2026-06-09
2026-06-09 21:17Z
CRIT

CVE-2026-47938 — Adobe: Campaign Classic (ACC) versions 7.4.3 build 9394 and earlier are affected by a

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-47938

Adobe Campaign Classic (ACC) versions 7.4.3 build 9394 and earlier are affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed. CVSSv3.1 10.0 (CRITICAL)

CWECWE 918VNDAdobeTYPVulnerability
10.0
CVSS v3.1
100
Edit Score
2026-06-09
2026-06-09 21:17Z
HIGH

CVE-2026-47932 — ColdFusion: versions 2023.19, 2025.8 and earlier are affected by an Improper Limitation of a

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-47932

ColdFusion versions 2023.19, 2025.8 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to access unauthorized files or directories outside the intended restrictions. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed. CVSSv3.1 8.8 (HIGH)

CWECWE 22VNDColdfusionTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-09
2026-06-09 21:17Z
HIGH

CVE-2026-47931 — ColdFusion: versions 2023.19, 2025.8 and earlier are affected by an Improper Input Validation vulnerability

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-47931

ColdFusion versions 2023.19, 2025.8 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed. CVSSv3.1 8.4 (HIGH)

CWECWE 20VNDColdfusionTYPVulnerability
8.4
CVSS v3.1
92
Edit Score
2026-06-09
2026-06-09 21:17Z
HIGH

CVE-2026-47930 — ColdFusion: versions 2023.19, 2025.8 and earlier are affected by an Improper Input Validation vulnerability

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-47930

ColdFusion versions 2023.19, 2025.8 and earlier are affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and gain unauthorized read and write access. Exploitation of this issue does not require user interaction. CVSSv3.1 8.1 (HIGH)

CWECWE 20VNDColdfusionTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-06-09
2026-06-09 21:17Z
HIGH

CVE-2026-47929 — ColdFusion: versions 2023.19, 2025.8 and earlier are affected by an Incorrect Authorization vulnerability that

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-47929

ColdFusion versions 2023.19, 2025.8 and earlier are affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. A high-privileged attacker could exploit this vulnerability to gain elevated access or control over the victim's account or session. Exploitation of this issue does not require user interaction. Scope is changed. CVSSv3.1 8.4 (HIGH)

CWECWE 863VNDColdfusionTYPVulnerability
8.4
CVSS v3.1
92
Edit Score
2026-06-09
2026-06-09 21:17Z
CRIT

CVE-2026-47928 — ColdFusion: versions 2023.19, 2025.8 and earlier are affected by an Improper Input Validation vulnerability

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-47928

ColdFusion versions 2023.19, 2025.8 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed. CVSSv3.1 9.6 (CRITICAL)

CWECWE 20VNDColdfusionTYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-06-09
2026-06-09 21:04Z
CRIT

Patch Tuesday - June 2026

Microsoft's June 2026 Patch Tuesday addresses 200 vulnerabilities, including multiple uncoordinated disclosures by researcher 'Nightmare Eclipse' covering Defender elevation-of-privilege flaws (MiniPlasma, GreenPlasma, RoguePlanet) and Secure Boot bypasses. Critical issues include HTTP/2 denial-of-service (CVE-2026-49160, CVE-2026-49975), PowerToys local EoP (CVE-2026-42902), and high-CVSS Azure/RDP/kernel vulnerabilities. The disclosure pattern—timed immediately after Patch Tuesday with full PoC code—represents a significant escalation in vulnerability disclosure friction.

SRFApplicationSRFOsSRFCloudOSWindowsVNDMicrosoftTYPAdvisorySTGPrivescSTGExecution
78
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-06-09
2026-06-09 20:16Z
HIGH

CVE-2026-47907 — Dreamweaver: Desktop versions 21.7 and earlier are affected by an Improper Access Control vulnerability

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-47907

Dreamweaver Desktop versions 21.7 and earlier are affected by an Improper Access Control vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access sensitive files and directories outside the intended access scope. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed. CVSSv3.1 8.2 (HIGH)

CWECWE 284VNDDreamweaverTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-06-09
2026-06-09 20:16Z
HIGH

CVE-2026-47906 — Dreamweaver: Desktop versions 21.7 and earlier are affected by a Dependency on Vulnerable Third-Party

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-47906

Dreamweaver Desktop versions 21.7 and earlier are affected by a Dependency on Vulnerable Third-Party Component vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed. CVSSv3.1 8.6 (HIGH)

VNDDreamweaverTYPVulnerability
8.6
CVSS v3.1
93
Edit Score
2026-06-09
2026-06-09 19:17Z
CRIT

CVE-2026-36727 — An insecure authentication vulnerability in the /api/social-sign-in endpoint of bookcars v8.3 allows attackers to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-36727

An insecure authentication vulnerability in the /api/social-sign-in endpoint of bookcars v8.3 allows attackers to bypass authentication via a forged JWT token. CVSSv3.1 9.1 (CRITICAL)

CWECWE 287TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-06-09
2026-06-09 19:17Z
HIGH

CVE-2026-36723 — An unrestricted file rename vulnerability in the /api/create-user component of bookcars v8.3 allows authenticated

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-36723

An unrestricted file rename vulnerability in the /api/create-user component of bookcars v8.3 allows authenticated attackers to leverage directory traversal sequences to move arbitrary files from temporary storage to arbitrary locations on the server filesystem. This enables unauthorized access to sensitive files, the overwriting of critical application files, and remote code execution (RCE). CVSSv3.1 8.8 (HIGH)

CWECWE 22TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-09
2026-06-09 19:17Z
CRIT

CVE-2026-36721 — A lack of cryptographic signature verification in the validateAccessToken function of bookcars v8.3 allows

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-36721

A lack of cryptographic signature verification in the validateAccessToken function of bookcars v8.3 allows attackers to bypass authentication via a forged JWT token. CVSSv3.1 9.8 (CRITICAL)

CWECWE 347TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-09
2026-06-09 19:17Z
HIGH

CVE-2026-36720 — Insecure permissions in bookcars v8.3 allows authenticated attackers to escalate privileges from user to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-36720

Insecure permissions in bookcars v8.3 allows authenticated attackers to escalate privileges from user to admin via modifying their user type. CVSSv3.1 8.1 (HIGH)

CWECWE 284TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-06-09
2026-06-09 19:17Z
CRIT

CVE-2026-30141 — A buffer overflow in the DecodeLZW function allows remote attackers to cause a denial

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-30141

An issue was discovered in bitbank2 AnimatedGIF v2.2.0. A buffer overflow in the DecodeLZW function allows remote attackers to cause a denial of service (crash) or potentially execute arbitrary code via a crafted GIF file. CVSSv3.1 9.8 (CRITICAL)

CWECWE 120TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-09
2026-06-09 19:17Z
CRIT

CVE-2026-10045 — Shenzhen: These vulnerabilities allow attackers to read and write to memory, modify firmware stored in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-10045

Shenzhen Kangda Xin Intelligent Network Technology Company's router, model DR300, version 2.1.2.121, contains hardcoded login credentials and has telnet enabled by default on WAN and LAN interfaces. These vulnerabilities allow attackers to read and write to memory, modify firmware stored in flash, inspect active connections, and view currently connected devices. CVSSv3.1 9.8 (CRITICAL)

VNDShenzhenTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-09
2026-06-09 19:16Z
HIGH

CVE-2023-29146 — Malwarebytes: This leads to an integer wrap-around if the data is larger than the maximum

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2023-29146

The utility functions used by Malwarebytes EDR 1.0.11 on Linux for calculating a cryptographic hash of data bytes truncate the hashed data if it exceeds 4GB. This leads to an integer wrap-around if the data is larger than the maximum unsigned integer value (32-bit). Attackers could create a colliding hash value for two different strings by attaching 4GB of data to a string that is less than 4GB in size. CVSSv3.1 8.2 (HIGH)

CWECWE 190VNDMalwarebytesTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-06-09
2026-06-09 18:17Z
HIGH

CVE-2026-50636 — RemoteControl: A remote, authenticated attacker holding the tokens/update permission on a survey can inject a

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-50636

The RemoteControl API methods invite_participants and remind_participants pass a caller-supplied token-ID array into TokenDynamic::findUninvited(), which concatenates the values directly into a tid IN ('...') SQL clause without parameterization or input validation. A remote, authenticated attacker holding the tokens/update permission on a survey can inject a crafted array element to perform SQL injection. Because LimeSurvey configures its PDO connection with emulated prepared CVSSv3.1 8.8 (HIGH)

CWECWE 89VNDRemotecontrolTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-09
2026-06-09 18:17Z
HIGH

CVE-2026-50635 — LimeSurvey: The optional allowedHosts allowlist that would constrain this is undefined in the default (and

