{
  "day": "2026-06-06",
  "boundary": "UTC calendar day",
  "published_count": 39,
  "by_severity": {
    "CRITICAL": 0,
    "HIGH": 7,
    "MEDIUM": 26,
    "LOW": 6
  },
  "kev_count": 0,
  "exploit_reference_count": 0,
  "awaiting_enrichment_count": 0,
  "ranking": "Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.",
  "results": [
    {
      "rank": 1,
      "cve_id": "CVE-2026-7665",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.07236,
      "epss_percentile": 0.93817,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wpdevteam",
      "product": "Essential Addons for Elementor – Popular Elementor Templates & Widgets",
      "cwe": "CWE-639",
      "title": "Essential Addons for Elementor <= 6.6.4 - Missing Authorization to Unauthenticated Information Exposure via 'load_more' AJAX Handler",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-7665"
    },
    {
      "rank": 2,
      "cve_id": "CVE-2026-11406",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.0123,
      "epss_percentile": 0.66532,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GL.iNet",
      "product": "MT3000",
      "cwe": "CWE-74",
      "title": "GL.iNet MT3000 OpenVPN Client Import Workflow ovpnclient.sh command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11406"
    },
    {
      "rank": 3,
      "cve_id": "CVE-2026-11408",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.01114,
      "epss_percentile": 0.6343,
      "kev": false,
      "kev_due_at": null,
      "vendor": "vertex-app",
      "product": "vertex",
      "cwe": "CWE-77",
      "title": "vertex-app vertex Log Viewer Endpoint LogMod.js os command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11408"
    },
    {
      "rank": 4,
      "cve_id": "CVE-2026-8839",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.01018,
      "epss_percentile": 0.60619,
      "kev": false,
      "kev_due_at": null,
      "vendor": "chrisvrichardson",
      "product": "MapPress Maps for WordPress",
      "cwe": "CWE-639",
      "title": "MapPress Maps for WordPress <= 2.96.6 - Unauthenticated Insecure Direct Object Reference via REST API Endpoints",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8839"
    },
    {
      "rank": 5,
      "cve_id": "CVE-2026-7537",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00659,
      "epss_percentile": 0.48785,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mdjm",
      "product": "MDJM Event Management",
      "cwe": "CWE-434",
      "title": "MDJM Event Management <= 1.7.8.3 - Authenticated (Administrator+) Arbitrary File Upload via 'mdjm_email_upload_file' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-7537"
    },
    {
      "rank": 6,
      "cve_id": "CVE-2026-7565",
      "cvss_base": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00646,
      "epss_percentile": 0.48206,
      "kev": false,
      "kev_due_at": null,
      "vendor": "thimpress",
      "product": "LearnPress – Backup & Migration Tool",
      "cwe": "CWE-22",
      "title": "LearnPress <= 4.1.4 - Authenticated (Administrator+) Path Traversal to Arbitrary File Read via 'import-user-file' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-7565"
    },
    {
      "rank": 7,
      "cve_id": "CVE-2026-9197",
      "cvss_base": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00601,
      "epss_percentile": 0.46128,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nextendweb",
      "product": "Smart Slider 3",
      "cwe": "CWE-22",
      "title": "Smart Slider 3 <= 3.5.1.36 - Authenticated (Administrator+) Path Traversal to Arbitrary File Read via 'src'/'srcset' Attribute in HTML Export",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9197"
    },
    {
      "rank": 8,
      "cve_id": "CVE-2026-8502",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00527,
      "epss_percentile": 0.42427,
      "kev": false,
      "kev_due_at": null,
      "vendor": "thimpress",
      "product": "LearnPress – WordPress LMS Plugin for Create and Sell Online Courses",
      "cwe": "CWE-862",
      "title": "LearnPress <= 4.3.6 - Unauthenticated Sensitive Information Exposure via 'c_status' and 'return_type' Parameters",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8502"
    },
    {
      "rank": 9,
      "cve_id": "CVE-2026-8438",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00486,
      "epss_percentile": 0.3991,
      "kev": false,
      "kev_due_at": null,
      "vendor": "davidanderson",
      "product": "All-In-One Security (AIOS) – Security and Firewall",
      "cwe": "CWE-79",
      "title": "All-In-One Security (AIOS) <= 5.4.7 - Unauthenticated Stored Cross-Site Scripting via REST API Request Path",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8438"
    },
    {
      "rank": 10,
      "cve_id": "CVE-2026-11413",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00481,
