VulnSea

Daily digest

Thursday 2 July 2026

A busier-than-usual day with 114 new CVEs (recent average about 87). Severity skewed high: 10 critical and 54 high, 56% of the total. 6 arrived with exploitation evidence or public exploit code already attached. openclaw was the most-affected vendor with 40.

114
New CVEs
10
Critical
0
KEV additions
0
Records changed

New this day, ranked by depth score

The 12 that matter most of the 114 published.

CVE-2026-9558Critical· 9.9PoC
2mo ago

Mautic has Server-Side Template Injection (SSTI) in Theme Templates

Mautic has Server-Side Template Injection (SSTI) in Theme Templates

▾ Abyssalmautic · mautic/coreEPSS 0.79%via GHSA
CVE-2026-49352Critical· 9.8PoC
2mo ago

9router's Hardcoded Default fallback JWT Secret Allows Authentication Bypass

9router's Hardcoded Default fallback JWT Secret Allows Authentication Bypass

▾ Abyssal9router · 9routerEPSS 0.60%via GHSA
CVE-2026-54998High· 8.8PoC
2mo ago

Microsoft Exchange Online Elevation of Privilege Vulnerability

Incorrect authorization in Microsoft Exchange Online allows an authorized attacker to elevate privileges over a network.

▾ MidnightMicrosoft · Microsoft Exchange OnlineEPSS 0.78%via CVEORG
CVE-2026-9559Critical· 9.9
2mo ago

Mautic vulnerable to Path Traversal via Campaign Import

Mautic vulnerable to Path Traversal via Campaign Import

▾ Midnightmautic · mautic/coreEPSS 0.93%via GHSA
CVE-2026-57100Critical· 9.9
2mo ago

Microsoft Entra Provisioning Service Elevation of Privilege Vulnerability

Server-side request forgery (ssrf) in Microsoft Entra Provisioning Service (SyncFabric) allows an authorized attacker to elevate privileges over a network.

▾ MidnightMicrosoft · Microsoft Entra Provisioning ServiceEPSS 0.78%via CVEORG
CVE-2026-45499Critical· 9.9
2mo ago

Azure OpenAI Elevation of Privilege Vulnerability

Server-side request forgery (ssrf) in Azure OpenAI allows an authorized attacker to elevate privileges over a network.

▾ MidnightMicrosoft · Azure Open AIEPSS 0.78%via CVEORG
CVE-2026-9809High· 7.6PoC
2mo ago

Mautic has Stored Cross-Site Scripting (XSS) in Projects Component

Mautic has Stored Cross-Site Scripting (XSS) in Projects Component

▾ Midnightmautic · mautic/coreEPSS 0.29%via GHSA
CVE-2026-59800Critical
2mo ago

9router: Missing Authorization and OS Command Injection

9router: Missing Authorization and OS Command Injection

▾ Midnight9router · 9routerEPSS 2.0%via GHSA
GHSA-w4v6-g3wm-w36cCritical
2mo ago

OpenClaw: QQBot admin commands could skip DM-only and allowFrom policy

OpenClaw: QQBot admin commands could skip DM-only and allowFrom policy

▾ Midnightopenclaw · openclawvia GHSA
GHSA-g6g7-pvmx-m74pCritical
2mo ago

9router: Missing Authorization and OS Command Injection

9router: Missing Authorization and OS Command Injection

▾ Midnight9router · 9routervia GHSA
CVE-2026-52830Critical· 9.4
2mo ago

fast-mcp-telegram: Bearer token path traversal bypasses reserved Telegram session protection

fast-mcp-telegram: Bearer token path traversal bypasses reserved Telegram session protection

▾ Midnightfast-mcp-telegram · fast-mcp-telegramEPSS 0.65%via GHSA
CVE-2026-50181High· 7.1PoC
2mo ago

Langroid: Path traversal in the file tools allows read/write outside configured current directory

Langroid: Path traversal in the file tools allows read/write outside configured current directory

▾ Midnightlangroid · langroidEPSS 0.18%via GHSA

Most-affected vendors

By CVEs published in the period.