31 vulnerabilities across 15 products scored HIGH or above on June 30, 2026.

  • 🟣 EMERGENCY: 5
  • πŸ”΄ CRITICAL: 14
  • 🟠 HIGH: 12

Exploit Status Upgrades

The following CVEs from previous bulletins have been upgraded based on new exploit intelligence:

  • [UPGRADED] CVE-2026-52785 (opf/openproject) β€” F1: exploitable β†’ functional, AAS: 11.1 β†’ 13.1 (HIGH β†’ CRITICAL). Originally in 2026-06-26 bulletin.
  • [UPGRADED] CVE-2026-45405 (dokku/dokku) β€” F1: exploitable β†’ itw, AAS: 10.3 β†’ 12.8 (HIGH β†’ CRITICAL). Originally in 2026-06-26 bulletin.
  • [UPGRADED] CVE-2026-54636 (dokku/dokku) β€” F1: exploitable β†’ itw, AAS: 10.3 β†’ 13.9 (HIGH β†’ CRITICAL). Originally in 2026-06-26 bulletin.
  • [UPGRADED] CVE-2026-52884 (notepad-plus-plus/notepad) β€” F1: exploitable β†’ functional, AAS: 9.1 β†’ 11.1 (HIGH β†’ HIGH). Originally in 2026-06-26 bulletin.
  • [UPGRADED] CVE-2026-54825 (wpdatatables/wpdatatables) β€” F1: exploitable β†’ functional, AAS: 9.6 β†’ 11.6 (HIGH β†’ HIGH). Originally in 2026-06-26 bulletin.
  • [UPGRADED] CVE-2026-50189 (appsmith/appsmith) β€” F1: exploitable β†’ functional, AAS: 9.7 β†’ 10.8 (HIGH β†’ HIGH). Originally in 2026-06-24 bulletin.
  • [UPGRADED] CVE-2026-54067 (siyuan-note/siyuan) β€” F1: exploitable β†’ functional, AAS: 9.2 β†’ 11.2 (HIGH β†’ HIGH). Originally in 2026-06-24 bulletin.
  • [UPGRADED] CVE-2026-52794 (sentry/sentry) β€” F1: exploitable β†’ itw, AAS: 9.3 β†’ 10.9 (HIGH β†’ HIGH). Originally in 2026-06-24 bulletin.

🟣 [EMERGENCY] adobe/coldfusion

9 CVEs | CVSS 3.1: 10.0 | AAS 16.3

  • cpe:2.3:a:adobe:coldfusion:*:*:*:*:*:*:*:*

Adobe ColdFusion is affected by nine vulnerabilities, including at least one critical path traversal flaw rated CVSS 10.0 that enables arbitrary code execution without user interaction and with a changed scope, meaning an attacker can pivot beyond the vulnerable component. Functional exploit code is available, making active exploitation highly likely. Organizations running ColdFusion 2025.9, 2023.20, or earlier should treat this as an emergency and apply patches immediately per Adobe’s advisory at helpx.adobe.com/security/products/coldfusion/apsb26-68.html.

Vendor Advisory


πŸ”΄ [CRITICAL] ibm/websphere_application_server

2 CVEs | CVSS 3.1: 9.3 | AAS 14.9

  • cpe:2.3:a:ibm:websphere_application_server:*:*:*:*:*:*:*:* (>= 8.5.0)
  • cpe:2.3:a:ibm:websphere_application_server:*:*:*:*:*:*:*:* (>= 9.0.0)

IBM WebSphere Application Server versions 8.5 and 9.0 are affected by two vulnerabilities, including at least one cross-site scripting flaw in the administrative console help system, with the most severe rated CVSS 9.3. Functional exploit code is available, increasing the risk of near-term exploitation against exposed admin consoles. Organizations running affected versions should apply fixes immediately per IBM’s advisory at www.ibm.com/support/pages/node/7278590 and ensure administrative consoles are not accessible from untrusted networks.