      "epss_percentile": 0.39579,
      "kev": false,
      "kev_due_at": null,
      "vendor": "JingDong",
      "product": "JD Cloud Box AX6600",
      "cwe": "CWE-119",
      "title": "JingDong JD Cloud Box AX6600 jdcweb_rpc set_macfilter stack-based overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11413"
    },
    {
      "rank": 11,
      "cve_id": "CVE-2026-9829",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00468,
      "epss_percentile": 0.38768,
      "kev": false,
      "kev_due_at": null,
      "vendor": "10web",
      "product": "Photo Gallery by 10Web – Mobile-Friendly Image Gallery",
      "cwe": "CWE-89",
      "title": "Photo Gallery by 10Web <= 1.8.41 - Authenticated (Contributor+) SQL Injection via 'compact_album_order_by' Shortcode Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9829"
    },
    {
      "rank": 12,
      "cve_id": "CVE-2026-7566",
      "cvss_base": 6.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0045,
      "epss_percentile": 0.37577,
      "kev": false,
      "kev_due_at": null,
      "vendor": "thimpress",
      "product": "LearnPress – Backup & Migration Tool",
      "cwe": "CWE-502",
      "title": "LearnPress – Backup & Migration Tool <= 4.1.4 - Authenticated (Administrator+) PHP Object Injection via WXR XML File Upload",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-7566"
    },
    {
      "rank": 13,
      "cve_id": "CVE-2026-10725",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00414,
      "epss_percentile": 0.34717,
      "kev": false,
      "kev_due_at": null,
      "vendor": "CRUX",
      "product": "Protocol::HTTP2",
      "cwe": "CWE-409",
      "title": "Protocol::HTTP2 versions before 1.13 for Perl is vulnerable to a HTTP/2 Bomb",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10725"
    },
    {
      "rank": 14,
      "cve_id": "CVE-2026-11437",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00409,
      "epss_percentile": 0.34236,
      "kev": false,
      "kev_due_at": null,
      "vendor": "perfree",
      "product": "go-fastdfs-web",
      "cwe": "CWE-918",
      "title": "perfree go-fastdfs-web Installation Endpoint checkServer server-side request forgery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11437"
    },
    {
      "rank": 15,
      "cve_id": "CVE-2026-7795",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00407,
      "epss_percentile": 0.34093,
      "kev": false,
      "kev_due_at": null,
      "vendor": "holithemes",
      "product": "Click to Chat – HoliThemes",
      "cwe": "CWE-79",
      "title": "Click to Chat <= 4.39 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'num' Shortcode Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-7795"
    },
    {
      "rank": 16,
      "cve_id": "CVE-2026-9280",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0036,
      "epss_percentile": 0.29262,
      "kev": false,
      "kev_due_at": null,
      "vendor": "spacetime",
      "product": "Ad Inserter – Ad Manager & AdSense Ads",
      "cwe": "CWE-79",
      "title": "Ad Inserter <= 2.8.15 - Reflected Cross-Site Scripting via URL Parameters in iframe Mode",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9280"
    },
    {
      "rank": 17,
      "cve_id": "CVE-2026-9851",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00358,
      "epss_percentile": 0.29064,
      "kev": false,
      "kev_due_at": null,
      "vendor": "masaakitanaka",
      "product": "Booking Package",
      "cwe": "CWE-639",
      "title": "Booking Package <= 1.7.16 - Authenticated (Editor+) Privilege Escalation via Account Takeover to updateUser AJAX Action",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9851"
    },
    {
      "rank": 18,
      "cve_id": "CVE-2026-7796",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00331,
      "epss_percentile": 0.26133,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wpdevteam",
      "product": "EmbedPress – PDF Embedder, Embed PDF viewer, YouTube Videos, 3D FlipBook, Social feeds & more",
      "cwe": "CWE-79",
      "title": "EmbedPress <= 4.5.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Block 'url' Attribute",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-7796"
    },
    {
      "rank": 19,
      "cve_id": "CVE-2026-2500",
      "cvss_base": 4.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00315,
      "epss_percentile": 0.24352,
      "kev": false,
      "kev_due_at": null,
      "vendor": "davidfcarr",
      "product": "Quick Playground",
      "cwe": "CWE-22",
      "title": "Quick Playground <= 1.3.4 - Authenticated (Administrator+) Arbitrary File Read via 'filename' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-2500"
    },
    {
      "rank": 20,
      "cve_id": "CVE-2026-8901",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00314,
      "epss_percentile": 0.24187,
      "kev": false,
      "kev_due_at": null,
