{
  "day": "2026-06-14",
  "boundary": "UTC calendar day",
  "published_count": 17,
  "by_severity": {
    "CRITICAL": 1,
    "HIGH": 10,
    "MEDIUM": 4,
    "LOW": 2
  },
  "kev_count": 0,
  "exploit_reference_count": 0,
  "awaiting_enrichment_count": 0,
  "ranking": "Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.",
  "results": [
    {
      "rank": 1,
      "cve_id": "CVE-2026-12197",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.02385,
      "epss_percentile": 0.82583,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Ruijie",
      "product": "EG105G-P",
      "cwe": "CWE-74",
      "title": "Ruijie EG105G-P JSON-RPC Diagnose Endpoint diagnose nslookup command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12197"
    },
    {
      "rank": 2,
      "cve_id": "CVE-2026-12186",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.01966,
      "epss_percentile": 0.78773,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GL.iNet",
      "product": "GL-MT3000",
      "cwe": "CWE-74",
      "title": "GL.iNet GL-MT3000 Tor Proxy Service Configuration tor replace_country command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12186"
    },
    {
      "rank": 3,
      "cve_id": "CVE-2026-12187",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.0194,
      "epss_percentile": 0.78496,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GL.iNet",
      "product": "GL-MT3000",
      "cwe": "CWE-74",
      "title": "GL.iNet GL-MT3000 Online Firmware Upgrade one_click_upgrade command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12187"
    },
    {
      "rank": 4,
      "cve_id": "CVE-2026-11526",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.01353,
      "epss_percentile": 0.69345,
      "kev": false,
      "kev_due_at": null,
      "vendor": "RURBAN",
      "product": "GD",
      "cwe": "CWE-73",
      "title": "GD versions before 2.86 for Perl allow OS command injection and file overwrite via a 2-arg open() of filename arguments in _make_filehandle",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11526"
    },
    {
      "rank": 5,
      "cve_id": "CVE-2026-11527",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.01068,
      "epss_percentile": 0.6215,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SHLOMIF",
      "product": "Config::IniFiles",
      "cwe": "CWE-73",
      "title": "Config::IniFiles versions before 3.001000 for Perl allow OS command injection and file overwrite via a 2-arg open() of the -file argument in _make_filehandle",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11527"
    },
    {
      "rank": 6,
      "cve_id": "CVE-2026-54410",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00541,
      "epss_percentile": 0.43145,
      "kev": false,
      "kev_due_at": null,
      "vendor": "debevv",
      "product": "nanoMODBUS",
      "cwe": "CWE-193",
      "title": "nanoMODBUS Off-by-One Buffer Overflow in recv_msg_header() via Crafted MBAP Length Field",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54410"
    },
    {
      "rank": 7,
      "cve_id": "CVE-2026-54412",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00407,
      "epss_percentile": 0.34109,
      "kev": false,
      "kev_due_at": null,
      "vendor": "LiamBindle",
      "product": "MQTT-C",
      "cwe": "CWE-125",
      "title": "MQTT-C Heap Out-of-Bounds Read and Integer Underflow in mqtt_unpack_publish_response()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54412"
    },
    {
      "rank": 8,
      "cve_id": "CVE-2026-54413",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00407,
      "epss_percentile": 0.34109,
      "kev": false,
      "kev_due_at": null,
      "vendor": "driftregion",
      "product": "iso14229",
      "cwe": "CWE-125",
      "title": "iso14229 Integer Underflow and Out-of-Bounds Read in Handle_0x27_SecurityAccess()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54413"
    },
    {
      "rank": 9,
      "cve_id": "CVE-2026-54411",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00333,
      "epss_percentile": 0.26289,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux-PAM",
      "product": "Linux-PAM",
      "cwe": "CWE-208",
      "title": "Linux-PAM pam_userdb Observable Timing Discrepancy in Plaintext Password Comparison",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54411"
    },
    {
      "rank": 10,
      "cve_id": "CVE-2026-12192",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00316,
      "epss_percentile": 0.24473,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GALAYOU",
      "product": "Y4",
      "cwe": "CWE-119",
      "title": "GALAYOU Y4 Web Server buffer overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12192"
    },
    {
      "rank": 11,
      "cve_id": "CVE-2026-54421",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00291,
      "epss_percentile": 0.21627,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenStack",
      "product": "Ironic",
      "cwe": "CWE-212",
      "title": "In OpenStack Ironic before 37.0.1, when applying a PATCH to update fields in volume properties the user is authorized for, Ironic can return unredacted sensitive information (such as iSCSI credentials). The PATCH outcome is a security issue; the POST outcome is not a security issue.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54421"
    },
    {
      "rank": 12,
      "cve_id": "CVE-2026-12188",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00196,
      "epss_percentile": 0.09747,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Grit42",
      "product": "Grit",
      "cwe": "CWE-74",
      "title": "Grit42 Grit GritEntityController grit_entity_controller.rb sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12188"
    },
    {
      "rank": 13,
      "cve_id": "CVE-2025-15546",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00159,
      "epss_percentile": 0.05536,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Iptanus File Upload",
      "cwe": "CWE-362",
      "title": "Iptanus File Upload < 5.1.7 - File Overwrite via Race Condition",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-15546"
    },
    {
      "rank": 14,
      "cve_id": "CVE-2026-12193",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00142,
      "epss_percentile": 0.04009,
      "kev": false,
      "kev_due_at": null,
      "vendor": "VS Revo",
      "product": "RevoUninstaller",
      "cwe": "CWE-119",
      "title": "VS Revo RevoUninstaller IOCTL RevoDetector.sys IOCtl_Handler heap-based overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12193"
    },
    {
      "rank": 15,
      "cve_id": "CVE-2026-12191",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00136,
      "epss_percentile": 0.03541,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Comma AI",
      "product": "Openpilot",
      "cwe": "CWE-20",
      "title": "Comma AI Openpilot Pickle modeld.py pickle.loads deserialization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12191"
    },
    {
      "rank": 16,
      "cve_id": "CVE-2026-12190",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00105,
      "epss_percentile": 0.01205,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Genspark",
      "product": "AI Workspace App",
      "cwe": "CWE-285",
      "title": "Genspark AI Workspace App ai.mainfunc.genspark improper authorization in handler for custom url scheme",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12190"
    },
    {
      "rank": 17,
      "cve_id": "CVE-2026-12189",
      "cvss_base": 1.9,
      "cvss_severity": "LOW",
      "epss_score": 0.00105,
      "epss_percentile": 0.01224,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Moovit",
      "product": "Bus & Public Transit App",
      "cwe": "CWE-285",
      "title": "Moovit Bus & Public Transit App com.tranzmate improper authorization in handler for custom url scheme",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12189"
    }
  ],
  "transactions": [
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-12188",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-12188 (Grit42 Grit). Public exploit reference added."
    }
  ],
  "attribution": "CVE Program, NVD (NIST), CISA KEV, FIRST EPSS, OSV. See /security/methodology/."
}
