CVE Weekly Report — Week of Jun 8 – June 14, 2026
2026-W24
13
Total CVEs
0
Critical
5
High
0
Actively exploited
🔴 Critical CVEs (5)
| CVE | Product | CVSS | KEV | Description | Published |
|---|---|---|---|---|---|
| CVE-2026-49261 | Mariadb | 10.0 | — | MariaDB server is a community developed fork of MySQL server. Versions 10.6.1 through 10.6.26, 10.11.1 through 10.11.17,… | Jun 11 |
| CVE-2026-46289 | Linux | 9.8 | — | In the Linux kernel, the following vulnerability has been resolved: lib/scatterlist: fix length calculations in extract… | Jun 8 |
| CVE-2026-46325 | Linux | 9.8 | — | In the Linux kernel, the following vulnerability has been resolved: RDMA/rxe: Fix iova-to-va conversion for MR page siz… | Jun 9 |
| CVE-2026-44170 | Mariadb | 9.8 | — | MariaDB server is a community developed fork of MySQL server. From versions 10.6.1 to before 10.6.26, 10.11.1 to before … | Jun 12 |
| CVE-2026-46316 | Linux | 9.3 | — | In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: vgic-its: Drop the translation cache re… | Jun 9 |
🟠 High CVEs (45)
| CVE | Product | CVSS | KEV | Description | Published |
|---|---|---|---|---|---|
| CVE-2026-46317 | Linux | 8.8 | — | In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: Reassign nested_mmus array behind mmu_l… | Jun 9 |
| CVE-2025-24284 | macOS | 8.8 | — | This issue was addressed with improved checks to prevent unauthorized actions. This issue is fixed in macOS Sequoia 15.4… | Jun 11 |
| CVE-2026-46288 | Linux | 8.4 | — | In the Linux kernel, the following vulnerability has been resolved: of: unittest: fix use-after-free in of_unittest_cha… | Jun 8 |
| CVE-2026-46326 | Linux | 8.4 | — | In the Linux kernel, the following vulnerability has been resolved: iio: pressure: mprls0025pa: fix spi_transfer struct… | Jun 9 |
| CVE-2026-46307 | Linux | 8.3 | — | In the Linux kernel, the following vulnerability has been resolved: wifi: ath5k: do not access array OOB Vincent repor… | Jun 8 |
| CVE-2026-46303 | Linux | 8.2 | — | In the Linux kernel, the following vulnerability has been resolved: isofs: validate Rock Ridge CE continuation extent a… | Jun 8 |
| CVE-2026-9753 | MongoDB | 8.1 | — | The $_internalApplyOplogUpdate aggregation pipeline stage can be used to execute a document diff containing a malformed … | Jun 9 |
| CVE-2026-44168 | Mariadb | 8.0 | — | MariaDB server is a community developed fork of MySQL server. From versions 10.6.1 to before 10.6.26, 10.11.1 to before … | Jun 12 |
| CVE-2026-46332 | Linux | 8.0 | — | In the Linux kernel, the following vulnerability has been resolved: greybus: gb-beagleplay: bound bootloader receive bu… | Jun 9 |
| CVE-2026-48165 | Mariadb | 8.0 | — | MariaDB server is a community developed fork of MySQL server. From versions 10.6.1 to before 10.6.27, 10.11.1 to before … | Jun 12 |
| CVE-2026-48163 | Mariadb | 8.0 | — | MariaDB server is a community developed fork of MySQL server. From versions 10.6.1 to before 10.6.27, 10.11.1 to before … | Jun 12 |
| CVE-2026-46301 | Linux | 7.8 | — | In the Linux kernel, the following vulnerability has been resolved: spi: topcliff-pch: fix use-after-free on unbind Gi… | Jun 8 |
| CVE-2026-46275 | Linux | 7.8 | — | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_uart: fix UAFs and race conditions i… | Jun 8 |
| CVE-2026-46294 | Linux | 7.8 | — | In the Linux kernel, the following vulnerability has been resolved: dm: fix a buffer overflow in ioctl processing Tony… | Jun 8 |
| CVE-2026-46274 | Linux | 7.8 | — | In the Linux kernel, the following vulnerability has been resolved: io-wq: check that the predecessor is hashed in io_w… | Jun 8 |
| CVE-2026-52907 | Linux | 7.8 | — | In the Linux kernel, the following vulnerability has been resolved: media: rockchip: rkcif: fix off by one bugs Change… | Jun 9 |
| CVE-2026-46330 | Linux | 7.8 | — | In the Linux kernel, the following vulnerability has been resolved: Revert "net/smc: Introduce TCP ULP support" This r… | Jun 9 |
| CVE-2026-46285 | Linux | 7.8 | — | In the Linux kernel, the following vulnerability has been resolved: mtd: docg3: fix use-after-free in docg3_release() … | Jun 8 |
| CVE-2026-46327 | Linux | 7.8 | — | In the Linux kernel, the following vulnerability has been resolved: dm: fix unlocked test for dm_suspended_md The func… | Jun 9 |
| CVE-2026-46281 | Linux | 7.8 | — | In the Linux kernel, the following vulnerability has been resolved: vmalloc: fix buffer overflow in vrealloc_node_align… | Jun 8 |
| CVE-2026-46280 | Linux | 7.8 | — | In the Linux kernel, the following vulnerability has been resolved: lib: test_hmm: evict device pages on file close to … | Jun 8 |
| CVE-2026-46279 | Linux | 7.8 | — | In the Linux kernel, the following vulnerability has been resolved: mm/alloc_tag: clear codetag for pages allocated bef… | Jun 8 |
| CVE-2026-46277 | Linux | 7.8 | — | In the Linux kernel, the following vulnerability has been resolved: mm/zone_device: do not touch device folio after cal… | Jun 8 |
| CVE-2026-46324 | Linux | 7.8 | — | In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: use list_del_rcu for netlink … | Jun 9 |
| CVE-2026-46323 | Linux | 7.8 | — | In the Linux kernel, the following vulnerability has been resolved: net: gro: don't merge zcopy skbs skb_gro_receive()… | Jun 9 |
| CVE-2026-46319 | Linux | 7.8 | — | In the Linux kernel, the following vulnerability has been resolved: net/sched: act_ct: Only release RCU read lock after… | Jun 9 |
| CVE-2025-31272 | macOS | 7.8 | — | The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.4. An app may be able to bypass la… | Jun 11 |
| CVE-2026-46311 | Linux | 7.8 | — | In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/userq: fix access to stale wptr mapping … | Jun 8 |
| CVE-2026-46308 | Linux | 7.8 | — | In the Linux kernel, the following vulnerability has been resolved: pmdomain: mediatek: fix use-after-free in scpsys_ge… | Jun 8 |
| CVE-2026-52906 | Linux | 7.7 | — | In the Linux kernel, the following vulnerability has been resolved: 9p: fix access mode flags being ORed instead of rep… | Jun 9 |
| CVE-2026-46304 | Linux | 7.5 | — | In the Linux kernel, the following vulnerability has been resolved: nvmet: avoid recursive nvmet-wq flush in nvmet_ctrl… | Jun 8 |
| CVE-2025-46315 | macOS | 7.5 | — | A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Tahoe 26.1. An app may be a… | Jun 11 |
| CVE-2026-46306 | Linux | 7.5 | — | In the Linux kernel, the following vulnerability has been resolved: flow_dissector: do not dissect PPPoE PFC frames RF… | Jun 8 |
| CVE-2026-49975 | nginx | 7.5 | — | Memory Allocation with Excessive Size Value vulnerability in Apache HTTP Server's mod_http leads to denial of service vi… | Jun 8 |
| CVE-2026-9740 | MongoDB | 7.5 | — | A vulnerability in MongoDB Server's BSON validation logic allows an unauthenticated user to crash the mongod process by … | Jun 9 |
| CVE-2026-9742 | MongoDB | 7.5 | — | When OIDC authentication is enabled in configuration, clients may set specific values in the "mechanism" parameter of th… | Jun 9 |
| CVE-2026-46320 | Linux | 7.4 | — | In the Linux kernel, the following vulnerability has been resolved: tap: free page on error paths in tap_get_user_xdp()… | Jun 9 |
| CVE-2026-46328 | Linux | 7.3 | — | In the Linux kernel, the following vulnerability has been resolved: apparmor: fix rlimit for posix cpu timers Posix cp… | Jun 9 |
