VulnSea

Daily digest

Thursday 9 July 2026

71 new CVEs this day, in line with the recent average. Severity skewed high: 6 critical and 31 high, 52% of the total. 3 arrived with exploitation evidence or public exploit code already attached. paloaltonetworks was the most-affected vendor with 10.

71
New CVEs
6
Critical
0
KEV additions
2
Records changed

New this day, ranked by depth score

The 12 that matter most of the 71 published.

CVE-2026-56291Critical· 9.8CISA KEV0dayPoC
2mo ago

The Joomla extension Balbooa Forms is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE.

The Joomla extension Balbooa Forms is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE.

▾ Hadalbalbooa · formsEPSS 15%via NVD
CVE-2026-59148High· 8.8PoC
2mo ago

Mockoon provides way to design and run mock APIs

Mockoon provides way to design and run mock APIs. Prior to 9.7.0, Mockoon's admin API in commons-server/src/libs/server/admin-api.ts is mounted on the same Express listener as user-defined mock routes, enabled by default in shipped runti…

▾ Midnightmockoon · mockoonEPSS 0.26%via NVD
CVE-2026-0284Critical· 9.9
2mo ago

An XML injection vulnerability in the Large Scale VPN (LSVPN) functionality of Palo Alto Networks PAN-OS® software enables an unauthenticated attacker with network access to inject malicious XML content, potentially leading to informatio…

An XML injection vulnerability in the Large Scale VPN (LSVPN) functionality of Palo Alto Networks PAN-OS® software enables an unauthenticated attacker with network access to inject malicious XML content, potentially leading to informatio…

▾ Midnightpaloaltonetworks · pan-osEPSS 0.46%via NVD
CVE-2026-56292High· 7.5PoC
2mo ago

A SQLi vulnerability in AcyMailing component < 10.11.1 for Joomla was discovered

A SQLi vulnerability in AcyMailing component < 10.11.1 for Joomla was discovered. Exploiting this flaw can lead to unauthorized database access and data leakage.

▾ Midnightacymailing · acymailingEPSS 1.4%via NVD
CVE-2026-52778Critical· 9.8
2mo ago

YesWiki has Unsafe eval() in its Formula Calculato, Leading to Remote Code Execution & Denial of Service

YesWiki has Unsafe eval() in its Formula Calculato, Leading to Remote Code Execution & Denial of Service

▾ Midnightyeswiki · yeswiki/yeswikiEPSS 0.94%via GHSA
CVE-2026-13461Critical· 9.6
2mo ago

When coupled with the SSL bypass vulnerability, JavaScript can be injected into a WebView in the PayRange version 7.0.7 app

When coupled with the SSL bypass vulnerability, JavaScript can be injected into a WebView in the PayRange version 7.0.7 app. The injection of specific JavaScript function calls allows the attacker to escape the WebView sandbox and perfor…

▾ MidnightEPSS 0.50%via NVD
CVE-2026-58122Critical· 9.1
2mo ago

Hermes WebUI before 0.51.307 contains an authentication bypass vulnerability that allows unauthenticated remote attackers to circumvent local-origin IP restrictions on onboarding endpoints by supplying a spoofed X-Forwarded-For header wi…

Hermes WebUI before 0.51.307 contains an authentication bypass vulnerability that allows unauthenticated remote attackers to circumvent local-origin IP restrictions on onboarding endpoints by supplying a spoofed X-Forwarded-For header wi…

▾ MidnightEPSS 0.37%via NVD
CVE-2026-47826Critical· 9.1
2mo ago

The blobs.yml path key traversal vulnerability in the BOSH CLI tool allows an attacker to write arbitrary files and exfiltrate sensitive information. Affected versions: BOSH CLI tool versions prior to v7.10.4.

The blobs.yml path key traversal vulnerability in the BOSH CLI tool allows an attacker to write arbitrary files and exfiltrate sensitive information. Affected versions: BOSH CLI tool versions prior to v7.10.4.

▾ Midnightcloudfoundry · bosh_cliEPSS 0.55%via NVD
CVE-2026-47828High· 8.8
2mo ago

During bosh create-env and bosh delete-env, the CLI uploads compiled CPI packages and rendered job templates to the new VM's DAV blobstore over HTTPS without verifying the server certificate, even though a CA certificate for that endpoin…

During bosh create-env and bosh delete-env, the CLI uploads compiled CPI packages and rendered job templates to the new VM's DAV blobstore over HTTPS without verifying the server certificate, even though a CA certificate for that endpoin…

▾ Twilightcloudfoundry · bosh_cliEPSS 0.29%via NVD
CVE-2026-44787High· 8.2
2mo ago

Discourse is an open-source discussion platform

Discourse is an open-source discussion platform. Prior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, the signup flow could allow newly registered users to set primary_group_id and gain whisper-group privileges without legitimate group m…

▾ TwilightEPSS 0.46%via NVD
CVE-2026-47829High· 7.8
2mo ago

Argument Injection in bosh-cli allows a compromised BOSH Director to inject arbitrary OpenSSH options into the locally-spawned ssh process when an operator runs bosh ssh -c, bosh logs -f, or other non-interactive SSH paths, leading to lo…

Argument Injection in bosh-cli allows a compromised BOSH Director to inject arbitrary OpenSSH options into the locally-spawned ssh process when an operator runs bosh ssh -c, bosh logs -f, or other non-interactive SSH paths, leading to lo…

▾ Twilightcloudfoundry · bosh_cliEPSS 0.42%via NVD
CVE-2026-41857High· 7.8
2mo ago

A compromised or malicious BOSH Director can execute arbitrary shell commands on the operator's workstation when the operator runs bosh ssh (or bosh scp/bosh logs -f) with default flags. Affected versions: BOSH CLI versions prior to 7.10.5.

A compromised or malicious BOSH Director can execute arbitrary shell commands on the operator's workstation when the operator runs bosh ssh (or bosh scp/bosh logs -f) with default flags. Affected versions: BOSH CLI versions prior to 7.10.5.

▾ Twilightcloudfoundry · bosh_cliEPSS 0.23%via NVD

Most-changed records

Existing CVEs whose severity, score, KEV or exploitation status moved.

  • CVE-2026-56290The Joomla extension Page Builder CK is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE.85
  • CVE-2022-25061TP-LINK TL-WR840N(ES)_V6.20_180709 was discovered to contain a command injection vulnerability via the component oal_setIp6DefaultRoute.78

Most-affected vendors

By CVEs published in the period.