixed langgraph-checkpoint-sqlite 3.0.1) | 2026-06-13 | 2026-06-14 | 2026-06-13 |
| CVE-2026-10520 | Ivanti Sentry pre-auth OS command injection to root (MICS handleMessage), CVSS 10.0; public PoC by watchTowr | 2026-06-10 | 2026-06-14 | 2026-06-14 +1 more |
| CVE-2026-10523 | Ivanti Sentry authentication bypass (CWE-288), companion to CVE-2026-10520 | 2026-06-10 | 2026-06-14 | 2026-06-10 |
| CVE-2026-11645 | Google Chrome V8 out-of-bounds read/write, exploited ITW, CISA KEV; fixed 149.0.7827.103 | 2026-06-10 | 2026-06-14 | 2026-06-10 |
| CVE-2026-12183 | BUK TS-G gas-station automation unauthenticated admin bypass, CVSS 9.8 (dropped from brief — aggregator-only sourcing) | 2026-06-14 | 2026-06-14 | — |
| CVE-2026-23111 | Linux kernel nf_tables use-after-free in nft_map_catchall_activate() (single-character genmask inversion) — local-root + container escape, working public exploit (Exodus Intelligence), patched upstream 2026-02-05, CVSS 7.8 | 2026-06-09 | 2026-06-14 | 2026-06-09 |
| CVE-2026-28277 | LangGraph unsafe msgpack deserialization on checkpoint load, chains with SQLi to RCE (CVSS 6.8; fixed langgraph 1.0.10) | 2026-06-13 | 2026-06-14 | 2026-06-13 |
| CVE-2026-3300 | Everest Forms Pro (WordPress) Calculation Addon unauthenticated eval() PHP code injection (CVSS 9.8); mass exploitation since 2026-04-13 creating rogue admin accounts; patched v1.9.13 (2026-03-18) | 2026-06-08 | 2026-06-14 | 2026-06-08 |
| CVE-2026-41089 | Windows Netlogon stack buffer overflow — unauthenticated remote RCE to SYSTEM on domain controllers (CVSS 9.8, May 2026 Patch Tuesday); active ITW exploitation confirmed by CCB Belgium 2026-06-01 | 2026-05-13 | 2026-06-14 | 2026-06-11 +3 more |
| CVE-2026-42271 | BerriAI LiteLLM MCP test endpoints command injection to host RCE (CVSS 8.8) — CISA KEV, actively exploited; unauthenticated when chained with CVE-2026-48710 | 2026-06-09 | 2026-06-14 | 2026-06-09 |
| CVE-2026-44748 | SAP NetWeaver AS ABAP SAML XML Signature Wrapping (CVSS 9.9), SAP_BASIS 702-919 | 2026-06-10 | 2026-06-14 | 2026-06-14 +1 more |
| CVE-2026-44963 | Veeam Backup & Replication 12.x authenticated domain-user deserialization RCE (CVSS 9.4); fixed 12.3.2.4854 | 2026-06-10 | 2026-06-14 | 2026-06-10 |
| CVE-2026-45585 | Windows YellowKey BitLocker bypass via WinRE | 2026-05-18 | 2026-06-14 | 2026-05-30 +2 more |
| CVE-2026-45586 | Windows CTFMON elevation of privilege (June 2026 Patch Tuesday); referenced in § 7 GreenPlasma cross-source discrepancy note | 2026-06-11 | 2026-06-14 | — |
| CVE-2026-45657 | Windows kernel TCP/IP use-after-free network RCE to SYSTEM (CVSS 9.8) | 2026-06-12 | 2026-06-14 | 2026-06-12 |
| CVE-2026-47210 | vm2 Node.js sandbox escape via WebAssembly JSPI Promise-species bypass, CVSS 9.8 (dropped from brief — out-of-window, no ITW) | 2026-06-14 | 2026-06-14 | — |
| CVE-2026-47344 | TYPO3 Core June 2026 (TYPO3-CORE-SA-2026-006) — XSS bypassing the HTML Sanitizer; lead CVE of the 13-advisory batch | 2026-06-10 | 2026-06-14 | 2026-06-10 |
| CVE-2026-47895 | strongSwan libstrongswan identity-clone double-free, unauth RCE over EAP; fixed 6.0.7 | 2026-06-10 | 2026-06-14 | 2026-06-10 |
| CVE-2026-49200 | Acer Wave-7 mesh router broken access control — unauthenticated cleartext credential log acer_cgi.log exposure (CVSS 10.0, no patch until ~end-June 2026) | 2026-06-08 | 2026-06-14 | 2026-06-08 |
| CVE-2026-49201 | Acer Wave-7 mesh router hardcoded AES key in upload.cgi backup handler — persistent backdoor injection (CVSS 10.0, no patch until ~end-June 2026) | 2026-06-08 | 2026-06-14 | 2026-06-08 |
| CVE-2026-49261 | MariaDB Server Galera wsrep_notify_cmd OS command injection (CVSS 10.0) | 2026-06-12 | 2026-06-14 | 2026-06-14 +1 more |
| CVE-2026-5027 | Langflow path traversal (POST /api/v2/files) -> arbitrary file write, pre-auth via default auto-login, exploited ITW | 2026-06-11 | 2026-06-14 | 2026-06-11 |
| CVE-2026-27022 | LangGraph Redis checkpointer RediSearch query injection (CVSS 6.5; fixed @langchain/langgraph-checkpoint-redis 1.0.1) | 2026-06-13 | 2026-06-13 | 2026-06-13 |
| CVE-2026-45447 | OpenSSL PKCS7_verify heap use-after-free on empty SignedData.digestAlgorithms (High; fixed 4.0.1/3.6.3/3.5.7/3.4.6/3.0.21) — out-of-window drop this run | 2026-06-13 | 2026-06-13 | — |
| CVE-2026-6552 | GitLab EE Group SAML identity API improper authorization, Group Owner account takeover (CVSS 8.7; fixed 19.0.2/18.11.5/18.10.8) — did not clear daily section-2 gate | 2026-06-13 | 2026-06-13 | — |
| CVE-2026-26142 | Nuance PowerScribe unauthenticated deserialization RCE (CVSS 9.8) | 2026-06-12 | 2026-06-12 | 2026-06-12 |
| CVE-2026-47643 | Azure Stack Edge external file path control RCE (CVSS 9.8) | 2026-06-12 | 2026-06-12 | 2026-06-12 |
| CVE-2026-48163 | MariaDB Galera wsrep parameter-injection (companion fix to CVE-2026-49261) | 2026-06-12 | 2026-06-12 | 2026-06-12 |
| CVE-2026-48165 | MariaDB Galera wsrep parameter-injection (companion fix to CVE-2026-49261) | 2026-06-12 | 2026-06-12 | 2026-06-12 |
| CVE-2026-48579 | Exchange Online improper-authorisation information disclosure (CVSS 9.1, service-side fix) | 2026-06-12 | 2026-06-12 | 2026-06-12 |
| CVE-2026-35616 | Fortinet FortiClient EMS 7.4.5/7.4.6 — improper-access-control on X-SSL-CLIENT-VERIFY header lets unauth attacker spoof mTLS state and reach management API; ITW exploited to push EKZ Infostealer per Arctic Wolf 2026-05-27 | 2026-05-25 | 2026-06-11 | 2026-05-29 +1 more |
| CVE-2026-50507 | Windows BitLocker physical-access bypass, publicly disclosed, June 2026 Patch Tuesday | 2026-06-10 | 2026-06-11 | 2026-06-10 |
| CVE-2026-22732 | SAP Commerce Cloud / Data Hub missing HTTP security headers via Spring Security (CVSS 9.1) | 2026-06-10 | 2026-06-10 | 2026-06-10 |
| CVE-2026-27671 | SAP NetWeaver/ABAP RFC kernel memory corruption, unauthenticated (CVSS 9.8) | 2026-06-10 | 2026-06-10 | 2026-06-10 |
| CVE-2026-40128 | SAP NetWeaver AS Java Web Container path traversal (CVSS 9.0) | 2026-06-10 | 2026-06-10 | 2026-06-10 |
| CVE-2026-44815 | Windows DHCP Client Service RCE (CVSS 9.8), June 2026 Patch Tuesday | 2026-06-10 | 2026-06-10 | 2026-06-10 |
| CVE-2026-47281 | Visual Studio Code EoP to SYSTEM via malicious .code-workspace (CVSS 9.6) | 2026-06-10 | 2026-06-10 | 2026-06-10 |
| CVE-2026-49160 | Windows HTTP.sys HTTP/2 compression-bomb DoS (IIS analogue of CVE-2026-49975); MaxHeadersCount mitigation | 2026-06-10 | 2026-06-10 | 2026-06-10 |
| CVE-2026-49975 | HTTP/2 Bomb — HPACK dynamic-table amplification + Slowloris stream-hold memory-exhaustion DoS vs nginx/Apache/IIS/Envoy/Pingora; nginx 1.29.8 & Apache mod_http2 2.0.41 patched, IIS/Envoy/Pingora unpatched at disclosure | 2026-06-01 | 2026-06-10 | 2026-06-04 +1 more |
| CVE-2026-48710 | Starlette/FastAPI host-header auth bypass (BadHost) | 2026-05-25 | 2026-06-09 | 2026-06-09 +2 more |
