VulnSea

Daily digest

Friday 10 July 2026

A heavy day: 198 new CVEs, well above the recent average of about 81. Of those, 20 critical and 43 high. 11 arrived with exploitation evidence or public exploit code already attached. CISA added 2 CVEs to the Known Exploited Vulnerabilities catalog. siyuan-note was the most-affected vendor with 7.

198
New CVEs
20
Critical
2
KEV additions
2
Records changed

Added to CISA KEV

Confirmed exploitation in the wild — federal remediation deadlines attach to these.

New this day, ranked by depth score

The 12 that matter most of the 198 published.

CVE-2026-61459Critical· 9.8PoC
2mo ago

MCP Server Kubernetes before 3.9.0 contains an argument injection vulnerability in structured tools (kubectl_get, kubectl_describe, kubectl_delete) that allows attackers to bypass the assertNoDangerousFlags security check by supplying re…

MCP Server Kubernetes before 3.9.0 contains an argument injection vulnerability in structured tools (kubectl_get, kubectl_describe, kubectl_delete) that allows attackers to bypass the assertNoDangerousFlags security check by supplying re…

▾ Abyssalsuyogs · mcp-server-kubernetesEPSS 2.4%via NVD
CVE-2026-54088CriticalPoC
2mo ago

File Browser: Command Injection via Authentication Hook Shell Substitution (Pre-Authentication RCE)

File Browser: Command Injection via Authentication Hook Shell Substitution (Pre-Authentication RCE)

▾ Abyssalfilebrowser · github.com/filebrowser/filebrowser/v2EPSS 0.76%via GHSA
CVE-2026-54069CriticalPoC
2mo ago

SiYuan: Unauthenticated Admin API Access via Blanket chrome-extension:// Origin Allowlist

SiYuan: Unauthenticated Admin API Access via Blanket chrome-extension:// Origin Allowlist

▾ Abyssalsiyuan-note · github.com/siyuan-note/siyuan/kernelEPSS 0.58%via GHSA
CVE-2026-57850High· 8.3PoC
2mo ago

RustDesk before 1.4.9 does not enforce a session's authorized connection scope on the server side, so a peer granted a limited session type (FileTransfer, PortForward, ViewCamera, or Terminal) can send control messages and login options …

RustDesk before 1.4.9 does not enforce a session's authorized connection scope on the server side, so a peer granted a limited session type (FileTransfer, PortForward, ViewCamera, or Terminal) can send control messages and login options …

▾ MidnightEPSS 0.50%via NVD
CVE-2026-54159Critical· 10.0
2mo ago

prestashop/ps_facetedsearch: PHP Object Injection in faceted search cache allows unauthenticated RCE

prestashop/ps_facetedsearch: PHP Object Injection in faceted search cache allows unauthenticated RCE

▾ Midnightprestashop · prestashop/ps_facetedsearchEPSS 0.75%via GHSA
CVE-2026-54158Critical· 9.9
2mo ago

SiYuan: Stored XSS to RCE via attribute-view cell rendering in genAVValueHTML()

SiYuan: Stored XSS to RCE via attribute-view cell rendering in genAVValueHTML()

▾ Midnightsiyuan-note · github.com/siyuan-note/siyuan/kernelEPSS 0.51%via GHSA
CVE-2026-54067Critical· 9.9
2mo ago

SiYuan: Stored XSS to RCE via CSS-snippet <style> breakout in renderSnippet()

SiYuan: Stored XSS to RCE via CSS-snippet <style> breakout in renderSnippet()

▾ Midnightsiyuan-note · github.com/siyuan-note/siyuan/kernelEPSS 0.54%via GHSA
CVE-2026-50551Critical· 9.9
2mo ago

SiYuan: Stored XSS to RCE via Unsanitized Attribute View Asset Cell Content

SiYuan: Stored XSS to RCE via Unsanitized Attribute View Asset Cell Content

▾ Midnightsiyuan-note · github.com/siyuan-note/siyuan/kernelEPSS 0.78%via GHSA
CVE-2026-14480Critical· 9.9
2mo ago

OpenPLC Runtime v3 contains an authenticated arbitrary file write vulnerability in the legacy web UI program‑upload workflow

OpenPLC Runtime v3 contains an authenticated arbitrary file write vulnerability in the legacy web UI program‑upload workflow. The application stores an attacker‑supplied filename (prog_file) directly into the Programs.File database fi…

▾ MidnightEPSS 0.62%via NVD
CVE-2026-5801Critical· 9.8
2mo ago

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Semtek Informatics Software Consulting Trade Ltd

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Semtek Informatics Software Consulting Trade Ltd. Co. SEM-PMP allows Command Line Execution through SQL Injection. This issue affects …

▾ MidnightEPSS 0.58%via NVD
CVE-2026-57807Critical· 9.8
2mo ago

Authentication Bypass Using an Alternate Path or Channel vulnerability in miniOrange Security Software Pvt Ltd

Authentication Bypass Using an Alternate Path or Channel vulnerability in miniOrange Security Software Pvt Ltd. OAuth Single Sign On - SSO (OAuth Client) allows Password Recovery Exploitation. This issue affects OAuth Single Sign On - S…

▾ MidnightEPSS 0.73%via NVD
CVE-2026-54066High· 7.5PoC
2mo ago

SiYuan: Path Traversal via Double URL Encoding in /assets/*path (publish mode arbitrary file─read), Incomplete fix of CVE-2026-41894

SiYuan: Path Traversal via Double URL Encoding in /assets/*path (publish mode arbitrary file─read), Incomplete fix of CVE-2026-41894

▾ Midnightsiyuan-note · github.com/siyuan-note/siyuan/kernelEPSS 2.4%via GHSA

Most-changed records

Existing CVEs whose severity, score, KEV or exploitation status moved.

  • CVE-2026-48939A vulnerability in the iCagenda extension for Joomla allows the upload of arbitrary files in the file attachment feature, ultimately resulting in PHP code upload and execution.83
  • CVE-2026-34486Missing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the fix for CVE-2026-29146 allowing the bypass of the EncryptInterceptor. This issue affects Apache Tomcat: 11.0.20, 10.1.53, 9.0.116. Users are recommended to …68

Most-affected vendors

By CVEs published in the period.