      "vendor": "plugcrux",
      "product": "Integration for Freshsales – Contact Form 7, WPForms, Elementor, Gravity Forms and More",
      "cwe": "CWE-79",
      "title": "Integration for Freshsales <= 1.0.15 - Unauthenticated Stored Cross-Site Scripting via Form Submission Data",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8901"
    },
    {
      "rank": 21,
      "cve_id": "CVE-2026-8991",
      "cvss_base": 4.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00312,
      "epss_percentile": 0.23976,
      "kev": false,
      "kev_due_at": null,
      "vendor": "glenwpcoder",
      "product": "Drag and Drop Multiple File Upload for Contact Form 7",
      "cwe": "CWE-79",
      "title": "Drag and Drop Multiple File Upload for Contact Form 7 <= 1.3.9.7 - Authenticated (Administrator+) Stored Cross-Site Scripting via 'drag_n_drop_text' and 'drag_n_drop_browse_text' Settings",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8991"
    },
    {
      "rank": 22,
      "cve_id": "CVE-2026-7792",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00301,
      "epss_percentile": 0.22787,
      "kev": false,
      "kev_due_at": null,
      "vendor": "smub",
      "product": "WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More",
      "cwe": "CWE-345",
      "title": "WPForms <= 1.10.0.4 - Unauthenticated Insufficient Verification of Data Authenticity via PayPal Commerce Webhook Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-7792"
    },
    {
      "rank": 23,
      "cve_id": "CVE-2026-7624",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00296,
      "epss_percentile": 0.22255,
      "kev": false,
      "kev_due_at": null,
      "vendor": "cifi",
      "product": "SEO Plugin by Squirrly SEO",
      "cwe": "CWE-862",
      "title": "SEO Plugin by Squirrly SEO <= 12.4.16 - Missing Authorization to Authenticated (Contributor+) Privileged Cloud API Operations",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-7624"
    },
    {
      "rank": 24,
      "cve_id": "CVE-2026-9594",
      "cvss_base": 4.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00294,
      "epss_percentile": 0.2197,
      "kev": false,
      "kev_due_at": null,
      "vendor": "flippercode",
      "product": "WP Maps – Google Maps,OpenStreetMap,Mapbox,Store Locator,Listing,Directory & Filters",
      "cwe": "CWE-79",
      "title": "WP Maps <= 4.9.4 - Authenticated (Admin+) Stored Cross-Site Scripting via 'location_messages' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9594"
    },
    {
      "rank": 25,
      "cve_id": "CVE-2026-11434",
      "cvss_base": 1.9,
      "cvss_severity": "LOW",
      "epss_score": 0.00275,
      "epss_percentile": 0.19921,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "FluentCMS",
      "cwe": "CWE-79",
      "title": "FluentCMS Blocks Plugin blocks cross site scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11434"
    },
    {
      "rank": 26,
      "cve_id": "CVE-2026-11436",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00263,
      "epss_percentile": 0.18344,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "Mage AI",
      "cwe": "CWE-79",
      "title": "Mage AI Sign-in Flow index.tsx useMutation cross site scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11436"
    },
    {
      "rank": 27,
      "cve_id": "CVE-2026-9016",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00261,
      "epss_percentile": 0.18038,
      "kev": false,
      "kev_due_at": null,
      "vendor": "qriouslad",
      "product": "Debug Log Manager – Conveniently Monitor and Inspect Errors",
      "cwe": "CWE-117",
      "title": "Debug Log Manager <= 2.5.0 - Unauthenticated Improper Output Neutralization for Logs via log_js_errors AJAX Action",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9016"
    },
    {
      "rank": 28,
      "cve_id": "CVE-2026-11435",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00259,
      "epss_percentile": 0.17811,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Jinher",
      "product": "OA",
      "cwe": "CWE-74",
      "title": "Jinher OA nextselectplan.aspx sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11435"
    },
    {
      "rank": 29,
      "cve_id": "CVE-2026-8978",
      "cvss_base": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00259,
      "epss_percentile": 0.1775,
      "kev": false,
      "kev_due_at": null,
      "vendor": "crafium",
      "product": "OptinCraft – Drag & Drop Optins & Popup Builder for WordPress",
      "cwe": "CWE-89",
      "title": "OptinCraft <= 1.2.0 - Authenticated (Administrator+) SQL Injection via 'order_by' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8978"
    },
    {
      "rank": 30,
      "cve_id": "CVE-2026-8611",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00234,
      "epss_percentile": 0.14531,
      "kev": false,
      "kev_due_at": null,