| CVE-2026-50752 | Check Point IKEv1 site-to-site VPN MitM via certificate validation weakness (CVSS 7.4) — no observed exploitation | 2026-06-09 | 2026-06-09 | 2026-06-09 |
| CVE-2021-27137 | DD-WRT UPnP/SSDP parser stack buffer overflow — FortiGuard-attributed propagation vector for C0XMO/Gafgyt botnet; DOES NOT RESOLVE ON NVD/MITRE (flagged 2026-06-08, vendor-attributed/unverified) | 2026-06-08 | 2026-06-08 | — |
| CVE-2026-10881 | Google Chrome ANGLE graphics engine out-of-bounds read/write → sandbox escape (CVSS 9.6); Chrome 149 record 429-patch release | 2026-06-07 | 2026-06-07 | 2026-06-07 |
| CVE-2026-37977 | Keycloak CORS ACAO reflected from unverified JWT azp claim on UMA endpoint (fixed 26.6.3) | 2026-06-07 | 2026-06-07 | 2026-06-07 |
| CVE-2026-39210 | FFmpeg parser/demuxer heap or stack overflow (depthfirst AI-agent discovery; PoC public, fixed upstream) | 2026-06-07 | 2026-06-07 | 2026-06-07 |
| CVE-2026-39211 | FFmpeg parser/demuxer heap or stack overflow (depthfirst AI-agent discovery; PoC public, fixed upstream) | 2026-06-07 | 2026-06-07 | 2026-06-07 |
| CVE-2026-39212 | FFmpeg parser/demuxer heap or stack overflow (depthfirst AI-agent discovery; PoC public, fixed upstream) | 2026-06-07 | 2026-06-07 | 2026-06-07 |
| CVE-2026-39213 | FFmpeg parser/demuxer heap or stack overflow (depthfirst AI-agent discovery; PoC public, fixed upstream) | 2026-06-07 | 2026-06-07 | 2026-06-07 |
| CVE-2026-39214 | FFmpeg parser/demuxer heap or stack overflow (depthfirst AI-agent discovery; PoC public, fixed upstream) | 2026-06-07 | 2026-06-07 | 2026-06-07 |
| CVE-2026-39215 | FFmpeg parser/demuxer heap or stack overflow (depthfirst AI-agent discovery; PoC public, fixed upstream) | 2026-06-07 | 2026-06-07 | 2026-06-07 |
| CVE-2026-39216 | FFmpeg parser/demuxer heap or stack overflow (depthfirst AI-agent discovery; PoC public, fixed upstream) | 2026-06-07 | 2026-06-07 | 2026-06-07 |
| CVE-2026-39217 | FFmpeg parser/demuxer heap or stack overflow (depthfirst AI-agent discovery; PoC public, fixed upstream) | 2026-06-07 | 2026-06-07 | 2026-06-07 |
| CVE-2026-39218 | FFmpeg parser/demuxer heap or stack overflow (depthfirst AI-agent discovery; PoC public, fixed upstream) | 2026-06-07 | 2026-06-07 | 2026-06-07 |
| CVE-2026-4874 | Keycloak SSRF via OIDC token endpoint manipulation (fixed 26.6.3) | 2026-06-01 | 2026-06-07 | 2026-06-07 +1 more |
| CVE-2026-8830 | Keycloak missing server-side WebAuthn credential-registration validation (fixed 26.6.3) | 2026-06-07 | 2026-06-07 | 2026-06-07 |
| CVE-2026-9704 | Keycloak token-exchange privilege escalation via silent subject_token removal (fixed 26.6.3) | 2026-06-01 | 2026-06-07 | 2026-06-07 +1 more |
| CVE-2026-9792 | Keycloak ROPC grant bypass of client-policy enforcement (fixed 26.6.3) | 2026-06-07 | 2026-06-07 | 2026-06-07 |
| CVE-2026-9802 | Keycloak refresh-token replay window after server restart resets startupTime (fixed 26.6.3) | 2026-06-07 | 2026-06-07 | 2026-06-07 |
| CVE-2026-10854 | MISP access-control bypass exposing private galaxy metadata to non-admin org users (CVSS 5.3) | 2026-06-06 | 2026-06-06 | — |
| CVE-2026-10868 | MISP mass-assignment account-takeover in UsersController::edit() (CVSS 9.0, patched 2026-06-04) | 2026-06-01 | 2026-06-06 | 2026-06-06 +1 more |
| CVE-2026-28318 | SolarWinds Serv-U uncontrolled resource consumption — unauthenticated DoS via Content-Encoding: deflate (CISA KEV 2026-06-05) | 2026-06-06 | 2026-06-06 | 2026-06-06 |
| CVE-2026-23479 | Redis use-after-free in unblockClientOnKey() → GOT-overwrite RCE (post-auth; default-passwordless) | 2026-06-05 | 2026-06-05 | 2026-06-05 |
| CVE-2026-34906 | Simple SA Wirtualna Uczelnia unauthenticated SSTI → RCE (redirectToUrl) | 2026-06-05 | 2026-06-05 | 2026-06-05 |
| CVE-2026-34907 | Simple SA Wirtualna Uczelnia reflected XSS (locale parameter) | 2026-06-05 | 2026-06-05 | 2026-06-05 |
| CVE-2026-41283 | OpenStack Mistral policy-enforcement bypass → authenticated arbitrary code execution (OSSA-2026-020; evaluated and dropped — see brief §7) | 2026-06-05 | 2026-06-05 | — |
| CVE-2026-10611 | MISP OTP bypass — session established in beforeFilter before OTP when LdapAuth.mixedAuth+require_otp both on; fix commit 39b3cb15 / >=2.5.37 | 2026-06-04 | 2026-06-04 | 2026-06-04 |
| CVE-2026-33829 | Windows Snipping Tool ms-screensketch: URI handler NTLM hash leak — patched April 2026; cited as structural predecessor of unpatched search: URI variant | 2026-06-04 | 2026-06-04 | — |
| CVE-2026-41100 | Microsoft 365 Copilot for Android OAuth-token theft via production debug flag (CVSS 4.4); patched 2026-05-12 | 2026-06-04 | 2026-06-04 | 2026-06-04 |
| CVE-2026-41101 | Microsoft Word for Android OAuth-token theft via production debug flag (CVSS 7.1); patched 2026-05-12 | 2026-06-04 | 2026-06-04 | 2026-06-04 |
| CVE-2026-41102 | Microsoft PowerPoint for Android OAuth-token theft via production debug flag (CVSS 7.1); patched 2026-05-12 | 2026-06-04 | 2026-06-04 | 2026-06-04 |
| CVE-2026-42832 | Microsoft Excel for Android OAuth-token theft via setIsDebugMode(true) debug flag left in production (CVSS 7.7); patched 2026-05-12 | 2026-06-04 | 2026-06-04 | 2026-06-04 |
| CVE-2026-45247 | Mirasvit Full Page Cache Warmer (Magento 2) unauthenticated PHP object-injection RCE via CacheWarmer cookie; CISA KEV 2026-06-03, ITW from 2026-04-24; fix v1.11.12 | 2026-06-04 | 2026-06-04 | 2026-06-04 |
| CVE-2026-7195 | Progress Sitefinity CMS web-services improper input validation (CWE-20); BSI WID-SEC-2026-1783 | 2026-06-04 | 2026-06-04 | — |
| CVE-2026-7198 | Progress Sitefinity CMS OData improper input validation (CVSS 9.8, CWE-20), affects 15.4.8623-15.4.8629; BSI WID-SEC-2026-1783 | 2026-06-04 | 2026-06-04 | — |
| CVE-2026-7201 | Progress Sitefinity CMS ServiceStack web-services credential exposure (CVSS 8.8, CWE-522); BSI WID-SEC-2026-1783 | 2026-06-04 | 2026-06-04 | — |
| CVE-2026-7312 | Progress Sitefinity CMS — CWE-522 Insufficiently Protected Credentials (Sitefinity Insight credential disclosure, gated on Insight integration/non-default config); CVSS 10.0 per NVD; BSI WID-SEC-2026-1783; evaluated 2026-06-04, dropped to §7 (no fetchable vendor primary, no ITW) | 2026-06-04 | 2026-06-04 | — |
| CVE-2026-7313 | Progress Sitefinity CMS legacy-branch flaw (CVSS 8.7), affects v8.0-13.3; BSI WID-SEC-2026-1783 | 2026-06-04 | 2026-06-04 | — |
| CVE-2026-7325 | Devolutions Server LDAP coercion exposing PAM credentials (DEVO-2026-0013, CVSS 7.1); evaluated 2026-06-04, dropped to §7 (no ITW, below §2 gate) | 2026-06-04 | 2026-06-04 | — |
| CVE-2026-8181 | Burst Statistics WordPress 3.4.0-3.4.1.1 unauthenticated REST auth-bypass (is_mainwp_authenticated) → admin impersonation/rogue admin; actively exploited; fix v3.4.2 | 2026-06-04 | 2026-06-04 | 2026-06-04 |
| CVE-2026-8206 | Kirki WordPress Freeform Page Builder 6.0.0-6.0.6 unauthenticated password-reset hijack → admin account takeover; actively exploited; fix v6.0.7 | 2026-06-04 | 2026-06-04 | 2026-06-04 |
