{
  "day": "2026-06-20",
  "boundary": "UTC calendar day",
  "published_count": 42,
  "by_severity": {
    "CRITICAL": 7,
    "HIGH": 9,
    "MEDIUM": 23,
    "LOW": 3
  },
  "kev_count": 0,
  "exploit_reference_count": 4,
  "awaiting_enrichment_count": 0,
  "ranking": "Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.",
  "results": [
    {
      "rank": 1,
      "cve_id": "CVE-2026-48909",
      "cvss_base": 9.5,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.07638,
      "epss_percentile": 0.94075,
      "kev": false,
      "kev_due_at": null,
      "vendor": "joomshaper.net",
      "product": "SP LMS extension for Joomla",
      "cwe": "CWE-502",
      "title": "Joomla Extension - joomshaper.com - PHP Object injection in SP LMS extension for Joomla < 4.1.4",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48909"
    },
    {
      "rank": 2,
      "cve_id": "CVE-2026-11911",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.01174,
      "epss_percentile": 0.65026,
      "kev": false,
      "kev_due_at": null,
      "vendor": "eemitch",
      "product": "Simple File List",
      "cwe": "CWE-22",
      "title": "Simple File List <= 6.3.7 - Unauthenticated Arbitrary File Deletion via Path Traversal in 'eeSubFolder' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11911"
    },
    {
      "rank": 3,
      "cve_id": "CVE-2022-50972",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.01137,
      "epss_percentile": 0.63999,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WooCommerce",
      "product": "WooCommerce",
      "cwe": "CWE-94",
      "title": "WooCommerce 7.1.0 Remote Code Execution via class-wc-meta-box-product-images.php",
      "url": "https://www.cve.org/CVERecord?id=CVE-2022-50972"
    },
    {
      "rank": 4,
      "cve_id": "CVE-2026-9843",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00939,
      "epss_percentile": 0.58156,
      "kev": false,
      "kev_due_at": null,
      "vendor": "crmperks",
      "product": "Database for Contact Form 7, WPforms, Elementor forms",
      "cwe": "CWE-22",
      "title": "Database for Contact Form 7, WPforms, Elementor forms <= 1.5.1 - Unauthenticated Arbitrary File Deletion via CF7 File Field POST Value",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9843"
    },
    {
      "rank": 5,
      "cve_id": "CVE-2024-58351",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00926,
      "epss_percentile": 0.57677,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Flowise",
      "product": "Flowise",
      "cwe": "CWE-94",
      "title": "Flowise - Remote Code Execution via overrideConfig Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2024-58351"
    },
    {
      "rank": 6,
      "cve_id": "CVE-2026-5366",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00874,
      "epss_percentile": 0.56133,
      "kev": false,
      "kev_due_at": null,
      "vendor": "prefecthq",
      "product": "prefecthq/prefect",
      "cwe": "CWE-94",
      "title": "Git Argument Injection in prefecthq/prefect",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-5366"
    },
    {
      "rank": 7,
      "cve_id": "CVE-2019-25763",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.008,
      "epss_percentile": 0.53734,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Ultimatebeaver",
      "product": "Ultimate Addons for Beaver Builder",
      "cwe": "CWE-288",
      "title": "WordPress Ultimate Addons for Beaver Builder 1.2.4.1 Authentication Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2019-25763"
    },
    {
      "rank": 8,
      "cve_id": "CVE-2026-9265",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00632,
      "epss_percentile": 0.47575,
      "kev": false,
      "kev_due_at": null,
      "vendor": "JONASBN",
      "product": "Crypt::OpenSSL::PKCS12",
      "cwe": "CWE-125",
      "title": "Crypt::OpenSSL::PKCS12 versions before 1.96 for Perl permits a heap OOB read in print_attribute UTF8STRING path",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9265"
    },
    {
      "rank": 9,
      "cve_id": "CVE-2020-37255",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00629,
      "epss_percentile": 0.47424,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Wptimecapsule",
      "product": "Time Capsule Plugin",
      "cwe": "CWE-288",
      "title": "WordPress Time Capsule Plugin 1.21.16 Authentication Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2020-37255"
    },
    {
      "rank": 10,
      "cve_id": "CVE-2026-56346",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00615,
      "epss_percentile": 0.46794,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AVideo",
      "product": "AVideo",
      "cwe": "CWE-306",
      "title": "AVideo - Unauthenticated PGP Message Decryption via decryptMessage.json.php Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56346"
