29 vulnerabilities across 15 products scored HIGH or above on June 25, 2026.
- ๐ฃ EMERGENCY: 4
- ๐ด CRITICAL: 6
- ๐ HIGH: 19
Exploit Status Upgrades
The following CVEs from previous bulletins have been upgraded based on new exploit intelligence:
- [UPGRADED] CVE-2026-50189 (appsmithorg/appsmith) โ F1: exploitable โ functional, AAS: 9.7 โ 11.7 (HIGH โ HIGH). Originally in 2026-06-24 bulletin.
- [UPGRADED] CVE-2026-54067 (siyuan-note/siyuan) โ F1: exploitable โ functional, AAS: 9.2 โ 11.2 (HIGH โ HIGH). Originally in 2026-06-24 bulletin.
๐ฃ [EMERGENCY] flowise/flowise
6 CVEs | CVSS 4.0: 10.0 | AAS 16.0
cpe:2.3:a:flowise:flowise:*:*:*:*:*:*:*:*
Flowise, an open-source AI workflow automation platform, is affected by six vulnerabilities including multiple critical issues, the most severe carrying a CVSS 4.0 score of 10.0. The lead vulnerability enables unsandboxed remote code execution through the Custom MCP feature, which is especially dangerous because Flowise runs without authentication by default unless credentials are explicitly configured. Active exploitation has been observed in the wild. Organizations running Flowise versions prior to 3.0.6 should upgrade immediately, enforce authentication by setting FLOWISE_USERNAME and FLOWISE_PASSWORD environment variables, and audit their deployments for signs of compromise. Refer to the vendor advisory at the Flowise GitHub security page for full details.
- ๐ฃ CVE-2025-71336 (CVSS 4.0: 9.3)
- ๐ฃ CVE-2025-71333 (CVSS 4.0: 9.3)
- ๐ฃ CVE-2025-71334 (CVSS 4.0: 9.3)
- ๐ฃ CVE-2025-71327 (CVSS 4.0: 9.3)
- ๐ด CVE-2025-71338 (CVSS 4.0: 10.0)
- ๐ด CVE-2025-71324 (CVSS 4.0: 8.7)
๐ด [CRITICAL] pnpm/pnpm
2 CVEs | CVSS 3.1: 8.8 | AAS 13.2
cpe:2.3:a:pnpm:pnpm:*:*:*:*:*:*:*:*
pnpm, a widely used JavaScript package manager, is affected by two vulnerabilities including at least one with a CVSS 3.1 score of 8.8. The lead issue allows a malicious repository to craft a poisoned pnpm-lock.yaml file that bypasses fresh package-manager resolution, potentially enabling arbitrary code execution when a developer runs pnpm in the cloned project. Proof-of-concept exploit code is available. Teams using pnpm should upgrade to version 10.34.2 or 11.5.3 immediately, exercise caution when cloning untrusted repositories, and review the vendor advisory on the pnpm GitHub security page for additional details.
- ๐ด CVE-2026-55698 (CVSS 3.1: 8.8)
- ๐ด CVE-2026-50016 (CVSS 3.1: 8.8)
๐ด [CRITICAL] cursor/cursor
2 CVEs | CVSS 4.0: 9.3 | AAS 12.2
cpe:2.3:a:anysphere:cursor:*:*:*:*:*:*:*:*(< 3.0)cpe:2.3:a:cursor:cursor:*:*:*:*:*:*:*:*
Cursor, an AI-powered code editor, is affected by two vulnerabilities including at least one with a CVSS 4.0 score of 9.3. The lead issue allows a malicious AI agent to escape the workspace sandbox by creating a symlink that forces path canonicalization to fail, causing Cursor to fall back to the unsanitized path and write files outside the workspace without user approval. Proof-of-concept exploit code is available. Development teams using Cursor should upgrade to version 3.0 or later immediately and review the vendor advisory on the Cursor GitHub security page for further guidance.
- ๐ด CVE-2026-50549 (CVSS 4.0: 9.3)
- ๐ด CVE-2026-50548 (CVSS 4.0: 9.3)
๐ [HIGH] gitlab/gitlab
2 CVEs | CVSS 3.1: 7.5 | AAS 11.9
cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*(>= 16.4.0, < 18.11.6)cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*(>= 19.0.0, < 19.0.3)
GitLab Enterprise Edition version 19.1 before 19.1.1 is affected by two vulnerabilities including at least one with a CVSS 3.1 score of 7.5. The lead issue involves insufficient output filtering in the Duo Workflows feature, which under certain conditions could allow a user to access sensitive information already committed to a project. Proof-of-concept exploit code is available. Organizations running GitLab EE 19.1 should upgrade to 19.1.1 immediately and review the vendor patch release notes for full details.