| CVE-2026-9047 | Devolutions Server MFA bypass via improper factor-key state handling (DEVO-2026-0013, CVSS 7.5); evaluated 2026-06-04, dropped to §7 (no ITW, below §2 gate) | 2026-06-04 | 2026-06-04 | — |
| CVE-2020-1472 | ZeroLogon — Netlogon privilege escalation; chained by Cl0p in South Staffordshire Water 2020-2022 intrusion (cited in ICO 2026-05-11 enforcement) | 2026-05-12 | 2026-06-03 | — |
| CVE-2022-0492 | Linux kernel cgroup v1 release_agent container escape (missing CAP_SYS_ADMIN check); CISA KEV 2026-06-02 | 2026-06-03 | 2026-06-03 | 2026-06-03 |
| CVE-2024-21182 | Oracle WebLogic Server unauth T3/IIOP data access (CVSS 7.5); CISA KEV 2026-06-01 on active exploitation | 2026-06-02 | 2026-06-03 | 2026-06-03 |
| CVE-2025-48595 | Android Framework integer-overflow LPE (no-interaction), limited targeted exploitation; June 2026 bulletin | 2026-06-03 | 2026-06-03 | 2026-06-03 |
| CVE-2026-34926 | Trend Micro Apex One On-Premise relative path traversal fleet-wide code injection | 2026-05-22 | 2026-06-03 | 2026-05-22 |
| CVE-2026-40402 | Windows Hyper-V UAF guest-to-host escape (May 2026 Patch Tuesday); evaluated 2026-06-03, not covered (out-of-window) | 2026-06-03 | 2026-06-03 | — |
| CVE-2026-41096 | Windows DNS Client (dnsapi.dll) heap buffer overflow — RCE via malicious DNS response (CVSS 9.8, May 2026 Patch Tuesday) | 2026-05-13 | 2026-06-03 | 2026-05-13 |
| CVE-2026-5426 | Digital Knowledge KnowledgeDeliver LMS — pre-shared ASP.NET machineKey ViewState deserialization RCE; exploited as zero-day pre-2026-02-24 | 2026-05-25 | 2026-06-03 | 2026-05-26 +1 more |
| CVE-2026-42251 | KAMSOFT KS-SOMED healthcare software — hardcoded FTP credentials in update client allow malicious-update injection / supply-chain (CVSS 4.0 8.7, CERT-PL) | 2026-06-02 | 2026-06-02 | — |
| CVE-2026-44825 | Apache Solr 9.4.0-9.10.1/10.0.0 — hardcoded BasicAuth template credentials allow unauthenticated remote admin (CVSS 8.1, BSI WID-SEC-2026-1740); no patch yet, manual workaround | 2026-06-02 | 2026-06-02 | 2026-06-02 |
| CVE-2026-46243 | CIFSwitch — Linux kernel CIFS/SMB-client LPE to root via forged cifs.spnego key requests (19-year-old bug; RHEL9/SLES15/Mint/Kali); dropped from 2026-06-02 brief as out-of-window + no Section 2 gate | 2026-06-02 | 2026-06-02 | — |
| CVE-2026-8732 | WP Maps Pro WordPress plugin <=6.1.0 — unauthenticated admin-account creation via disclosed nonce + wp_ajax_nopriv_ handler; actively exploited (CVSS 9.8); fixed 6.1.1 | 2026-06-02 | 2026-06-02 | 2026-06-02 |
| CVE-2026-8931 | Disig Web Signer 2.0.3-2.5.3 — unauthenticated RCE in Slovak eIDAS qualified-signature client (CVSS 4.0 9.4, SK-CERT); fixed 2.5.5 | 2026-06-02 | 2026-06-02 | 2026-06-02 |
| CVE-2026-46818 | Oracle E-Business Suite — May 2026 CPU critical (referenced in §7, dropped) | 2026-06-01 | 2026-06-01 | — |
| CVE-2026-46819 | Oracle E-Business Suite — May 2026 CPU critical (referenced in §7, dropped) | 2026-06-01 | 2026-06-01 | — |
| CVE-2026-46820 | Oracle E-Business Suite — May 2026 CPU critical (referenced in §7, dropped) | 2026-06-01 | 2026-06-01 | — |
| CVE-2026-46821 | Oracle E-Business Suite — May 2026 CPU critical (referenced in §7, dropped) | 2026-06-01 | 2026-06-01 | — |
| CVE-2025-62582 | Delta Electronics DIAView SCADA — unauthenticated remote database access (predecessor to CVE-2026-9642 mitigation bypass) | 2026-05-27 | 2026-05-31 | — |
| CVE-2026-26980 | Ghost CMS Content API unauthenticated SQLi (CVSS 9.4); ITW-exploited in ClickFix campaign; fixed 6.19.1 | 2026-05-25 | 2026-05-31 | 2026-05-25 |
| CVE-2026-32996 | Veeam Agent for Microsoft Windows — local privilege escalation enabling arbitrary command execution / lateral movement (CVSS 7.3) | 2026-05-29 | 2026-05-31 | 2026-05-29 |
| CVE-2026-32997 | Veeam Software Appliance (Linux) — authenticated Backup Administrator can write arbitrary files (CVSS 8.6) | 2026-05-29 | 2026-05-31 | 2026-05-29 |
| CVE-2026-33384 | QuickCMS (OpenSolution) session fixation — CERT-PL; dropped (niche, CVSS 4.8) | 2026-05-31 | 2026-05-31 | — |
| CVE-2026-33386 | QuickCMS (OpenSolution) MITM-XSS via HTTP plugin fetch — CERT-PL; dropped (niche, CVSS 2.3) | 2026-05-31 | 2026-05-31 | — |
| CVE-2026-35087 | Slican PBX administrative protocol authentication bypass — attacker bypasses login by executing a specific command; CVSS 4.0: 9.3; CERT Polska disclosure 2026-05-27 | 2026-05-28 | 2026-05-31 | 2026-05-28 |
| CVE-2026-35089 | Slican PBX deterministic secure-key generation from publicly-obtainable system properties — admin credentials recoverable without auth; CVSS 4.0: 8.7; CERT Polska | 2026-05-28 | 2026-05-31 | 2026-05-28 |
| CVE-2026-35090 | Slican PBX remote management modem interface — hardcoded caller-ID bypasses admin auth and temporarily re-enables remote access when configured off; CVSS 4.0: 9.3; CERT Polska | 2026-05-28 | 2026-05-31 | 2026-05-28 |
| CVE-2026-41052 | SUSE Rancher — project-owner role can flip namespace PSA labels to privileged, enabling container-to-host escape (CVSS 8.4) | 2026-05-29 | 2026-05-31 | 2026-05-29 |
| CVE-2026-41053 | SUSE Rancher GitHub App auth — group principals granted for every team in GitHub org to any team-belonging user (CVSS 8.8) | 2026-05-29 | 2026-05-31 | 2026-05-29 |
| CVE-2026-4408 | Samba SAMR RPC server — unauthenticated shell injection via %u substitution in check password script (CVSS 10.0) | 2026-05-25 | 2026-05-31 | 2026-05-29 +1 more |
| CVE-2026-4480 | Samba print-command subsystem — unauthenticated shell injection via %J substitution; raw/classic printing only (CVSS 10.0) | 2026-05-25 | 2026-05-31 | 2026-05-29 +1 more |
| CVE-2026-44848 | Portainer CE — Docker plugin endpoints not registered in proxy authorization handler; non-admin can install/enable plugins → root host execution (CVSS 9.4) | 2026-05-29 | 2026-05-31 | 2026-05-29 |
| CVE-2026-44849 | Portainer CE Docker Swarm service API — EndpointSecuritySettings restrictions not enforced; non-admin escapes to host via privileged containers (CVSS 9.4) | 2026-05-29 | 2026-05-31 | 2026-05-29 |
| CVE-2026-44939 | SUSE Rancher cluster-import endpoint — command injection via URL-encoded newline in authImage YAML field; control-plane node RCE (CVSS 9.6) | 2026-05-29 | 2026-05-31 | 2026-05-29 |
| CVE-2026-4776 | Mautic API contact-filtering SQL injection (post-auth) | 2026-05-31 | 2026-05-31 | 2026-05-31 |
| CVE-2026-48172 | LiteSpeed User-End cPanel plugin lsws.redisAble priv-esc to root (CVSS 10.0, ITW) | 2026-05-18 | 2026-05-31 | 2026-05-24 +1 more |
| CVE-2026-4868 | GitLab CE/EE Duo AI integration — improper user identity resolution allows authenticated user to impersonate another user when triggering Duo AI workflows (CVSS 8.2) | 2026-05-29 | 2026-05-31 | 2026-05-29 |
| CVE-2026-48842 | Roundcube Webmail pre-auth SQL injection in virtuser_query plugin via preg_replace backslash escape bypass; CVSS 8.1; patched in 1.6.16 LTS / 1.7.1 | 2026-05-25 | 2026-05-31 | 2026-05-28 +1 more |
