vulnfeed weekly: 10645 CVEs · 675 critical — 2026-06-21
vulnfeed
Weekly digest — 2026-06-21
TL;DR — 10,056 CVEs tracked this week — 675 critical. Notable: CVE-2025-21298 (Windows OLE Remote Code Execution Vulnerability, CVSS 9.8); CVE-2024-38077 (Windows Remote Desktop Licensing Service Remote Code Executi, CVSS 9.8); CVE-2024-12084 (rsync due to improper checksum length handling, CVSS 9.8).
Must-patch this week
CVE-2024-38077CRITICAL
Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability
CVSS 9.8 · EPSS 75.4%
CVE-2024-12084CRITICAL
Rsync: heap buffer overflow in rsync due to improper checksum length handling
CVSS 9.8 · EPSS 71.9%
CVE-2024-49112CRITICAL
Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
CVSS 9.8 · EPSS 70.9%
CVE-2025-32463CRITICAL
Sudo before 1.9.17p1 allows local users to obtain root access
CVSS 9.3 · EPSS 48.0%
Kubernetes — 1 CVE this week
CVE-2026-3865MEDIUM
CSI Driver for SMB path traversal via subDir may delete unintended directories on the SMB server
CVSS 6.5
OpenStack — 5 CVEs this week
OSS-20260616-5UNKNOWN
[OSSA-2026-022] OpenStack Nova: Nova scheduler hint injection
bypasses Placement resource claims and scheduli
CVE-2026-54421UNKNOWN
[OSSA-2026-023] Ironic: Sensitive properties returned unredacted in
POST and PATCH HTTP responses (CVE-2026-5
EPSS 0.3%
CVE-2026-46447UNKNOWN
[OSSA-2026-017] Errata 1: Ironic: Script injection during node boot
via linux command line override (CVE-2026
EPSS 0.3%
CVE-2026-46448UNKNOWN
OSSA-2026-022: Nova scheduler hint injection bypasses Placement resource claims and scheduling constraints
EPSS 0.3%
Linux Kernel — 5 CVEs this week
USN-8390-2UNKNOWN
USN-8390-2: Linux kernel vulnerability
USN-8441-1UNKNOWN
USN-8441-1: Linux kernel vulnerabilities
USN-8361-3UNKNOWN
USN-8361-3: Linux kernel vulnerability
USN-8440-1UNKNOWN
USN-8440-1: Linux kernel (Azure) vulnerabilities
USN-8426-2UNKNOWN
USN-8426-2: Linux kernel (Azure) vulnerabilities
nginx / Traefik — 5 CVEs this week
CVE-2026-45552CRITICAL
Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and
CVSS 9.9
CVE-2026-45556CRITICAL
Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and
CVSS 9.9
CVE-2026-45558CRITICAL
Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and
CVSS 9.9
CVE-2026-42055CRITICAL
NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_proxy_v2_module and ngx_http_grpc_module
CVSS 9.2 · EPSS 0.6%
CVE-2026-45550CRITICAL
Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and
CVSS 9.1
vulnfeed weekly digest.
Unsubscribe
Don't miss what's next. Subscribe to Vulnfeed: