Weekly digest
Week 25, 2026 (15–21 Jun)
A heavy week: 766 new CVEs, well above the recent average of about 237. Severity skewed high: 88 critical and 327 high, 54% of the total. 32 arrived with exploitation evidence or public exploit code already attached. No new KEV entries. openclaw was the most-affected vendor with 54.
New this week, ranked by depth score
The 12 that matter most of the 766 published.
CVE-2026-12569Critical· 9.8CISA KEVA critical remote code execution (RCE) vulnerability has been reported in PTC Windchill PDMlink and PTC FlexPLM
A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill PDMlink and PTC FlexPLM. The vulnerability may be exploited through the deserialization of untrusted data. * This advisory also applies to all CPS…
CVE-2026-48939Critical· 9.8CISA KEVPoCA vulnerability in the iCagenda extension for Joomla allows the upload of arbitrary files in the file attachment feature, ultimately resulting in PHP code upload and execution.
A vulnerability in the iCagenda extension for Joomla allows the upload of arbitrary files in the file attachment feature, ultimately resulting in PHP code upload and execution.
CVE-2026-55255Critical· 9.9CISA KEVPoCLangflow: IDOR Vulnerability in `/api/v1/responses` Endpoint Allows Authenticated Attackers to Access Another User's Flow
Langflow: IDOR Vulnerability in `/api/v1/responses` Endpoint Allows Authenticated Attackers to Access Another User's Flow
CVE-2026-0755Critical· 9.80daygemini-mcp-tool vulnerable to OS command injection and @file exfiltration via prompt quoting (CVE-2026-0755)
gemini-mcp-tool vulnerable to OS command injection and @file exfiltration via prompt quoting (CVE-2026-0755)
CVE-2026-7273High· 8.8CISA KEVPoCA stack-based buffer overflow vulnerability in the CGI program of Zyxel GS1900-48HPv2 firmware versions through 2.90(ABTQ.1)C0 could allow a LAN-based, unauthenticated attacker to exploit the flaw and potentially execute OS commands via …
A stack-based buffer overflow vulnerability in the CGI program of Zyxel GS1900-48HPv2 firmware versions through 2.90(ABTQ.1)C0 could allow a LAN-based, unauthenticated attacker to exploit the flaw and potentially execute OS commands via …
CVE-2026-56265Critical· 9.8PoCCrawl4AI: authentication bypass vulnerability due to a hardcoded default JWT signing key in the Docker API server
Crawl4AI: authentication bypass vulnerability due to a hardcoded default JWT signing key in the Docker API server
CVE-2026-47103Critical· 9.8PoCpython-statemachine SCXML <data expr> Eval Injection
python-statemachine SCXML <data expr> Eval Injection
CVE-2026-53753Critical· 9.8PoCCrawl4AI: AST Sandbox Escape via gi_frame.f_back Chain - Pre-Auth RCE in Docker API
Crawl4AI: AST Sandbox Escape via gi_frame.f_back Chain - Pre-Auth RCE in Docker API
CVE-2026-49468Critical· 9.8PoCLiteLLM: Authentication Bypass via Host Header Injection
LiteLLM: Authentication Bypass via Host Header Injection
CVE-2026-12295Critical· 9.6PoCSandbox escape in the DOM: Navigation component
Sandbox escape in the DOM: Navigation component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird 152, and Thunderbird 140.12.
CVE-2026-55450Critical· 9.3PoCLangflow: Unauthenticated file upload leads to DoS (space exhaustion) and information leak
Langflow: Unauthenticated file upload leads to DoS (space exhaustion) and information leak
CVE-2026-54157Critical· 9.0PoCLobeHub: Unauthenticated SSRF in `/webapi/proxy`
LobeHub: Unauthenticated SSRF in `/webapi/proxy`
Most-affected vendors
By CVEs published in the period.