      "vendor": "klamra22",
      "product": "Klamra Paycal for Aspaclaria",
      "cwe": "CWE-639",
      "title": "Klamra Paycal for Aspaclaria <= 1.1.4 - Insecure Direct Object Reference to Authenticated (Subscriber+) Sensitive Information Exposure via 'invoice_id' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8611"
    },
    {
      "rank": 31,
      "cve_id": "CVE-2026-9008",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00224,
      "epss_percentile": 0.13262,
      "kev": false,
      "kev_due_at": null,
      "vendor": "webvitaly",
      "product": "Page-list",
      "cwe": "CWE-862",
      "title": "Page-list <= 6.2 - Missing Authorization to Authenticated (Contributor+) Sensitive Information Disclosure via Shortcode Attributes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9008"
    },
    {
      "rank": 32,
      "cve_id": "CVE-2026-9281",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00214,
      "epss_percentile": 0.12122,
      "kev": false,
      "kev_due_at": null,
      "vendor": "litonice13",
      "product": "Master Addons For Elementor – Widgets, Extensions, Theme Builder, Popup Builder & Template Kits",
      "cwe": "CWE-79",
      "title": "Master Addons For Elementor <= 3.1.0 - Authenticated (Author+) Stored Cross-Site Scripting via 'jtlma_custom_js' Page Setting (Custom JS Extension)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9281"
    },
    {
      "rank": 33,
      "cve_id": "CVE-2026-11438",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00214,
      "epss_percentile": 0.12017,
      "kev": false,
      "kev_due_at": null,
      "vendor": "theonedev",
      "product": "onedev",
      "cwe": "CWE-266",
      "title": "theonedev projects improper authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11438"
    },
    {
      "rank": 34,
      "cve_id": "CVE-2026-11439",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00214,
      "epss_percentile": 0.12018,
      "kev": false,
      "kev_due_at": null,
      "vendor": "theonedev",
      "product": "onedev",
      "cwe": "CWE-266",
      "title": "theonedev Parent Project projects improper authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11439"
    },
    {
      "rank": 35,
      "cve_id": "CVE-2026-11440",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00214,
      "epss_percentile": 0.12018,
      "kev": false,
      "kev_due_at": null,
      "vendor": "theonedev",
      "product": "onedev",
      "cwe": "CWE-266",
      "title": "theonedev REST API default-branch improper authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11440"
    },
    {
      "rank": 36,
      "cve_id": "CVE-2026-11441",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00214,
      "epss_percentile": 0.12017,
      "kev": false,
      "kev_due_at": null,
      "vendor": "theonedev",
      "product": "onedev",
      "cwe": "CWE-266",
      "title": "theonedev Pull Request issues canAccessIssue improper authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11441"
    },
    {
      "rank": 37,
      "cve_id": "CVE-2026-11412",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00196,
      "epss_percentile": 0.09747,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Jinher",
      "product": "OA",
      "cwe": "CWE-74",
      "title": "Jinher OA GetFormSn.aspx sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11412"
    },
    {
      "rank": 38,
      "cve_id": "CVE-2026-11411",
      "cvss_base": 1.9,
      "cvss_severity": "LOW",
      "epss_score": 0.00171,
      "epss_percentile": 0.06832,
      "kev": false,
      "kev_due_at": null,
      "vendor": "iAI Lab",
      "product": "PDF AI App",
      "cwe": "CWE-22",
      "title": "iAI Lab PDF AI App chatpdf.pro getExternalCacheDir path traversal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11411"
    },
    {
      "rank": 39,
      "cve_id": "CVE-2026-26422",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00164,
      "epss_percentile": 0.06054,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Clash Verge Rev",
      "product": "clash-verge-service-ipc",
      "cwe": "CWE-732",
      "title": "clash-verge-service-ipc before 2.3.0 has a world-reachable IPC endpoint, leading to local privilege escalation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-26422"
    }
  ],
  "transactions": [
    {
      "type": "DUE_DATE_PASSED",
      "cve_id": "CVE-2022-0492",
      "detail": "DUE DATE PASSED — CVE-2022-0492 (Linux Kernel). CISA remediation deadline was June 5, 2026; still in catalog."
    },
    {
      "type": "DUE_DATE_PASSED",
      "cve_id": "CVE-2025-48595",
      "detail": "DUE DATE PASSED — CVE-2025-48595 (Google Android). CISA remediation deadline was June 5, 2026; still in catalog."
    }
  ],
  "attribution": "CVE Program, NVD (NIST), CISA KEV, FIRST EPSS, OSV. See /security/methodology/."
}
