CRITICAL severity only · CVSS ≥ 9.0
Critical CVEs
The 50 most recently published CRITICAL-severity CVEs. These are the highest-impact vulnerabilities by CVSS score, most worth triaging first.
- CVE-2026-350752026-06-03Hardcoded default Password for Service AccountMBS / Single-A · MBS / Double-A Profibus · MBS / Double-A x-linkCRITICAL9.3v4.0
- CVE-2026-470652026-06-03Apache MINA: Critical Deserialization Allow-list Bypass via resolveProxyClass - ZDRES-232Apache Software Foundation / Apache MINACRITICAL9.8v3.1
- CVE-2026-40352026-06-03Environment Variable Resolution Vulnerability in mlflow/mlflowmlflow / mlflow/mlflowCRITICAL9.1v3.0
- CVE-2026-365762026-06-03An OS command injection vulnerability in the appn/a / n/aCRITICAL9.8v3.1
- CVE-2026-367482026-06-03RockRMS v16n/a / n/aCRITICAL9.0v3.1
- CVE-2026-326252026-06-02LibreChat Exfiltrates Server Secrets via MCP Server URL Injectiondanny-avila / LibreChatCRITICAL9.6v3.1
- CVE-2026-494482026-06-02authentik: SourceStage bypass via empty POSTgoauthentik / authentikCRITICAL9.8v3.1
- CVE-2026-428492026-06-02authentik: Reflected XSS in SFE AutosubmitStage allows IDP account takeovergoauthentik / authentikCRITICAL9.3v3.1
- CVE-2026-50762026-06-02ARMember Premium <= 7.3.1 - Insecure Password Reset Mechanism to Unauthenticated Privilege Escalationarmember / ARMember Premium – Membership Plugin, Content Restriction, Member Levels, User Profile & User signupCRITICAL9.8v3.1
- CVE-2026-06112026-06-02Spacelabs Healthcare Sentinel 10.5.x < 11.6.0 Unauthenticated RCE via .NET RemotingSpacelabs Healthcare / SentinelCRITICAL9.2v4.0
- CVE-2026-420742026-06-02OpenClaude: Sandbox Bypass via Model-Controlled `dangerouslyDisableSandbox` InputGitlawb / openclaudeCRITICAL9.3v4.0
- CVE-2026-471172026-06-02OpenMed < 1.5.2 Remote Code Execution via PII Model Loadingmaziyarpanahi / openmedCRITICAL9.3v4.0
- CVE-2026-73122026-06-02CWE‑522: Insufficiently Protected Credentials in web services in Progress SitefinityProgress Software / SitefinityCRITICAL10.0v3.1
- CVE-2026-71982026-06-02CWE-284: Improper Access Control in web services in Progress SitefinityProgress Software / SitefinityCRITICAL9.8v3.1
- CVE-2026-426842026-06-02WordPress WP Job Portal plugin <= 2.5.1 - SQL Injection vulnerabilityAhmad / WP Job PortalCRITICAL9.3v3.1
- CVE-2026-349062026-06-02Server-Side Template Injection (SSTI) in Wirtualna UczelniaSimple SA / Wirtualna UczelniaCRITICAL9.3v4.0
- CVE-2026-82062026-06-02Kirki 6.0.0 - 6.0.6 - Unauthenticated Privilege Escalation via 'handle_forgot_password'themeum / Kirki – Freeform Page Builder, Website Builder & CustomizerCRITICAL9.8v3.1
- CVE-2026-389672026-06-02CrowCpp Crow through v1n/a / n/aCRITICAL9.8v3.1
- CVE-2026-258792026-06-01Langroid has Prompt to SQL Injection, Leading to RCElangroid / langroidCRITICAL9.8v3.1
- CVE-2026-409652026-06-01Cloud Foundry UAA versions v76Cloud Foundry Foundation / uaa_release · Cloud Foundry Foundation / CF DeploymentCRITICAL10.0v4.0
- CVE-2026-93192026-06-01IBM WebSphere Application Server is affected by a remote code execution vulnerabilityIBM / WebSphere Application ServerCRITICAL9.0v3.1
- CVE-2026-93112026-06-01IBM WebSphere Application Server is affected by remote code executionIBM / WebSphere Application ServerCRITICAL9.0v3.1
- CVE-2026-86442026-06-01IBM WebSphere Application Server is affected by an identity spoofing vulnerabilityIBM / WebSphere Application ServerCRITICAL9.1v3.1
- CVE-2026-00722026-06-01In addInputMethodListener of comGoogle / Android XRCRITICAL10.0v4.0
- CVE-2026-491212026-06-01AI Tensor Engine for ROCm (AITER) 0.1.14 Unauthenticated RCE via MessageQueue.recv() Pickle DeserializationROCm / aiterCRITICAL9.2v4.0
- CVE-2026-451312026-06-01CloudPirates Open Source Helm Charts: GitHub Actions pull_request_target workflow allows secret exfiltration via fork pull requestsCloudPirates-io / helm-chartsCRITICAL10.0v3.1
