Daily digest
Monday 29 June 2026
65 new CVEs this day, in line with the recent average. Of those, 6 critical and 23 high. 4 arrived with exploitation evidence or public exploit code already attached. apache was the most-affected vendor with 5.
New this day, ranked by depth score
The 12 that matter most of the 65 published.
CVE-2026-56290Critical· 9.8CISA KEVPoCThe Joomla extension Page Builder CK is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE.
The Joomla extension Page Builder CK is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE.
CVE-2020-7941Critical· 9.8Plone Unauthenticated Write Vulnerability
Plone Unauthenticated Write Vulnerability
CVE-2026-8023High· 7.5PoCZephyr's HTTP server (subsys/net/lib/http) provides a static-filesystem resource type (HTTP_RESOURCE_TYPE_STATIC_FS, available when CONFIG_FILE_SYSTEM is enabled) that serves files from a configured root directory
Zephyr's HTTP server (subsys/net/lib/http) provides a static-filesystem resource type (HTTP_RESOURCE_TYPE_STATIC_FS, available when CONFIG_FILE_SYSTEM is enabled) that serves files from a configured root directory. Before this fix, both …
CVE-2026-44840High· 7.5PoCDgraph Vulnerable to DQL Injection via checkUserPassword GraphQL Query
Dgraph Vulnerable to DQL Injection via checkUserPassword GraphQL Query
CVE-2026-55276Critical· 9.1⚖ disputedAlways-Incorrect Control Flow Implementation vulnerability in Apache Tomcat meant that special roles and empty authorisation constraints were not included when the effective web.xml was logged. This issue affects Apache Tomcat: from 11.…
Always-Incorrect Control Flow Implementation vulnerability in Apache Tomcat meant that special roles and empty authorisation constraints were not included when the effective web.xml was logged. This issue affects Apache Tomcat: from 11.…
CVE-2026-53434Critical· 9.1⚖ disputedDetection of Error Condition Without Action vulnerability in Apache Tomcat when configuring CRLs for a FFM based connector. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.22, from 10.1.0-M7 through 10.1.55, from 9.0.83 th…
Detection of Error Condition Without Action vulnerability in Apache Tomcat when configuring CRLs for a FFM based connector. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.22, from 10.1.0-M7 through 10.1.55, from 9.0.83 th…
CVE-2026-27197Critical· 9.1Sentry: Improper authentication on SAML SSO process allows user identity linking
Sentry: Improper authentication on SAML SSO process allows user identity linking
CVE-2026-11720Critical· 9.1MCP Toolbox HTTP tool path parameters allow traversal to unintended endpoints
MCP Toolbox HTTP tool path parameters allow traversal to unintended endpoints
CVE-2026-13539High· 8.8A vulnerability was identified in Wavlink WL-NU516U1-A M16U1_V240425
A vulnerability was identified in Wavlink WL-NU516U1-A M16U1_V240425. The impacted element is the function sub_407504 of the file /cgi-bin/wireless.cgi of the component POST Parameter Handler. Such manipulation of the argument Guest_ssid…
CVE-2026-13519High· 8.8A vulnerability was found in Tenda JD12L 16.03.53.23
A vulnerability was found in Tenda JD12L 16.03.53.23. This impacts the function fromNatStaticSetting of the file /goform/NatStaticSetting. The manipulation of the argument page results in stack-based buffer overflow. The attack can be ex…
CVE-2026-13518High· 8.8A vulnerability has been found in Tenda JD12L 16.03.53.23
A vulnerability has been found in Tenda JD12L 16.03.53.23. This affects the function fromAddressNat of the file /goform/addressNat. The manipulation of the argument page leads to stack-based buffer overflow. Remote exploitation of the at…
CVE-2026-13517High· 8.8A flaw has been found in Tenda JD12L 16.03.53.23
A flaw has been found in Tenda JD12L 16.03.53.23. The impacted element is the function formWifiBasicSet of the file /goform/WifiBasicSet. Executing a manipulation of the argument security_5g can lead to stack-based buffer overflow. The a…
Most-affected vendors
By CVEs published in the period.