2 vulnerabilities across 1 product scored HIGH or above on June 25, 2026.

  • 🟠 HIGH: 2

Exploit Status Upgrades

The following CVEs from previous bulletins have been upgraded based on new exploit intelligence:

  • [UPGRADED] CVE-2026-48721 (warpdotdev/warp) β€” F1: exploitable β†’ functional, AAS: 10.4 β†’ 12.4 (HIGH β†’ CRITICAL). Originally in 2026-06-24 bulletin.
    • X trend: 4 exploit mentions in 9 tweets
  • [UPGRADED] CVE-2026-48725 (warpdotdev/warp) β€” F1: exploitable β†’ functional, AAS: 9.9 β†’ 11.9 (HIGH β†’ HIGH). Originally in 2026-06-24 bulletin.
    • X trend: 4 exploit mentions in 9 tweets
  • [UPGRADED] CVE-2026-48720 (warpdotdev/warp) β€” F1: theoretical β†’ functional, AAS: 9.6 β†’ 12.6 (HIGH β†’ CRITICAL). Originally in 2026-06-24 bulletin.
    • X trend: 4 exploit mentions in 9 tweets
  • [UPGRADED] CVE-2026-48719 (warpdotdev/warp) β€” F1: exploitable β†’ functional, AAS: 9.3 β†’ 11.3 (HIGH β†’ HIGH). Originally in 2026-06-24 bulletin.
    • X trend: 4 exploit mentions in 6 tweets
  • [UPGRADED] CVE-2026-49980 (rclone/rclone) β€” F1: exploitable β†’ functional, AAS: 11.1 β†’ 12.9 (HIGH β†’ CRITICAL). Originally in 2026-06-24 bulletin.
    • X trend: 3 exploit mentions in 5 tweets
  • [UPGRADED] CVE-2026-49851 (lepture/mistune) β€” F1: exploitable β†’ functional, AAS: 9.1 β†’ 11.1 (HIGH β†’ HIGH). Originally in 2026-06-24 bulletin.
    • X trend: 4 exploit mentions in 9 tweets
  • [UPGRADED] CVE-2026-49247 (jellyfin/jellyfin) β€” F1: theoretical β†’ functional, AAS: 9.1 β†’ 12.1 (HIGH β†’ CRITICAL). Originally in 2026-06-24 bulletin.
    • X trend: 4 exploit mentions in 6 tweets
  • [UPGRADED] CVE-2026-54010 (open-webui/open-webui) β€” F1: exploitable β†’ functional, AAS: 10.1 β†’ 12.1 (HIGH β†’ CRITICAL). Originally in 2026-06-23 bulletin.
    • X trend: 3 exploit mentions in 5 tweets
  • [UPGRADED] CVE-2025-58048 (paymenter/paymenter) β€” F1: exploitable β†’ functional, AAS: 10.2 β†’ 12.2 (HIGH β†’ CRITICAL). Originally in 2026-06-22 bulletin.
    • X trend: 3 exploit mentions in 4 tweets
  • [UPGRADED] CVE-2026-48909 (joomshaper.net/sp_lms_extension_for_joomla) β€” F1: exploitable β†’ functional, AAS: 9.8 β†’ 11.8 (HIGH β†’ HIGH). Originally in 2026-06-20 bulletin.
    • X trend: 1 exploit mentions in 2 tweets
  • [UPGRADED] CVE-2026-54005 (getkirby/cms) β€” F1: exploitable β†’ functional, AAS: 9.3 β†’ 11.3 (HIGH β†’ HIGH). Originally in 2026-06-18 bulletin.
    • X trend: 3 exploit mentions in 3 tweets

🟠 [HIGH] gitlab/gitlab

2 CVEs | CVSS 3.1: 8.7 | AAS 10.0

  • cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:* (>= 16.4, < 18.11.6)
  • cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:* (>= 19.0, < 19.0.3)
  • cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:* (>= 19.1, < 19.1.1)

GitLab has disclosed 2 vulnerabilities affecting GitLab EE across a wide range of versions, from 16.4 through 19.1, including at least one high-severity stored XSS flaw (CVSS 8.7) that allows an authenticated user with developer permissions to execute arbitrary code in another user’s browser session through improper input sanitization. Organizations running self-managed GitLab EE instances should treat this as a priority patch cycle, as the broad version range and low privilege requirement make exploitation practical in most enterprise environments.

Administrators should upgrade immediately to GitLab 18.11.6, 19.0.3, or 19.1.1, depending on their current release track, and review the vendor advisory at docs.gitlab.com for full details on both fixes.

Vendor Advisory