- CVE-2026-451322026-06-01CloudPirates Open Source Helm Charts: GitHub Actions workflow leaks PAT and SSH signing key via unsafe credential handlingCloudPirates-io / helm-chartsCRITICAL10.0v3.1
- CVE-2026-442112026-06-01Cline Kanban Server has a Cross-Origin WebSocket Hijacking Vulnerabilitycline / clineCRITICAL9.6v3.1
- CVE-2026-426722026-06-01WordPress WP Directory Kit plugin <= 1.5.1 - SQL Injection vulnerabilityWp Directory Kit / WP Directory KitCRITICAL9.3v3.1
- CVE-2026-08262026-06-01Poly Voice – Possible Remote Control of Certain Poly DevicesHP Inc. / poly_trio_8300 · HP Inc. / poly_trio_8500 · HP Inc. / poly_trio_8800CRITICAL9.2v4.0
- CVE-2026-426802026-06-01WordPress Contest Gallery Pro plugin <= 29.0.1 - Privilege Escalation vulnerabilityWasiliy Strecker / ContestGallery developer / Contest Gallery ProCRITICAL9.8v3.1
- CVE-2026-426822026-06-01WordPress wpForo Forum plugin <= 3.0.6 - Broken Access Control vulnerabilityTomdever / wpForo ForumCRITICAL9.1v3.1
- CVE-2026-488662026-06-01WordPress Gravity Forms plugin <= 2.10.0.1 - Arbitrary File Deletion vulnerabilityRocketgenius Inc. / Gravity FormsCRITICAL9.6v3.1
- CVE-2026-488792026-06-01WordPress AIWU plugin <= 1.4.17 - Privilege Escalation vulnerabilitySergey / AIWUCRITICAL9.8v3.1
- CVE-2026-89312026-06-01Critical RCE vulnerability in Disig Web SignerDisig / Web SignerCRITICAL9.4v4.0
- CVE-2026-422522026-06-01Apache Airflow: BashOperator Jinja2 injection via dag_run.conf — low-privilege user patternApache Software Foundation / Apache AirflowCRITICAL9.1v3.1
- CVE-2026-78582026-06-01Deserialization of Untrusted Data vulnerability affecting Teamwork Cloud from No Magic Release 2022x through No Magic Release 2026x and Magic Collaboration Studio from CATIA Magic Release 2022x through CATIA Magic Release 2026xDassault Systèmes / Teamwork Cloud - Standard Edition · Dassault Systèmes / Teamwork Cloud - Business Edition · Dassault Systèmes / Teamwork Cloud - Business Pro EditionCRITICAL9.8v3.1
- CVE-2026-481882026-06-01SQL Injection via MySQL Quote MethodOTRS AG / OTRS · OTRS AG / ((OTRS)) Community EditionCRITICAL9.1v3.1
- CVE-2026-101872026-05-31Totolink N300RH Web Management wireless.so setWiFiBasicConfig stack-based overflowTotolink / N300RHCRITICAL9.3v4.0
- CVE-2026-453722026-05-29cpp-httplib: HTTP header value percent-decoding in server-side `parse_header` enables CRLF injectionyhirose / cpp-httplibCRITICAL9.9v3.1
- CVE-2026-456972026-05-29Formie: Pre-authenticated server-side template injection in Hidden fieldsverbb / formieCRITICAL9.8v3.1
- CVE-2026-90512026-05-29Authentication Bypass Vulnerability in NI SystemLink EnterpriseNI / SystemLink EnterpriseCRITICAL9.3v4.0
- CVE-2026-477442026-05-29Shopper: Authorization bypass and RBAC privilege escalation in team settingsshopperlabs / shopperCRITICAL9.9v3.1
- CVE-2026-446502026-05-29SillyTavern: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')SillyTavern / SillyTavernCRITICAL9.1v3.1
- CVE-2026-446492026-05-29SillyTavern: Authentication Bypass via SSO Header InjectionSillyTavern / SillyTavernCRITICAL9.8v3.1
- CVE-2026-456682026-05-29Trilium Notes : Note Import to RCE via #docName Path Traversal (Safe Import Enabled)TriliumNext / TriliumCRITICAL9.3v4.0
- CVE-2026-77862026-05-29Jinan USR IOT Technology Limited (PUSR) USR-W610 RS232/485 to Wi-Fi/Ethernet Converter Use of Hard-coded CredentialsJinan USR IOT Technology Limited (PUSR) / USR-W610 RS232/485 to Wi-Fi/Ethernet ConverterCRITICAL9.8v3.1
- CVE-2026-456252026-05-29Arcane: Missing admin authorization on git repository endpoints allows non-admin users to exfiltrate stored Git credentials and tamper with GitOps configsgetarcaneapp / arcaneCRITICAL9.9v3.1
- CVE-2026-456292026-05-29Dokploy: Authenticated Remote Code Execution via Command Injection in /listen-deployment WebSocket EndpointDokploy / dokployCRITICAL9.9v3.1
- CVE-2026-456282026-05-29Dokploy: Command Injection via Unescaped Branch Fields in Deployment PipelineDokploy / dokployCRITICAL9.6v3.1