Vendor Advisory


πŸ”΄ [CRITICAL] rancher/rancher

2 CVEs | CVSS 4.0: 9.5 | AAS 14.1

  • cpe:2.3:a:suse:rancher:*:*:*:*:*:*:*:* (>= 2.14.0, < 2.14.3)
  • cpe:2.3:a:suse:rancher:*:*:*:*:*:*:*:* (>= 2.13.0, < 2.13.6)

Rancher versions 2.14.0 through 2.14.2 are affected by two vulnerabilities, including at least one SAML authentication replay flaw in the Assertion Consumer Service handler that fails to enforce one-time use of SAML assertions, enabling person-in-the-middle attacks against Rancher clusters. These vulnerabilities are being exploited in the wild, making immediate action essential for any organization using Rancher for Kubernetes management. Administrators should upgrade to Rancher 2.14.3 or later without delay and review the security advisory at github.com/rancher/rancher/security/advisories/GHSA-c5jm-xcmq-9j95 for additional mitigation guidance.

Vendor Advisory


πŸ”΄ [CRITICAL] ibm/langflow_oss

7 CVEs | CVSS 3.1: 10.0 | AAS 13.2

  • cpe:2.3:a:ibm:langflow_oss:*:*:*:*:*:*:*:* (>= 1.0.0, < 1.9.7)

IBM Langflow OSS versions 1.0.0 through 1.9.3 are affected by seven vulnerabilities, including multiple flaws rated up to CVSS 10.0 that allow attackers to read secrets, modify flows and stored data, access internal services and cloud metadata endpoints, move laterally across tenants, and establish persistent code execution through modified public flows. Functional exploit code is available, and the breadth of impact β€” from secret exfiltration to persistent backdoor installation β€” makes this an urgent priority for any organization running Langflow in production. Administrators should upgrade beyond version 1.9.3 immediately and review IBM’s advisory at www.ibm.com/support/pages/node/7277559, paying particular attention to any signs of tampered flows or unauthorized modifications in existing deployments.

Vendor Advisory


πŸ”΄ [CRITICAL] hiyouga/llamafactory

1 CVE | CVSS 4.0: 9.3 | AAS 12.7

  • cpe:2.3:a:hiyouga:llamafactory:*:*:*:*:*:*:*:*

LLaMA-Factory through version 0.9.5 contains a critical remote code execution vulnerability that allows anyone with WebUI access to execute arbitrary Python code by supplying a malicious model path in the Chat or Training interfaces, exploiting a hardcoded trust_remote_code=True parameter that causes the Hugging Face transformers library to fetch and run attacker-controlled code. Functional exploit code is available, and since LLaMA-Factory WebUI instances are often exposed for team use, the attack surface may be significant in AI and ML engineering environments. Organizations running affected versions should restrict WebUI access immediately, upgrade past version 0.9.5 when a fix is available, and review the advisory at the vendor’s published disclosure for further detail.

Vendor Advisory


πŸ”΄ [CRITICAL] @fastify/express/@fastify/express

1 CVE | CVSS 3.1: 9.1 | AAS 12.7

  • cpe:2.3:a:fastify_express:fastify_express:*:*:*:*:*:*:*:* (< 4.0.7)

@fastify/express versions 4.0.6 and earlier contain a critical middleware bypass vulnerability where non-string mount paths such as arrays and regular expressions are not correctly rewritten within prefixed plugin scopes, allowing attackers to bypass authentication, authorization, rate limiting, and other security middleware on affected routes. This vulnerability is being exploited in the wild and carries a CVSS 9.1 rating, making it an immediate concern for any Node.js application using @fastify/express with path-scoped security middleware inside prefixed scopes. Teams should upgrade beyond version 4.0.6 as soon as possible and review the advisory at cna.openjsf.org/security-advisories.html, auditing any middleware registrations that use array or regex mount paths to confirm security controls are being applied as intended.

