Daily digest
Wednesday 10 June 2026
A busier-than-usual day with 85 new CVEs (recent average about 63). Severity skewed high: 7 critical and 37 high, 52% of the total. 10 arrived with exploitation evidence or public exploit code already attached. vmware was the most-affected vendor with 14.
New this day, ranked by depth score
The 12 that matter most of the 85 published.
CVE-2026-53435High· 8.8PoCIn Jenkins 2.567 and earlier, LTS 2.555.2 and earlier, it is possible for attackers to have Jenkins deserialize arbitrary types defined in Jenkins core or plugins from an attacker-controlled `config.xml` submission in a way that allows t…
In Jenkins 2.567 and earlier, LTS 2.555.2 and earlier, it is possible for attackers to have Jenkins deserialize arbitrary types defined in Jenkins core or plugins from an attacker-controlled `config.xml` submission in a way that allows t…
CVE-2026-48060High· 8.1PoCLitestar has HTML Injection Through its CSRF Token
Litestar has HTML Injection Through its CSRF Token
CVE-2026-41729High· 8.1PoCSpring Data REST is vulnerable to SpEL expression injection through map-typed properties when processing JSON Patch (application/json-patch+json) requests
Spring Data REST is vulnerable to SpEL expression injection through map-typed properties when processing JSON Patch (application/json-patch+json) requests. When a persistent entity exposes a Map-typed property, the JSON Pointer path segm…
CVE-2026-46529High· 7.8PoCAtril Document Viewer is the default document reader of the MATE desktop environment for Linux
Atril Document Viewer is the default document reader of the MATE desktop environment for Linux. A single-click remote code execution vulnerability in versions prior to 1.26.3 and 1.28.4 allows an attacker to achieve arbitrary code execut…
CVE-2026-53476Critical· 9.6Assisted Migration Agent: Path traversal in gzipped tarball handling enables arbitrary file write and remote code execution
Assisted Migration Agent: Path traversal in gzipped tarball handling enables arbitrary file write and remote code execution
CVE-2026-53474Critical· 9.6Openshift Migration Advisor: Improper input sanitization allows specially crafted RVTools .xlsx files to include malicious SQL commands
Openshift Migration Advisor: Improper input sanitization allows specially crafted RVTools .xlsx files to include malicious SQL commands
CVE-2026-53471Critical· 9.6Openshift Migration Advisor agent-API fails to validate JWT source_id claim, allowing cross-tenant data manipulation
Openshift Migration Advisor agent-API fails to validate JWT source_id claim, allowing cross-tenant data manipulation
CVE-2026-53470Critical· 9.6Openshift Migration Advisor: Broken access control in migration-planner image-url endpoint exposes other users' OVA images and agent JWTs
Openshift Migration Advisor: Broken access control in migration-planner image-url endpoint exposes other users' OVA images and agent JWTs
CVE-2026-46625High· 7.5PoCJavaScript Cookie is a JavaScript API for handling cookies, client-side
JavaScript Cookie is a JavaScript API for handling cookies, client-side. Prior to version 3.0.7, js-cookie's internal assign() helper copies properties with for...in + plain assignment. When the source object is produced by JSON.parse, t…
CVE-2025-71329High· 7.5PoCimage-size: JXL and HEIF parsers allow denial of service through infinite loops
image-size: JXL and HEIF parsers allow denial of service through infinite loops
CVE-2026-11837High· 7.3PoCA local privilege escalation vulnerability was found in the ansible.posix authorized_key module
A local privilege escalation vulnerability was found in the ansible.posix authorized_key module. The module's keyfile() function uses os.chown() instead of os.lchown() and opens files without O_NOFOLLOW when managing SSH authorized keys.…
CVE-2026-0273High· 7.2PoCA command injection vulnerability in Palo Alto Networks PAN-OS® software enables an authenticated administrator to bypass system restrictions and run arbitrary commands as a root user
A command injection vulnerability in Palo Alto Networks PAN-OS® software enables an authenticated administrator to bypass system restrictions and run arbitrary commands as a root user. To be able to exploit this issue, the user must have…
Most-affected vendors
By CVEs published in the period.