CVE Weekly Report — Week of Jun 8 – June 14, 2026

2026-W24

13
Total CVEs
0
Critical
5
High
0
Actively exploited

🔴 Critical CVEs (5)

CVEProductCVSSKEVDescriptionPublished
CVE-2026-49261Mariadb10.0MariaDB server is a community developed fork of MySQL server. Versions 10.6.1 through 10.6.26, 10.11.1 through 10.11.17,…Jun 11
CVE-2026-46289Linux9.8In the Linux kernel, the following vulnerability has been resolved: lib/scatterlist: fix length calculations in extract…Jun 8
CVE-2026-46325Linux9.8In the Linux kernel, the following vulnerability has been resolved: RDMA/rxe: Fix iova-to-va conversion for MR page siz…Jun 9
CVE-2026-44170Mariadb9.8MariaDB server is a community developed fork of MySQL server. From versions 10.6.1 to before 10.6.26, 10.11.1 to before …Jun 12
CVE-2026-46316Linux9.3In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: vgic-its: Drop the translation cache re…Jun 9

🟠 High CVEs (45)

CVEProductCVSSKEVDescriptionPublished
CVE-2026-46317Linux8.8In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: Reassign nested_mmus array behind mmu_l…Jun 9
CVE-2025-24284macOS8.8This issue was addressed with improved checks to prevent unauthorized actions. This issue is fixed in macOS Sequoia 15.4…Jun 11
CVE-2026-46288Linux8.4In the Linux kernel, the following vulnerability has been resolved: of: unittest: fix use-after-free in of_unittest_cha…Jun 8
CVE-2026-46326Linux8.4In the Linux kernel, the following vulnerability has been resolved: iio: pressure: mprls0025pa: fix spi_transfer struct…Jun 9
CVE-2026-46307Linux8.3In the Linux kernel, the following vulnerability has been resolved: wifi: ath5k: do not access array OOB Vincent repor…Jun 8
CVE-2026-46303Linux8.2In the Linux kernel, the following vulnerability has been resolved: isofs: validate Rock Ridge CE continuation extent a…Jun 8
CVE-2026-9753MongoDB8.1The $_internalApplyOplogUpdate aggregation pipeline stage can be used to execute a document diff containing a malformed …Jun 9
CVE-2026-44168Mariadb8.0MariaDB server is a community developed fork of MySQL server. From versions 10.6.1 to before 10.6.26, 10.11.1 to before …Jun 12
CVE-2026-46332Linux8.0In the Linux kernel, the following vulnerability has been resolved: greybus: gb-beagleplay: bound bootloader receive bu…Jun 9
CVE-2026-48165Mariadb8.0MariaDB server is a community developed fork of MySQL server. From versions 10.6.1 to before 10.6.27, 10.11.1 to before …Jun 12
CVE-2026-48163Mariadb8.0MariaDB server is a community developed fork of MySQL server. From versions 10.6.1 to before 10.6.27, 10.11.1 to before …Jun 12
CVE-2026-46301Linux7.8In the Linux kernel, the following vulnerability has been resolved: spi: topcliff-pch: fix use-after-free on unbind Gi…Jun 8
CVE-2026-46275Linux7.8In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_uart: fix UAFs and race conditions i…Jun 8
CVE-2026-46294Linux7.8In the Linux kernel, the following vulnerability has been resolved: dm: fix a buffer overflow in ioctl processing Tony…Jun 8
CVE-2026-46274Linux7.8In the Linux kernel, the following vulnerability has been resolved: io-wq: check that the predecessor is hashed in io_w…Jun 8
CVE-2026-52907Linux7.8In the Linux kernel, the following vulnerability has been resolved: media: rockchip: rkcif: fix off by one bugs Change…Jun 9
CVE-2026-46330Linux7.8In the Linux kernel, the following vulnerability has been resolved: Revert "net/smc: Introduce TCP ULP support" This r…Jun 9
CVE-2026-46285Linux7.8In the Linux kernel, the following vulnerability has been resolved: mtd: docg3: fix use-after-free in docg3_release() …Jun 8
CVE-2026-46327Linux7.8In the Linux kernel, the following vulnerability has been resolved: dm: fix unlocked test for dm_suspended_md The func…Jun 9
CVE-2026-46281Linux7.8In the Linux kernel, the following vulnerability has been resolved: vmalloc: fix buffer overflow in vrealloc_node_align…Jun 8
CVE-2026-46280Linux7.8In the Linux kernel, the following vulnerability has been resolved: lib: test_hmm: evict device pages on file close to …Jun 8
CVE-2026-46279Linux7.8In the Linux kernel, the following vulnerability has been resolved: mm/alloc_tag: clear codetag for pages allocated bef…Jun 8
CVE-2026-46277Linux7.8In the Linux kernel, the following vulnerability has been resolved: mm/zone_device: do not touch device folio after cal…Jun 8
CVE-2026-46324Linux7.8In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: use list_del_rcu for netlink …Jun 9
CVE-2026-46323Linux7.8In the Linux kernel, the following vulnerability has been resolved: net: gro: don't merge zcopy skbs skb_gro_receive()…Jun 9
CVE-2026-46319Linux7.8In the Linux kernel, the following vulnerability has been resolved: net/sched: act_ct: Only release RCU read lock after…Jun 9
CVE-2025-31272macOS7.8The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.4. An app may be able to bypass la…Jun 11
CVE-2026-46311Linux7.8In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/userq: fix access to stale wptr mapping …Jun 8
CVE-2026-46308Linux7.8In the Linux kernel, the following vulnerability has been resolved: pmdomain: mediatek: fix use-after-free in scpsys_ge…Jun 8
CVE-2026-52906Linux7.7In the Linux kernel, the following vulnerability has been resolved: 9p: fix access mode flags being ORed instead of rep…Jun 9
CVE-2026-46304Linux7.5In the Linux kernel, the following vulnerability has been resolved: nvmet: avoid recursive nvmet-wq flush in nvmet_ctrl…Jun 8
CVE-2025-46315macOS7.5A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Tahoe 26.1. An app may be a…Jun 11
CVE-2026-46306Linux7.5In the Linux kernel, the following vulnerability has been resolved: flow_dissector: do not dissect PPPoE PFC frames RF…Jun 8
CVE-2026-49975nginx7.5Memory Allocation with Excessive Size Value vulnerability in Apache HTTP Server's mod_http leads to denial of service vi…Jun 8
CVE-2026-9740MongoDB7.5A vulnerability in MongoDB Server's BSON validation logic allows an unauthenticated user to crash the mongod process by …Jun 9
CVE-2026-9742MongoDB7.5When OIDC authentication is enabled in configuration, clients may set specific values in the "mechanism" parameter of th…Jun 9
CVE-2026-46320Linux7.4In the Linux kernel, the following vulnerability has been resolved: tap: free page on error paths in tap_get_user_xdp()…Jun 9
CVE-2026-46328Linux7.3In the Linux kernel, the following vulnerability has been resolved: apparmor: fix rlimit for posix cpu timers Posix cp…Jun 9
CVE-2026-46322Linux7.1In the Linux kernel, the following vulnerability has been resolved: tun: free page on build_skb failure in tun_xdp_one(…Jun 9
CVE-2022-26758macOS7.1A malicious application may cause unexpected changes in memory shared between processes. A memory corruption issue was a…Jun 10
CVE-2026-46293Linux7.1In the Linux kernel, the following vulnerability has been resolved: clk: microchip: mpfs-ccc: fix out of bounds access …Jun 8
CVE-2026-46321Linux7.1In the Linux kernel, the following vulnerability has been resolved: tun: free page on short-frame rejection in tun_xdp_…Jun 9
CVE-2026-46299Linux7.0In the Linux kernel, the following vulnerability has been resolved: hfsplus: fix held lock freed on hfsplus_fill_super(…Jun 8
CVE-2026-54230Fedora7.0A symlink following vulnerability was found in the ABRT post-create event handler scripts in libreport. Event scripts wr…Jun 13
CVE-2026-46309Linux7.0In the Linux kernel, the following vulnerability has been resolved: drm/xe/uapi: Reject coh_none PAT index for CPU cach…Jun 8

