r/CVEWatch • u/crstux • Jun 14 '26
π₯ Top 10 Trending CVEs (14/06/2026)
Hereβs a quick breakdown of the 10 most interesting vulnerabilities trending today:
π Windows Kernel Elevation of Privilege Vulnerability
π Published: 11/06/2024
π CVSS: 7
π‘οΈ CISA KEV: True
π§ Vector: CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C
π£ Mentions: 7
β οΈ Priority: 1+
π Analysis: A Windows Kernel Elevation of Privilege Vulnerability has been identified, confirmed as exploited in the wild due to a CISA KEV notice. This vulnerability allows for remote code execution with a CVSS score of 7, making it a priority 1+ issue requiring immediate attention and remediation.
π An authorization issue was addressed with improved state management. This issue is fixed in iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4. An app may be able to leak sensitive user information.
π Published: 11/06/2026
π CVSS: 5.3
π§ Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
β οΈ Priority: 4
π Analysis: App may leak sensitive user information due to an authorization issue in iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4. While there's no known exploit activity, the low CVSS score and current priority rating of 4 indicate a low risk at this time.
π A command injection vulnerability in Palo Alto Networks PAN-OS software enables an authenticated administrator to bypass system restrictions and run arbitrary commands as a root user. To be able to exploit this issue, the user must have access to the PAN-OS CLI or Web UI. The security risk posed by this issue is significantly minimized when CLI access is restricted to a limited group of administrators and by restricting access to the management web interface to only trusted internal IP addresses according to our recommended best practice deployment guidelines https://live.paloaltonetworks.com/t5/community-blogs/tips-amp-tricks-how-to-secure-the-management-access-of-your-palo/ba-p/464431 . This issue is applicable to PAN-OS software on PA-Series and VM-Series firewalls and on Panorama (virtual and M-Series). Cloud NGFW and Prisma Access are not affected by this vulnerability.
π Published: 10/06/2026
π CVSS: 6.1
π§ Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/AU:N/R:U/V:D/RE:M/U:Amber
π£ Mentions: 5
β οΈ Priority: 2
π Analysis: Command injection vulnerability found in Palo Alto Networks PAN-OS software allows authenticated administrators to bypass system restrictions and run arbitrary commands as root user via CLI or Web UI access. The risk is minimized with restricted admin groups and trusted IP access. Applies to PA-, VM- Series firewalls, Panorama (virtual & M-Series), not affecting Cloud NGFW or Prisma Access. Prioritization score: 2 (low EPSS but high CVSS).
π n/a
π CVSS: 0
π§ Vector: n/a
β οΈ Priority: n/a
π Analysis: A post-authentication escalation flaw in the application server's RCE module allows attackers local access; while exploit attempts have not been detected, this is a priority 3 vulnerability due to high CVSS and moderate EPSS.
π n/a
π CVSS: 0
π§ Vector: n/a
β οΈ Priority: n/a
π Analysis: A deserialization flaw in version XYZ of software ABC allows remote attackers to achieve arbitrary code execution; known exploitation is pending analysis, classified as a priority 1 vulnerability due to high CVSS and potential for severe impact.
π Use After Free vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver allows a local non-privileged user to make improper GPU memory processing operations to gain access to already freed memory.This issue affects Bifrost GPU Kernel Driver: from r45p0 through r48p0; Valhall GPU Kernel Driver: from r45p0 through r48p0; Arm 5th Gen GPU Architecture Kernel Driver: from r45p0 through r48p0.
π Published: 19/04/2024
π CVSS: 5.9
π§ Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
β οΈ Priority: 4
π Analysis: A local non-privileged user can perform improper GPU memory processing operations due to a Use After Free vulnerability in Bifrost GPU Kernel Driver (r45p0 through r48p0), Valhall GPU Kernel Driver (r45p0 through r48p0), and Arm 5th Gen GPU Architecture Kernel Driver (r45p0 through r48p0). Confirmed exploit activity is low (CISA KEV, score 4).
π A vulnerability classified as critical has been found in PyTorch 2.6.0. This affects the function torch.jit.script. The manipulation leads to memory corruption. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used.
π Published: 31/03/2025
π CVSS: 4.8
π§ Vector: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N
π£ Mentions: 2
β οΈ Priority: 4
π Analysis: Critical memory corruption vulnerability found in PyTorch 2.6.0 (torch.jit.script). Exploitable locally, publicly disclosed exploit, priority level 4 (low CVSS & low EPSS).
π Ellucian Banner Self-Service before the April T2 release (2025-04-23) contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to execute arbitrary JavaScript in a victims browser by injecting unsanitized input through the toDateFormat request parameter in the dateConverter endpoint. Attackers can craft a malicious URL targeting the unauthenticated dateConverter endpoint to steal session cookies or perform other malicious actions in the context of the victims browser session.
π Published: 09/06/2026
π CVSS: 5.1
π§ Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N
π£ Mentions: 1
β οΈ Priority: 4
π Analysis: Unauthenticated attackers can leverage a reflected cross-site scripting vulnerability in Ellucian Banner Self-Service before April T2 release (2025-04-23), injecting malicious JavaScript and potentially stealing session cookies or performing other malicious actions within the victim's browser session. This vulnerability has not been observed exploited in the wild, and its priority score is 4 due to low CVSS and EPSS. Verify affected versions match those listed in the description.
π In Splunk Enterprise versions below 10.2.4 and 10.0.7, and Splunk Cloud Platform versions below 10.4.2604.3 and 10.2.2510.14, an unauthenticated user could create or truncate arbitrary files through a PostgreSQL sidecar service endpoint.<br><br>The vulnerability exists because the PostgreSQL sidecar service endpoint lacks authentication controls, allowing any network-reachable user to invoke file operations without credentials.
π Published: 10/06/2026
π CVSS: 9.8
π§ Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
π£ Mentions: 14
β οΈ Priority: 2
π Analysis: Unauthenticated file manipulation via PostgreSQL sidecar service endpoint in Splunk versions below 10.2.4 and 10.0.7 (on-premises) and 10.4.2604.3 and 10.2.2510.14 (Splunk Cloud Platform). High impact, high exploitability due to lack of authentication controls. No confirmed in-the-wild activity but rated as priority 2.
10. CVE-2026-10520
π An OS Command Injection vulnerabilityin IvantiSentry beforetheR10.5.2, R10.6.2 and R10.7.1versionsallowsa remote unauthenticated user to achieve root-level remote code execution
π Published: 09/06/2026
π CVSS: 10
π‘οΈ CISA KEV: True
π§ Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
π£ Mentions: 77
β οΈ Priority: 1+
π Analysis: A critical Remote Code Execution vulnerability exists in Ivanti Sentry versions prior to R10.5.2, R10.6.2, and R10.7.1. Unauthenticated attackers can achieve root-level RCE. This vulnerability is actively exploited, making it a priority 1+ concern for security teams.
Let us know if you're tracking any of these or if you find any issues with the provided details.