Weekly digest
Week 23, 2026 (1–7 Jun)
227 new CVEs this week, in line with the recent average. Of those, 13 critical and 84 high. 13 arrived with exploitation evidence or public exploit code already attached. No new KEV entries. google was the most-affected vendor with 19.
New this week, ranked by depth score
The 12 that matter most of the 227 published.
CVE-2026-8037Critical· 9.6CISA KEVPoCOS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an un-authenticated attacker to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in multiple command en…
OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an un-authenticated attacker to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in multiple command en…
CVE-2026-47117Critical· 9.8PoCOpenMed vulnerable to remote code injection through privacy-filter model loading path
OpenMed vulnerable to remote code injection through privacy-filter model loading path
CVE-2024-52011High· 8.3PoClaunch-editor allows users to open files with line numbers in editor from Node.js
launch-editor allows users to open files with line numbers in editor from Node.js. Prior to version 2.9.0, due to the insufficient sanitization of the `file` argument in the `launchEditor`, an attacker can execute arbitrary commands on W…
CVE-2026-41283Critical· 9.9OpenStack Mistral allows Arbitrary Remote Code Execution when the API is exposed
OpenStack Mistral allows Arbitrary Remote Code Execution when the API is exposed
CVE-2026-0091High· 7.8PoCIn multiple locations, there is a possible way to execute code in the launcher process due to an over-privileged shell user
In multiple locations, there is a possible way to execute code in the launcher process due to an over-privileged shell user. This could lead to local escalation of privilege with no additional execution privileges needed. User interactio…
CVE-2026-0009High· 7.8PoCIn multiple locations, there is a possible tapjacking due to a logic error in the code
In multiple locations, there is a possible tapjacking due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
CVE-2026-25550Critical· 9.8Seagull Software BarTender 2010, 2016, and 2019 contain an unauthenticated remote code execution vulnerability in the .NET Remoting service exposed on TCP port 7375 via BtSystem.Service.exe
Seagull Software BarTender 2010, 2016, and 2019 contain an unauthenticated remote code execution vulnerability in the .NET Remoting service exposed on TCP port 7375 via BtSystem.Service.exe. The service registers an unauthenticated singl…
CVE-2026-47065Critical· 9.8ZDRES-232: resolveProxyClass Not Overridden - acceptMatchers Filter Bypass via java.lang.reflect.Proxy Assessment: Fully addressed. When the serialised stream contains a TC_PROXYCLASSDESC (the marker for a java.lang.reflect.Proxy ),…
ZDRES-232: resolveProxyClass Not Overridden - acceptMatchers Filter Bypass via java.lang.reflect.Proxy Assessment: Fully addressed. When the serialised stream contains a TC_PROXYCLASSDESC (the marker for a java.lang.reflect.Proxy ),…
CVE-2026-35075Critical· 9.8An unauthenticated remote attacker can recover a default, hard coded password from a firmware image and thus gain full access to all affected devices.
An unauthenticated remote attacker can recover a default, hard coded password from a firmware image and thus gain full access to all affected devices.
CVE-2026-41567High· 7.2PoCMoby is an open source container framework
Moby is an open source container framework. In versions prior to 29.5.1 and in moby/moby v2 prior to v2.0.0-beta.14, when a compressed archive is uploaded to a container via `PUT /containers/{id}/archive` or piped through `docker cp -`, …
CVE-2026-10290High· 7.3PoCA weakness has been identified in code-projects Hotel and Tourism Reservation System 1.0
A weakness has been identified in code-projects Hotel and Tourism Reservation System 1.0. The affected element is an unknown function of the file tour.php of the component GET Parameter Handler. Executing a manipulation of the argument t…
CVE-2026-46243High· 7.1PoCIn the Linux kernel, the following vulnerability has been resolved: smb: client: reject userspace cifs.spnego descriptions cifs.spnego key descriptions contain authority-bearing fields such as pid, uid, creduid, and upcall_target that …
In the Linux kernel, the following vulnerability has been resolved: smb: client: reject userspace cifs.spnego descriptions cifs.spnego key descriptions contain authority-bearing fields such as pid, uid, creduid, and upcall_target that …
Most-affected vendors
By CVEs published in the period.