vulnfeed weekly: 9582 CVEs · 617 critical — 2026-06-18
vulnfeed
Weekly digest — 2026-06-18
TL;DR — 9,114 CVEs tracked this week — 617 critical. Notable: CVE-2026-48567 (Azure HorizonDB Elevation of Privilege Vulnerability, CVSS 10.0); CVE-2026-40175 (Axios has Unrestricted Cloud Metadata Exfiltration, CVSS 10.0); CVE-2017-20230 (Storable versions before 3.05 for Perl has a stack overflow, CVSS 10.0).
Must-patch this week
CVE-2026-40175CRITICAL
Axios has Unrestricted Cloud Metadata Exfiltration via Header Injection Chain
CVSS 10.0
Kubernetes — 1 CVE this week
CVE-2026-3865MEDIUM
CSI Driver for SMB path traversal via subDir may delete unintended directories on the SMB server
CVSS 6.5
OpenStack — 5 CVEs this week
OSS-20260616-5UNKNOWN
[OSSA-2026-022] OpenStack Nova: Nova scheduler hint injection
bypasses Placement resource claims and scheduli
CVE-2026-54421UNKNOWN
[OSSA-2026-023] Ironic: Sensitive properties returned unredacted in
POST and PATCH HTTP responses (CVE-2026-5
CVE-2026-43003UNKNOWN
[OSSN-0100] Ironic: Command Injection in IPA (CVE-2026-43003)
CVE-2026-46447UNKNOWN
[OSSA-2026-017] Errata 1: Ironic: Script injection during node boot
via linux command line override (CVE-2026
CVE-2026-50266UNKNOWN
OSSA-2026-021: Neutron port RBAC policy bypass allows project managers to set trusted device owners on shared
Linux Kernel — 5 CVEs this week
USN-8390-2UNKNOWN
USN-8390-2: Linux kernel vulnerability
USN-8441-1UNKNOWN
USN-8441-1: Linux kernel vulnerabilities
USN-8361-3UNKNOWN
USN-8361-3: Linux kernel vulnerability
USN-8440-1UNKNOWN
USN-8440-1: Linux kernel (Azure) vulnerabilities
USN-8426-2UNKNOWN
USN-8426-2: Linux kernel (Azure) vulnerabilities
nginx / Traefik — 5 CVEs this week
CVE-2026-45552CRITICAL
Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and
CVSS 9.9
CVE-2026-45556CRITICAL
Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and
CVSS 9.9
CVE-2026-45558CRITICAL
Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and
CVSS 9.9
CVE-2026-42055CRITICAL
NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_proxy_v2_module and ngx_http_grpc_module
CVSS 9.2
CVE-2026-42530CRITICAL
NGINX Open Source has a vulnerability in the ngx_http_v3_module module. When NGINX Open Source is configured t
CVSS 9.2
vulnfeed weekly digest.
Unsubscribe
Don't miss what's next. Subscribe to Vulnfeed: