Daily digest
Monday 15 June 2026
A busier-than-usual day with 91 new CVEs (recent average about 76). Of those, 6 critical and 33 high. 5 arrived with exploitation evidence or public exploit code already attached. angular was the most-affected vendor with 13.
New this day, ranked by depth score
The 12 that matter most of the 91 published.
CVE-2026-48853Critical· 9.2PoCDeserialization of Untrusted Data and Allocation of Resources Without Limits or Throttling vulnerabilities in elixir-grpc grpc allow unauthenticated attackers to crash the BEAM node via atom table exhaustion and, when a decoded term flow…
Deserialization of Untrusted Data and Allocation of Resources Without Limits or Throttling vulnerabilities in elixir-grpc grpc allow unauthenticated attackers to crash the BEAM node via atom table exhaustion and, when a decoded term flow…
CVE-2026-48854High· 8.7PoCAllocation of Resources Without Limits or Throttling vulnerability in elixir-grpc grpc allows unauthenticated attackers to exhaust the BEAM's memory and crash the server by streaming a large or slow-trickle unary request body. 'Elixir.G…
Allocation of Resources Without Limits or Throttling vulnerability in elixir-grpc grpc allows unauthenticated attackers to exhaust the BEAM's memory and crash the server by streaming a large or slow-trickle unary request body. 'Elixir.G…
CVE-2026-9862Critical· 9.8Fortra's Core Privileged Access Manager (BoKS) contains an OS command injection vulnerability in the boks_autoregisterd service
Fortra's Core Privileged Access Manager (BoKS) contains an OS command injection vulnerability in the boks_autoregisterd service. A remote attacker with network access to the service may be able to cause commands to be executed with the …
CVE-2026-53633Critical· 9.8Vitest Browser: Exposed Browser Mode API Can Proxy CDP and Overwrite Config Files, Leading to RCE
Vitest Browser: Exposed Browser Mode API Can Proxy CDP and Overwrite Config Files, Leading to RCE
CVE-2026-48599High· 7.6PoCAuthorization Bypass Through User-Controlled Key vulnerability in elixir-grpc grpc allows authenticated attackers to access or modify resources belonging to other users by smuggling a conflicting value for any path-bound field via the qu…
Authorization Bypass Through User-Controlled Key vulnerability in elixir-grpc grpc allows authenticated attackers to access or modify resources belonging to other users by smuggling a conflicting value for any path-bound field via the qu…
CVE-2026-30120Critical· 9.8Remotion: remote code execution (RCE) vulnerability
Remotion: remote code execution (RCE) vulnerability
CVE-2026-53571HighPoCvite: `server.fs.deny` bypass on Windows alternate paths
vite: `server.fs.deny` bypass on Windows alternate paths
CVE-2026-54257CriticalElectron: Buffer performs incorrect byte length calculations resulting in heap buffer under/overflow
Electron: Buffer performs incorrect byte length calculations resulting in heap buffer under/overflow
CVE-2026-11417High· 7.3PoCaws-cdk-lib: OS Command Injection in NodejsFunction Bundling
aws-cdk-lib: OS Command Injection in NodejsFunction Bundling
CVE-2026-30121Critical· 9.1Remotion: arbitrary file write vulnerability
Remotion: arbitrary file write vulnerability
CVE-2026-52720High· 8.8A heap buffer overflow vulnerability was found in GStreamer's librfb (RFB/VNC client)
A heap buffer overflow vulnerability was found in GStreamer's librfb (RFB/VNC client). The rectangle bounds check incorrectly validates area rather than individual dimensions, allowing a malicious VNC server to send a rectangle that exte…
CVE-2026-50884High· 8.8statping-ng allows attackers to escalate privileges to Administrator and access sensitive components
statping-ng allows attackers to escalate privileges to Administrator and access sensitive components
Most-affected vendors
By CVEs published in the period.