| CVE-2026-8992 | Ivanti Secure Access Client local privilege escalation | 2026-05-30 | 2026-05-31 | 2026-05-30 |
| CVE-2026-9058 | Szafir SDK (KIR) improper certificate verification / auth bypass — Polish qualified e-signature SDK; fixed v463 | 2026-05-26 | 2026-05-31 | 2026-05-26 |
| CVE-2026-9170 | IBM HTTP Server / WebSphere Application Server — pre-auth RCE via improper input validation in HTTP request parser (CVSS 9.8); NCSC.ch flagged 2026-05-28 | 2026-05-25 | 2026-05-31 | 2026-05-29 +1 more |
| CVE-2026-9312 | GitHub Enterprise Server < 3.22 — unauthenticated SSRF via upload-endpoint path traversal exposes internal services and credentials (CVSS 4.0 = 9.2; GHSA-fwfp-h68w-2hcr) | 2026-05-27 | 2026-05-31 | 2026-05-27 |
| CVE-2026-9557 | Mautic Focus component SSRF (post-auth; reaches internal/cloud-metadata) | 2026-05-31 | 2026-05-31 | 2026-05-31 |
| CVE-2026-9558 | Mautic stored XSS (post-auth) | 2026-05-31 | 2026-05-31 | 2026-05-31 |
| CVE-2026-9559 | Mautic stored XSS / JS injection (post-auth) | 2026-05-31 | 2026-05-31 | 2026-05-31 |
| CVE-2026-9642 | Delta Electronics DIAView SCADA — incomplete fix / mitigation bypass of CVE-2025-62582 unauthenticated remote database access (CVSS 3.1 = 9.8; Tenable TRA-2026-44) | 2026-05-27 | 2026-05-31 | 2026-05-27 |
| CVE-2026-9808 | Mautic file inclusion / path traversal (post-auth) | 2026-05-31 | 2026-05-31 | 2026-05-31 |
| CVE-2026-9809 | Mautic path traversal / file manipulation (post-auth) | 2026-05-31 | 2026-05-31 | 2026-05-31 |
| CVE-2026-9811 | Mautic JavaScript code injection (post-auth) | 2026-05-31 | 2026-05-31 | 2026-05-31 |
| CVE-2024-39930 | Gogs prior argument-injection variant (referenced in Rapid7 2026-05-29 disclosure as same-class predecessor) | 2026-05-29 | 2026-05-29 | — |
| CVE-2026-1402 | GitLab CE/EE — Wiki DoS via insufficient validation of malformed markup (CVSS 6.5) | 2026-05-29 | 2026-05-29 | 2026-05-29 |
| CVE-2026-2601 | GitLab EE — Developer-role users can access deployment data (pipeline environment variables, deployment keys) via missing authorization checks (CVSS 4.3) | 2026-05-29 | 2026-05-29 | 2026-05-29 |
| CVE-2026-26194 | Gogs argument-injection RCE (CVE id claimed by S3 sub-agent — unverified against authoritative NVD entry; Rapid7 publication states no CVE assigned at disclosure; deferred to next-run verification) | 2026-05-29 | 2026-05-29 | — |
| CVE-2026-2710 | GitLab CE/EE — seventh CVE in 19.0.1 / 18.11.4 / 18.10.7 patch release (defender-relevance not enumerated; left to vendor page) | 2026-05-29 | 2026-05-29 | — |
| CVE-2026-5296 | GitLab EE — Developer-role users can bypass group-level flow restrictions when foundational flows enabled (CVSS 4.3) | 2026-05-29 | 2026-05-29 | 2026-05-29 |
| CVE-2026-6713 | GitLab CE/EE — unauthenticated enumeration of private project paths via API (CVSS 5.3) | 2026-05-29 | 2026-05-29 | 2026-05-29 |
| CVE-2026-8716 | GitLab CE/EE — Authenticated users can access CI data from unintended reference types via incorrect reference resolution (CVSS 4.3) | 2026-05-29 | 2026-05-29 | 2026-05-29 |
| CVE-2026-8834 | IBM HTTP Server Administration Server — heap-based buffer overflow (CVSS 8.0) | 2026-05-29 | 2026-05-29 | — |
| CVE-2026-8850 | IBM HTTP Server mod_ibm_upload — DoS via NULL pointer dereference (CVSS 7.5) | 2026-05-29 | 2026-05-29 | — |
| CVE-2026-8854 | IBM HTTP Server mod_mem_cache — DoS via expired pointer dereference (CVSS 7.5) | 2026-05-29 | 2026-05-29 | — |
| CVE-2026-8855 | IBM HTTP Server — RCE in TLS mutual-authentication configurations (CVSS 8.1) | 2026-05-29 | 2026-05-29 | — |
| CVE-2026-8856 | IBM HTTP Server — DoS via uncontrolled resource consumption (CVSS 7.7) | 2026-05-29 | 2026-05-29 | — |
| CVE-2026-27771 | Gitea container registry access-control failure — private repo container images unauthenticatedly pullable across all versions < 1.26.2 (4-year exposure window); Forgejo confirmed affected; § 7 drop 2026-05-28 | 2026-05-28 | 2026-05-28 | — |
| CVE-2026-42945 | NGINX ngx_http_rewrite_module heap buffer overflow (earlier of two May 2026 disclosures); exploitation attempts per NCSC-NL; § 7 drop (primary 2026-05-18 out-of-window) | 2026-05-15 | 2026-05-28 | 2026-05-18 +1 more |
| CVE-2026-45321 | TanStack Router npm credential-stealing payload — exfiltrated Nx contributor GitHub CLI OAuth token (precursor to CVE-2026-48027 Nx Console compromise); CISA KEV 2026-05-27 | 2026-05-22 | 2026-05-28 | 2026-05-28 |
| CVE-2026-48027 | Nx Console v18.95.0 VS Code extension supply-chain compromise — credential-stealing payload harvested 1Password, Claude Code config, npm, GitHub, AWS creds; CISA KEV 2026-05-27 | 2026-05-28 | 2026-05-28 | 2026-05-28 |
| CVE-2026-48843 | Roundcube Webmail CSS sanitisation failure via SVG animate attributeName=style — info disclosure / SSRF in HTML email rendering; patched in 1.6.16 LTS / 1.7.1 | 2026-05-28 | 2026-05-28 | 2026-05-28 |
| CVE-2026-48844 | Roundcube Webmail code injection via LDAP autovalues option — arbitrary PHP code evaluation when option is configured; patched in 1.6.16 LTS / 1.7.1 | 2026-05-28 | 2026-05-28 | 2026-05-28 |
| CVE-2026-48848 | Roundcube Webmail HTML sanitisation bypass via SVG document permitting CSS injection; patched in 1.6.16 LTS / 1.7.1 | 2026-05-28 | 2026-05-28 | 2026-05-28 |
| CVE-2026-8398 | DAEMON Tools Lite signed-build trojanisation (12.5.0.2421–12.5.0.2434) via Disc Soft Limited build infrastructure; CISA KEV 2026-05-27 | 2026-05-28 | 2026-05-28 | 2026-05-28 |
| CVE-2026-9256 | NGINX ngx_http_rewrite_module heap buffer overflow — out-of-bounds write in worker process memory pool via overlapping regex capture groups; CVSS v3.1 8.1 / v4.0 9.2; exploitation attempts per NCSC-NL; § 7 drop (primary 2026-05-22 out-of-window) | 2026-05-24 | 2026-05-28 | — |
| CVE-2026-44895 | yoda-digital mcp-gitlab-server < 0.6.0 — no-auth SSE RPC endpoint bound to 0.0.0.0 with wildcard CORS exposes operator GitLab PAT (CVSS 4.0 = 9.2; GHSA-8jr5-6gvj-rfpf); noted in § 7 (niche package) | 2026-05-27 | 2026-05-27 | — |
| CVE-2024-12802 | SonicWall Gen6 SSL-VPN MFA bypass via UPN vs SAM account-name split; Akira-linked actors exploited Feb-Mar 2026; firmware update insufficient without 6-step LDAP reconfiguration | 2026-05-18 | 2026-05-25 | 2026-05-21 +1 more |
| CVE-2024-55591 | FortiOS / FortiProxy authentication bypass — weaponised by 'The Gentlemen' RaaS initial access | 2026-05-10 | 2026-05-25 | — |
| CVE-2025-32433 | Erlang SSH RCE (Cisco context) — confirmed by Check Point Research as initial-access CVE for The Gentlemen RaaS | 2026-05-17 | 2026-05-25 | — |
| CVE-2025-34291 | Langflow CORS misconfiguration + SameSite=None refresh token theft | 2026-05-22 | 2026-05-25 | 2026-05-22 |
| CVE-2026-0300 | Palo Alto PAN-OS Captive Portal unauthenticated root RCE (CVSS 9.3, ITW, KEV deadline 2026-05-09) | 2026-05-04 | 2026-05-25 | 2026-05-18 +4 more |
