VulnSea

Daily digest

Monday 8 June 2026

A heavy day: 85 new CVEs, well above the recent average of about 30. Of those, 4 critical and 26 high. 3 arrived with exploitation evidence or public exploit code already attached. CISA added one CVE to the Known Exploited Vulnerabilities catalog. juev was the most-affected vendor with 5.

85
New CVEs
4
Critical
1
KEV additions
0
Records changed

Added to CISA KEV

Confirmed exploitation in the wild — federal remediation deadlines attach to these.

New this day, ranked by depth score

The 12 that matter most of the 85 published.

CVE-2026-45034CriticalPoC
3mo ago

PHPSpreadsheet has a patch bypass for CVE-2026-34084

PHPSpreadsheet has a patch bypass for CVE-2026-34084

▾ Abyssalphpoffice · phpoffice/phpspreadsheetEPSS 0.46%via GHSA
CVE-2026-47724Critical· 9.9
3mo ago

nebula-mesh: API endpoints lack ownership checks, enabling cross-operator privilege escalation

nebula-mesh: API endpoints lack ownership checks, enabling cross-operator privilege escalation

▾ Midnightjuev · github.com/juev/nebula-meshEPSS 0.48%via GHSA
CVE-2026-46275High· 7.8PoC
3mo ago

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_uart: fix UAFs and race conditions in close and init paths Vulnerabilities leading to Use-After-Free (UAF) and Null Pointer Dereference (NPD) conditions…

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_uart: fix UAFs and race conditions in close and init paths Vulnerabilities leading to Use-After-Free (UAF) and Null Pointer Dereference (NPD) conditions…

▾ MidnightEPSS 0.13%via NVD
CVE-2026-46289Critical· 9.8
3mo ago

In the Linux kernel, the following vulnerability has been resolved: lib/scatterlist: fix length calculations in extract_kvec_to_sg Patch series "Fix bugs in extract_iter_to_sg()", v3. Fix bugs in the kvec and user variants of extract_…

In the Linux kernel, the following vulnerability has been resolved: lib/scatterlist: fix length calculations in extract_kvec_to_sg Patch series "Fix bugs in extract_iter_to_sg()", v3. Fix bugs in the kvec and user variants of extract_…

▾ MidnightEPSS 0.67%via NVD
CVE-2026-42536High· 7.5PoC
3mo ago

Heap-based Buffer Overflow vulnerability in Apache HTTP Server with mod_xml2enc, xml2StartParse, and untrusted content This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67. Users are recommended to upgrade to version 2.4.68…

Heap-based Buffer Overflow vulnerability in Apache HTTP Server with mod_xml2enc, xml2StartParse, and untrusted content This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67. Users are recommended to upgrade to version 2.4.68…

▾ Midnightapache · http_serverEPSS 2.7%via NVD
CVE-2026-47430Critical
3mo ago

Cordova Plugin InAppBrowser: iOS: Arbitrary Cordova callback IDs can be dispatched without validation from InAppBrowser WebViews.

Cordova Plugin InAppBrowser: iOS: Arbitrary Cordova callback IDs can be dispatched without validation from InAppBrowser WebViews.

▾ Midnightcordova-plugin-inappbrowser · cordova-plugin-inappbrowserEPSS 0.77%via GHSA
CVE-2026-39910High· 8.8
3mo ago

STACKIT IaaS API contains a missing authorization check vulnerability that allows authenticated, low-privileged attackers to escalate privileges to full organization compromise by attaching arbitrary service accounts to virtual machines …

STACKIT IaaS API contains a missing authorization check vulnerability that allows authenticated, low-privileged attackers to escalate privileges to full organization compromise by attaching arbitrary service accounts to virtual machines …

▾ TwilightEPSS 0.47%via NVD
CVE-2026-46307High· 8.3
3mo ago

In the Linux kernel, the following vulnerability has been resolved: wifi: ath5k: do not access array OOB Vincent reports: > The ath5k driver seems to do an array-index-out-of-bounds access as > shown by the UBSAN kernel message: > UBSA…

In the Linux kernel, the following vulnerability has been resolved: wifi: ath5k: do not access array OOB Vincent reports: > The ath5k driver seems to do an array-index-out-of-bounds access as > shown by the UBSAN kernel message: > UBSA…

▾ TwilightEPSS 0.35%via NVD
CVE-2026-46288High· 8.4
3mo ago

In the Linux kernel, the following vulnerability has been resolved: of: unittest: fix use-after-free in of_unittest_changeset() The variable 'parent' is assigned the value of 'nchangeset' earlier in the function, meaning both point to …

In the Linux kernel, the following vulnerability has been resolved: of: unittest: fix use-after-free in of_unittest_changeset() The variable 'parent' is assigned the value of 'nchangeset' earlier in the function, meaning both point to …

▾ TwilightEPSS 0.19%via NVD
CVE-2026-46303High· 8.2
3mo ago

In the Linux kernel, the following vulnerability has been resolved: isofs: validate Rock Ridge CE continuation extent against volume size rock_continue() reads rs->cont_extent verbatim from the Rock Ridge CE record and passes it to sb_…

In the Linux kernel, the following vulnerability has been resolved: isofs: validate Rock Ridge CE continuation extent against volume size rock_continue() reads rs->cont_extent verbatim from the Rock Ridge CE record and passes it to sb_…

▾ Twilightlinux · linux_kernelEPSS 0.55%via NVD
CVE-2026-46311High· 7.8
3mo ago

In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/userq: fix access to stale wptr mapping Use drm_exec to take both locks i.e vm root bo and wptr_obj bo to access the mapping data properly. This fixes the …

In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/userq: fix access to stale wptr mapping Use drm_exec to take both locks i.e vm root bo and wptr_obj bo to access the mapping data properly. This fixes the …

▾ TwilightRed Hat · Red Hat Enterprise Linux BaseOS (v. 10)EPSS 0.17%via NVD
CVE-2026-46280High· 7.8
3mo ago

In the Linux kernel, the following vulnerability has been resolved: lib: test_hmm: evict device pages on file close to avoid use-after-free Patch series "Minor hmm_test fixes and cleanups". Two bugfixes a cleanup for the HMM kernel se…

In the Linux kernel, the following vulnerability has been resolved: lib: test_hmm: evict device pages on file close to avoid use-after-free Patch series "Minor hmm_test fixes and cleanups". Two bugfixes a cleanup for the HMM kernel se…

▾ TwilightEPSS 0.17%via NVD

Most-affected vendors

By CVEs published in the period.