VulnSea

Weekly digest

Week 24, 2026 (8–14 Jun)

A heavy week: 402 new CVEs, well above the recent average of about 208. Of those, 31 critical and 164 high. 33 arrived with exploitation evidence or public exploit code already attached. CISA added one CVE to the Known Exploited Vulnerabilities catalog. vmware was the most-affected vendor with 35.

402
New CVEs
31
Critical
1
KEV additions
0
Records changed

Added to CISA KEV

Confirmed exploitation in the wild — federal remediation deadlines attach to these.

New this week, ranked by depth score

The 12 that matter most of the 402 published.

CVE-2026-25089Critical· 9.8CISA KEVPoC
3mo ago

A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox 4.2 all versions, FortiSandbox Cloud …

A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox 4.2 all versions, FortiSandbox Cloud …

Hadalfortinet · fortisandboxEPSS 76%via NVD
CVE-2026-53435High· 8.8PoC
3mo ago

In Jenkins 2.567 and earlier, LTS 2.555.2 and earlier, it is possible for attackers to have Jenkins deserialize arbitrary types defined in Jenkins core or plugins from an attacker-controlled `config.xml` submission in a way that allows t…

In Jenkins 2.567 and earlier, LTS 2.555.2 and earlier, it is possible for attackers to have Jenkins deserialize arbitrary types defined in Jenkins core or plugins from an attacker-controlled `config.xml` submission in a way that allows t…

MidnightJenkins Project · JenkinsEPSS 53%via CVEORG
CVE-2026-48030Critical· 9.9PoC
3mo ago

Pheditor: OS Command Injection in terminal handler via unsanitized 'dir' parameter

Pheditor: OS Command Injection in terminal handler via unsanitized 'dir' parameter

Abyssalpheditor · pheditor/pheditorEPSS 5.8%via GHSA
CVE-2026-8467CriticalPoC
3mo ago

PhoenixStorybook: Unauthenticated remote code execution via HEEx template injection in phoenix_storybook playground

PhoenixStorybook: Unauthenticated remote code execution via HEEx template injection in phoenix_storybook playground

Abyssalphoenix_storybook · phoenix_storybookEPSS 2.1%via GHSA
CVE-2026-45833CriticalPoC
3mo ago

ChromaDB has a code injection vulnerability

ChromaDB has a code injection vulnerability

Abyssalchromadb · chromadbEPSS 0.34%via OSV
CVE-2026-45034CriticalPoC
3mo ago

PHPSpreadsheet has a patch bypass for CVE-2026-34084

PHPSpreadsheet has a patch bypass for CVE-2026-34084

Abyssalphpoffice · phpoffice/phpspreadsheetEPSS 0.46%via GHSA
CVE-2026-44990Critical· 9.3PoC
3mo ago

ApostropheCMS is an open-source Node.js content management system, and sanitize-html provides a simple HTML sanitizer with a clear API

ApostropheCMS is an open-source Node.js content management system, and sanitize-html provides a simple HTML sanitizer with a clear API. Under the default configuration, versions of `sanitize-html` prior to 2.17.4 can turn attacker-contro…

Abyssalapostrophecms · sanitize-htmlEPSS 0.60%via NVD
CVE-2026-46316Critical· 9.3PoC⚖ disputed
3mo ago

In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: vgic-its: Drop the translation cache reference only for the erased entry vgic_its_invalidate_cache() walks the per-ITS translation cache with xa_for_each()…

In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: vgic-its: Drop the translation cache reference only for the erased entry vgic_its_invalidate_cache() walks the per-ITS translation cache with xa_for_each()…

Abyssallinux · linux_kernelEPSS 0.44%via NVD
CVE-2026-45504High· 8.8PoC
3mo ago

Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.

Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.

Midnightmicrosoft · exchange_serverEPSS 0.85%via NVD
CVE-2026-45447High· 8.8PoC
3mo ago

Issue summary: A specially crafted PKCS#7 or S/MIME signed message could trigger a use-after-free during PKCS#7 signature verification. Impact summary: A use-after-free may result in process crashes, heap corruption, or potentially remo…

Issue summary: A specially crafted PKCS#7 or S/MIME signed message could trigger a use-after-free during PKCS#7 signature verification. Impact summary: A use-after-free may result in process crashes, heap corruption, or potentially remo…

Midnightopenssl · opensslEPSS 3.6%via NVD
CVE-2026-45674High· 8.7PoC
3mo ago

Netty is a network application framework for development of protocol servers and clients

Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, Netty's DnsResolveContext fails to validate the origin (bailiwick) of CNAME records in DNS respon…

Midnightnetty · nettyEPSS 0.30%via NVD
CVE-2026-44494High· 8.7PoC
3mo ago

Axios is a promise based HTTP client for the browser and Node.js

Axios is a promise based HTTP client for the browser and Node.js. From 1.0.0 to before 1.16.0, the Axios library is vulnerable to a Prototype Pollution "Gadget" attack that allows any Object.prototype pollution in the application's depen…

Midnightaxios · axiosEPSS 1.0%via NVD

Most-affected vendors

By CVEs published in the period.