VulnSea

Weekly digest

Week 26, 2026 (22–28 Jun)

A heavy week: 574 new CVEs, well above the recent average of about 312. Of those, 51 critical and 224 high. 26 arrived with exploitation evidence or public exploit code already attached. CISA added 2 CVEs to the Known Exploited Vulnerabilities catalog. linux was the most-affected vendor with 95.

574
New CVEs
51
Critical
2
KEV additions
0
Records changed

Added to CISA KEV

Confirmed exploitation in the wild — federal remediation deadlines attach to these.

New this week, ranked by depth score

The 12 that matter most of the 574 published.

CVE-2026-49869Critical· 10.0CISA KEVPoC
2mo ago

Kestra is an open-source, event-driven orchestration platform

Kestra is an open-source, event-driven orchestration platform. Prior to 1.0.45 and 1.3.21, AuthenticationFilter in Kestra OSS uses request.getPath().endsWith("/configs") to whitelist the public configuration endpoint from Basic Auth. Bec…

Hadalkestra · kestraEPSS 1.9%via NVD
CVE-2026-53266High· 8.8CISA KEVPoC
2mo ago

In the Linux kernel, the following vulnerability has been resolved: netfilter: bridge: make ebt_snat ARP rewrite writable The ebtables SNAT target keeps the Ethernet source address rewrite behind skb_ensure_writable(skb, 0)

In the Linux kernel, the following vulnerability has been resolved: netfilter: bridge: make ebt_snat ARP rewrite writable The ebtables SNAT target keeps the Ethernet source address rewrite behind skb_ensure_writable(skb, 0). This is i…

Abyssallinux · linux_kernelEPSS 0.28%via NVD
CVE-2026-2050High· 7.80day
3mo ago

GIMP HDR File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability

GIMP HDR File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vu…

Abyssalgimp · gimpEPSS 0.61%via NVD
CVE-2026-52806Critical· 9.9PoC
3mo ago

Gogs vulnerable to RCE via git rebase --exec argument injection in pull request merge

Gogs vulnerable to RCE via git rebase --exec argument injection in pull request merge

Abyssalgogs · gogs.io/gogsEPSS 7.9%via GHSA
CVE-2025-71338Critical· 10.0PoC
2mo ago

Flowise through 2.2.7 fails to sanitize path segments in the document-store loader endpoint, allowing unauthenticated attackers to write files outside the storage directory

Flowise through 2.2.7 fails to sanitize path segments in the document-store loader endpoint, allowing unauthenticated attackers to write files outside the storage directory. Attackers can use parent-directory sequences to escape the stor…

Abyssalflowiseai · flowiseEPSS 1.2%via NVD
CVE-2026-54350Critical· 10.0PoC
3mo ago

Budibase has nonymous NoSQL operator injection via published-app query templates

Budibase has nonymous NoSQL operator injection via published-app query templates

Abyssalbudibase · @budibase/serverEPSS 0.54%via GHSA
CVE-2026-52813Critical· 10.0PoC
3mo ago

Gogs has Path Traversal in organization name that results in RCE through Git hooks

Gogs has Path Traversal in organization name that results in RCE through Git hooks

Abyssalgogs · gogs.io/gogsEPSS 1.1%via GHSA
CVE-2026-44024Critical· 9.8PoC
2mo ago

Fluentd is Vulnerable to Remote Code Execution (RCE) via Arbitrary File Write in `${tag}` Placeholder

Fluentd is Vulnerable to Remote Code Execution (RCE) via Arbitrary File Write in `${tag}` Placeholder

Abyssalfluentd · fluentdEPSS 1.1%via GHSA
CVE-2026-56121Critical· 9.8PoC
3mo ago

Feast before 0.63.0 contains an unsafe deserialization vulnerability that allows unauthenticated or unauthorized attackers to achieve remote code execution by sending a crafted gRPC request to the registry server

Feast before 0.63.0 contains an unsafe deserialization vulnerability that allows unauthenticated or unauthorized attackers to achieve remote code execution by sending a crafted gRPC request to the registry server. The user_defined_functi…

AbyssalEPSS 1.4%via NVD
CVE-2026-52924Critical· 9.8PoC
3mo ago

In the Linux kernel, the following vulnerability has been resolved: sctp: purge outqueue on stale COOKIE-ECHO handling sctp_stream_update() is only invoked when the association is moved into COOKIE_WAIT during association setup/reconfi…

In the Linux kernel, the following vulnerability has been resolved: sctp: purge outqueue on stale COOKIE-ECHO handling sctp_stream_update() is only invoked when the association is moved into COOKIE_WAIT during association setup/reconfi…

Abyssallinux · linux_kernelEPSS 0.44%via NVD
CVE-2026-11746Critical· 9.4PoC
3mo ago

A vulnerability has been identified in centraldogma-server versions prior to 0.84.0, where enabling ZooKeeper replication without setting replication.secret causes the server to silently fall back to a hard-coded, publicly known secret

A vulnerability has been identified in centraldogma-server versions prior to 0.84.0, where enabling ZooKeeper replication without setting replication.secret causes the server to silently fall back to a hard-coded, publicly known secret. …

AbyssalLY Corporation · Central DogmaEPSS 0.23%via NVD
CVE-2026-53519Critical· 9.1PoC
2mo ago

Nezha Monitoring: Pre-auth path traversal via /dashboard.. prefix confusion leaks jwt_secret_key

Nezha Monitoring: Pre-auth path traversal via /dashboard.. prefix confusion leaks jwt_secret_key

Abyssalnezhahq · github.com/nezhahq/nezhaEPSS 1.9%via GHSA

Most-affected vendors

By CVEs published in the period.