40 vulnerabilities across 15 products scored HIGH or above on June 16, 2026.

  • CRITICAL: 17
  • HIGH: 23

[CRITICAL] pip/langflow

3 CVEs | CVSS 3.1: 9.6 | AAS 13.4

  • cpe:2.3:a:pip:langflow:*:*:*:*:*:*:*:*

Langflow contains three critical vulnerabilities affecting its Shareable Playground feature, with CVE-2026-48519 rated CVSS 9.6, enabling remote code execution when workflows are shared via public links. Organizations using Langflow should immediately apply patches or disable public flow sharing functionality, as exploits are publicly available. Consult the vendor advisory at https://github.com/advisories/GHSA-v5ff-9q35-q26f for guidance on affected versions and remediation steps.

Vendor Advisory


[CRITICAL] oracle_corporation/weblogic_server

11 CVEs | CVSS 3.1: 10.0 | AAS 13.3

  • cpe:2.3:a:oracle:weblogic_server:*:*:*:*:*:*:*:* (>= 14.1.0.0)
  • cpe:2.3:a:oracle:weblogic_server:*:*:*:*:*:*:*:* (>= 15.1.0.0)
  • cpe:2.3:a:oracle:weblogic_server:*:*:*:*:*:*:*:* (>= 12.2.1.4.0)
  • cpe:2.3:a:oracle:weblogic_server:*:*:*:*:*:*:*:* (>= 14.1.1.0.0)
  • cpe:2.3:a:oracle:weblogic_server:*:*:*:*:*:*:*:* (>= 12.2.1.0.0)

Oracle WebLogic Server versions 14.1.2.0.0 and 15.1.1.0.0 are affected by eleven critical vulnerabilities, including multiple with CVSS ratings up to 10.0, though current exploitation remains theoretical. Organizations operating these WebLogic Server versions should immediately plan patching when vendor updates are released. Consult the vendor security alert at https://www.oracle.com/security-alerts/cspujun2026.html for affected versions, vulnerability details, and remediation guidance.

Vendor Advisory


[CRITICAL] dell/openmanage

1 CVE | CVSS 3.1: 8.8 | AAS 13.1

  • cpe:2.3:a:dell:openmanage:*:*:*:*:*:*:*:*

Dell OpenManage Integration with Microsoft Windows Admin Center contains a critical remote code execution vulnerability (CVE-2024-24909, CVSS 8.8) in the gateway plugin, allowing authenticated users to escalate privileges and execute arbitrary code remotely. The vulnerability is actively exploitable and organizations should immediately apply the available security patch. Review the vendor advisory at https://www.dell.com/support/kbdoc/en-us/000222075/dsa-2024-084-security-update-for-dell-openmanage-integration-with-microsoft-windows-admin-center for complete details and remediation guidance.

Vendor Advisory


[CRITICAL] go/traefik

2 CVEs | CVSS 3.1: 8.0 | AAS 12.8

  • cpe:2.3:a:go:traefik:*:*:*:*:*:*:*:*

Traefik contains two critical vulnerabilities including multiple that affect SNICheck domain-fronting protection, with maximum CVSS 8.0, allowing unauthenticated clients to bypass mutual TLS requirements on wildcard router configurations. Organizations using Traefik with wildcard TLS options should immediately apply available security patches. Refer to the vendor advisory at https://github.com/advisories/GHSA-5r4w-85f3-pw66 for affected versions and remediation guidance.

Vendor Advisory


[HIGH] oracle_corporation/oracle_coherence

7 CVEs | CVSS 3.1: 10.0 | AAS 11.3

  • cpe:2.3:a:oracle:oracle_coherence:*:*:*:*:*:*:*:* (>= 12.2.1.4.0)
  • cpe:2.3:a:oracle:oracle_coherence:*:*:*:*:*:*:*:* (>= 14.1.1.0.0)
  • cpe:2.3:a:oracle:oracle_coherence:*:*:*:*:*:*:*:* (>= 14.1.2.0.0)
  • cpe:2.3:a:oracle:oracle_coherence:*:*:*:*:*:*:*:* (>= 15.1.1.0.0)

Oracle Coherence versions 12.2.1.4.0, 14.1.1.0.0, and 14.1.2.0.0 are vulnerable to seven issues, including multiple with CVSS ratings up to 10.0, though current exploitation remains theoretical. Organizations operating these Coherence versions should immediately review patch availability and plan updates. Consult the vendor security alert at https://www.oracle.com/security-alerts/cspujun2026.html for complete vulnerability details and remediation guidance.

