Daily digest
Tuesday 23 June 2026
101 new CVEs this day, in line with the recent average. Of those, 9 critical and 37 high. 8 arrived with exploitation evidence or public exploit code already attached. CISA added one CVE to the Known Exploited Vulnerabilities catalog. gogs was the most-affected vendor with 16.
Added to CISA KEV
Confirmed exploitation in the wild — federal remediation deadlines attach to these.
New this day, ranked by depth score
The 12 that matter most of the 101 published.
CVE-2026-52806Critical· 9.9PoCGogs vulnerable to RCE via git rebase --exec argument injection in pull request merge
Gogs vulnerable to RCE via git rebase --exec argument injection in pull request merge
CVE-2026-54350Critical· 10.0PoCBudibase has nonymous NoSQL operator injection via published-app query templates
Budibase has nonymous NoSQL operator injection via published-app query templates
CVE-2026-52813Critical· 10.0PoCGogs has Path Traversal in organization name that results in RCE through Git hooks
Gogs has Path Traversal in organization name that results in RCE through Git hooks
CVE-2026-54512High· 8.1PoCjackson-databind: jackson-databind: Arbitrary code execution via PolymorphicTypeValidator bypass (CVE-2026-54512)
A flaw was found in jackson-databind. This vulnerability allows a remote attacker to bypass the PolymorphicTypeValidator (PTV) when polymorphic typing is enabled and a type identifier contains generic parameters. By crafting a malicious ty…
GHSA-qxvg-h7q2-hcxhCritical· 9.8motionEye: LFI → pass‑the‑hash admin → unsafe restore → unauth action exec (RCE)
motionEye: LFI → pass‑the‑hash admin → unsafe restore → unauth action exec (RCE)
GHSA-g7vj-qw6x-g3p8Critical· 9.8Duplicate Advisory: PickleScan has multiple stdlib modules with direct RCE not in blocklist
Duplicate Advisory: PickleScan has multiple stdlib modules with direct RCE not in blocklist
CVE-2026-12866Critical· 9.8expr-eval vulnerable to Code Execution
expr-eval vulnerable to Code Execution
CVE-2026-52810HighPoCGogs allows users to write to readonly repositories using receive-pack + service=git-upload-pack confusion
Gogs allows users to write to readonly repositories using receive-pack + service=git-upload-pack confusion
CVE-2026-11807Critical· 9.6A missing authorization vulnerability was found in the Event-Driven Ansible (EDA) websocket API
A missing authorization vulnerability was found in the Event-Driven Ansible (EDA) websocket API. The /api/eda/ws/ansible-rulebook endpoint does not verify user permissions when processing Worker messages. Any authenticated user can send …
GHSA-phv5-334h-mxcwCriticalmotionEye Partial Authentication Bypass: Unauthenticated Admin Credential Theft via Path Traversal
motionEye Partial Authentication Bypass: Unauthenticated Admin Credential Theft via Path Traversal
CVE-2026-52811CriticalGogs: UploadRepoFiles writes outside repo working tree via committed parent sym
Gogs: UploadRepoFiles writes outside repo working tree via committed parent sym
CVE-2026-41862High· 8.8Spring Statemachine's Kryo-based persistence backends (JPA, MongoDB, Redis and ZooKeeper) deserialise persisted state-machine contexts without enforcing a class allowlist (CWE-502, deserialisation of untrusted data), which can lead to re…
Spring Statemachine's Kryo-based persistence backends (JPA, MongoDB, Redis and ZooKeeper) deserialise persisted state-machine contexts without enforcing a class allowlist (CWE-502, deserialisation of untrusted data), which can lead to re…
Most-affected vendors
By CVEs published in the period.