Daily digest
Monday 1 June 2026
A heavy day: 81 new CVEs, well above the recent average of about 25. Severity skewed high: 4 critical and 41 high, 56% of the total. 6 arrived with exploitation evidence or public exploit code already attached. google was the most-affected vendor with 19.
New this day, ranked by depth score
The 12 that matter most of the 81 published.
CVE-2024-52011High· 8.3PoClaunch-editor allows users to open files with line numbers in editor from Node.js
launch-editor allows users to open files with line numbers in editor from Node.js. Prior to version 2.9.0, due to the insufficient sanitization of the `file` argument in the `launchEditor`, an attacker can execute arbitrary commands on W…
CVE-2026-0091High· 7.8PoCIn multiple locations, there is a possible way to execute code in the launcher process due to an over-privileged shell user
In multiple locations, there is a possible way to execute code in the launcher process due to an over-privileged shell user. This could lead to local escalation of privilege with no additional execution privileges needed. User interactio…
CVE-2026-0009High· 7.8PoCIn multiple locations, there is a possible tapjacking due to a logic error in the code
In multiple locations, there is a possible tapjacking due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
CVE-2026-10290High· 7.3PoCA weakness has been identified in code-projects Hotel and Tourism Reservation System 1.0
A weakness has been identified in code-projects Hotel and Tourism Reservation System 1.0. The affected element is an unknown function of the file tour.php of the component GET Parameter Handler. Executing a manipulation of the argument t…
CVE-2026-46243High· 7.1PoCIn the Linux kernel, the following vulnerability has been resolved: smb: client: reject userspace cifs.spnego descriptions cifs.spnego key descriptions contain authority-bearing fields such as pid, uid, creduid, and upcall_target that …
In the Linux kernel, the following vulnerability has been resolved: smb: client: reject userspace cifs.spnego descriptions cifs.spnego key descriptions contain authority-bearing fields such as pid, uid, creduid, and upcall_target that …
CVE-2026-9319Critical· 9.0IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to potential remote code execution due to deserialization of untrusted data via JAX-WS endpoints with WS-Security.
IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to potential remote code execution due to deserialization of untrusted data via JAX-WS endpoints with WS-Security.
CVE-2026-9311Critical· 9.0IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to remote code execution caused by the bypass of security controls.
IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to remote code execution caused by the bypass of security controls.
CVE-2026-8644Critical· 9.1IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to identity spoofing.
IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to identity spoofing.
CVE-2026-42252Critical· 9.1Apache Airflow vulnerable to Improper Neutralization of Special Elements Used in a Template Engine
Apache Airflow vulnerable to Improper Neutralization of Special Elements Used in a Template Engine
CVE-2026-7770High· 8.8IBM i Access Family 1.1.5.0 through 1.1.9.12 IBM i Access Client Solutions (ACS) is vulnerable to remote code execution when configured to listen for requests from IBM i Navigator.
IBM i Access Family 1.1.5.0 through 1.1.9.12 IBM i Access Client Solutions (ACS) is vulnerable to remote code execution when configured to listen for requests from IBM i Navigator.
CVE-2026-49298High· 8.8Apache Airflow: Execution API JWT leaked via KubernetesExecutor worker command-line args
Apache Airflow: Execution API JWT leaked via KubernetesExecutor worker command-line args
CVE-2026-42359High· 8.8Apache Airflow has a Deserialization of Untrusted Data vulnerability
Apache Airflow has a Deserialization of Untrusted Data vulnerability
Most-affected vendors
By CVEs published in the period.