Daily digest
Friday 26 June 2026
126 new CVEs this day, in line with the recent average. Severity skewed high: 12 critical and 53 high, 52% of the total. 4 arrived with exploitation evidence or public exploit code already attached. pnpm was the most-affected vendor with 13.
New this day, ranked by depth score
The 12 that matter most of the 126 published.
CVE-2026-49869Critical· 10.0CISA KEVPoCKestra is an open-source, event-driven orchestration platform
Kestra is an open-source, event-driven orchestration platform. Prior to 1.0.45 and 1.3.21, AuthenticationFilter in Kestra OSS uses request.getPath().endsWith("/configs") to whitelist the public configuration endpoint from Basic Auth. Bec…
CVE-2026-52782Critical· 9.9PoCOpenProject is open-source, web-based project management software
OpenProject is open-source, web-based project management software. Prior to 17.3.3 and 17.4.1, there is an IDOR through /projects/<A>/settings/project_storages/<A_ps_id> via PATCH parameter "storages_project_storage[project_folder_id]" l…
CVE-2026-44024Critical· 9.8PoCFluentd is Vulnerable to Remote Code Execution (RCE) via Arbitrary File Write in `${tag}` Placeholder
Fluentd is Vulnerable to Remote Code Execution (RCE) via Arbitrary File Write in `${tag}` Placeholder
CVE-2026-53519Critical· 9.1PoCNezha Monitoring: Pre-auth path traversal via /dashboard.. prefix confusion leaks jwt_secret_key
Nezha Monitoring: Pre-auth path traversal via /dashboard.. prefix confusion leaks jwt_secret_key
CVE-2026-49257Critical· 10.0mcp-pinot: Unauthenticated tool invocation via default oauth_enabled=False + host 0.0.0.0 bind
mcp-pinot: Unauthenticated tool invocation via default oauth_enabled=False + host 0.0.0.0 bind
CVE-2026-49252Critical· 9.9deepstream is vulnerable to prototype pollution
deepstream is vulnerable to prototype pollution
CVE-2026-46386Critical· 9.9OpenProject is open-source, web-based project management software
OpenProject is open-source, web-based project management software. Prior to , the official openproject/openproject Docker image ships ENV SECRET_KEY_BASE=OVERWRITE_ME as the default Rails master key. Combined with cookies_serializer = :m…
GHSA-q6xx-5vr8-p898Critical· 9.9Nezha vulnerable to cross-tenant terminal/file-manager session hijack via WebSocket stream UUID without ownership check
Nezha vulnerable to cross-tenant terminal/file-manager session hijack via WebSocket stream UUID without ownership check
GHSA-98x5-vq43-vc5pCriticalsemantic-router exposed to compromised litellm wheel (CVE-2026-42208) via unbounded transitive pin
semantic-router exposed to compromised litellm wheel (CVE-2026-42208) via unbounded transitive pin
CVE-2026-48797CriticalBackpropagate: backprop ui --auth and backprop ui --share do not enforce authentication
Backpropagate: backprop ui --auth and backprop ui --share do not enforce authentication
CVE-2026-54636Critical· 9.0Dokku is a docker-powered PaaS
Dokku is a docker-powered PaaS. Prior to 0.38.7, the cron plugin utilizes commands in the app.json file to manage system cron running as the Dokku user. An app.json cron command utilizing special shell characters - including, but not lim…
CVE-2026-49454Critical· 9.1Relyra SAML SignatureValue not cryptographically verified -> authentication bypass
Relyra SAML SignatureValue not cryptographically verified -> authentication bypass
Most-affected vendors
By CVEs published in the period.