🟡 Medium CVEs (15)

CVEProductCVSSKEVDescriptionPublished
CVE-2026-9741MongoDB6.5A bug in query analysis processing of the $vectorSearch aggregation stage for Queryable Encryption (QE) or Client-Side F…Jun 9
CVE-2026-9752MongoDB6.5An authorized user could trigger a server crash by running a query with a 2dsphere index on a field that stores a GeoJSO…Jun 9
CVE-2026-9750MongoDB6.5An authenticated user can cause a MongoDB server to crash or return incorrect results by creating documents that interfe…Jun 9
CVE-2026-9749MongoDB6.5This issue can occur when running an aggregation pipeline that uses the internal $exchange stage configured with key-ran…Jun 9
CVE-2026-9748MongoDB6.5The $_internalConvertBucketIndexStats stage used PauseExecution as a way to signal "skip this document" when an index st…Jun 9
CVE-2026-9754MongoDB6.5An authenticated user with the read role may read limited amounts of uninitialized stack memory via specially-crafted is…Jun 9
CVE-2026-9747MongoDB6.5Adding fromRouter:true and runtimeConstants.userRoles could cause aggregations to crash mongodb server.Jun 9
CVE-2026-9743MongoDB6.5In MongoDB Server 8.0, an aggregation stage can leave its _subPipeline field null during processing of certain pipelines…Jun 9
CVE-2026-9746MongoDB6.5When using $changestreams and $_requestReshardingResumeToken with the exchange option the server hits an invariant which…Jun 9
CVE-2026-44171Mariadb6.3MariaDB server is a community developed fork of MySQL server. From versions 10.6.1 to before 10.6.26, 10.11.1 to before …Jun 12
CVE-2025-71315Linux5.5In the Linux kernel, the following vulnerability has been resolved: drm/vkms: Convert to DRM's vblank timer Replace vk…Jun 8
CVE-2026-54231Fedora5.5A content injection vulnerability was found in the ABRT post-create event handler scripts in libreport. The event script…Jun 13
CVE-2025-46293macOS5.5This issue was addressed with improved handling of symlinks. This issue is fixed in macOS Sequoia 15.4. An app may be ab…Jun 11
CVE-2025-43339macOS5.5An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Tahoe 26.1. A malicious…Jun 11
CVE-2025-30459macOS5.5A privacy issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sequoia 15.4. An app may be …Jun 11

📦 Most affected products