29 vulnerabilities across 15 products scored HIGH or above on June 26, 2026.

  • πŸ”΄ CRITICAL: 6
  • 🟠 HIGH: 23

Exploit Status Upgrades

The following CVEs from previous bulletins have been upgraded based on new exploit intelligence:

  • [UPGRADED] CVE-2026-50189 (appsmith/appsmith) β€” F1: exploitable β†’ functional, AAS: 9.7 β†’ 10.8 (HIGH β†’ HIGH). Originally in 2026-06-24 bulletin.
  • [UPGRADED] CVE-2026-54067 (siyuan-note/siyuan) β€” F1: exploitable β†’ functional, AAS: 9.2 β†’ 11.2 (HIGH β†’ HIGH). Originally in 2026-06-24 bulletin.

πŸ”΄ [CRITICAL] jdx/mise

2 CVEs | CVSS 3.1: 9.6 | AAS 14.5

  • cpe:2.3:a:jdx:mise:*:*:*:*:*:*:*:*

jdx mise, a developer tool version manager for languages and utilities like Node, Python, and Terraform, is affected by 2 critical vulnerabilities including CVE-2026-33646 and CVE-2026-55441, with a maximum CVSS score of 9.6. The most severe issue allows arbitrary command execution through malicious .tool-versions files that bypass mise’s trust verification, meaning an attacker can embed a crafted file in a git repository and achieve code execution when a victim simply navigates into the cloned directory with mise activated. A functional exploit is available, making this an immediate patching priority. Development teams using mise should upgrade to version 2026.3.10 or later without delay, and review any recently cloned or untrusted repositories for suspicious .tool-versions files.

Vendor Advisory


πŸ”΄ [CRITICAL] budibase/budibase

2 CVEs | CVSS 3.1: 10.0 | AAS 13.2

  • cpe:2.3:a:budibase:budibase:*:*:*:*:*:*:*:*

Budibase, an open-source low-code application platform, is affected by 2 critical vulnerabilities including CVE-2026-54350 and CVE-2026-54352, with the most severe carrying a maximum CVSS score of 10.0. An unauthenticated attacker can exploit a parameter injection flaw in query context handling to read or modify every document in connected backend databases, including MongoDB, CouchDB, Elasticsearch, and DynamoDB, through a single HTTP request to any published Budibase app. A functional exploit is publicly available, making this an urgent priority for any organization running Budibase. Administrators should upgrade to version 3.39.12 or later immediately and audit connected data stores for signs of unauthorized access or modification.

Vendor Advisory


πŸ”΄ [CRITICAL] kestra-io/kestra

3 CVEs | CVSS 3.1: 10.0 | AAS 12.8

  • cpe:2.3:a:kestra-io:kestra:*:*:*:*:*:*:*:*

Kestra, an open-source event-driven orchestration platform by kestra-io, is affected by 3 critical vulnerabilities including CVE-2026-53576, CVE-2026-49869, and CVE-2026-55069, with the most severe carrying a maximum CVSS score of 10.0. The lead issue is an authentication bypass in the REST API where any request path ending in /configs is treated as a public endpoint and forwarded without credential checks, allowing unauthenticated attackers to access and manipulate flows, executions, namespace key-value stores, and other tenant resources. Proof-of-concept exploit code is available. Organizations running Kestra should upgrade to version 1.0.45 or 1.3.21 or later immediately, and review access logs for any unauthorized API activity against orchestration resources.

Vendor Advisory


πŸ”΄ [CRITICAL] opf/openproject

5 CVEs | CVSS 3.1: 9.9 | AAS 12.6

  • cpe:2.3:a:opf:openproject:*:*:*:*:*:*:*:* (< 17.3.3)
  • cpe:2.3:a:opf:openproject:*:*:*:*:*:*:*:* (>= 17.4.0, < 17.4.1)

OpenProject, an open-source web-based project management platform by opf, is affected by 5 vulnerabilities including CVE-2026-46386, CVE-2026-52780, CVE-2026-52784, CVE-2026-52785, and CVE-2026-52782, with the most severe carrying a CVSS score of 9.9. The lead issue is a critical remote code execution path in the official Docker image, which ships with a hardcoded default Rails secret key combined with Marshal-based cookie deserialization, allowing any authenticated user to achieve arbitrary code execution on the server via crafted session cookies. Proof-of-concept exploit code is available. Organizations running OpenProject, particularly via the official Docker image, should upgrade to the latest patched release immediately, rotate the SECRET_KEY_BASE value, and review systems for signs of compromise.

