15 vulnerabilities across 12 products scored HIGH or above on June 19, 2026.
- π΄ CRITICAL: 3
- π HIGH: 12
π΄ [CRITICAL] langflow-ai/langflow
2 CVEs | CVSS 3.1: 9.9 | AAS 13.1
cpe:2.3:a:langflow-ai:langflow:*:*:*:*:*:*:*:*
Langflow by langflow-ai is affected by 2 vulnerabilities, including at least one rated CRITICAL with a CVSS score of 9.9. The most severe issue is an Insecure Direct Object Reference flaw in the responses API endpoint that allows any authenticated user to execute flows belonging to other users by simply specifying a victim’s flow ID, effectively bypassing all access controls between tenants.
Organizations running Langflow should treat this as an urgent priority. Review the vendor advisory at the link above, apply available patches immediately, and audit access logs for any unauthorized cross-user flow execution.
- π΄ CVE-2026-55255 (CVSS 3.1: 9.9)
- π CVE-2026-55447 (CVSS 3.1: 9.6)
π΄ [CRITICAL] sysown/proxysql
2 CVEs | CVSS 3.1: 10.0 | AAS 12.8
cpe:2.3:a:sysown:proxysql:*:*:*:*:*:*:*:*
ProxySQL versions 2.0.0 through 3.0.8 are affected by 2 vulnerabilities, including at least one rated CRITICAL with a CVSS score of 10.0. The most severe issue involves improper handling of PROXY protocol v1 headers, where ProxySQL incorrectly parses address fields from frames marked as UNKNOWN, contrary to the HAProxy specification that mandates these fields be ignored, potentially allowing an attacker to spoof client identity or otherwise compromise the proxy layer.
Database and infrastructure teams running ProxySQL in front of MySQL, PostgreSQL, or compatible forks should upgrade to version 3.0.9 immediately. Review the vendor advisory for full details and assess whether any upstream load balancers or proxies in your environment send PROXY protocol headers that could be leveraged in an attack.
- π΄ CVE-2026-48772 (CVSS 3.1: 10.0)
- π΄ CVE-2026-48773 (CVSS 3.1: 9.8)
π [HIGH] betterdocs/betterdocs_pro
1 CVE | CVSS 3.1: 9.8 | AAS 11.6
cpe:2.3:a:betterdocs:betterdocs_pro:*:*:*:*:*:*:*:*(< 3.8.1)
The BetterDocs Pro plugin for WordPress versions up to and including 3.8.0 is affected by a HIGH severity local file inclusion vulnerability with a CVSS score of 9.8, and proof-of-concept exploit code is available. The flaw in the doc_style parameter allows unauthenticated attackers to include and execute arbitrary PHP files on the server, potentially leading to full site compromise, sensitive data exposure, and remote code execution.
WordPress administrators using BetterDocs Pro should update beyond version 3.8.0 immediately and audit their sites for signs of exploitation, particularly any unexpected PHP file uploads or unauthorized access patterns.
- π CVE-2026-7515 (CVSS 3.1: 9.8)
π [HIGH] craftcms/cms
1 CVE | CVSS 3.1: 9.5 | AAS 10.3
cpe:2.3:a:craftcms:cms:*:*:*:*:*:*:*:*
Craft CMS is affected by a HIGH severity server-side request forgery and arbitrary JavaScript injection vulnerability with a CVSS score of 9.5, and the flaw is confirmed exploitable. An attacker can poison Host or X-Forwarded-Host headers against the resource-js endpoint to bypass internal URL validation, forcing the backend to fetch and reflect malicious payloads from an attacker-controlled server, particularly dangerous in default configurations with permissive trustedHosts settings.
Teams running Craft CMS should review the vendor advisory, apply available patches, and harden their trustedHosts configuration to restrict accepted host headers to known legitimate values.
- π CVE-2026-55791 (CVSS 3.1: 9.5)
π [HIGH] suse/rancher
1 CVE | CVSS 4.0: 9.4 | AAS 10.3
cpe:2.3:a:suse:rancher:*:*:*:*:*:*:*:*(< 2.14.2)
SUSE Rancher Manager versions prior to 2.14.2 are affected by a HIGH severity command injection vulnerability with a CVSS 4.0 score of 9.4, and the flaw is confirmed exploitable. The cluster import endpoint accepts unsanitized YAML parameters, allowing remote attackers to inject commands, break out of a container image, and execute malicious containers on the underlying infrastructure.
Organizations using Rancher to manage Kubernetes clusters should upgrade to version 2.14.2 or later immediately and review cluster import logs for any suspicious activity or unauthorized YAML submissions.
- π CVE-2026-44939 (CVSS 4.0: 9.4)
π [HIGH] github.com/tilt-dev/tilt
1 CVE | CVSS 3.1: 9.5 | AAS 10.3
cpe:2.3:a:github.com:tilt-dev_tilt:*:*:*:*:*:*:*:*
Tilt by tilt-dev is affected by a HIGH severity vulnerability with a CVSS score of 9.5, and the flaw is confirmed exploitable. The Tilt HUD HTTP server exposes state-changing and sensitive-read endpoints with no authentication, allowing a network attacker to trigger developer-defined Tiltfile resources, tamper with arguments, read full engine state including session tokens, and proxy into the Tilt apiserver when the HUD is bound to a non-loopback address.
Development teams using Tilt should review the vendor advisory immediately, ensure the HUD is bound only to localhost, and apply any available patches to enforce authentication on exposed endpoints.