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-50635

LimeSurvey constructs account password-reset links from the client-supplied HTTP Host header without validating it. The optional allowedHosts allowlist that would constrain this is undefined in the default (and documented) configuration, so LSHttpRequest::checkIsAllowedHost() results in no operation. A remote, unauthenticated attacker who submits a forgotten-password request for a known account (requiring only the target's username and email) with a spoofed Host header causes CVSSv3.1 8.8 (HIGH)

CWECWE 640VNDLimesurveyTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-09
2026-06-09 18:16Z
HIGH

CVE-2026-34693 — Adobe: Experience Manager Forms JEE versions LTS SP1, 6.5.24.0 and earlier are affected by

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-34693

Adobe Experience Manager Forms JEE versions LTS SP1, 6.5.24.0 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this vulnerability to inject malicious scripts into a web page, potentially gaining elevated access or control over the victim's account or session. Exploit depends on conditions beyond the attacker's control. Exploitation of this issue requires user interaction in that a victim must visit a maliciously craft CVSSv3.1 8.0 (HIGH)

CWECWE 79VNDAdobeTYPVulnerability
8.0
CVSS v3.1
90
Edit Score
2026-06-09
2026-06-09 18:16Z
CRIT

CVE-2026-34691 — Adobe: Experience Manager Forms JEE versions LTS SP1, 6.5.24.0 and earlier are affected by

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-34691

Adobe Experience Manager Forms JEE versions LTS SP1, 6.5.24.0 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field, potentially gaining elevated access or control over the victim's account or session. Scope is changed. CVSSv3.1 9.3 (CRITICAL)

CWECWE 79VNDAdobeTYPVulnerability
9.3
CVSS v3.1
97
Edit Score
2026-06-09
2026-06-09 18:12Z
CRIT

The June 2026 Security Update Review

Microsoft released a record 208 CVEs in June 2026 (571 total including third-party), with 38 rated Critical, marking the largest monthly patch release since tracking began in 2017. Adobe released 11 bulletins addressing 123 CVEs, including two CVSS 10.0 bugs in Campaign Classic and critical RCE vulnerabilities in ColdFusion, Reader, and Experience Manager. Notable Microsoft vulnerabilities include three wormable CVSS 9.8 RCEs (Windows Kernel, HTTP.sys, DHCP Client) and BitLocker bypass bugs tied to ongoing researcher disclosures.

SRFApplicationSRFOsTACTA0004TACTA0001TACTA0002VNDMicrosoftVNDAdobeTYPAdvisory
82
Edit Score
2026-06-09
2026-06-09 17:17Z
HIGH

CVE-2026-9213 — Netgear Mr70_firmware: A vulnerability in the affected NETGEAR gaming routers allows attackers with the ability to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-9213

A vulnerability in the affected NETGEAR gaming routers allows attackers with the ability to intercept and tamper with traffic between the router and the Internet, to execute code on the device. CVSSv3.1 8.1 (HIGH) · EPSS 25th percentile

CWECWE 20VNDNetgearTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-06-09
2026-06-09 17:17Z
HIGH

CVE-2026-9212 — Netgear Lbr1020_firmware: Insufficient authentication and input validation in the listed NETGEAR models allow users connected to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-9212

Insufficient authentication and input validation in the listed NETGEAR models allow users connected to the local network to execute commands impacting the product's confidentiality or change certain configurations. CVSSv3.1 8.0 (HIGH) · EPSS 19th percentile

CWECWE 306CWECWE 20VNDNetgearTYPVulnerability
8.0
CVSS v3.1
90
Edit Score
2026-06-09
2026-06-09 17:17Z
HIGH

CVE-2026-9211 — Netgear Cax30_firmware: An unauthenticated user on the local network can gain control of the router and

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-9211

An unauthenticated user on the local network can gain control of the router and make unauthorized changes to its operation. CVSSv3.1 8.8 (HIGH) · EPSS 11th percentile

CWECWE 20VNDNetgearTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-09
2026-06-09 17:17Z
HIGH

CVE-2026-7383 — Issue: summary: A signed integer overflow when sizing the destination buffer for Unicode output

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-7383

Issue summary: A signed integer overflow when sizing the destination buffer for Unicode output in ASN1_mbstring_ncopy() can lead to a heap buffer overflow. Impact summary: A heap buffer overflow may lead to a crash or possibly attacker controlled code execution or other undefined behaviour. In ASN1_mbstring_copy() and ASN1_mbstring_ncopy() the destination size for Unicode output is computed in a signed int: by left shift of the input character count for BMPSTRING (UTF-16) a CVSSv3.1 8.1 (HIGH)

CWECWE 787TYPVulnerability
8.1
CVSS v3.1
91
Edit Score