Vendor Advisory


πŸ”΄ [CRITICAL] uncanny_owl/uncanny_automator_pro

1 CVE | CVSS 3.1: 9.8 | AAS 12.1

  • cpe:2.3:a:uncanny_owl:uncanny_automator_pro:*:*:*:*:*:*:*:*

Uncanny Automator Pro, a popular WordPress automation plugin by Uncanny Owl, is affected by a critical PHP Object Injection vulnerability tracked as CVE-2026-56057 with a CVSS score of 9.8. The flaw allows users with privileges as low as Subscriber to inject arbitrary PHP objects, which depending on the gadget chains available in the WordPress environment could lead to remote code execution, file manipulation, or full site compromise. A functional exploit is available, making this an immediate risk. WordPress site administrators running Uncanny Automator Pro version 7.3.0.6 or earlier should upgrade to the latest patched release without delay.

Vendor Advisory


🟠 [HIGH] dokku/dokku

4 CVEs | CVSS 3.1: 9.9 | AAS 11.8

  • cpe:2.3:a:dokku:dokku:*:*:*:*:-:*:*:* (< 0.38.2)
  • cpe:2.3:a:dokku:dokku:*:*:*:*:-:*:*:* (< 0.38.7)

Dokku, a Docker-powered platform-as-a-service, is affected by 4 vulnerabilities including CVE-2026-45408, CVE-2026-45405, CVE-2026-54636, and CVE-2026-45406, with the most severe carrying a CVSS score of 9.9. The lead issue is a command injection flaw where insufficient app name validation allows shell metacharacters to be embedded into an unquoted bash heredoc in the git pre-receive hook, enabling any authenticated user with git push access to execute arbitrary commands as the dokku user on the host system. Proof-of-concept exploit code is available. Organizations running Dokku should upgrade to version 0.38.2 or later immediately and audit existing app names for suspicious characters or signs of exploitation.

Vendor Advisory


🟠 [HIGH] pluggabl/booster_for_woocommerce

1 CVE | CVSS 3.1: 9.9 | AAS 11.2

  • cpe:2.3:a:pluggabl:booster_for_woocommerce:*:*:*:*:*:*:*:*

Booster for WooCommerce, a widely used WordPress plugin by Pluggabl, is affected by a critical arbitrary file upload vulnerability tracked as CVE-2026-56027 with a CVSS score of 9.9. The flaw allows users with customer-level privileges to upload arbitrary files to the server, which can lead to remote code execution and full site compromise. Proof-of-concept exploit code is available. WordPress site administrators running Booster for WooCommerce version 8.0.1 or earlier should upgrade to the latest patched release immediately and review their upload directories for any suspicious or unexpected files.

Vendor Advisory


🟠 [HIGH] fluent/fluentd

1 CVE | CVSS 3.1: 9.8 | AAS 11.1

  • cpe:2.3:a:fluent:fluentd:*:*:*:*:*:*:*:* (>= 0.14.0, < 1.16.3)

Fluentd, a widely deployed open-source log collection and forwarding agent by Fluent, is affected by a critical path traversal vulnerability tracked as CVE-2026-44024 with a CVSS score of 9.8. Insufficient validation of the ${tag} placeholder in file path configurations allows an attacker sending logs from untrusted sources to inject path traversal characters, potentially enabling arbitrary file writes on the system when combined with certain formatting options. This flaw is considered exploitable in the wild. Organizations using Fluentd should upgrade to the latest patched version immediately and review configurations to ensure instances receiving logs from untrusted sources do not use the ${tag} placeholder in file path parameters such as the out_file plugin.

Vendor Advisory


🟠 [HIGH] wso2/wso2_api_manager

1 CVE | CVSS 3.1: 8.3 | AAS 11.0

  • cpe:2.3:a:wso2:wso2_api_manager:*:*:*:*:*:*:*:*

WSO2 API Manager is affected by a server-side request forgery vulnerability tracked as CVE-2026-2053 with a CVSS score of 8.3. The message flow component fails to properly validate user-controlled input within WS-Addressing headers, allowing an unauthenticated attacker to manipulate these headers to direct server-initiated requests to arbitrary destinations, potentially enabling unauthorized access to internal services and sensitive resources behind the API gateway. Proof-of-concept exploit code is available. Organizations running WSO2 API Manager should apply the vendor-provided patch immediately and review network segmentation to limit the impact of any server-side request forgery from the API Manager host.

Vendor Advisory


🟠 [HIGH] zaproxy/zap-extensions

1 CVE | CVSS 4.0: 8.7 | AAS 10.8

  • cpe:2.3:a:zaproxy:zap-extensions:*:*:*:*:*:*:*:*

The ZAP ViewState add-on for OWASP Zed Attack Proxy is affected by an insecure deserialization vulnerability tracked as CVE-2026-57527 with a CVSS 4.0 score of 8.7. An attacker controlling a proxied web server can embed a malicious serialized Java object in the javax.faces.ViewState HTTP response parameter, which the add-on deserializes without any filtering or type restrictions, leading to arbitrary code execution on the machine running ZAP. Proof-of-concept exploit code is available. Security teams and penetration testers using ZAP with the ViewState add-on should update to version 4 or later immediately, noting that this vulnerability turns the security testing tool itself into an attack surface when scanning untrusted targets.