- ๐ CVE-2026-12053 (CVSS 3.1: 7.5)
- ๐ CVE-2026-10086 (CVSS 3.1: 5.4)
๐ [HIGH] tooljet/tooljet
2 CVEs | CVSS 4.0: 9.4 | AAS 11.8
cpe:2.3:a:tooljet:tooljet:*:*:*:*:*:*:*:*
ToolJet, an open-source platform for building internal tools, workflows, and AI agents, is affected by two vulnerabilities including at least one with a CVSS 4.0 score of 9.4. The lead issue allows any authenticated user with a builder role, available on the free tier, to overwrite a globally shared marketplace plugin with arbitrary JavaScript that executes server-side with full Node.js access, achieving both remote code execution and supply-chain compromise across all users on the instance. Proof-of-concept exploit code is available. Organizations running ToolJet should upgrade to version 3.20.178-lts or later immediately and review the vendor advisory on the ToolJet GitHub security page for additional details.
- ๐ CVE-2026-55413 (CVSS 4.0: 9.4)
- ๐ CVE-2026-55412 (CVSS 3.1: 8.3)
๐ [HIGH] wolfssl/wolfssl
2 CVEs | CVSS 4.0: 8.8 | AAS 11.7
cpe:2.3:a:wolfssl:wolfssl:*:*:*:*:*:*:*:*(>= 5.4.0, < 5.9.2)
wolfSSL, a widely embedded TLS library, is affected by two vulnerabilities including at least one with a CVSS 4.0 score of 8.8. The lead issue is a heap buffer overflow in the DTLS 1.3 ACK serialization path triggered before the connecting peer is authenticated, caused by an integer truncation that results in an undersized buffer allocation and subsequent overrun. A functional exploit is available, heightening the urgency. Organizations using wolfSSL 5.9.0 or earlier with DTLS 1.3 enabled should upgrade to version 5.9.1 immediately and review the vendor pull request on the wolfSSL GitHub repository for technical details.
- ๐ CVE-2026-6679 (CVSS 4.0: 8.8)
- ๐ CVE-2026-55958 (CVSS 4.0: 8.3)
๐ [HIGH] netflix/lemur
2 CVEs | CVSS 3.1: 9.9 | AAS 11.7
cpe:2.3:a:netflix:lemur:*:*:*:*:*:*:*:*
Netflix Lemur, an open-source certificate management framework, is affected by two vulnerabilities including at least one with a CVSS 3.1 score of 9.9. The issues allow any SSO-authenticated user to achieve AWS IAM compromise and permanent PKI key access through an SSRF flaw in the ACME acme_url parameter combined with a creator-equality IDOR, effectively granting low-privileged users access far beyond their intended scope. Proof-of-concept exploit code is available. Organizations running Lemur 1.9.0 or earlier should review the vendor advisory on GitHub immediately, apply any available patches, and audit their environments for unauthorized certificate issuance or AWS IAM activity.
- ๐ CVE-2026-55166 (CVSS 3.1: 9.9)
- ๐ CVE-2026-48508 (CVSS 3.1: 8.8)
๐ [HIGH] marketingfire/widget_options
1 CVE | CVSS 3.1: 9.9 | AAS 11.7
cpe:2.3:a:marketingfire:widget_options:*:*:*:*:*:*:*:*
Widget Options, a popular WordPress plugin by MarketingFire, is affected by a remote code execution vulnerability with a CVSS 3.1 score of 9.9. The flaw allows users with contributor-level privileges or higher to execute arbitrary code on the server, making any WordPress site with this plugin and open registration or multiple user roles a target. Proof-of-concept exploit code is available. Site administrators running Widget Options version 4.2.3 or earlier should update immediately and review the Patchstack advisory for full details.
- ๐ CVE-2026-54823 (CVSS 3.1: 9.9)
๐ [HIGH] filebrowser/filebrowser
2 CVEs | CVSS 3.1: 9.3 | AAS 11.5
cpe:2.3:a:filebrowser:filebrowser:*:*:*:*:*:*:*:*
File Browser, an open-source web-based file management interface, is affected by two vulnerabilities including at least one with a CVSS 3.1 score of 9.3. The lead issue impacts instances configured with proxy authentication, where any unauthenticated attacker who can reach the server directly can impersonate any user, including admin, by sending a single forged HTTP header, with non-existent usernames being automatically created. Proof-of-concept exploit code is available. Organizations running File Browser version 2.0.0-rc.1 or later with proxy authentication should restrict direct server access immediately, review the vendor source on GitHub for available fixes, and audit logs for signs of unauthorized access.
- ๐ CVE-2026-54089 (CVSS 3.1: 9.1)
- ๐ CVE-2026-54088 (CVSS 4.0: 9.3)
๐ [HIGH] apache_software_foundation/apache_shiro
1 CVE | CVSS 4.0: 8.2 | AAS 11.4
cpe:2.3:a:apache:apache_shiro:*:*:*:*:*:*:*:*
Apache Shiro, a widely used Java security framework, is affected by an authentication bypass vulnerability with a CVSS 4.0 score of 8.2. The flaw allows an attacker to bypass authentication via a specially crafted HTTP request when the shiro-guice module is used in a web servlet context, similar to the previously disclosed CVE-2020-1957 which affected the shiro-spring module. A functional exploit is available. Organizations using any Apache Shiro 2.x version or 3.0.0-alpha-1 with the shiro-guice module should upgrade immediately and review the Apache mailing list advisory for patched version details.