- π CVE-2026-55884 (CVSS 3.1: 9.5)
π [HIGH] @tinacms/cli
1 CVE | CVSS 3.1: 7.8 | AAS 9.6
cpe:2.3:a:tinacms:cli:*:*:*:*:*:*:*:*(< 1.6.8)
The TinaCMS CLI package is affected by a HIGH severity remote code execution vulnerability with a CVSS score of 7.8, and the flaw is confirmed exploitable. During Forestry-to-Tina migration, unsanitized label and name fields from Forestry YAML configuration files are injected into generated JavaScript code, allowing an attacker who controls a Forestry-style project to execute arbitrary code on the developer’s machine when the migration command is run.
Teams using TinaCMS CLI for Forestry migrations should review the vendor advisory, update to a patched version, and carefully audit any third-party or untrusted Forestry project files before running the migration command.
- π CVE-2026-54074 (CVSS 3.1: 7.8)
π [HIGH] themefusion/avada_(fusion)_builder
1 CVE | CVSS 3.1: 9.1 | AAS 9.4
cpe:2.3:a:themefusion:avada_fusion_builder:*:*:*:*:*:*:*:*(< 3.15.4)
The Avada (Fusion) Builder plugin for WordPress versions up to and including 3.15.3 is affected by a HIGH severity arbitrary file deletion vulnerability with a CVSS score of 9.1, and the flaw is confirmed exploitable. Insufficient file path validation in the maybe_delete_files function allows unauthenticated attackers to delete arbitrary files on the server, which can lead to remote code execution by removing critical files such as wp-config.php, particularly on sites with a published Avada form configured to save entries to the database.
WordPress administrators using Avada Builder should update beyond version 3.15.3 immediately, audit their sites for any unauthorized file deletions, and verify the integrity of core WordPress files including wp-config.php.
- π CVE-2026-8713 (CVSS 3.1: 9.1)
π [HIGH] red_hat/red_hat_enterprise_linux_10
2 CVEs | CVSS 3.1: 7.6 | AAS 9.4
cpe:2.3:a:redhat:enterprise_linux:*:*:*:*:*:*:*:*
Red Hat Enterprise Linux 10 is affected by 2 vulnerabilities in libaom, the reference AV1 codec implementation, including at least one rated HIGH with a CVSS score of 7.6 and confirmed exploitable. The most severe issue is a heap buffer overflow in the AV1 encoder’s Look-Ahead Processing mode, where a ring buffer wrap-around guard is bypassed when lag-in-frames is configured, resulting in a 232-byte out-of-bounds write on every encoded frame that corrupts adjacent heap objects, posing a serious risk to transcoding services and WebRTC deployments.
Organizations running RHEL 10 systems with AV1 encoding workloads should review the Red Hat advisory, apply available patches, and assess exposure in any services where external users can influence encoder configuration.
- π CVE-2026-56208 (CVSS 3.1: 7.6)
- π CVE-2026-56209 (CVSS 3.1: 7.1)
π [HIGH] tinacms/tinacms
1 CVE | CVSS 3.1: 8.0 | AAS 9.3
cpe:2.3:a:tinacms:tinacms:*:*:*:*:*:*:*:*
TinaCMS is affected by a HIGH severity vulnerability with a CVSS score of 8.0, and the flaw is confirmed exploitable. Multiple window message listeners across the editor overlay, OAuth popup handler, and admin-to-preview iframe communication fail to verify event origin or source, allowing an attacker-controlled page to forge messages that drive the editor, inject preview content, or hijack the OAuth authentication flow to take over an admin session.
Teams using TinaCMS should review the vendor advisory, apply available patches, and assess whether any Tina admin instances are accessible in environments where users may visit untrusted pages or open external links during editing sessions.
- π CVE-2026-55660 (CVSS 3.1: 8.0)
π [HIGH] microsoft/azure_synapse
1 CVE | CVSS 3.1: 9.9 | AAS 9.2
cpe:2.3:a:microsoft:azure_synapse:*:*:*:*:*:*:*:*
Microsoft Azure Synapse is affected by a HIGH severity privilege escalation vulnerability with a CVSS score of 9.9, and the flaw is confirmed exploitable. The service executes operations with unnecessary privileges, allowing an authenticated attacker to escalate their access over the network and potentially gain control beyond their intended authorization scope.
Organizations using Azure Synapse should review the Microsoft Security Response Center advisory immediately, apply any available updates or mitigations, and audit access controls and activity logs for signs of unauthorized privilege escalation.
- π CVE-2026-48584 (CVSS 3.1: 9.9)
π [HIGH] microsoft/microsoft_365_copilot
1 CVE | CVSS 3.1: 8.8 | AAS 9.1
cpe:2.3:a:microsoft:microsoft_365_copilot:*:*:*:*:*:*:*:*
Microsoft 365 Copilot is affected by a HIGH severity open redirect vulnerability in its Business Chat feature with a CVSS score of 8.8, and the flaw is confirmed exploitable. An unauthorized attacker can exploit URL redirection to route users to untrusted sites, enabling privilege escalation over the network through credential theft or phishing attacks that appear to originate from a trusted Microsoft service.
Organizations using Microsoft 365 Copilot should review the Microsoft Security Response Center advisory, ensure any available mitigations are applied, and alert users to be cautious of unexpected redirects originating from Copilot Business Chat interactions.
- π CVE-2026-47645 (CVSS 3.1: 8.8)