| CVE-2026-20223 | Cisco Secure Workload internal REST API zero-auth Site Admin CVSS 10.0 | 2026-05-18 | 2026-05-25 | 2026-05-22 +1 more |
| CVE-2026-2743 | SEPPmail Secure E-Mail Gateway — pre-auth path traversal in LFT /v1/file.app → arbitrary file write as nobody → RCE via /etc/syslog.conf overwrite | 2026-05-20 | 2026-05-25 | 2026-05-20 |
| CVE-2026-31635 | Linux kernel RxGK rxgk_decrypt_skb() page-cache write (missing COW guard) — DirtyDecrypt LPE; affects Fedora / Arch / openSUSE Tumbleweed (CONFIG_RXGK=y) | 2026-05-20 | 2026-05-25 | 2026-05-20 |
| CVE-2026-41091 | Microsoft Defender Malware Protection Engine — link-following EoP to SYSTEM (CWE-59); Engine ≤ 1.1.26030.3008; actively exploited | 2026-05-18 | 2026-05-25 | 2026-05-22 +2 more |
| CVE-2026-42096 | Sparx Pro Cloud Server — authenticated SQL injection via database API endpoint; PCS ≤ 6.1 | 2026-05-18 | 2026-05-25 | 2026-05-20 +1 more |
| CVE-2026-42097 | Sparx Pro Cloud Server — pre-auth bypass via model-parameter omission in POST binary blob → unauthenticated SQL query execution; CVSS4 9.3 | 2026-05-18 | 2026-05-25 | 2026-05-20 +1 more |
| CVE-2026-42098 | Sparx Enterprise Architect ≤ 17.1 — client-side RBAC bypass via EA client binary patch (CWE-603); CVSS4 8.7 | 2026-05-18 | 2026-05-25 | 2026-05-20 +1 more |
| CVE-2026-42099 | Sparx Pro Cloud Server WebEA — race condition in /data_api/dl_internal_artifact.php → RCE in web-server context (CWE-362); CVSS4 7.7 | 2026-05-18 | 2026-05-25 | 2026-05-20 +1 more |
| CVE-2026-42100 | Sparx Pro Cloud Server — malformed SQL crash (DoS); CWE-835 | 2026-05-18 | 2026-05-25 | 2026-05-20 +1 more |
| CVE-2026-42231 | n8n self-hosted automation — xml2js prototype pollution (CWE-1321), root of authenticated-to-RCE chain via Git node SSH | 2026-05-19 | 2026-05-25 | 2026-05-19 |
| CVE-2026-42822 | Microsoft Azure Local Disconnected Operations (ALDO) — CVSS 10.0 unauthenticated network elevation-of-privilege; MSRC Exploitation More Likely | 2026-05-18 | 2026-05-25 | 2026-05-21 +1 more |
| CVE-2026-43997 | vm2 Node.js sandbox — host-object access via BaseHandler.getPrototypeOf trap; sandbox escape to host context; CVSS 10.0; patched 3.11.0 | 2026-05-20 | 2026-05-25 | 2026-05-20 |
| CVE-2026-45498 | Microsoft Defender Antivirus local DoS — exploited alongside CVE-2026-41091 in combined out-of-band engine update 4.18.26040.7 | 2026-05-18 | 2026-05-25 | 2026-05-22 +1 more |
| CVE-2026-45584 | Microsoft Defender Malware Protection Engine — heap-based buffer overflow over network → unauthenticated RCE in Defender process context; CVSS 8.1 | 2026-05-20 | 2026-05-25 | 2026-05-20 |
| CVE-2026-45829 | ChromaDB Python FastAPI server pre-auth RCE via embedding-function model loading before auth check (CVSS 4.0 = 10.0; v1.5.9 unpatched at disclosure) | 2026-05-18 | 2026-05-25 | 2026-05-21 +1 more |
| CVE-2026-7507 | Keycloak OIDC login flow session fixation enabling account takeover (Keycloak 26.6.2; BSI WID-SEC-2026-1612 HIGH) | 2026-05-18 | 2026-05-25 | 2026-05-21 +1 more |
| CVE-2026-9082 | Drupal core highly-critical pre-auth SQL injection in database abstraction API on PostgreSQL backends; CISA KEV-listed 2026-05-22 (SA-CORE-2026-004) | 2026-05-18 | 2026-05-25 | 2026-05-23 +2 more |
| CVE-2025-9086 | Stormshield SNS remote DoS (CERTFR-2026-AVI-0631); dropped from §2, mentioned in §7 | 2026-05-24 | 2026-05-24 | — |
| CVE-2026-33278 | NLnet Labs Unbound DNSSEC validator UAF (CVSS 9.8), fixed 1.25.1 | 2026-05-24 | 2026-05-24 | 2026-05-24 |
| CVE-2026-3593 | ISC BIND 9 DoH use-after-free (CVSS 7.4), fixed 9.20.23 | 2026-05-24 | 2026-05-24 | 2026-05-24 |
| CVE-2026-37979 | Keycloak OIDC token introspection endpoint does not enforce audience restriction; lightweight access tokens leak claims cross-client (Keycloak 26.6.2) | 2026-05-18 | 2026-05-24 | 2026-05-21 +1 more |
| CVE-2026-37982 | Keycloak execute-actions token replay enabling unauthorised WebAuthn / FIDO2 credential enrollment on victim account (Keycloak 26.6.2) | 2026-05-18 | 2026-05-24 | 2026-05-21 +1 more |
| CVE-2026-42944 | NLnet Labs Unbound heap overflow, default-config (CVSS 8.6), fixed 1.25.1 | 2026-05-24 | 2026-05-24 | 2026-05-24 |
| CVE-2026-4630 | Keycloak Authorization Services Protection API cross-realm IDOR allowing realm-A authenticated attacker to access realm-B resources (Keycloak 26.6.2) | 2026-05-18 | 2026-05-24 | 2026-05-21 +1 more |
| CVE-2026-46333 | ssh-keysign-pwn — 9-year ptrace race in Linux kernel __ptrace_may_access() reaches root + SSH host-key exfiltration; four public Qualys exploits on default major distros | 2026-05-23 | 2026-05-24 | 2026-05-23 |
| CVE-2026-5946 | ISC BIND 9 non-Internet CLASS DoS (CVSS 7.5), fixed 9.18.49/9.20.23 | 2026-05-24 | 2026-05-24 | 2026-05-24 |
| CVE-2019-13272 | Linux kernel ptrace credential-window LPE (Jann Horn, 2019) — historical predecessor cited as background in 2026-05-23 CVE-2026-46333 deep dive | 2026-05-23 | 2026-05-23 | — |
| CVE-2021-4034 | PwnKit — polkit pkexec local root (Qualys, 2022) — historical reference cited in 2026-05-23 CVE-2026-46333 deep dive as functional-equivalent outcome | 2026-05-23 | 2026-05-23 | — |
| CVE-2023-4911 | Looney Tunables — glibc ld.so local privilege escalation (Qualys, 2023) — historical reference cited in 2026-05-23 CVE-2026-46333 deep dive as disclosure-pattern precedent | 2026-05-23 | 2026-05-23 | — |
| CVE-2026-23652 | Microsoft Azure CVSS 10.0 cluster — server-side mitigated, no customer action required (MSRC May 2026) | 2026-05-22 | 2026-05-22 | — |
| CVE-2026-40411 | Microsoft Azure CVSS 10.0 cluster — server-side mitigated, no customer action required (MSRC May 2026) | 2026-05-22 | 2026-05-22 | — |
| CVE-2026-42823 | Microsoft Azure CVSS 10.0 cluster — server-side mitigated, no customer action required (MSRC May 2026) | 2026-05-22 | 2026-05-22 | — |
| CVE-2026-42901 | Microsoft Entra ID / Azure CVSS 10.0 cluster — server-side mitigated, no customer action required (MSRC May 2026) | 2026-05-22 | 2026-05-22 | — |
| CVE-2026-47280 | Microsoft Entra ID / Azure CVSS 10.0 cluster — server-side mitigated, no customer action required (MSRC May 2026) | 2026-05-22 | 2026-05-22 | — |
| CVE-2017-7692 | SquirrelMail post-auth RCE — used by Webworm against Serbian government targets per ESET 2026-05-20 (initial-access probe after credential theft) | 2026-05-21 | 2026-05-21 | — |
| CVE-2026-37978 | Keycloak admin evaluate-scopes endpoint cross-role PII leakage bypassing user-view permissions (Keycloak 26.6.2) | 2026-05-21 | 2026-05-21 | 2026-05-21 |
| CVE-2026-6856 | Keycloak WebAuthn packed self-attestation acceptable-AAGUID policy bypass enabling enrolment of hardware tokens outside policy (Keycloak 26.6.2) | 2026-05-21 | 2026-05-21 | 2026-05-21 |
| CVE-2026-26083 | Fortinet FortiSandbox unauthenticated RCE in Web UI (CWE-862, CVSS 9.1 vendor / 9.8 NVD) — pre-auth, patch in 4.4.9 / 5.0.2 / Cloud 5.0.6; Cloud 23/24 require migration | 2026-05-11 | 2026-05-20 | 2026-05-13 +1 more |