Vendor Advisory


πŸ”΄ [CRITICAL] adobe/adobe_campaign_classic_(acc)

1 CVE | CVSS 3.1: 10.0 | AAS 12.3

  • cpe:2.3:a:adobe:adobe_campaign_classic_acc:*:*:*:*:*:*:*:*

Adobe Campaign Classic (ACC) versions 7.4.3 build 9396 and earlier are affected by an incorrect authorization vulnerability rated CVSS 10.0 that enables arbitrary code execution without user interaction and with a changed scope, meaning attackers can pivot beyond the vulnerable component to compromise additional systems. Functional exploit code is available, making this an urgent threat for any organization using ACC for marketing campaign management. Administrators should apply the patch from Adobe’s advisory at helpx.adobe.com/security/products/campaign/apsb26-69.html immediately and audit ACC environments for any signs of unauthorized access or unexpected code execution.

Vendor Advisory


🟠 [HIGH] coollabsio/coolify

1 CVE | CVSS 3.1: 8.8 | AAS 11.6

  • cpe:2.3:a:coollabsio:coolify:*:*:*:*:*:*:*:*

Coolify versions prior to 4.0.0-beta.464 contain an authenticated command injection vulnerability in the CA Certificate management feature that allows any authenticated user to execute arbitrary commands as the configured SSH user on managed server hosts, typically resulting in complete server compromise since the SSH user is usually root or has Docker group privileges. Functional exploit code is available, and because Coolify is widely used for self-hosted application and database management, any authenticated user β€” not just administrators β€” can exploit this to take full control of managed infrastructure. Teams should upgrade to version 4.0.0-beta.464 or later immediately and review the advisory at github.com/coollabsio/coolify/security/advisories/GHSA-7g97-c4xv-3cjx, auditing managed servers for signs of unauthorized command execution.

Vendor Advisory


🟠 [HIGH] ibm/db2

1 CVE | CVSS 3.1: 9.8 | AAS 11.4

  • cpe:2.3:a:ibm:db2:*:*:*:*:*:*:*:* (>= 11.5.0, < 11.5.10)
  • cpe:2.3:a:ibm:db2:*:*:*:*:*:*:*:* (>= 12.1.0, < 12.1.5)

IBM Db2 versions 11.5.0 through 11.5.9 and 12.1.0 through 12.1.4 are affected by a pre-authentication remote code execution vulnerability in the DRDA handshake handling, rated CVSS 9.8, meaning attackers can compromise vulnerable Db2 instances without any credentials. The flaw is confirmed exploitable and targets a network protocol handler that is exposed by default on any reachable Db2 instance, making this a severe risk for enterprise database environments. Organizations running affected versions should apply patches from IBM’s advisory at www.ibm.com/support/pages/node/7277424 immediately and ensure Db2 listener ports are not exposed to untrusted networks.

Vendor Advisory


🟠 [HIGH] linuxcnc/linuxcnc

1 CVE | CVSS 3.1: 8.4 | AAS 11.2

  • cpe:2.3:a:linuxcnc:linuxcnc:*:*:*:*:*:*:*:*

LinuxCNC versions before 2.9.9 contain a local privilege escalation vulnerability in the rtapi_app component of linuxcnc-uspace, where the SUID root binary performs insufficient validation of user-supplied module names passed to dlopen(), allowing path traversal to load arbitrary shared libraries with root privileges. Functional exploit code is available, making this an immediate concern for any system running LinuxCNC for CNC machine control, particularly in manufacturing and industrial environments where local user access may be broadly shared. Administrators should upgrade to LinuxCNC 2.9.9 or later and review the advisory at bugs.debian.org/1140943, auditing affected systems for signs of unauthorized privilege escalation.

Vendor Advisory


🟠 [HIGH] woodpecker-ci/woodpecker

1 CVE | CVSS 4.0: 9.2 | AAS 10.8

  • cpe:2.3:a:woodpecker-ci:woodpecker:*:*:*:*:*:*:*:* (< 3.15.0)

Woodpecker CI versions before 3.15.0 contain an approval bypass vulnerability where the ApprovalAllowedUsers check matches against the git commit author name from webhook payloads, which is attacker-controlled and not verified by GitLab, allowing anyone who can open a merge request from a fork to spoof an approved user and run pipelines without required approval. This is confirmed exploitable and poses a serious supply chain risk for organizations using Woodpecker with GitLab, as unauthorized code can execute in CI pipelines with access to secrets, deployment credentials, and production infrastructure. Teams should upgrade to Woodpecker 3.15.0 or later immediately and review the fix at the vendor’s commit, auditing pipeline execution logs for any pipelines that ran without proper approval from fork-originated merge requests.

