VulnSea

Weekly digest

Week 27, 2026 (29 Jun – 5 Jul)

A busier-than-usual week with 574 new CVEs (recent average about 370). Severity skewed high: 49 critical and 239 high, 50% of the total. 47 arrived with exploitation evidence or public exploit code already attached. CISA added one CVE to the Known Exploited Vulnerabilities catalog. Microsoft was the most-affected vendor with 50.

574
New CVEs
49
Critical
1
KEV additions
0
Records changed

Added to CISA KEV

Confirmed exploitation in the wild — federal remediation deadlines attach to these.

New this week, ranked by depth score

The 12 that matter most of the 574 published.

CVE-2026-56290Critical· 9.8CISA KEVPoC
2mo ago

The Joomla extension Page Builder CK is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE.

The Joomla extension Page Builder CK is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE.

Hadaljoomlack · page_builder_ckEPSS 31%via NVD
CVE-2026-9558Critical· 9.9PoC
2mo ago

Mautic has Server-Side Template Injection (SSTI) in Theme Templates

Mautic has Server-Side Template Injection (SSTI) in Theme Templates

Abyssalmautic · mautic/coreEPSS 0.57%via GHSA
CVE-2026-9079Critical· 9.8PoC⚖ disputed
2mo ago

libcurl had a flaw that when instructed to clear proxy authentication credentials which made it not do so, leaving the old credentials around to get used for subsequent transfers that should not know nor use them.

libcurl had a flaw that when instructed to clear proxy authentication credentials which made it not do so, leaving the old credentials around to get used for subsequent transfers that should not know nor use them.

Abyssalhaxx · curlEPSS 0.58%via NVD
CVE-2026-8925Critical· 9.8PoC
2mo ago

The curl logic that works with SASL authentication could end up cleaning up the GSASL context *twice* without clearing the pointer in between, making it `free()` the same pointer twice.

The curl logic that works with SASL authentication could end up cleaning up the GSASL context *twice* without clearing the pointer in between, making it `free()` the same pointer twice.

Abyssalhaxx · curlEPSS 0.67%via NVD
CVE-2026-20896Critical· 9.8PoC
2mo ago

Gitea Docker image versions up to and including 1.26.2 use REVERSE_PROXY_TRUSTED_PROXIES=* by default, allowing any source IP to impersonate a user when reverse-proxy authentication headers such as X-WEBAUTH-USER are enabled.

Gitea Docker image versions up to and including 1.26.2 use REVERSE_PROXY_TRUSTED_PROXIES=* by default, allowing any source IP to impersonate a user when reverse-proxy authentication headers such as X-WEBAUTH-USER are enabled.

AbyssalEPSS 2.8%via NVD
CVE-2026-11856Critical· 9.8PoC
2mo ago

Successfully using libcurl to do a transfer to a specific HTTP origin (`hostA`) with **Digest** authentication and then changing the origin to a different one (`hostB`) for a second transfer, reusing the same handle, makes libcurl wrongl…

Successfully using libcurl to do a transfer to a specific HTTP origin (`hostA`) with **Digest** authentication and then changing the origin to a different one (`hostB`) for a second transfer, reusing the same handle, makes libcurl wrongl…

Abyssalhaxx · curlEPSS 0.69%via NVD
CVE-2026-10536Critical· 9.8PoC⚖ disputed
2mo ago

A use-after-free vulnerability exists in libcurl when an application configures an HTTP/2 stream-dependency tree via `CURLOPT_STREAM_DEPENDS` or `CURLOPT_STREAM_DEPENDS_E`, subsequently invokes `curl_easy_reset()`, and finally terminates…

A use-after-free vulnerability exists in libcurl when an application configures an HTTP/2 stream-dependency tree via `CURLOPT_STREAM_DEPENDS` or `CURLOPT_STREAM_DEPENDS_E`, subsequently invokes `curl_easy_reset()`, and finally terminates…

Abyssalhaxx · curlEPSS 0.60%via NVD
CVE-2026-49352Critical· 9.8PoC
2mo ago

9router's Hardcoded Default fallback JWT Secret Allows Authentication Bypass

9router's Hardcoded Default fallback JWT Secret Allows Authentication Bypass

Abyssal9router · 9routerEPSS 0.60%via GHSA
CVE-2026-22874Critical· 9.6PoC
2mo ago

Gitea versions up to and including 1.26.2 have incomplete SSRF protection in webhook and migration allow-list filtering.

Gitea versions up to and including 1.26.2 have incomplete SSRF protection in webhook and migration allow-list filtering.

AbyssalEPSS 0.46%via NVD
CVE-2026-14382Critical· 9.6PoC
2mo ago

Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page

Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

Abyssalgoogle · chromeEPSS 0.34%via NVD
CVE-2026-8927Critical· 9.1PoC
2mo ago

When reusing a libcurl handle for sequential transfers driven by environment-variable proxy configuration, libcurl fails to clear the proxy authentication state between requests

When reusing a libcurl handle for sequential transfers driven by environment-variable proxy configuration, libcurl fails to clear the proxy authentication state between requests. Specifically, if the initial transfer authenticates agains…

Abyssalhaxx · curlEPSS 0.50%via NVD
CVE-2026-8926Critical· 9.1PoC
2mo ago

When asking curl to use a `.netrc` file to find credentials and at the same time specifying a URL with a username (without a password), like `https://[email protected]/`, curl could wrongly get and use the password for *another* user set …

When asking curl to use a `.netrc` file to find credentials and at the same time specifying a URL with a username (without a password), like `https://[email protected]/`, curl could wrongly get and use the password for *another* user set …

Abyssalhaxx · curlEPSS 0.44%via NVD

Most-affected vendors

By CVEs published in the period.