Vendor Advisory


[HIGH] pip/crawl4ai

2 CVEs | CVSS 3.1: 9.8 | AAS 11.1

  • cpe:2.3:a:pip:crawl4ai:*:*:*:*:*:*:*:*

Crawl4ai contains two vulnerabilities, including multiple affecting the computed fields feature, with maximum CVSS 9.8, enabling unauthenticated remote code execution through AST validation bypass when processing extraction schemas. The vulnerabilities require no authentication and can be triggered via a POST request to /crawl. Organizations deploying Crawl4ai should immediately apply vendor patches and review access controls; refer to https://github.com/advisories/GHSA-qxjp-w3pj-48m7 for remediation details.

Vendor Advisory


[HIGH] github.com/rclone/rclone

1 CVE | CVSS 3.1: 9.8 | AAS 11.1

  • cpe:2.3:a:github.com:rclone_rclone:*:*:*:*:*:*:*:* (>= 1.55.0)

Rclone’s rcd daemon accepts unauthenticated GET and HEAD requests that parse inline remote configuration, enabling remote code execution as the rclone process user (CVE-2026-49980, CVSS 9.8). An attacker can trigger command execution by crafting a request with malicious backend options. Organizations running rclone rcd daemon should immediately disable the service or apply patches; consult https://github.com/advisories/GHSA-qw24-gh76-8rvv for remediation guidance.

Vendor Advisory


[HIGH] truelockmc/streambert

1 CVE | CVSS 3.1: 10.0 | AAS 10.8

  • cpe:2.3:a:truelockmc:streambert:*:*:*:*:*:*:*:* (< 2.4.1)

Streambert versions prior to 2.5.0 contain a critical Zip Slip vulnerability in subtitle extraction that fails to sanitize archive entry filenames, enabling arbitrary file write to the host filesystem (CVE-2026-48055, CVSS 10.0). The vulnerability is actively exploitable and allows local privilege escalation or system compromise. Users should immediately upgrade to Streambert 2.5.0 or later; consult the vendor advisory at https://github.com/truelockmc/streambert/security/advisories/GHSA-3q2x-3q9p-qwfc for remediation guidance.

Vendor Advisory


[HIGH] oracle_corporation/oracle_access_manager

1 CVE | CVSS 3.1: 9.9 | AAS 10.7

  • cpe:2.3:a:oracle:oracle_access_manager:*:*:*:*:*:*:*:* (>= 12.2.1.4.0)
  • cpe:2.3:a:oracle:oracle_access_manager:*:*:*:*:*:*:*:* (>= 14.1.2.1.0)

Oracle Access Manager versions 12.2.1.4.0 and 14.1.2.1.0 contain a critical vulnerability (CVE-2026-35313, CVSS 9.9), though current exploitation remains theoretical. Organizations operating these Access Manager versions should immediately review patch availability and plan upgrades. Consult the vendor security alert at https://www.oracle.com/security-alerts/cspujun2026.html for complete details and remediation steps.

Vendor Advisory


[HIGH] oracle_corporation/identity_manager

4 CVEs | CVSS 3.1: 9.9 | AAS 10.6

  • cpe:2.3:a:oracle:identity_manager:*:*:*:*:*:*:*:* (>= 12.2.1.0.0, < 12.2.1.4.0)
  • cpe:2.3:a:oracle:identity_manager:*:*:*:*:*:*:*:* (>= 14.1.2.0.0, < 14.1.2.1.0)
  • cpe:2.3:a:oracle:identity_manager:*:*:*:*:*:*:*:* (>= 12.2.1.4.0)
  • cpe:2.3:a:oracle:identity_manager:*:*:*:*:*:*:*:* (>= 14.1.2.1.0)
  • cpe:2.3:a:oracle:identity_manager:*:*:*:*:*:*:*:* (>= 12.2.1.0.0)

Oracle Identity Manager versions 12.2.1.4.0 and 14.1.2.1.0 contain four vulnerabilities, including multiple with maximum CVSS 9.9, though current exploitation remains theoretical. Organizations operating these Identity Manager versions should immediately review patch availability and plan upgrades. Consult the vendor security alert at https://www.oracle.com/security-alerts/cspujun2026.html for complete details and remediation steps.