Vendor Advisory


🟠 [HIGH] notepad-plus-plus/notepad-plus-plus

4 CVEs | CVSS 3.1: 7.8 | AAS 10.6

  • cpe:2.3:a:notepad-plus-plus:notepad-plus-plus:*:*:*:*:*:*:*:* (< 8.9.6.1)
  • cpe:2.3:a:notepad-plus-plus:notepad-plus-plus:*:*:*:*:*:*:*:* (< 8.9.6.4)

Notepad++, the widely used open-source text and source code editor for Windows, is affected by 4 vulnerabilities including CVE-2026-48778, CVE-2026-48800, CVE-2026-52885, and CVE-2026-52884, with the most severe carrying a CVSS score of 7.8. The lead issue involves the config.xml file accepting an arbitrary command line interpreter path without validation or signature checks, which is then executed via ShellExecute when a user triggers the Open Containing Folder menu action, allowing an attacker who can modify or supply a crafted config.xml to achieve arbitrary code execution. Proof-of-concept exploit code is available for multiple issues. Users and organizations deploying Notepad++ should upgrade to version 8.9.6.1 or later and ensure configuration files are not sourced from untrusted locations.

Vendor Advisory


🟠 [HIGH] paolo/geodirectory

1 CVE | CVSS 3.1: 9.3 | AAS 10.3

  • cpe:2.3:a:paolo:geodirectory:*:*:*:*:*:*:*:*

GeoDirectory, a WordPress business directory plugin by Paolo, is affected by a critical unauthenticated SQL injection vulnerability tracked as CVE-2026-54831 with a CVSS score of 9.3. The flaw allows attackers with no authentication to inject arbitrary SQL queries, potentially enabling full database extraction, modification, or deletion of site data including user credentials. This vulnerability is considered exploitable in the wild. WordPress site administrators running GeoDirectory version 2.8.162 or earlier should upgrade to the latest patched release immediately and audit database logs for any signs of unauthorized queries or data exfiltration.

Vendor Advisory


🟠 [HIGH] wpdatatables/wpdatatables

1 CVE | CVSS 3.1: 9.3 | AAS 9.6

  • cpe:2.3:a:wpdatatables:wpdatatables:*:*:*:*:*:*:*:*

wpDataTables, a popular WordPress plugin for creating interactive tables and charts, is affected by a critical unauthenticated SQL injection vulnerability tracked as CVE-2026-54825 with a CVSS score of 9.3. The flaw allows attackers with no authentication to execute arbitrary SQL queries against the WordPress database, potentially leading to full data extraction, modification, or deletion including sensitive user credentials and site content. This vulnerability is considered exploitable in the wild. WordPress site administrators running wpDataTables version 7.4 or earlier should upgrade to the latest patched release immediately and audit database activity for any signs of unauthorized access or data exfiltration.

Vendor Advisory


🟠 [HIGH] codemstory/μ›Œλ“œν”„λ ˆμŠ€_결제_μ‹¬ν”ŒνŽ˜μ΄

1 CVE | CVSS 3.1: 9.3 | AAS 9.6

  • cpe:2.3:a:codemstory::*:*:*:*:*:*:*:*

μ›Œλ“œν”„λ ˆμŠ€ 결제 μ‹¬ν”ŒνŽ˜μ΄ (WordPress Simple Pay), a WooCommerce payment gateway plugin by codemstory, is affected by a critical unauthenticated SQL injection vulnerability tracked as CVE-2026-56036 with a CVSS score of 9.3. The flaw allows attackers with no authentication to execute arbitrary SQL queries against the WordPress database, potentially enabling full extraction of sensitive data including customer payment information, user credentials, and order details. Proof-of-concept exploit code is available. WordPress site administrators running this plugin at version 5.5.6 or earlier should upgrade to the latest patched release immediately and review database logs for any signs of unauthorized query activity.

Vendor Advisory


🟠 [HIGH] rustfs/rustfs

1 CVE | CVSS 3.1: 8.6 | AAS 9.5

  • cpe:2.3:a:rustfs:rustfs:*:*:*:*:*:*:*:*

RustFS, a Rust-based distributed object storage system, is affected by a critical path traversal vulnerability tracked as CVE-2026-49991 with a CVSS score of 8.6. The flaw chains three weaknesses in the Snowball auto-extract feature, including missing path sanitization, IAM wildcard matching on raw paths, and filesystem path cleaning inconsistencies, allowing an authenticated user with only PutObject permission on their own bucket to write arbitrary objects into other users’ buckets and completely break multi-tenant isolation. This vulnerability is considered exploitable in the wild. Organizations running RustFS version 1.0.0-beta.4 should upgrade immediately and audit object storage logs for any cross-bucket write activity that may indicate exploitation.

Vendor Advisory