    },
    {
      "rank": 11,
      "cve_id": "CVE-2026-11912",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00516,
      "epss_percentile": 0.41788,
      "kev": false,
      "kev_due_at": null,
      "vendor": "eemitch",
      "product": "Simple File List",
      "cwe": "CWE-862",
      "title": "Simple File List <= 6.3.7 - Missing Authorization to Unauthenticated File Modification via simplefilelist_edit_job AJAX Action",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11912"
    },
    {
      "rank": 12,
      "cve_id": "CVE-2026-56228",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00467,
      "epss_percentile": 0.38662,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Capgo",
      "product": "Capgo",
      "cwe": "CWE-20",
      "title": "Capgo - Denial of Service via Improper Password Policy Length Validation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56228"
    },
    {
      "rank": 13,
      "cve_id": "CVE-2026-12119",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00467,
      "epss_percentile": 0.38705,
      "kev": false,
      "kev_due_at": null,
      "vendor": "eemitch",
      "product": "Simple File List",
      "cwe": "CWE-862",
      "title": "Simple File List <= 6.3.7 - Missing Authorization to Authenticated (Contributor+) Arbitrary File Operations (Deletion / Move / Folder Creation / Download) via 'frontmanage' Shortcode Attribute",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12119"
    },
    {
      "rank": 14,
      "cve_id": "CVE-2026-56267",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00465,
      "epss_percentile": 0.38524,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Flowise",
      "product": "Flowise",
      "cwe": "CWE-200",
      "title": "Flowise - PII Disclosure via Unauthenticated Forgot Password Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56267"
    },
    {
      "rank": 15,
      "cve_id": "CVE-2026-56214",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00459,
      "epss_percentile": 0.3817,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Capgo",
      "product": "Capgo",
      "cwe": "CWE-200",
      "title": "Capgo - Unauthenticated Organization Enumeration and Billing Status Disclosure via Supabase RPC",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56214"
    },
    {
      "rank": 16,
      "cve_id": "CVE-2026-56341",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00459,
      "epss_percentile": 0.38203,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AVideo",
      "product": "AVideo",
      "cwe": "CWE-862",
      "title": "AVideo - Unauthenticated Access to Payment Log DataTables Endpoints via list.json.php",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56341"
    },
    {
      "rank": 17,
      "cve_id": "CVE-2026-56345",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00453,
      "epss_percentile": 0.37778,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AVideo",
      "product": "AVideo",
      "cwe": "CWE-287",
      "title": "AVideo - Arbitrary User Session Hijacking via Meet Plugin uploadRecordedVideo Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56345"
    },
    {
      "rank": 18,
      "cve_id": "CVE-2026-56304",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00443,
      "epss_percentile": 0.37017,
      "kev": false,
      "kev_due_at": null,
      "vendor": "picklescan",
      "product": "picklescan",
      "cwe": "CWE-502",
      "title": "picklescan - Arbitrary File Creation via logging.FileHandler Deserialization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56304"
    },
    {
      "rank": 19,
      "cve_id": "CVE-2026-56216",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00442,
      "epss_percentile": 0.36981,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Capgo",
      "product": "Capgo",
      "cwe": "CWE-269",
      "title": "Capgo - Scope Escalation via API Key Creation in /functions/v1/apikey",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56216"
    },
    {
      "rank": 20,
      "cve_id": "CVE-2026-56355",
      "cvss_base": 3.7,
      "cvss_severity": "LOW",
      "epss_score": 0.00404,
      "epss_percentile": 0.33799,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GNU",
      "product": "Savane",
      "cwe": "CWE-696",
      "title": "GNU Savannah Administration Savane through 3.17 uses untrusted data as part of authorization.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56355"
    },
    {
      "rank": 21,
      "cve_id": "CVE-2026-12673",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00403,
      "epss_percentile": 0.33751,
      "kev": false,
      "kev_due_at": null,
      "vendor": "liquidfiles",
      "product": "liquidfiles",
