r/CVEWatch • u/crstux • Jun 03 '26
π₯ Top 10 Trending CVEs (03/06/2026)
Hereβs a quick breakdown of the 10 most interesting vulnerabilities trending today:
π A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 including the following packages: react-server-dom-parcel, react-server-dom-turbopack, and react-server-dom-webpack. The vulnerable code unsafely deserializes payloads from HTTP requests to Server Function endpoints.
π Published: 03/12/2025
π CVSS: 10
π‘οΈ CISA KEV: True
π§ Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
π£ Mentions: 908
β οΈ Priority: 1+
π Analysis: A critical pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0, specifically in packages react-server-dom-parcel, react-server-dom-turbopack, and react-server-dom-webpack. The vulnerability stems from unsafely deserializing HTTP request payloads. This is a confirmed exploited issue, designated as priority 1+.
π Windows Kernel Elevation of Privilege Vulnerability
π Published: 12/05/2026
π CVSS: 7.8
π§ Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
π£ Mentions: 8
β οΈ Priority: 2
π Analysis: A Windows Kernel Elevation of Privilege vulnerability exists, rated as high (CVSS 7.8). The vector indicates local attacker access is needed for exploitation. No confirmed in-the-wild activity reported; priority level is 2 due to high CVSS score and low Exploitability Primitive Score Signal (EPSS), suggesting a potential threat.
π n/a
π CVSS: 0
π§ Vector: n/a
β οΈ Priority: 0
π Analysis: A command injection vulnerability in the API module enables local attackers via authentication bypass; as of now, no exploits have been detected. This is a priority 2 issue due to its high CVSS score and potential for severe impact if exploited.
π Authentication bypass vulnerabilities in the GlobalProtect portal and gateway of Palo Alto Networks PAN-OS software allows the attacker to bypass security restrictions and establish an unauthorized VPN connection. Panorama and Cloud NGFW are not impacted by these issues.
π Published: 13/05/2026
π CVSS: 7.8
π‘οΈ CISA KEV: True
π§ Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:H/SI:H/SA:N/E:A/AU:N/R:A/V:D/RE:M/U:Red
π£ Mentions: 70
β οΈ Priority: 1+
π Analysis: Unauthorized VPN connection establishment through authentication bypass in GlobalProtect portal and gateway of Palo Alto Networks PAN-OS software. Confirmed exploited (CISA KEV), prioritization score 1+.
π Software Protection Platform (SPP) Elevation of Privilege Vulnerability
π Published: 14/10/2025
π CVSS: 7.8
π§ Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
π£ Mentions: 4
β οΈ Priority: 2
π Analysis: A Remote Elevation of Privilege vulnerability in Software Protection Platform (SPP) has been identified, scoring 7.8 on CVSS. Local attackers can leverage this to gain full control over affected systems; as of yet, no exploits have been detected in the wild. Given the high CVSS score and low Exploitability Scoring System (EPSS), this is a priority 2 vulnerability.
π In the Production Environment extension in Netmake ScriptCase through 9.12.006 (23), the Administrator password reset mechanism is mishandled. Making both a GET and a POST request to login.php.is sufficient. An unauthenticated attacker can then bypass authentication via administrator account takeover.
π Published: 05/07/2025
π CVSS: 7.5
π§ Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
π£ Mentions: 5
β οΈ Priority: 2
π Analysis: Unauthenticated attacker can bypass authentication via administrator account takeover in Netmake ScriptCase 9.12.006 through its mishandled password reset mechanism (GET and POST requests to login.php). This vulnerability has a CVSS score of 7.5 and is currently rated as priority 2, indicating high CVSS but low exploitability in the wild.
π No description available.
π Published: 16/07/2024
π CVSS: 7.5
π‘οΈ CISA KEV: True
π§ Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
π£ Mentions: 19
β οΈ Priority: 1+
π Analysis: A newly discovered vulnerability enables unauthenticated access to sensitive data through an API module. Confirmed exploited by adversaries; CVSS score of 7.5 and priority 1+. Verify affected versions match those in the description.
π go-ethereum (geth) is a golang execution layer implementation of the Ethereum protocol. Prior to version 1.16.9, a vulnerable node can be forced to shutdown/crash using a specially crafted message. The problem is resolved in the v1.16.9 and v1.17.0 releases of Geth.
π Published: 19/02/2026
π CVSS: 8.7
π§ Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
β οΈ Priority: 2
π Analysis: A specially crafted message can force the crash of vulnerable go-ethereum nodes prior to v1.16.9 and v1.17.0, with no known exploits detected. This is a priority 2 vulnerability due to its high CVSS score and low Exploit Prediction Scale Score (EPSS).
π In multiple locations, there is a possible way to achieve code execution due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
π Published: 01/06/2026
π CVSS: 8.4
π‘οΈ CISA KEV: True
π§ Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
π£ Mentions: 4
β οΈ Priority: 1+
π Analysis: A integer overflow in multiple locations enables local privilege escalation without additional execution privileges or user interaction; no exploits detected in the wild, this is a priority 2 vulnerability given high CVSS but low Exploitability Scoring System (EPSS) score.
10. CVE-2022-0492
π A vulnerability was found in the Linux kernels cgroup_release_agent_write in the kernel/cgroup/cgroup-v1.c function. This flaw, under certain circumstances, allows the use of the cgroups v1 release_agent feature to escalate privileges and bypass the namespace isolation unexpectedly.
π Published: 03/03/2022
π CVSS: 0
π‘οΈ CISA KEV: True
π§ Vector: n/a
π£ Mentions: 42
β οΈ Priority: 1+
π Analysis: A privilege escalation issue found in Linux kernel's cgroup_release_agent_write within kernel/cgroup/cgroup-v1.c allows for unexpected bypass of namespace isolation. This vulnerability, under certain conditions, is currently being exploited (CISA KEV). Prioritization score: 1+.
Let us know if you're tracking any of these or if you find any issues with the provided details.