Vendor Advisory


[HIGH] pip/vllm

1 CVE | CVSS 3.1: 9.1 | AAS 10.4

  • cpe:2.3:a:pip:vllm:*:*:*:*:*:*:*:*

vLLM’s OpenAI API implementation contains an authentication bypass vulnerability that allows unauthenticated access without the configured VLLM_API_KEY or –api-key (CVE-2026-48746, CVSS 9.1). The vulnerability stems from improper URL path handling in ASGI web servers and Starlette. Organizations running vLLM should immediately apply available patches; consult https://github.com/advisories/GHSA-94f4-hr76-p5j6 for remediation details.

Vendor Advisory


[HIGH] npm/n8n

3 CVEs | CVSS 3.1: 10.0 | AAS 10.3

  • cpe:2.3:a:npm:n8n:*:*:*:*:*:*:*:* (< 2.25.7)
  • cpe:2.3:a:npm:n8n:*:*:*:*:*:*:*:* (>= 2.26.0, < 2.26.2)

n8n is affected by three vulnerabilities, including multiple in the @n8n/mcp-browser component operating in HTTP transport mode, with maximum CVSS 10.0, enabling unauthenticated access to browser-control tools such as navigation and JavaScript execution. When the n8n AI Browser Bridge extension is installed and active, any network-reachable client can invoke these capabilities remotely. Organizations using n8n should immediately apply vendor patches or disable the MCP browser component; consult https://github.com/advisories/GHSA-qrx8-25qr-5r7v for remediation guidance.

Vendor Advisory


[HIGH] gitroomhq/postiz-app

1 CVE | CVSS 3.1: 9.9 | AAS 10.2

  • cpe:2.3:a:gitroomhq:postiz-app:*:*:*:*:*:*:*:* (< 2.21.8)

Postiz versions prior to 2.21.8 contain a critical privilege escalation vulnerability that allows authenticated users to forge SUPERADMIN session tokens and gain full access to the platform (CVE-2026-48781, CVSS 9.9). The flaw exists in the Skool integration callback, which signs attacker-controlled JWT claims without proper validation. Organizations deploying Postiz should immediately upgrade to version 2.21.8 or later; consult https://github.com/gitroomhq/postiz-app/security/advisories/GHSA-j77w-h625-56q2 for remediation guidance.

Vendor Advisory


[HIGH] schiocco/support_board

1 CVE | CVSS 3.1: 9.8 | AAS 10.1

  • cpe:2.3:a:schiocco:support_board:*:*:*:*:*:*:*:* (< 3.8.9)

Support Board versions prior to 3.8.9 contain an unauthenticated privilege escalation vulnerability enabling attackers to gain elevated access without authentication (CVE-2026-27395, CVSS 9.8). The vulnerability is currently exploitable and represents critical risk to WordPress installations. Organizations deploying Support Board should immediately upgrade to version 3.8.9 or later; consult https://patchstack.com/database/wordpress/plugin/supportboard/vulnerability/wordpress-support-board-plugin-3-8-9-privilege-escalation-vulnerability?_s_id=cve for remediation guidance.

Vendor Advisory


[HIGH] liquid_web_/_stellarwp/the_events_calendar

1 CVE | CVSS 3.1: 9.3 | AAS 10.1

  • cpe:2.3:a:liquid_web_stellarwp:the_events_calendar:*:*:*:*:*:*:*:*

The Events Calendar versions 6.15.12 through 6.16.2 contain a blind SQL injection vulnerability enabling database extraction and potential unauthorized access (CVE-2026-49772, CVSS 9.3). The vulnerability is currently exploitable and affects WordPress installations of this plugin. Organizations deploying The Events Calendar should immediately upgrade to a patched version; consult https://patchstack.com/database/wordpress/plugin/the-events-calendar/vulnerability/wordpress-the-events-calendar-plugin-6-15-12-6-16-2-sql-injection-vulnerability?_s_id=cve for remediation guidance.

Vendor Advisory