      "cwe": "CWE-285",
      "title": "Liquidfiles versions before 4.2.12 are affected by a broken access control vulnerability resulting in privilege escalation from an Admin in a secondary domain to a Sysadmin by modifying a group in their managed secondary (non-default) group.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12673"
    },
    {
      "rank": 22,
      "cve_id": "CVE-2026-56282",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00396,
      "epss_percentile": 0.32979,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Capgo",
      "product": "Capgo",
      "cwe": "CWE-200",
      "title": "Capgo - Information Disclosure via Unauthenticated /replication Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56282"
    },
    {
      "rank": 23,
      "cve_id": "CVE-2026-56342",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00391,
      "epss_percentile": 0.32456,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AVideo",
      "product": "AVideo",
      "cwe": "CWE-918",
      "title": "AVideo - Server-Side Request Forgery in Live/test.php via statsURL Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56342"
    },
    {
      "rank": 24,
      "cve_id": "CVE-2026-56235",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00389,
      "epss_percentile": 0.32209,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cap-go",
      "product": "capgo",
      "cwe": "CWE-200",
      "title": "Capgo - Unauthenticated Cross-Tenant Metrics Disclosure via RPC Functions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56235"
    },
    {
      "rank": 25,
      "cve_id": "CVE-2026-56215",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00388,
      "epss_percentile": 0.32175,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Capgo",
      "product": "Capgo",
      "cwe": "CWE-639",
      "title": "Capgo - Account Merge via Poisoned public.users.email in SSO Provisioning",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56215"
    },
    {
      "rank": 26,
      "cve_id": "CVE-2026-56307",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00373,
      "epss_percentile": 0.30613,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cap-go",
      "product": "capgo",
      "cwe": "CWE-670",
      "title": "Cap-go - Broken Cursor Pagination in /private/devices Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56307"
    },
    {
      "rank": 27,
      "cve_id": "CVE-2026-56276",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00366,
      "epss_percentile": 0.29834,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Flowise",
      "product": "Flowise",
      "cwe": "CWE-915",
      "title": "Flowise - Mass Assignment in PUT /api/v1/user Allows Password Hash Override",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56276"
    },
    {
      "rank": 28,
      "cve_id": "CVE-2026-56213",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00353,
      "epss_percentile": 0.28471,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Capgo",
      "product": "Capgo",
      "cwe": "CWE-862",
      "title": "Capgo - Unauthenticated Cross-Tenant Metrics Poisoning via upsert_version_meta RPC",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56213"
    },
    {
      "rank": 29,
      "cve_id": "CVE-2026-56340",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00352,
      "epss_percentile": 0.28387,
      "kev": false,
      "kev_due_at": null,
      "vendor": "vLLM",
      "product": "vLLM",
      "cwe": "CWE-20",
      "title": "vLLM - Denial of Service via Unvalidated Multimodal Embeddings",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56340"
    },
    {
      "rank": 30,
      "cve_id": "CVE-2026-56218",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00343,
      "epss_percentile": 0.27418,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Capgo",
      "product": "Capgo",
      "cwe": "CWE-200",
      "title": "Capgo - EXIF Metadata Exposure via Image Upload",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56218"
    },
    {
      "rank": 31,
      "cve_id": "CVE-2026-56212",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00342,
      "epss_percentile": 0.27299,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Capgo",
      "product": "Capgo",
      "cwe": "CWE-269",
      "title": "Capgo - Improper 2FA Enforcement Logic via Team Security Settings",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56212"
    },
    {
      "rank": 32,
      "cve_id": "CVE-2026-56325",
      "cvss_base": 2.3,
      "cvss_severity": "LOW",
      "epss_score": 0.00337,
      "epss_percentile": 0.26701,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Capgo",
      "product": "Capgo",
      "cwe": "CWE-20",