| CVE-2026-26956 | vm2 Node.js sandbox — symbol-to-string coercion TypeError sandbox bypass; patched 3.10.5 | 2026-05-20 | 2026-05-20 | 2026-05-20 |
| CVE-2026-31431 | Copy Fail — Linux kernel algif_aead local privilege escalation (ITW, KEV) | 2026-05-04 | 2026-05-20 | — |
| CVE-2026-43999 | vm2 NodeVM allow-list bypass — Module._load() reachable when child_process is explicitly permitted → OS command execution; CVSS 9.9 | 2026-05-20 | 2026-05-20 | 2026-05-20 |
| CVE-2026-44005 | vm2 prototype pollution via attacker-controlled JS; CVSS 10.0; affects 3.9.6 – 3.10.5; patched 3.11.0 | 2026-05-20 | 2026-05-20 | 2026-05-20 |
| CVE-2026-44006 | vm2 code injection via BaseHandler.getPrototypeOf; CVSS 10.0; patched 3.11.0 | 2026-05-20 | 2026-05-20 | 2026-05-20 |
| CVE-2026-44008 | vm2 null-proto exception exploitation; CVSS 9.8; affects ≤ 3.11.1; patched 3.11.2 | 2026-05-20 | 2026-05-20 | 2026-05-20 |
| CVE-2026-44009 | vm2 neutralizeArraySpeciesBatch() bypass via null-proto exception; CVSS 9.8; affects ≤ 3.11.1; patched 3.11.2 | 2026-05-20 | 2026-05-20 | 2026-05-20 |
| CVE-2026-44128 | SEPPmail Secure Email Gateway — unauthenticated RCE via exposed GINAv2 test endpoints (CVSS 9.3) | 2026-05-04 | 2026-05-20 | 2026-05-11 +1 more |
| CVE-2026-44277 | Fortinet FortiAuthenticator unauthenticated RCE in management interface (CWE-284, CVSS 9.8) — pre-auth, patch in 6.5.7 / 6.6.9 / 8.0.3 | 2026-05-11 | 2026-05-20 | 2026-05-13 +1 more |
| CVE-2026-45185 | Exim 4.97–4.99.2 GnuTLS builds — BDAT/CHUNKING use-after-free (Dead.Letter), pre-auth RCE (CVSS 9.8, ENISA EUVD critical); fixed in Exim 4.99.3 | 2026-05-13 | 2026-05-20 | 2026-05-13 |
| CVE-2026-41702 | VMware Fusion 25H2 (macOS) — TOCTOU SETUID race condition LPE (CVSS 7.8); dropped from § 2 in 2026-05-19 brief (did not clear inclusion gates) | 2026-05-19 | 2026-05-19 | — |
| CVE-2026-42232 | n8n HTTP Request Node injection — companion amplifier to CVE-2026-42231 prototype-pollution chain | 2026-05-19 | 2026-05-19 | 2026-05-19 |
| CVE-2026-44789 | n8n XML Node injection — companion amplifier to CVE-2026-42231 prototype-pollution chain | 2026-05-19 | 2026-05-19 | 2026-05-19 |
| CVE-2026-44790 | n8n Git node SSH chain — terminal sink of CVE-2026-42231 prototype-pollution to RCE | 2026-05-19 | 2026-05-19 | 2026-05-19 |
| CVE-2026-44791 | n8n XML Node injection — companion amplifier to CVE-2026-42231 prototype-pollution chain | 2026-05-19 | 2026-05-19 | 2026-05-19 |
| CVE-2026-46351 | BigBlueButton bbb-web < 3.0.21 — insecure sessionToken generation (CWE-330) enables session hijack | 2026-05-19 | 2026-05-19 | 2026-05-19 |
| CVE-2026-46353 | BigBlueButton bbb-web < 3.0.21 — presentationUploadExternalUrl API checksum bypass (CWE-284) | 2026-05-19 | 2026-05-19 | 2026-05-19 |
| CVE-2026-46404 | BigBlueButton bbb-web < 3.0.23 — SSRF in presentation URL validation (CWE-918) | 2026-05-19 | 2026-05-19 | 2026-05-19 |
| CVE-2023-33241 | Fireblocks GG18/GG20 Paillier missing-ZK-proof flaw (TSSHOCK class; cited as background-class for THORChain 2026-05-15 GG20 TSS exploit) | 2026-05-18 | 2026-05-18 | — |
| CVE-2025-54518 | AMD-SB-7052 — Zen 2 µop-cache corruption / SoC isolation LPE (CVSS 7.3 CVSS 4.0) | 2026-05-16 | 2026-05-18 | 2026-05-16 |
| CVE-2026-34260 | SAP S/4HANA Enterprise Search ABAP — authenticated SQL injection in SAP_BASIS 751–758 / 816 (CVSS 9.6) | 2026-05-11 | 2026-05-18 | 2026-05-13 +1 more |
| CVE-2026-34263 | SAP Commerce Cloud — unauthenticated arbitrary code execution via Spring Security misordering on cloud-config endpoint (CVSS 9.6, SAP Note 3733064) | 2026-05-11 | 2026-05-18 | 2026-05-13 +1 more |
| CVE-2026-41103 | Microsoft SSO Plugin for Jira/Confluence — unauthenticated Entra ID credential forgery (CVSS 9.1, More Likely exploitation) | 2026-05-13 | 2026-05-18 | 2026-05-13 |
| CVE-2026-41225 | F5 BIG-IP iControl REST Manager-role authenticated RCE (May 2026 Quarterly Notification, CVSS 9.1) | 2026-05-17 | 2026-05-18 | 2026-05-17 |
| CVE-2026-41553 | DHTMLX PDF Export Module — unauthenticated server-side JavaScript injection RCE (CVSS 4.0 score 10.0) | 2026-05-17 | 2026-05-18 | 2026-05-17 |
| CVE-2026-44088 | KIR SzafirHost — JAR zip-polyglot signature-verification bypass enabling RCE in Polish qualified e-signature browser helper (CVSS 8.6) | 2026-05-11 | 2026-05-18 | 2026-05-17 +1 more |
| CVE-2026-44112 | OpenClaw / Clawdbot — OpenShell sandbox TOCTOU write escape (CVSS 9.6, Claw Chain) | 2026-05-16 | 2026-05-18 | 2026-05-16 |
| CVE-2026-45691 | Nextcloud Server/Enterprise Server 2FA bypass via WebDAV pre-authenticated session token reuse | 2026-05-15 | 2026-05-18 | — |
| CVE-2026-45793 | PHP Composer GitHub Actions token disclosure in error messages (fixed in 2.9.8 / 2.2.28) | 2026-05-15 | 2026-05-18 | — |
| CVE-2026-7182 | DHTMLX Diagram export module — path traversal (CVSS 4.0 score 9.2) | 2026-05-17 | 2026-05-18 | 2026-05-17 |
| CVE-2026-8043 | Ivanti Xtraction < 2026.2 external control of file name/path (CWE-73, CVSS 9.6) — arbitrary file read + HTML write to web tree; auth required | 2026-05-14 | 2026-05-18 | 2026-05-14 |
| CVE-2023-38831 | WinRAR file-extension spoofing arbitrary code execution (cited as veteran exploit by Kaspersky Q1 2026 report) | 2026-05-10 | 2026-05-17 | — |
| CVE-2025-33073 | RelayKing NTLM relay — post-access primitive used by The Gentlemen RaaS | 2026-05-17 | 2026-05-17 | — |
| CVE-2025-69690 | Netgate pfSense Community Edition authenticated root RCE — vendor refuses to fix | 2026-05-11 | 2026-05-17 | 2026-05-11 |
| CVE-2025-69691 | Netgate pfSense Community Edition authenticated root RCE companion to CVE-2025-69690 — vendor refuses to fix | 2026-05-11 | 2026-05-17 | 2026-05-11 |
| CVE-2026-20122 | Cisco Catalyst SD-WAN companion CVE (exploited since March 2026) | 2026-05-15 | 2026-05-17 | — |
| CVE-2026-20128 | Cisco Catalyst SD-WAN companion CVE (exploited since March 2026) | 2026-05-15 | 2026-05-17 | — |
| CVE-2026-20133 | Cisco Catalyst SD-WAN companion CVE (exploited since March 2026) | 2026-05-15 | 2026-05-17 | — |
| CVE-2026-33634 | Checkmarx Jenkins AST plugin backdoor (TeamPCP/UNC6780 supply-chain compromise, SANDCLOCK credential stealer, CVSS 9.4) | 2026-05-12 | 2026-05-17 | 2026-05-12 |
| CVE-2026-34176 | F5 BIG-IP privilege escalation via misconfigured permissions (May 2026 Quarterly, CVSS 8.7) | 2026-05-17 | 2026-05-17 | — |
| CVE-2026-40061 | F5 BIG-IP privilege escalation via misconfigured permissions (May 2026 Quarterly, CVSS 8.7) | 2026-05-17 | 2026-05-17 | — |
| CVE-2026-40631 | F5 BIG-IP privilege escalation via misconfigured permissions (May 2026 Quarterly, CVSS 8.7) | 2026-05-17 | 2026-05-17 | — |
| CVE-2026-40698 | F5 BIG-IP SSH password exposure in iControl REST audit logs (May 2026 Quarterly, CVSS 8.7) | 2026-05-17 | 2026-05-17 | — |
| CVE-2026-41552 | DHTMLX PDF Export Module — path traversal via src attribute (CVSS 4.0 score 9.2) | 2026-05-17 | 2026-05-17 | 2026-05-17 |
