Daily digest
Thursday 2 July 2026
A busier-than-usual day with 114 new CVEs (recent average about 87). Severity skewed high: 10 critical and 54 high, 56% of the total. 6 arrived with exploitation evidence or public exploit code already attached. openclaw was the most-affected vendor with 40.
New this day, ranked by depth score
The 12 that matter most of the 114 published.
CVE-2026-9558Critical· 9.9PoCMautic has Server-Side Template Injection (SSTI) in Theme Templates
Mautic has Server-Side Template Injection (SSTI) in Theme Templates
CVE-2026-49352Critical· 9.8PoC9router's Hardcoded Default fallback JWT Secret Allows Authentication Bypass
9router's Hardcoded Default fallback JWT Secret Allows Authentication Bypass
CVE-2026-54998High· 8.8PoCMicrosoft Exchange Online Elevation of Privilege Vulnerability
Incorrect authorization in Microsoft Exchange Online allows an authorized attacker to elevate privileges over a network.
CVE-2026-9559Critical· 9.9Mautic vulnerable to Path Traversal via Campaign Import
Mautic vulnerable to Path Traversal via Campaign Import
CVE-2026-57100Critical· 9.9Microsoft Entra Provisioning Service Elevation of Privilege Vulnerability
Server-side request forgery (ssrf) in Microsoft Entra Provisioning Service (SyncFabric) allows an authorized attacker to elevate privileges over a network.
CVE-2026-45499Critical· 9.9Azure OpenAI Elevation of Privilege Vulnerability
Server-side request forgery (ssrf) in Azure OpenAI allows an authorized attacker to elevate privileges over a network.
CVE-2026-9809High· 7.6PoCMautic has Stored Cross-Site Scripting (XSS) in Projects Component
Mautic has Stored Cross-Site Scripting (XSS) in Projects Component
CVE-2026-59800Critical9router: Missing Authorization and OS Command Injection
9router: Missing Authorization and OS Command Injection
GHSA-w4v6-g3wm-w36cCriticalOpenClaw: QQBot admin commands could skip DM-only and allowFrom policy
OpenClaw: QQBot admin commands could skip DM-only and allowFrom policy
GHSA-g6g7-pvmx-m74pCritical9router: Missing Authorization and OS Command Injection
9router: Missing Authorization and OS Command Injection
CVE-2026-52830Critical· 9.4fast-mcp-telegram: Bearer token path traversal bypasses reserved Telegram session protection
fast-mcp-telegram: Bearer token path traversal bypasses reserved Telegram session protection
CVE-2026-50181High· 7.1PoCLangroid: Path traversal in the file tools allows read/write outside configured current directory
Langroid: Path traversal in the file tools allows read/write outside configured current directory
Most-affected vendors
By CVEs published in the period.