- ๐ CVE-2026-56091 (CVSS 4.0: 8.2)
๐ [HIGH] tomojitakasu/rtklib
1 CVE | CVSS 4.0: 9.3 | AAS 11.2
cpe:2.3:a:rtklib:rtklib:*:*:*:*:*:*:*:*(<= 2.4.3)
RTKLIB, an open-source GNSS positioning library widely used in precision navigation and surveying applications, is affected by an out-of-bounds write vulnerability with a CVSS 4.0 score of 9.3. The flaw in the decode_type1033 function fails to clamp length counters to destination buffer sizes, allowing up to 191 bytes of overflow into fixed 64-byte descriptor fields, enabling an attacker who controls an NTRIP or serial RTCM3 correction stream to achieve arbitrary code execution or denial of service via a crafted type-1033 message. Proof-of-concept exploit code is available. Organizations using RTKLIB 2.4.3 or earlier should monitor the vendor issue on GitHub for a fix, restrict access to RTCM3 correction streams to trusted sources, and evaluate mitigations such as input validation at the network boundary.
- ๐ CVE-2026-56786 (CVSS 4.0: 9.3)
๐ [HIGH] vanhauser-thc/thc-hydra
1 CVE | CVSS 4.0: 8.6 | AAS 11.2
cpe:2.3:a:vanhauser-thc:thc-hydra:*:*:*:*:*:*:*:*
THC Hydra, a widely used network authentication testing tool, is affected by a stack buffer overflow vulnerability with a CVSS 4.0 score of 8.6. The flaw exists in NTLM authentication handling across multiple modules including SMTP, POP3, IMAP, HTTP, and others, where a malicious server can send a crafted NTLM Type-2 challenge with an excessively long domain string to overflow a 500-byte stack buffer by up to 330 bytes, potentially enabling remote code execution on systems without stack protection. Proof-of-concept exploit code is available. Organizations using Hydra 9.7 or earlier should update to the latest version incorporating commit 9cc84c2 and exercise caution when targeting untrusted servers during penetration testing engagements.
- ๐ CVE-2026-56766 (CVSS 4.0: 8.6)
๐ [HIGH] vim/vim
1 CVE | CVSS 4.0: 8.4 | AAS 10.8
cpe:2.3:a:vim:vim:*:*:*:*:*:*:*:*(< 9.2.0699)
Vim, the widely used open-source command line text editor, is affected by a code execution vulnerability with a CVSS 4.0 score of 8.4. The flaw exists in Vim’s Python omni-completion feature, where docstrings from the current buffer are inserted verbatim into triple-quoted literals without escaping before being passed to exec(), allowing a maliciously crafted file to break out of the string literal and execute arbitrary Python code when a user triggers completion. Proof-of-concept exploit code is available. Users running Vim prior to version 9.2.0699 should update immediately and exercise caution when editing untrusted files with Python omni-completion enabled.
- ๐ CVE-2026-57456 (CVSS 4.0: 8.4)
๐ [HIGH] seaweedfs/seaweedfs
1 CVE | CVSS 4.0: 7.8 | AAS 10.7
cpe:2.3:a:seaweedfs:seaweedfs:*:*:*:*:*:*:*:*
SeaweedFS, a distributed storage system supporting S3-compatible object storage, file systems, and Iceberg tables, is affected by a path traversal vulnerability with a CVSS 4.0 score of 7.8. The flaw arises because the S3 API gateway and Iceberg REST catalog gateway disable path cleaning in their routers, allowing dot-dot segments in URLs to survive routing and enabling an attacker to access or manipulate objects in unauthorized buckets by crafting requests that traverse outside the intended bucket path. Proof-of-concept exploit code is available. Organizations running SeaweedFS prior to version 4.30 should upgrade immediately and review the vendor pull request on GitHub for further details.
- ๐ CVE-2026-54917 (CVSS 4.0: 7.8)
๐ [HIGH] nicolargo/glances
3 CVEs | CVSS 3.1: 7.8 | AAS 10.6
cpe:2.3:a:nicolargo:glances:*:*:*:*:*:*:*:*
Glances, an open-source cross-platform system monitoring tool, is affected by three vulnerabilities including at least one with a CVSS 3.1 score of 7.8. The lead issue involves unsafe use of pickle deserialization to read a version-check cache file stored at a predictable, world-accessible path without any integrity check or signature verification, allowing an attacker with local or container-level write access to that path to achieve arbitrary code execution. Proof-of-concept exploit code is available. System administrators running Glances prior to version 4.5.5 should upgrade immediately, particularly in shared or containerized environments, and review the vendor release notes on GitHub for full details.
- ๐ CVE-2026-46607 (CVSS 3.1: 7.8)
- ๐ CVE-2026-53925 (CVSS 3.1: 7.8)
- ๐ CVE-2026-46606 (CVSS 3.1: 7.8)