| CVE-2026-41953 | F5 BIG-IP iControl REST command injection (May 2026 Quarterly, CVSS 8.7) | 2026-05-17 | 2026-05-17 | — |
| CVE-2026-42406 | F5 BIG-IP iControl REST command injection (May 2026 Quarterly, CVSS 8.7) | 2026-05-17 | 2026-05-17 | — |
| CVE-2026-42898 | Microsoft Dynamics 365 On-Premises — authenticated code injection with scope change (CVSS 9.9, May 2026 Patch Tuesday) | 2026-05-13 | 2026-05-17 | 2026-05-13 |
| CVE-2026-42924 | F5 BIG-IP iControl REST command injection (May 2026 Quarterly, CVSS 8.7) | 2026-05-17 | 2026-05-17 | — |
| CVE-2026-42930 | F5 BIG-IP iControl REST command injection (May 2026 Quarterly, CVSS 8.7) | 2026-05-17 | 2026-05-17 | — |
| CVE-2026-44113 | OpenClaw / Clawdbot — TOCTOU read escape / file disclosure (CVSS 7.7, Claw Chain) | 2026-05-16 | 2026-05-17 | 2026-05-16 |
| CVE-2026-44115 | OpenClaw / Clawdbot — command-parser allowlist bypass (CVSS 8.8, Claw Chain) | 2026-05-16 | 2026-05-17 | 2026-05-16 |
| CVE-2026-44118 | OpenClaw / Clawdbot — MCP loopback senderIsOwner privilege escalation (CVSS 7.8, Claw Chain) | 2026-05-16 | 2026-05-17 | 2026-05-16 |
| CVE-2026-4670 | Progress MOVEit Automation unauthenticated authentication bypass (CVSS 9.8) | 2026-05-06 | 2026-05-17 | — |
| CVE-2026-6073 | GitLab CE/EE — stored XSS in analytics dashboards (CVSS 8.7); cited as dropped from § 2 | 2026-05-17 | 2026-05-17 | — |
| CVE-2026-6722 | PHP SOAP extension UAF in SOAP_GLOBAL(ref_map) (with companions CVE-2026-7261, CVE-2026-7262); patched in PHP 8.4.8 / 8.3.22 / 8.2.30 | 2026-05-11 | 2026-05-17 | 2026-05-11 |
| CVE-2026-7261 | PHP SOAP companion to CVE-2026-6722; patched 2026-05-08 | 2026-05-11 | 2026-05-17 | 2026-05-11 |
| CVE-2026-7262 | PHP SOAP companion to CVE-2026-6722; patched 2026-05-08 | 2026-05-11 | 2026-05-17 | 2026-05-11 |
| CVE-2026-7377 | GitLab CE/EE — stored XSS in container registry virtual registry upstreams (CVSS 8.7); cited as dropped from § 2 | 2026-05-17 | 2026-05-17 | — |
| CVE-2026-7481 | GitLab CE/EE — stored XSS in Jira integration (CVSS 8.7); cited as dropped from § 2 | 2026-05-17 | 2026-05-17 | — |
| CVE-2021-34473 | Microsoft Exchange Server pre-auth RCE (ProxyShell) — cited in 2026-05-16 § 5 deep dive Background | 2026-05-16 | 2026-05-16 | — |
| CVE-2023-42793 | JetBrains TeamCity authentication bypass — cited in 2026-05-16 § 3 SentinelOne CI/CD subversion case study | 2026-05-16 | 2026-05-16 | — |
| CVE-2022-20775 | Cisco SD-WAN local privilege escalation (UAT-8616 version-downgrade re-exploitation technique) | 2026-05-15 | 2026-05-15 | — |
| CVE-2026-33825 | BlueHammer — Windows zero-day by Nightmare Eclipse (confirmed ITW by Huntress, April 2026) | 2026-05-15 | 2026-05-15 | — |
| CVE-2026-45690 | Nextcloud Server SQL injection in column-type parameter (Moderate) | 2026-05-15 | 2026-05-15 | — |
| CVE-2026-8511 | Google Chrome CVE (mentioned in recency-dropped items, 2026-05-12) | 2026-05-15 | 2026-05-15 | — |
| CVE-2026-8580 | Google Chrome CVE (mentioned in recency-dropped items, 2026-05-12) | 2026-05-15 | 2026-05-15 | — |
| CVE-2022-41040 | Microsoft Exchange Server SSRF (ProxyNotShell) — cited as initial-access vector in 2026-05-14 FamousSparrow deep dive; chained with CVE-2022-41082 | 2026-05-14 | 2026-05-14 | — |
| CVE-2022-41082 | Microsoft Exchange Server PowerShell remoting deserialization RCE (ProxyNotShell) — cited as initial-access vector in 2026-05-14 FamousSparrow deep dive; chained with CVE-2022-41040 | 2026-05-14 | 2026-05-14 | — |
| CVE-2026-23819 | HPE ArubaOS AOS-10 stored XSS in web management interface (CVSS 8.8) — referenced in 2026-05-14 § 7 drop note (gate not cleared) | 2026-05-14 | 2026-05-14 | — |
| CVE-2026-44211 | Cline kanban npm package cross-origin WebSocket hijack (CVSS 9.6) — referenced in 2026-05-14 § 7 drop note (out-of-window) | 2026-05-14 | 2026-05-14 | — |
| CVE-2026-34259 | SAP Forecasting & Replenishment — authenticated OS-command injection (CVSS 8.2, SAP May 2026 patch day) | 2026-05-13 | 2026-05-13 | — |
| CVE-2026-40361 | Microsoft Word Preview Pane RCE (CVSS 8.4, More Likely exploitation, May 2026 Patch Tuesday) | 2026-05-13 | 2026-05-13 | — |
| CVE-2026-40364 | Microsoft Word Preview Pane RCE (CVSS 8.4, More Likely exploitation, May 2026 Patch Tuesday) | 2026-05-13 | 2026-05-13 | — |
| CVE-2026-40366 | Microsoft Word Preview Pane RCE (CVSS 8.4, May 2026 Patch Tuesday) | 2026-05-13 | 2026-05-13 | — |
| CVE-2026-40367 | Microsoft Word Preview Pane RCE (CVSS 8.4, May 2026 Patch Tuesday) | 2026-05-13 | 2026-05-13 | — |
| CVE-2026-40478 | Earlier Thymeleaf CVE referenced in § 7 disambiguating the dropped Thymeleaf item; CSO Online article 2026-04-17 covered this CVE rather than CVE-2026-41901 | 2026-05-13 | 2026-05-13 | — |
| CVE-2026-41901 | Thymeleaf SSTI sandbox bypass — referenced in § 7 explaining out-of-window drop (GHSA published 2026-04-29) | 2026-05-13 | 2026-05-13 | — |
| CVE-2024-1708 | ConnectWise ScreenConnect path traversal — chained with CVE-2024-1709 by Kimsuky/Storm-1175; KEV deadline 2026-05-12 (out-of-window per § 7 of 2026-05-12 brief) | 2026-05-12 | 2026-05-12 | — |
| CVE-2024-1709 | ConnectWise ScreenConnect authentication bypass (CVSS 10.0) — chained with CVE-2024-1708; cited as 2026-05-12 drop | 2026-05-12 | 2026-05-12 | — |
| CVE-2026-0073 | Android adbd wireless ADB authentication bypass (CVSS 8.8, adjacent-network, public PoC 2026-05-11) — § 2 gate not cleared | 2026-05-12 | 2026-05-12 | — |
| CVE-2026-5786 | Ivanti EPMM remote authenticated → administrative-access via improper access control (CVSS 8.8, May 2026 update) | 2026-05-04 | 2026-05-12 | 2026-05-10 |
| CVE-2026-5787 | Ivanti EPMM on-prem improper certificate validation → pre-auth Sentry impersonation (CVSS 9.1, ITW, KEV chain) | 2026-05-04 | 2026-05-12 | 2026-05-10 +1 more |
| CVE-2026-5788 | Ivanti EPMM unauthenticated arbitrary method invocation (CVSS 7.0, May 2026 update) | 2026-05-04 | 2026-05-12 | 2026-05-10 |
| CVE-2026-6973 | Ivanti EPMM on-prem admin API improper input validation → RCE (CVSS 7.2, ITW, KEV deadline 2026-05-10) | 2026-05-04 | 2026-05-12 | 2026-05-10 +1 more |
| CVE-2026-7821 | Ivanti EPMM — fourth companion CVE in May 2026 EPMM update (high-severity per BleepingComputer / SecurityWeek) | 2026-05-04 | 2026-05-12 | 2026-05-10 |
| CVE-2017-11882 | Microsoft Office Equation Editor RCE (cited as veteran exploit by Kaspersky Q1 2026 exploit report) | 2026-05-10 | 2026-05-10 | — |
| CVE-2018-0802 | Microsoft Office Equation Editor RCE (cited as largest-share detected exploit by Kaspersky Q1 2026 report) | 2026-05-10 | 2026-05-10 | — |
| CVE-2023-35078 | Ivanti EPMM pre-auth API access (2023, exploited by APT29; cited as historical precedent in 2026-05-08 deep dive) | 2026-05-08 | 2026-05-10 | — |
| CVE-2024-57726 | SimpleHelp RMM unauthenticated privilege escalation (ITW) | 2026-05-07 | 2026-05-10 | — |
| CVE-2024-57728 | SimpleHelp RMM path traversal — unauthenticated file download (ITW) | 2026-05-07 | 2026-05-10 | — |
