VulnSea

Daily digest

Tuesday 9 June 2026

A heavy day: 263 new CVEs, well above the recent average of about 41. Severity skewed high: 17 critical and 158 high, 67% of the total. 11 arrived with exploitation evidence or public exploit code already attached. microsoft was the most-affected vendor with 200.

263
New CVEs
17
Critical
0
KEV additions
0
Records changed

New this day, ranked by depth score

The 12 that matter most of the 263 published.

CVE-2026-25089Critical· 9.8CISA KEVPoC
3mo ago

A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox 4.2 all versions, FortiSandbox Cloud …

A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox 4.2 all versions, FortiSandbox Cloud …

▾ Hadalfortinet · fortisandboxEPSS 76%via NVD
CVE-2026-48030Critical· 9.9PoC
3mo ago

Pheditor: OS Command Injection in terminal handler via unsanitized 'dir' parameter

Pheditor: OS Command Injection in terminal handler via unsanitized 'dir' parameter

▾ Abyssalpheditor · pheditor/pheditorEPSS 7.5%via GHSA
CVE-2026-8467CriticalPoC
3mo ago

PhoenixStorybook: Unauthenticated remote code execution via HEEx template injection in phoenix_storybook playground

PhoenixStorybook: Unauthenticated remote code execution via HEEx template injection in phoenix_storybook playground

▾ Abyssalphoenix_storybook · phoenix_storybookEPSS 2.1%via GHSA
CVE-2026-46316Critical· 9.3PoC⚖ disputed
3mo ago

In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: vgic-its: Drop the translation cache reference only for the erased entry vgic_its_invalidate_cache() walks the per-ITS translation cache with xa_for_each()…

In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: vgic-its: Drop the translation cache reference only for the erased entry vgic_its_invalidate_cache() walks the per-ITS translation cache with xa_for_each()…

▾ Abyssallinux · linux_kernelEPSS 0.20%via NVD
CVE-2026-45504High· 8.8PoC
3mo ago

Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.

Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.

▾ Midnightmicrosoft · exchange_serverEPSS 0.78%via NVD
CVE-2026-45447High· 8.8PoC
3mo ago

Issue summary: A specially crafted PKCS#7 or S/MIME signed message could trigger a use-after-free during PKCS#7 signature verification. Impact summary: A use-after-free may result in process crashes, heap corruption, or potentially remo…

Issue summary: A specially crafted PKCS#7 or S/MIME signed message could trigger a use-after-free during PKCS#7 signature verification. Impact summary: A use-after-free may result in process crashes, heap corruption, or potentially remo…

▾ Midnightopenssl · opensslEPSS 4.0%via NVD
CVE-2026-47938Critical· 10.0
3mo ago

Adobe Campaign Classic (ACC) versions 7.4.3 build 9394 and earlier are affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in privilege escalation

Adobe Campaign Classic (ACC) versions 7.4.3 build 9394 and earlier are affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in privilege escalation. Exploitation of this issue does not require user interaction…

▾ Midnightadobe · campaignEPSS 0.95%via NVD
CVE-2026-42980High· 7.8PoC
3mo ago

Integer underflow (wrap or wraparound) in Windows NT OS Kernel allows an authorized attacker to elevate privileges locally.

Integer underflow (wrap or wraparound) in Windows NT OS Kernel allows an authorized attacker to elevate privileges locally.

▾ Midnightmicrosoft · windows_10_1607EPSS 0.33%via NVD
CVE-2026-42978High· 7.8PoC
3mo ago

Windows Push Notifications Elevation of Privilege Vulnerability

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elevate privileges locally.

▾ MidnightMicrosoft · Windows 10 Version 1809EPSS 0.20%via CVEORG
CVE-2026-9698Critical· 9.8
3mo ago

DBI versions before 1.648 for Perl saved errors in a limited-sized buffer. Error messages that were returned when RaiseError, PrintError or HandleError were set were written to a 200-byte buffer without a length limit. Attackers that c…

DBI versions before 1.648 for Perl saved errors in a limited-sized buffer. Error messages that were returned when RaiseError, PrintError or HandleError were set were written to a 200-byte buffer without a length limit. Attackers that c…

▾ Midnightperl · dbiEPSS 0.82%via NVD
CVE-2026-47643Critical· 9.8
3mo ago

Azure Stack Edge Remote Code Execution Vulnerability

External control of file name or path in Azure Stack Edge allows an unauthorized attacker to execute code over a network.

▾ MidnightMicrosoft · Azure Stack EdgeEPSS 0.97%via CVEORG
CVE-2026-47291Critical· 9.8
3mo ago

HTTP.sys Remote Code Execution Vulnerability

Integer overflow or wraparound in Windows HTTP.sys allows an unauthorized attacker to execute code over a network.

▾ MidnightMicrosoft · Windows 10 Version 1607EPSS 0.97%via CVEORG

Most-affected vendors

By CVEs published in the period.