VulnSea

Daily digest

Friday 26 June 2026

126 new CVEs this day, in line with the recent average. Severity skewed high: 12 critical and 53 high, 52% of the total. 4 arrived with exploitation evidence or public exploit code already attached. pnpm was the most-affected vendor with 13.

126
New CVEs
12
Critical
0
KEV additions
0
Records changed

New this day, ranked by depth score

The 12 that matter most of the 126 published.

CVE-2026-49869Critical· 10.0CISA KEVPoC
3mo ago

Kestra is an open-source, event-driven orchestration platform

Kestra is an open-source, event-driven orchestration platform. Prior to 1.0.45 and 1.3.21, AuthenticationFilter in Kestra OSS uses request.getPath().endsWith("/configs") to whitelist the public configuration endpoint from Basic Auth. Bec…

▾ Hadalkestra · kestraEPSS 2.1%via NVD
CVE-2026-52782Critical· 9.9PoC
3mo ago

OpenProject is open-source, web-based project management software

OpenProject is open-source, web-based project management software. Prior to 17.3.3 and 17.4.1, there is an IDOR through /projects/<A>/settings/project_storages/<A_ps_id> via PATCH parameter "storages_project_storage[project_folder_id]" l…

▾ AbyssalEPSS 0.45%via NVD
CVE-2026-44024Critical· 9.8PoC
3mo ago

Fluentd is Vulnerable to Remote Code Execution (RCE) via Arbitrary File Write in `${tag}` Placeholder

Fluentd is Vulnerable to Remote Code Execution (RCE) via Arbitrary File Write in `${tag}` Placeholder

▾ Abyssalfluentd · fluentdEPSS 1.1%via GHSA
CVE-2026-53519Critical· 9.1PoC
3mo ago

Nezha Monitoring: Pre-auth path traversal via /dashboard.. prefix confusion leaks jwt_secret_key

Nezha Monitoring: Pre-auth path traversal via /dashboard.. prefix confusion leaks jwt_secret_key

▾ Abyssalnezhahq · github.com/nezhahq/nezhaEPSS 2.3%via GHSA
CVE-2026-49257Critical· 10.0
3mo ago

mcp-pinot: Unauthenticated tool invocation via default oauth_enabled=False + host 0.0.0.0 bind

mcp-pinot: Unauthenticated tool invocation via default oauth_enabled=False + host 0.0.0.0 bind

▾ Midnightmcp-pinot-server · mcp-pinot-serverEPSS 0.93%via GHSA
CVE-2026-49252Critical· 9.9
3mo ago

deepstream is vulnerable to prototype pollution

deepstream is vulnerable to prototype pollution

▾ Midnightdeepstream · @deepstream/serverEPSS 0.47%via GHSA
CVE-2026-46386Critical· 9.9
3mo ago

OpenProject is open-source, web-based project management software

OpenProject is open-source, web-based project management software. Prior to , the official openproject/openproject Docker image ships ENV SECRET_KEY_BASE=OVERWRITE_ME as the default Rails master key. Combined with cookies_serializer = :m…

▾ MidnightEPSS 0.49%via NVD
GHSA-q6xx-5vr8-p898Critical· 9.9
3mo ago

Nezha vulnerable to cross-tenant terminal/file-manager session hijack via WebSocket stream UUID without ownership check

Nezha vulnerable to cross-tenant terminal/file-manager session hijack via WebSocket stream UUID without ownership check

▾ Midnightnezhahq · github.com/nezhahq/nezhavia GHSA
GHSA-98x5-vq43-vc5pCritical
3mo ago

semantic-router exposed to compromised litellm wheel (CVE-2026-42208) via unbounded transitive pin

semantic-router exposed to compromised litellm wheel (CVE-2026-42208) via unbounded transitive pin

▾ Midnightsemantic-router · semantic-routervia GHSA
CVE-2026-48797Critical
3mo ago

Backpropagate: backprop ui --auth and backprop ui --share do not enforce authentication

Backpropagate: backprop ui --auth and backprop ui --share do not enforce authentication

▾ Midnightbackpropagate · backpropagateEPSS 0.57%via OSV
CVE-2026-54636Critical· 9.0
3mo ago

Dokku is a docker-powered PaaS

Dokku is a docker-powered PaaS. Prior to 0.38.7, the cron plugin utilizes commands in the app.json file to manage system cron running as the Dokku user. An app.json cron command utilizing special shell characters - including, but not lim…

▾ MidnightEPSS 0.53%via NVD
CVE-2026-49454Critical· 9.1
3mo ago

Relyra SAML SignatureValue not cryptographically verified -> authentication bypass

Relyra SAML SignatureValue not cryptographically verified -> authentication bypass

▾ Midnightrelyra · relyraEPSS 0.23%via GHSA

Most-affected vendors

By CVEs published in the period.