VulnSea

Daily digest

Wednesday 3 June 2026

A busier-than-usual day with 47 new CVEs (recent average about 38). Severity skewed high: 5 critical and 22 high, 57% of the total. One arrived with exploitation evidence or public exploit code already attached. mbs-solutions was the most-affected vendor with 11.

47
New CVEs
5
Critical
0
KEV additions
0
Records changed

New this day, ranked by depth score

The 12 that matter most of the 47 published.

CVE-2026-47065Critical· 9.8
3mo ago

ZDRES-232: resolveProxyClass Not Overridden - acceptMatchers Filter Bypass via java.lang.reflect.Proxy Assessment: Fully addressed. When the serialised stream contains a TC_PROXYCLASSDESC (the marker for a java.lang.reflect.Proxy ),…

ZDRES-232: resolveProxyClass Not Overridden - acceptMatchers Filter Bypass via java.lang.reflect.Proxy Assessment: Fully addressed. When the serialised stream contains a TC_PROXYCLASSDESC (the marker for a java.lang.reflect.Proxy ),…

▾ Midnightapache · minaEPSS 0.50%via NVD
CVE-2026-35075Critical· 9.8
3mo ago

An unauthenticated remote attacker can recover a default, hard coded password from a firmware image and thus gain full access to all affected devices.

An unauthenticated remote attacker can recover a default, hard coded password from a firmware image and thus gain full access to all affected devices.

▾ Midnightmbs-solutions · universal_gateway_firmwareEPSS 0.59%via NVD
CVE-2026-46266Critical· 9.1⚖ disputed
3mo ago

In the Linux kernel, the following vulnerability has been resolved: inet: RAW sockets using IPPROTO_RAW MUST drop incoming ICMP Yizhou Zhao reported that simply having one RAW socket on protocol IPPROTO_RAW (255) was dangerous. sock…

In the Linux kernel, the following vulnerability has been resolved: inet: RAW sockets using IPPROTO_RAW MUST drop incoming ICMP Yizhou Zhao reported that simply having one RAW socket on protocol IPPROTO_RAW (255) was dangerous. sock…

▾ Midnightlinux · linux_kernelEPSS 0.70%via NVD
CVE-2026-46244Critical· 9.1
3mo ago

In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_inner: Fix IPv6 inner_thoff desync In nft_inner_parse_l2l3(), when processing inner IPv6 packets, ipv6_find_hdr() correctly computes the transport heade…

In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_inner: Fix IPv6 inner_thoff desync In nft_inner_parse_l2l3(), when processing inner IPv6 packets, ipv6_find_hdr() correctly computes the transport heade…

▾ Midnightlinux · linux_kernelEPSS 0.46%via NVD
CVE-2026-4035Critical· 9.1
3mo ago

MLflow: Environment variable injection in AI Gateway secrets enables server-side credential exfiltration

MLflow: Environment variable injection in AI Gateway secrets enables server-side credential exfiltration

▾ Midnightmlflow · mlflowEPSS 0.66%via OSV
CVE-2026-35085High· 8.8
3mo ago

A remote attacker with user privileges can exploit a stack buffer overflow in gdv-serverconfig to gain full system access as root.

A remote attacker with user privileges can exploit a stack buffer overflow in gdv-serverconfig to gain full system access as root.

▾ Twilightmbs-solutions · universal_gateway_firmwareEPSS 0.58%via NVD
CVE-2026-35084High· 8.8
3mo ago

A remote attacker with user privileges can exploit a stack buffer overflow in dali-devconfig to gain full system access as root.

A remote attacker with user privileges can exploit a stack buffer overflow in dali-devconfig to gain full system access as root.

▾ Twilightmbs-solutions · universal_gateway_firmwareEPSS 0.58%via NVD
CVE-2026-35083High· 8.8
3mo ago

A remote attacker with user privileges can exploit a stack buffer overflow to gain full system access as root.

A remote attacker with user privileges can exploit a stack buffer overflow to gain full system access as root.

▾ Twilightmbs-solutions · universal_gateway_firmwareEPSS 0.58%via NVD
CVE-2026-35082High· 8.8
3mo ago

The ugw-logread method allows a remote attacker with user privileges to access arbitrary local files due to insufficient validation of user-supplied input.

The ugw-logread method allows a remote attacker with user privileges to access arbitrary local files due to insufficient validation of user-supplied input.

▾ Twilightmbs-solutions · universal_gateway_firmwareEPSS 0.68%via NVD
CVE-2026-6657High· 8.8
3mo ago

A vulnerability in jupyter-server versions 1.12.0 through 2.17.0 allows an attacker to bypass CORS origin validation when the `allow_origin_pat` configuration is used

A vulnerability in jupyter-server versions 1.12.0 through 2.17.0 allows an attacker to bypass CORS origin validation when the `allow_origin_pat` configuration is used. The issue arises from the use of `re.match()` for validating the `Ori…

▾ Twilightjupyter · jupyter_serverEPSS 0.27%via NVD
CVE-2026-26824Medium· 6.5PoC
3mo ago

libxls through version 1.6.3 contains a use of uninitialized memory vulnerability in the OLE container parser

libxls through version 1.6.3 contains a use of uninitialized memory vulnerability in the OLE container parser. Memory allocated for the Master Sector Allocation Table (MSAT) in read_MSAT() is not fully initialized before being consumed b…

▾ Twilightlibxls_project · libxlsEPSS 0.45%via NVD
CVE-2026-22055High· 8.8
3mo ago

Active IQ OneCollect version 2.7.3 contains hard-coded credentials that could allow an authenticated attacker with low privileges to perform unauthorized AutoSupport operations.

Active IQ OneCollect version 2.7.3 contains hard-coded credentials that could allow an authenticated attacker with low privileges to perform unauthorized AutoSupport operations.

▾ Twilightnetapp · active_iq_onecollectEPSS 0.24%via NVD

Most-affected vendors

By CVEs published in the period.