Vendor Advisory


🟠 [HIGH] conductor-oss/conductor

1 CVE | CVSS 4.0: 9.3 | AAS 10.7

  • cpe:2.3:a:conductor-oss:conductor:*:*:*:*:*:*:*:* (>= 3.21.21, < 3.30.2)

Orkes Conductor versions 3.21.21 through 3.30.1 contain an unauthenticated remote code execution vulnerability that allows attackers to execute arbitrary OS commands by submitting inline workflow definitions with malicious JavaScript or Python expressions to the workflow API endpoint, exploiting unsandboxed GraalVM evaluators configured with full host access. This is confirmed exploitable without any authentication, making any internet-exposed Conductor instance an immediate target for full system compromise. Organizations running affected versions should upgrade to 3.30.2 or later without delay and review the fix at the vendor’s commit, ensuring workflow API endpoints are not accessible from untrusted networks while patching is underway.

Vendor Advisory


🟠 [HIGH] openbmb/chatdev

1 CVE | CVSS 4.0: 8.8 | AAS 10.2

  • cpe:2.3:a:openbmb:chatdev:*:*:*:*:*:*:*:*

OpenBMB ChatDev through version 2.2.0 contains a path traversal vulnerability in the file upload endpoint that allows unauthenticated remote attackers to write or delete arbitrary files on the server by supplying crafted filenames with path traversal sequences, potentially leading to full system compromise through overwriting critical files or planting malicious code. This is confirmed exploitable without authentication, making any exposed ChatDev instance an immediate target for AI and ML research teams running the platform. Organizations should update to the fixed commit 4fd4da6 or later and review the advisory at the vendor’s GitHub repository, auditing servers for any unauthorized file modifications or unexpected files outside the intended upload directory.

Vendor Advisory


🟠 [HIGH] threemammals/ocelot

1 CVE | CVSS 4.0: 9.3 | AAS 9.7

  • cpe:2.3:a:threemammals:ocelot:*:*:*:*:*:*:*:*

Ocelot API gateway through version 24.1.0 contains a security control bypass vulnerability where WebSocket upgrade requests completely skip the SecurityMiddleware pipeline, allowing clients from blocked IP addresses to circumvent configured allow and block lists and reach downstream services without restriction. This is confirmed exploitable and critically undermines any organization relying on Ocelot’s IP-based access controls to protect backend services, as attackers simply need to initiate a WebSocket connection to bypass all enforcement. Teams should update to the fixed commit f156fd4 or later and review the advisory at the vendor’s GitHub repository, treating any WebSocket-accessible downstream services as potentially exposed until the patch is applied.

Vendor Advisory


🟠 [HIGH] jeecgboot/jeecgboot

1 CVE | CVSS 4.0: 8.6 | AAS 9.5

  • cpe:2.3:a:jeecgboot:jeecgboot:*:*:*:*:*:*:*:*

JeecgBoot through version 3.9.2 contains a broken access control vulnerability where the OpenAPI credential management endpoints lack Shiro authorization annotations, allowing any authenticated low-privilege user to perform full create, read, update, and delete operations on all AK/SK credential pairs, with secret keys returned in plaintext. This is confirmed exploitable and poses a serious risk for organizations using JeecgBoot as a low-code development platform, as compromised API credentials can enable lateral movement and unauthorized access to integrated services. Teams should review the issue at github.com/jeecgboot/JeecgBoot/issues/9705, restrict access to the OpenApiAuthController and OpenApiPermissionController endpoints immediately, and rotate all exposed AK/SK credentials as a precaution until a patched version is available.

Vendor Advisory