16 vulnerabilities across 8 products scored HIGH or above on June 08, 2026.

  • CRITICAL: 2
  • HIGH: 14

[CRITICAL] checkpoint/quantum_security_gateway

2 CVEs | CVSS 3.1: 9.3 | AAS 13.8

Checkpoint Quantum Security Gateway is affected by multiple critical vulnerabilities (CVE-2026-50751 and CVE-2026-50752, CVSS 9.3) that allow unauthenticated remote attackers to bypass user authentication and establish remote access VPN connections without valid credentials. The issue stems from logic flow weaknesses in certificate validation for Remote Access and Mobile Access via deprecated IKEv1 key exchange. Organizations running affected Quantum Security Gateway instances should immediately apply available patches per Checkpoint’s advisory at https://support.checkpoint.com/results/sk/sk185033 to mitigate exploitation risk.

Vendor Advisory


[HIGH] apache_software_foundation/apache_http_server

7 CVEs | CVSS 3.1: 7.5 | AAS 11.8

Apache HTTP Server versions 2.4.0 through 2.4.67 are affected by multiple vulnerabilities including at least one heap-based buffer overflow in mod_xml2enc (CVSS 7.5) triggered by untrusted content. The advisory addresses a total of seven CVEs in this range. Organizations running Apache HTTP Server should upgrade to version 2.4.68 immediately; see https://httpd.apache.org/security/vulnerabilities_24.html for complete details.

Vendor Advisory


[HIGH] webkul/bagisto

1 CVE | CVSS 4.0: 8.7 | AAS 11.6

Bagisto is vulnerable to a path traversal vulnerability (CVE-2026-9506, CVSS 8.7) in the ImageCacheController component that allows unauthenticated remote attackers to access arbitrary files on the system. The flaw stems from improper validation of user-supplied input in the filename parameter, enabling attackers to read sensitive files outside the intended directory. Organizations using Bagisto should apply available patches promptly; see https://www.cert-in.org.in/s2cMainServlet?pageid=PUBVLNOTES01&VLCODE=CIVN-2026-0292 for guidance.

Vendor Advisory


[HIGH] phpoffice/phpspreadsheet

1 CVE | CVSS 3.1: 9.5 | AAS 10.8

PHPSpreadsheet contains a stream wrapper bypass vulnerability (CVE-2026-45034, CVSS 9.5) in the File::prohibitWrappers validation logic that can be circumvented using paths with multiple slashes in the scheme, such as phar:///path/file.phar/inner. An attacker could exploit this to access sensitive files or execute arbitrary code via restricted stream wrappers. Organizations using PHPSpreadsheet should update to the latest patched version; see https://github.com/advisories/GHSA-87m4-826x-3crx for details.

Vendor Advisory


[HIGH] stackit/iaas_api

1 CVE | CVSS 4.0: 9.3 | AAS 10.2

STACKIT IaaS API contains a privilege escalation vulnerability (CVE-2026-39910, CVSS 9.3) stemming from missing authorization checks on the service-accounts endpoint. An authenticated, low-privileged attacker can exploit this to attach high-privileged service accounts to virtual machines under their control and retrieve OAuth2 tokens via the Instance Metadata Service, achieving full organization compromise. Organizations using STACKIT IaaS should contact the vendor for patching guidance at https://status.stackit.cloud.

Vendor Advisory


[HIGH] flowiseai/flowise

2 CVEs | CVSS 4.0: 9.4 | AAS 9.8

Flowise prior to version 3.1.2 contains multiple vulnerabilities including at least one missing authorization check in the POST /api/v1/node-custom-function endpoint (CVSS 9.4) that allows any authenticated user to submit arbitrary JavaScript code to the Custom JS Function node. In common deployments without E2B_APIKEY configured, the NodeVM sandbox can be escaped to execute system commands with the privileges of the Flowise process. Organizations running Flowise should upgrade to version 3.1.2 or later immediately; see https://github.com/FlowiseAI/Flowise/releases/tag/flowise%403.1.2 for details.

Vendor Advisory


[HIGH] nginxproxymanager/nginx-proxy-manager

1 CVE | CVSS 4.0: 7.7 | AAS 9.5

Nginx Proxy Manager versions 2.9.14 through 2.15.1 contain a remote code execution vulnerability (CVE-2026-40519, CVSS 7.7) in the setupCertbotPlugins() function where the dns_provider_credentials field is directly interpolated into a shell command without sanitization. An authenticated attacker with certificates:manage permission can exploit this to execute arbitrary commands on the host system. Organizations running affected versions should upgrade immediately to the patched version; see https://github.com/NginxProxyManager/nginx-proxy-manager/commit/a5db5ed156355e3088e7d1ceb0533d4bae922def for remediation.

Vendor Advisory


[HIGH] python_software_foundation/cpython

1 CVE | CVSS 4.0: 8.2 | AAS 9.5

CPython’s bz2.BZ2Decompressor object can be exploited via a buffer overflow vulnerability (CVE-2026-9669, CVSS 8.2) when reused after a decompression error. If an application catches the decompression error and retries using the same decompressor object with crafted input, an attacker can trigger out-of-bounds writes to the stack and crash the process. Organizations running CPython and processing untrusted bz2-compressed data should upgrade to a patched version; see https://github.com/python/cpython/issues/150599 for details.

Vendor Advisory