| CVE-2026-46322 | Linux | 7.1 | — | In the Linux kernel, the following vulnerability has been resolved: tun: free page on build_skb failure in tun_xdp_one(… | Jun 9 |
| CVE-2022-26758 | macOS | 7.1 | — | A malicious application may cause unexpected changes in memory shared between processes. A memory corruption issue was a… | Jun 10 |
| CVE-2026-46293 | Linux | 7.1 | — | In the Linux kernel, the following vulnerability has been resolved: clk: microchip: mpfs-ccc: fix out of bounds access … | Jun 8 |
| CVE-2026-46321 | Linux | 7.1 | — | In the Linux kernel, the following vulnerability has been resolved: tun: free page on short-frame rejection in tun_xdp_… | Jun 9 |
| CVE-2026-46299 | Linux | 7.0 | — | In the Linux kernel, the following vulnerability has been resolved: hfsplus: fix held lock freed on hfsplus_fill_super(… | Jun 8 |
| CVE-2026-54230 | Fedora | 7.0 | — | A symlink following vulnerability was found in the ABRT post-create event handler scripts in libreport. Event scripts wr… | Jun 13 |
| CVE-2026-46309 | Linux | 7.0 | — | In the Linux kernel, the following vulnerability has been resolved: drm/xe/uapi: Reject coh_none PAT index for CPU cach… | Jun 8 |
🟡 Medium CVEs (15)
| CVE | Product | CVSS | KEV | Description | Published |
|---|---|---|---|---|---|
| CVE-2026-9741 | MongoDB | 6.5 | — | A bug in query analysis processing of the $vectorSearch aggregation stage for Queryable Encryption (QE) or Client-Side F… | Jun 9 |
| CVE-2026-9752 | MongoDB | 6.5 | — | An authorized user could trigger a server crash by running a query with a 2dsphere index on a field that stores a GeoJSO… | Jun 9 |
| CVE-2026-9750 | MongoDB | 6.5 | — | An authenticated user can cause a MongoDB server to crash or return incorrect results by creating documents that interfe… | Jun 9 |
| CVE-2026-9749 | MongoDB | 6.5 | — | This issue can occur when running an aggregation pipeline that uses the internal $exchange stage configured with key-ran… | Jun 9 |
| CVE-2026-9748 | MongoDB | 6.5 | — | The $_internalConvertBucketIndexStats stage used PauseExecution as a way to signal "skip this document" when an index st… | Jun 9 |
| CVE-2026-9754 | MongoDB | 6.5 | — | An authenticated user with the read role may read limited amounts of uninitialized stack memory via specially-crafted is… | Jun 9 |
| CVE-2026-9747 | MongoDB | 6.5 | — | Adding fromRouter:true and runtimeConstants.userRoles could cause aggregations to crash mongodb server. | Jun 9 |
| CVE-2026-9743 | MongoDB | 6.5 | — | In MongoDB Server 8.0, an aggregation stage can leave its _subPipeline field null during processing of certain pipelines… | Jun 9 |
| CVE-2026-9746 | MongoDB | 6.5 | — | When using $changestreams and $_requestReshardingResumeToken with the exchange option the server hits an invariant which… | Jun 9 |
| CVE-2026-44171 | Mariadb | 6.3 | — | MariaDB server is a community developed fork of MySQL server. From versions 10.6.1 to before 10.6.26, 10.11.1 to before … | Jun 12 |
| CVE-2025-71315 | Linux | 5.5 | — | In the Linux kernel, the following vulnerability has been resolved: drm/vkms: Convert to DRM's vblank timer Replace vk… | Jun 8 |
| CVE-2026-54231 | Fedora | 5.5 | — | A content injection vulnerability was found in the ABRT post-create event handler scripts in libreport. The event script… | Jun 13 |
| CVE-2025-46293 | macOS | 5.5 | — | This issue was addressed with improved handling of symlinks. This issue is fixed in macOS Sequoia 15.4. An app may be ab… | Jun 11 |
| CVE-2025-43339 | macOS | 5.5 | — | An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Tahoe 26.1. A malicious… | Jun 11 |
| CVE-2025-30459 | macOS | 5.5 | — | A privacy issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sequoia 15.4. An app may be … | Jun 11 |
