Daily digest
Saturday 13 June 2026
A quiet day: only 8 new CVEs against a recent average of about 81. Severity skewed high: 2 critical and 4 high, 75% of the total.
New this day, ranked by depth score
The 8 that matter most of the 8 published.
CVE-2026-12183Critical· 9.8Nefteprodukttekhnika BUK TS-G Gas Station Automation System 2.9.1 through 2.10.2 on Linux contains an Improper Authentication vulnerability (CWE-287) in the system configuration module.
Nefteprodukttekhnika BUK TS-G Gas Station Automation System 2.9.1 through 2.10.2 on Linux contains an Improper Authentication vulnerability (CWE-287) in the system configuration module.
CVE-2026-11624CriticalMCP Toolbox for Databases has an Origin Validation Error
MCP Toolbox for Databases has an Origin Validation Error
CVE-2026-54228High· 7.8A time-of-check time-of-use (TOCTOU) race condition was found in the abrt-dbus D-Bus service's SetElement method
A time-of-check time-of-use (TOCTOU) race condition was found in the abrt-dbus D-Bus service's SetElement method. Between dump directory creation and post-create event execution, any local user can call SetElement to write arbitrary text…
CVE-2026-6428High· 7.6SQL Injection in reports/catalogue_out.pl in Koha Community Koha through 22.11.37, 23.x, 24.x before 24.11.16, 25.05.x before 25.05.11, 25.11.x before 25.11.05, 26.05.x before 26.05.01, and 26.11.x before 26.11.00 allows an authenticated…
SQL Injection in reports/catalogue_out.pl in Koha Community Koha through 22.11.37, 23.x, 24.x before 24.11.16, 25.05.x before 25.05.11, 25.11.x before 25.11.05, 26.05.x before 26.05.01, and 26.11.x before 26.11.00 allows an authenticated…
CVE-2026-54230High· 7.0A symlink following vulnerability was found in the ABRT post-create event handler scripts in libreport
A symlink following vulnerability was found in the ABRT post-create event handler scripts in libreport. Event scripts write output files using shell redirections without the O_NOFOLLOW flag. If the target file is replaced with a symlink,…
CVE-2026-54229High· 7.0A race condition was found in the abrt-dbus D-Bus service's ChownProblemDir method
A race condition was found in the abrt-dbus D-Bus service's ChownProblemDir method. ChownProblemDir opens the dump directory with DD_OPEN_READONLY and calls dd_chown to change ownership of all files to the caller's uid, succeeding even w…
CVE-2026-54231Medium· 5.5A content injection vulnerability was found in the ABRT post-create event handler scripts in libreport
A content injection vulnerability was found in the ABRT post-create event handler scripts in libreport. The event script queries the systemd journal for log entries matching the crashed process and writes the results to files in the dump…
GHSA-v82c-5c2q-hx9gMediumDuplicate Advisory: Privilege escalation from namespace admin to cluster admin via GrafanaDashboard jsonnetLib fileName
Duplicate Advisory: Privilege escalation from namespace admin to cluster admin via GrafanaDashboard jsonnetLib fileName
Most-affected vendors
By CVEs published in the period.