| CVE-2024-7399 | Samsung MagicINFO 9 Server unauthenticated arbitrary file write → RCE (CVSS 8.8, ITW) | 2026-05-07 | 2026-05-10 | — |
| CVE-2025-0283 | Ivanti EPMM critical (January 2025, state-actor exploitation; cited as historical precedent in 2026-05-08 deep dive) | 2026-05-08 | 2026-05-10 | — |
| CVE-2025-29927 | Next.js middleware authorisation bypass via crafted header — weaponised by PCPJack worm | 2026-05-10 | 2026-05-10 | — |
| CVE-2025-48703 | CentOS Web Panel FileManager shell injection — weaponised by PCPJack worm | 2026-05-10 | 2026-05-10 | — |
| CVE-2025-68670 | xrdp pre-authentication stack buffer overflow → RCE | 2026-05-09 | 2026-05-10 | 2026-05-09 |
| CVE-2025-9501 | W3 Total Cache PHP injection via mfunc comment processor — weaponised by PCPJack worm | 2026-05-10 | 2026-05-10 | — |
| CVE-2026-1281 | Ivanti EPMM January 2026 critical — historical precedent cited in 2026-05-09 Ivanti UPDATE | 2026-05-09 | 2026-05-10 | — |
| CVE-2026-1340 | Ivanti EPMM January 2026 critical companion — historical precedent cited in 2026-05-09 Ivanti UPDATE | 2026-05-09 | 2026-05-10 | — |
| CVE-2026-1357 | WPVivid Backup unauthenticated file upload — weaponised by PCPJack worm | 2026-05-10 | 2026-05-10 | — |
| CVE-2026-20034 | Cisco Unity Connection authenticated RCE in management API (CVSS 8.8, NATO NCSC discovery; logged § 7 — dropped from § 2, gate not cleared) | 2026-05-10 | 2026-05-10 | — |
| CVE-2026-20035 | Cisco Unity Connection unauthenticated SSRF in default-enabled Web Inbox (CVSS 7.2; logged § 7 — dropped from § 2, gate not cleared) | 2026-05-10 | 2026-05-10 | — |
| CVE-2026-21510 | Windows Shell LNK exploit predecessor — APT28 weaponised against Ukraine and EU; February 2026 patch left CVE-2026-32202 residual | 2026-05-04 | 2026-05-10 | — |
| CVE-2026-23918 | Apache HTTP Server 2.4.66 HTTP/2 double-free — DoS and potential RCE (CVSS 8.8) | 2026-05-06 | 2026-05-10 | — |
| CVE-2026-23926 | Zabbix frontend stored XSS in map element labels (CVSS 6.1) | 2026-05-07 | 2026-05-10 | — |
| CVE-2026-23927 | Zabbix API confidentiality — unprivileged user can read admin host data (CVSS 5.3) | 2026-05-07 | 2026-05-10 | — |
| CVE-2026-23928 | Zabbix frontend reflected XSS in host-group filter (CVSS 6.1) | 2026-05-07 | 2026-05-10 | — |
| CVE-2026-25592 | Microsoft Semantic Kernel .NET SDK — unintended [KernelFunction] on SessionsPythonPlugin Download/UploadFileAsync → arbitrary file write → sandbox escape (CVSS 9.9) | 2026-05-04 | 2026-05-10 | 2026-05-10 |
| CVE-2026-26030 | Microsoft Semantic Kernel Python SDK — prompt-injection-to-RCE via InMemoryVectorStore filter (CVSS 9.9, PoC public) | 2026-05-04 | 2026-05-10 | 2026-05-10 |
| CVE-2026-28780 | Apache httpd mod_proxy_ajp heap overflow → remote crash / potential RCE (CVSS 7.5) | 2026-05-07 | 2026-05-10 | — |
| CVE-2026-29201 | cPanel/WHM CVE cluster — dropped from § 3 (embargoed, gate not cleared) | 2026-05-04 | 2026-05-10 | 2026-05-10 |
| CVE-2026-29202 | cPanel/WHM CVE cluster — dropped from § 3 (embargoed, gate not cleared) | 2026-05-04 | 2026-05-10 | 2026-05-10 |
| CVE-2026-29203 | cPanel/WHM unsafe symlink handling — chmod abuse on arbitrary files (CVSS 8.8, second emergency TSR) | 2026-05-04 | 2026-05-10 | 2026-05-10 |
| CVE-2026-32202 | Windows Shell protection mechanism failure → NTLM coercion / spoofing (CVSS 4.3, APT28 ITW, KEV deadline 2026-05-12) | 2026-05-04 | 2026-05-10 | 2026-05-08 |
| CVE-2026-32305 | Traefik proxy mTLS bypass via fragmented TLS ClientHello | 2026-05-06 | 2026-05-10 | — |
| CVE-2026-32312 | GLPI < 10.0.25 / 11.0.7 SSRF (CERTFR-2026-AVI-0551) | 2026-05-08 | 2026-05-10 | 2026-05-08 |
| CVE-2026-33725 | Metabase Enterprise Java serialization → authenticated RCE (CVSS 8.8) | 2026-05-07 | 2026-05-10 | — |
| CVE-2026-40108 | GLPI < 10.0.25 / 11.0.7 data integrity compromise (CERTFR-2026-AVI-0551) | 2026-05-08 | 2026-05-10 | 2026-05-08 |
| CVE-2026-40981 | Spring Cloud Config Server Google Secrets Manager backend flaw (HIGH) | 2026-05-09 | 2026-05-10 | — |
| CVE-2026-40982 | Spring Cloud Config Server pre-auth directory traversal (CVSS 9.8) | 2026-05-09 | 2026-05-10 | 2026-05-09 |
| CVE-2026-41002 | Spring Cloud Config Server companion CVE (HIGH) | 2026-05-09 | 2026-05-10 | — |
| CVE-2026-41004 | Spring Cloud Config Server companion CVE (MEDIUM) | 2026-05-09 | 2026-05-10 | — |
| CVE-2026-41940 | cPanel/WHM authentication bypass via CRLF injection (mass exploitation ongoing, KEV) | 2026-05-06 | 2026-05-10 | — |
| CVE-2026-42208 | LiteLLM Proxy pre-auth SQL injection — all upstream LLM API keys at risk (CVSS 9.3, KEV deadline 2026-05-11) | 2026-05-04 | 2026-05-10 | 2026-05-09 |
| CVE-2026-42317 | GLPI < 10.0.25 / 11.0.7 XSS (CERTFR-2026-AVI-0551) | 2026-05-08 | 2026-05-10 | 2026-05-08 |
| CVE-2026-42318 | GLPI < 10.0.25 / 11.0.7 XSS (CERTFR-2026-AVI-0551) | 2026-05-08 | 2026-05-10 | 2026-05-08 |
| CVE-2026-42320 | GLPI < 10.0.25 / 11.0.7 XSS (CERTFR-2026-AVI-0551) | 2026-05-08 | 2026-05-10 | 2026-05-08 |
| CVE-2026-42321 | GLPI < 10.0.25 / 11.0.7 XSS (CERTFR-2026-AVI-0551) | 2026-05-08 | 2026-05-10 | 2026-05-08 |
| CVE-2026-44125 | SEPPmail GINAv2 — missing authentication in admin REST API (CVSS 9.3) | 2026-05-04 | 2026-05-10 | 2026-05-09 |
| CVE-2026-44126 | SEPPmail GINAv2 — insecure deserialisation via session cookie → RCE (CVSS 9.2) | 2026-05-04 | 2026-05-10 | 2026-05-09 |
| CVE-2026-44127 | SEPPmail appliance management — LFI and arbitrary file deletion (CVSS 8.8) | 2026-05-04 | 2026-05-10 | 2026-05-09 |
| CVE-2026-44129 | SEPPmail GINAv2 — server-side template injection via Freemarker (CVSS 8.3) | 2026-05-04 | 2026-05-10 | 2026-05-09 |
| CVE-2026-5174 | Progress MOVEit Automation authenticated privilege escalation (CVSS 8.8) | 2026-05-06 | 2026-05-10 | — |
| CVE-2026-5385 | GLPI < 10.0.25 / 11.0.7 security policy bypass / auth bypass (CERTFR-2026-AVI-0551) | 2026-05-08 | 2026-05-10 | 2026-05-08 |
| CVE-2026-6022 | Progress Telerik RadAsyncUpload DoS via path traversal (CVSS 7.5) | 2026-05-07 | 2026-05-10 | — |
| CVE-2026-6023 | Progress Telerik RadFilter deserialization → unauthenticated RCE (CVSS 9.8) | 2026-05-07 | 2026-05-10 | — |
| CVE-2026-7864 | SEPPmail appliance management — information disclosure (CVSS 6.9) | 2026-05-04 | 2026-05-10 | 2026-05-09 |
| CVE-2026-25077 | Apache CloudStack post-auth authentication token flaw — dropped from § 3 (gate not cleared) | 2026-05-09 | 2026-05-09 | — |
| CVE-2026-21509 | Microsoft Office Protected View bypass — security feature bypass (CVSS 7.8, KEV deadline 2026-02-16 already passed; deferred from §4) | 2026-05-08 | 2026-05-08 | — |
| CVE-2026-21513 | Microsoft Office Protected View chain CVE (deferred from §4; see CVE-2026-21509 series) | 2026-05-08 | 2026-05-08 | — |
| CVE-2026-21514 | Microsoft Office Protected View chain CVE (deferred from §4; see CVE-2026-21509 series) | 2026-05-08 | 2026-05-08 | — |