VulnSea

Daily digest

Thursday 4 June 2026

33 new CVEs this day, in line with the recent average. Of those, 5 critical and 5 high. One arrived with exploitation evidence or public exploit code already attached. Microsoft was the most-affected vendor with 6.

33
New CVEs
5
Critical
0
KEV additions
0
Records changed

New this day, ranked by depth score

The 12 that matter most of the 33 published.

CVE-2026-8037Critical· 9.6CISA KEVPoC
3mo ago

OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an un-authenticated attacker to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in multiple command en…

OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an un-authenticated attacker to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in multiple command en…

▾ Hadalprogress · connection_manager_for_objectscaleEPSS 77%via NVD
CVE-2026-48567Critical· 10.0
3mo ago

Azure HorizonDB Elevation of Privilege Vulnerability

Authentication bypass by spoofing in Azure HorizonDB allows an unauthorized attacker to elevate privileges over a network.

▾ MidnightMicrosoft · Azure HorizonDBEPSS 0.92%via CVEORG
CVE-2026-41283Critical· 9.9
3mo ago

OpenStack Mistral allows Arbitrary Remote Code Execution when the API is exposed

OpenStack Mistral allows Arbitrary Remote Code Execution when the API is exposed

▾ Midnightmistral · mistralEPSS 0.92%via OSV
CVE-2026-25550Critical· 9.8
3mo ago

Seagull Software BarTender 2010, 2016, and 2019 contain an unauthenticated remote code execution vulnerability in the .NET Remoting service exposed on TCP port 7375 via BtSystem.Service.exe

Seagull Software BarTender 2010, 2016, and 2019 contain an unauthenticated remote code execution vulnerability in the .NET Remoting service exposed on TCP port 7375 via BtSystem.Service.exe. The service registers an unauthenticated singl…

▾ MidnightSeagull Software, LLC. · BarTender 2010EPSS 1.4%via NVD
CVE-2026-48579Critical· 9.1
3mo ago

Microsoft Exchange Online Information Disclosure Vulnerability

Improper authorization in Microsoft Exchange Online allows an unauthorized attacker to disclose information over a network.

▾ MidnightMicrosoft · Microsoft Exchange OnlineEPSS 1.00%via CVEORG
CVE-2026-25551High· 7.8
3mo ago

Seagull Software BarTender 2021 R1 through 12.0.1 contains an insecure deserialization vulnerability that allows low-privileged local users to escalate privileges

Seagull Software BarTender 2021 R1 through 12.0.1 contains an insecure deserialization vulnerability that allows low-privileged local users to escalate privileges. The DataServiceSingleton .NET Remoting endpoint is bound to localhost on …

▾ TwilightEPSS 0.36%via NVD
CVE-2026-45497High· 7.7
3mo ago

Microsoft M365 Copilot Remote Code Execution Vulnerability

Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an authorized attacker to execute code over a network.

▾ TwilightMicrosoft · Microsoft 365 CopilotEPSS 0.61%via CVEORG
CVE-2026-44393High· 7.4
3mo ago

OpenStack oslo.messaging does not verify RabbitMQ broker hostname during TLS handshake

OpenStack oslo.messaging does not verify RabbitMQ broker hostname during TLS handshake

▾ Twilightoslo-messaging · oslo-messagingEPSS 0.28%via OSV
CVE-2026-41178High· 7.5
3mo ago

github.com/open-telemetry/opentelemetry-go: go.opentelemetry.io/otel/baggage: go.opentelemetry.io/otel/propagation: OpenTelemetry-Go: Denia…

A flaw was found in OpenTelemetry-Go. This vulnerability allows a remote attacker to cause a Denial of Service (DoS) by sending oversized or invalid baggage headers. The `Parse` function, in affected versions, failed to reject raw-length i…

▾ TwilightRed Hat · Red Hat Openshift Data Foundation 4.22EPSS 0.34%via CSAF
CVE-2026-10840High· 7.1
3mo ago

A flaw was found in the OpenShift Pipelines operator

A flaw was found in the OpenShift Pipelines operator. The tekton-scheduler-rolebinding ClusterRoleBinding grants the system:authenticated group write access to Kueue and cert-manager custom resources via the tekton-scheduler-role Cluster…

▾ TwilightEPSS 0.22%via NVD
CVE-2026-7764Medium· 6.8
3mo ago

An out-of-bounds read vulnerability in the morse.ko HaLow Wi-Fi kernel driver in Morse Micro HaLowLink 2 software versions prior to 2.11.12 allows an unauthenticated attacker within radio range to disclose a small amount of kernel heap m…

An out-of-bounds read vulnerability in the morse.ko HaLow Wi-Fi kernel driver in Morse Micro HaLowLink 2 software versions prior to 2.11.12 allows an unauthenticated attacker within radio range to disclose a small amount of kernel heap m…

▾ Sunlitmorsemicro · halowlink_2_firmwareEPSS 0.19%via NVD
CVE-2026-10805Medium· 6.7
3mo ago

A flaw was found in NetworkManager

A flaw was found in NetworkManager. This local privilege escalation vulnerability exists in NetworkManager's dhclient backend when processing malformed Manufacturer Usage Description (MUD) URLs. A local user can exploit this flaw to esca…

▾ SunlitRed Hat · NetworkManagerEPSS 0.17%via NVD

Most-affected vendors

By CVEs published in the period.