Daily digest
Friday 10 July 2026
A heavy day: 198 new CVEs, well above the recent average of about 81. Of those, 20 critical and 43 high. 11 arrived with exploitation evidence or public exploit code already attached. CISA added 2 CVEs to the Known Exploited Vulnerabilities catalog. siyuan-note was the most-affected vendor with 7.
Added to CISA KEV
Confirmed exploitation in the wild — federal remediation deadlines attach to these.
CVE-2026-48939Critical· 9.8CISA KEVPoCA vulnerability in the iCagenda extension for Joomla allows the upload of arbitrary files in the file attachment feature, ultimately resulting in PHP code upload and execution.
A vulnerability in the iCagenda extension for Joomla allows the upload of arbitrary files in the file attachment feature, ultimately resulting in PHP code upload and execution.
CVE-2026-56291Critical· 9.8CISA KEV0dayPoCThe Joomla extension Balbooa Forms is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE.
The Joomla extension Balbooa Forms is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE.
New this day, ranked by depth score
The 12 that matter most of the 198 published.
CVE-2026-61459Critical· 9.8PoCMCP Server Kubernetes before 3.9.0 contains an argument injection vulnerability in structured tools (kubectl_get, kubectl_describe, kubectl_delete) that allows attackers to bypass the assertNoDangerousFlags security check by supplying re…
MCP Server Kubernetes before 3.9.0 contains an argument injection vulnerability in structured tools (kubectl_get, kubectl_describe, kubectl_delete) that allows attackers to bypass the assertNoDangerousFlags security check by supplying re…
CVE-2026-54088CriticalPoCFile Browser: Command Injection via Authentication Hook Shell Substitution (Pre-Authentication RCE)
File Browser: Command Injection via Authentication Hook Shell Substitution (Pre-Authentication RCE)
CVE-2026-54069CriticalPoCSiYuan: Unauthenticated Admin API Access via Blanket chrome-extension:// Origin Allowlist
SiYuan: Unauthenticated Admin API Access via Blanket chrome-extension:// Origin Allowlist
CVE-2026-57850High· 8.3PoCRustDesk before 1.4.9 does not enforce a session's authorized connection scope on the server side, so a peer granted a limited session type (FileTransfer, PortForward, ViewCamera, or Terminal) can send control messages and login options …
RustDesk before 1.4.9 does not enforce a session's authorized connection scope on the server side, so a peer granted a limited session type (FileTransfer, PortForward, ViewCamera, or Terminal) can send control messages and login options …
CVE-2026-54159Critical· 10.0prestashop/ps_facetedsearch: PHP Object Injection in faceted search cache allows unauthenticated RCE
prestashop/ps_facetedsearch: PHP Object Injection in faceted search cache allows unauthenticated RCE
CVE-2026-54158Critical· 9.9SiYuan: Stored XSS to RCE via attribute-view cell rendering in genAVValueHTML()
SiYuan: Stored XSS to RCE via attribute-view cell rendering in genAVValueHTML()
CVE-2026-54067Critical· 9.9SiYuan: Stored XSS to RCE via CSS-snippet <style> breakout in renderSnippet()
SiYuan: Stored XSS to RCE via CSS-snippet <style> breakout in renderSnippet()
CVE-2026-50551Critical· 9.9SiYuan: Stored XSS to RCE via Unsanitized Attribute View Asset Cell Content
SiYuan: Stored XSS to RCE via Unsanitized Attribute View Asset Cell Content
CVE-2026-14480Critical· 9.9OpenPLC Runtime v3 contains an authenticated arbitrary file write vulnerability in the legacy web UI program‑upload workflow
OpenPLC Runtime v3 contains an authenticated arbitrary file write vulnerability in the legacy web UI program‑upload workflow. The application stores an attacker‑supplied filename (prog_file) directly into the Programs.File database fi…
CVE-2026-5801Critical· 9.8Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Semtek Informatics Software Consulting Trade Ltd
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Semtek Informatics Software Consulting Trade Ltd. Co. SEM-PMP allows Command Line Execution through SQL Injection. This issue affects …
CVE-2026-57807Critical· 9.8Authentication Bypass Using an Alternate Path or Channel vulnerability in miniOrange Security Software Pvt Ltd
Authentication Bypass Using an Alternate Path or Channel vulnerability in miniOrange Security Software Pvt Ltd. OAuth Single Sign On - SSO (OAuth Client) allows Password Recovery Exploitation. This issue affects OAuth Single Sign On - S…
CVE-2026-54066High· 7.5PoCSiYuan: Path Traversal via Double URL Encoding in /assets/*path (publish mode arbitrary file─read), Incomplete fix of CVE-2026-41894
SiYuan: Path Traversal via Double URL Encoding in /assets/*path (publish mode arbitrary file─read), Incomplete fix of CVE-2026-41894
Most-changed records
Existing CVEs whose severity, score, KEV or exploitation status moved.
- CVE-2026-48939A vulnerability in the iCagenda extension for Joomla allows the upload of arbitrary files in the file attachment feature, ultimately resulting in PHP code upload and execution.kev, exploited83
- CVE-2026-34486Missing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the fix for CVE-2026-29146 allowing the bypass of the EncryptInterceptor. This issue affects Apache Tomcat: 11.0.20, 10.1.53, 9.0.116. Users are recommended to …epss68
Most-affected vendors
By CVEs published in the period.