Daily digest
Wednesday 17 June 2026
A busier-than-usual day with 113 new CVEs (recent average about 97). Severity skewed high: 20 critical and 47 high, 59% of the total. 14 arrived with exploitation evidence or public exploit code already attached. open-webui was the most-affected vendor with 16.
New this day, ranked by depth score
The 12 that matter most of the 113 published.
CVE-2026-55450Critical· 9.3PoCLangflow: Unauthenticated file upload leads to DoS (space exhaustion) and information leak
Langflow: Unauthenticated file upload leads to DoS (space exhaustion) and information leak
CVE-2025-26240High· 8.4PoCpdfkit: Path traversal in from_string
pdfkit: Path traversal in from_string
CVE-2026-55200High· 8.1PoClibssh2 through 1.11.1, fixed in commit 7acf3df contains an out-of-bounds write vulnerability in ssh2_transport_read() that fails to enforce upper bounds on packet_length field
libssh2 through 1.11.1, fixed in commit 7acf3df contains an out-of-bounds write vulnerability in ssh2_transport_read() that fails to enforce upper bounds on packet_length field. Remote attackers can send crafted SSH packets with excessiv…
CVE-2026-54415High· 8.1PoCMissing Authorization in the server management routes (routes/admin.php) in Azuriom Azuriom CMS before 1.2.11 on all platforms allows an authenticated attacker with the admin.access permission to create AzLink server tokens and take over…
Missing Authorization in the server management routes (routes/admin.php) in Azuriom Azuriom CMS before 1.2.11 on all platforms allows an authenticated attacker with the admin.access permission to create AzLink server tokens and take over…
CVE-2026-42530High· 8.1PoCNGINX Open Source has a vulnerability in the ngx_http_v3_module module
NGINX Open Source has a vulnerability in the ngx_http_v3_module module. When NGINX Open Source is configured to use the HTTP/3 QUIC module, a remote unauthenticated attacker along with conditions beyond their control can use a specially …
CVE-2026-42055High· 8.1PoCNGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_proxy_v2_module and ngx_http_grpc_module modules
NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_proxy_v2_module and ngx_http_grpc_module modules. This vulnerability exists when the proxy_http_version to 2 or grpc_pass directives are used to proxy HTTP/2 traffic, …
GHSA-82fg-2r99-h7v6Critical· 10.0Duplicate Advisory: PickleScan's pkgutil.resolve_name has a universal blocklist bypass
Duplicate Advisory: PickleScan's pkgutil.resolve_name has a universal blocklist bypass
CVE-2026-25470Critical· 10.0Unauthenticated Remote Code Execution (RCE) in ACPT (Pro) - Custom Post Types Plugin for WordPress <= 2.0.47 versions.
Unauthenticated Remote Code Execution (RCE) in ACPT (Pro) - Custom Post Types Plugin for WordPress <= 2.0.47 versions.
GHSA-rmpp-8wf5-xx5qCritical· 9.8Duplicate Advisory: Picklescan vulnerable to Arbitrary File Writing
Duplicate Advisory: Picklescan vulnerable to Arbitrary File Writing
GHSA-j6c9-qvp8-699fCritical· 9.8Duplicate Advisory: picklescan missing detection by simple obfuscation of a `builtins.eval` call
Duplicate Advisory: picklescan missing detection by simple obfuscation of a `builtins.eval` call
GHSA-7f79-rvx6-vxc4Critical· 9.8Duplicate Advisory: Picklescan does not block ctypes
Duplicate Advisory: Picklescan does not block ctypes
GHSA-6v84-v468-3c7fCritical· 9.8Duplicate Advisory: Picklescan has Incomplete List of Disallowed Inputs
Duplicate Advisory: Picklescan has Incomplete List of Disallowed Inputs
Most-affected vendors
By CVEs published in the period.