VulnSea

Daily digest

Wednesday 8 July 2026

79 new CVEs this day, in line with the recent average. Of those, 3 critical and 27 high. 5 arrived with exploitation evidence or public exploit code already attached. linuxfoundation was the most-affected vendor with 9.

79
New CVEs
3
Critical
0
KEV additions
2
Records changed

New this day, ranked by depth score

The 12 that matter most of the 79 published.

CVE-2026-59822High· 8.2CISA KEVPoC
2mo ago

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.84.0, LiteLLM's MCP Streamable HTTP endpoint allowed an unauthenticated attacker to use a fabricated Authorization header to trigger an OAut…

▾ Abyssallitellm · litellmEPSS 0.84%via NVD
CVE-2026-31309Critical· 9.8PoC
2mo ago

Improper authorization in the /tequilapi/config/user endpoint of Mysterium Node from v1.21.1-rc0 before v1.36.0 allows an unauthenticated attacker to arbitrarily overwrite the node's configuration and achieve a full node takeover via a c…

Improper authorization in the /tequilapi/config/user endpoint of Mysterium Node from v1.21.1-rc0 before v1.36.0 allows an unauthenticated attacker to arbitrarily overwrite the node's configuration and achieve a full node takeover via a c…

▾ AbyssalEPSS 0.62%via NVD
CVE-2026-59702Critical· 9.3PoC
2mo ago

repomix - Server-Side Request Forgery via Unvalidated Repository URLs in POST /api/pack

repomix contains a server-side request forgery vulnerability in the POST /api/pack endpoint that allows unauthenticated attackers to make arbitrary outbound requests. The endpoint fails to properly validate http://, https://, and file://…

▾ Abyssalrepomix · repomixEPSS 0.44%via CVEORG
CVE-2026-59703High· 7.5PoC
2mo ago

repomix - Local File Inclusion via file:// URL Scheme in Git Clone Endpoint

repomix contains a local file inclusion vulnerability in the git clone endpoint that allows unauthenticated attackers to read arbitrary local git repositories. The isValidRemoteValue function in src/core/git/gitRemoteParse.ts fails to bl…

▾ Midnightrepomix · repomixEPSS 0.51%via CVEORG
CVE-2026-47646Critical· 9.3
2mo ago

Dynamics 365 Customer Voice Spoofing Vulnerability

Improper neutralization of input during web page generation ('cross-site scripting') in Dynamics 365 Customer Voice allows an unauthorized attacker to perform spoofing over a network.

▾ MidnightMicrosoft · Dynamics 365 Customer VoiceEPSS 0.47%via CVEORG
CVE-2026-59262Medium· 6.5PoC
2mo ago

AFFiNE's histories GraphQL field fails to validate Doc.Read permission before exposing document edit history, allowing authenticated workspace members to retrieve restricted content timelines

AFFiNE's histories GraphQL field fails to validate Doc.Read permission before exposing document edit history, allowing authenticated workspace members to retrieve restricted content timelines. Attackers can supply arbitrary document GUID…

▾ Twilightaffine · monorepoEPSS 0.41%via NVD
CVE-2026-58253High· 8.8
2mo ago

NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system

NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.0, 2.12.7, and 2.11.16, when no_auth_user was configured, a parser fast path intended for ordinary client connections could a…

▾ Twilightlinuxfoundation · nats-serverEPSS 0.37%via NVD
CVE-2026-50197High· 8.7
2mo ago

Skipper: opaAuthorizeRequestWithBody filter bypasses OPA policy on Transfer-Encoding — chunked / HTTP/2 requests

Skipper: opaAuthorizeRequestWithBody filter bypasses OPA policy on Transfer-Encoding — chunked / HTTP/2 requests

▾ Twilightzalando · github.com/zalando/skipperEPSS 0.55%via GHSA
CVE-2026-56002High· 8.5
2mo ago

A heap bufferflow in pcfReadFont() due to missing glyph bounds checking in libXfont2 before 2.0.8  allows attackers authenticated as X client to execute code within the X server.

A heap bufferflow in pcfReadFont() due to missing glyph bounds checking in libXfont2 before 2.0.8  allows attackers authenticated as X client to execute code within the X server.

▾ Twilightx · libxfontEPSS 0.56%via NVD
CVE-2026-49471High· 8.3
2mo ago

Serena: Unauthenticated Flask dashboard on fixed port enables DNS rebinding → memory poisoning → RCE

Serena: Unauthenticated Flask dashboard on fixed port enables DNS rebinding → memory poisoning → RCE

▾ Twilightserena-agent · serena-agentEPSS 0.37%via GHSA
CVE-2026-58525High· 8.2
2mo ago

Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability

Improper access control in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass a security feature over a network.

▾ TwilightMicrosoft · Microsoft Edge (Chromium-based)EPSS 0.51%via CVEORG
CVE-2026-39822High· 7.8
2mo ago

On Unix systems, opening a file in an os.Root improperly follows symlinks to locations outside of the Root when the final path component of the a path is a symbolic link and the path ends in /

On Unix systems, opening a file in an os.Root improperly follows symlinks to locations outside of the Root when the final path component of the a path is a symbolic link and the path ends in /. For example, 'root.Open("symlink/")' will o…

▾ Twilightgolang · goEPSS 0.18%via NVD

Most-changed records

Existing CVEs whose severity, score, KEV or exploitation status moved.

  • CVE-2026-56290The Joomla extension Page Builder CK is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE.85
  • CVE-2026-55255Langflow: IDOR Vulnerability in `/api/v1/responses` Endpoint Allows Authenticated Attackers to Access Another User's Flow80

Most-affected vendors

By CVEs published in the period.