      "title": "Capgo - App ID Confusion via ILIKE Wildcard in Preview Subdomain Lookup",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56325"
    },
    {
      "rank": 33,
      "cve_id": "CVE-2025-71379",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00321,
      "epss_percentile": 0.25022,
      "kev": false,
      "kev_due_at": null,
      "vendor": "vllm",
      "product": "vllm",
      "cwe": "CWE-1333",
      "title": "vllm - Regular Expression Denial of Service in Multiple Components",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-71379"
    },
    {
      "rank": 34,
      "cve_id": "CVE-2026-56295",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00312,
      "epss_percentile": 0.24022,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Capgo",
      "product": "Capgo",
      "cwe": "CWE-285",
      "title": "Capgo - Policy Enforcement Bypass in Webhook Management Endpoints via Non-Expiring API Keys",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56295"
    },
    {
      "rank": 35,
      "cve_id": "CVE-2026-56319",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00306,
      "epss_percentile": 0.23314,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Capgo",
      "product": "Capgo",
      "cwe": "CWE-203",
      "title": "Capgo - App Existence Oracle via GET /statistics/app/:app_id",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56319"
    },
    {
      "rank": 36,
      "cve_id": "CVE-2026-56332",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00299,
      "epss_percentile": 0.22561,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Capgo",
      "product": "Capgo",
      "cwe": "CWE-601",
      "title": "Capgo - Open Redirect via confirmation_url Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56332"
    },
    {
      "rank": 37,
      "cve_id": "CVE-2026-56347",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00263,
      "epss_percentile": 0.18248,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WWBN",
      "product": "AVideo",
      "cwe": "CWE-79",
      "title": "AVideo TopMenu Plugin - Stored Cross-Site Scripting via Unescaped Menu Item Fields",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56347"
    },
    {
      "rank": 38,
      "cve_id": "CVE-2026-56227",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0026,
      "epss_percentile": 0.17922,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Capgo",
      "product": "Capgo",
      "cwe": "CWE-918",
      "title": "Capgo - Server-Side Request Forgery via Webhook URL Validation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56227"
    },
    {
      "rank": 39,
      "cve_id": "CVE-2026-56330",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00253,
      "epss_percentile": 0.16997,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Capgo",
      "product": "Capgo",
      "cwe": "CWE-601",
      "title": "Capgo - Open Redirect via Unvalidated Stripe Billing URLs",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56330"
    },
    {
      "rank": 40,
      "cve_id": "CVE-2025-71331",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00222,
      "epss_percentile": 0.13008,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Flowise",
      "product": "Flowise",
      "cwe": "CWE-80",
      "title": "Flowise - Cross-Site Scripting in Chat Messages and Agent Workflows",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-71331"
    },
    {
      "rank": 41,
      "cve_id": "CVE-2026-56294",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00217,
      "epss_percentile": 0.12447,
      "kev": false,
      "kev_due_at": null,
      "vendor": "capacitor-native-biometric",
      "product": "capacitor-native-biometric",
      "cwe": "CWE-287",
      "title": "capacitor-native-biometric - Authentication Bypass via Unvalidated CryptoObject in onAuthenticationSucceeded",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56294"
    },
    {
      "rank": 42,
      "cve_id": "CVE-2026-56317",
      "cvss_base": 2.3,
      "cvss_severity": "LOW",
      "epss_score": 0.00209,
      "epss_percentile": 0.11378,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Nuxt",
      "product": "Nuxt",
      "cwe": "CWE-79",
      "title": "Nuxt - Cross-Site Scripting via NoScript Component Slot Content",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56317"
    }
  ],
  "transactions": [
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2025-71331",
      "detail": "EXPLOIT PUBLISHED — CVE-2025-71331 (Flowise). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2025-71379",
      "detail": "EXPLOIT PUBLISHED — CVE-2025-71379 (vllm). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-5366",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-5366 (prefecthq/prefect). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-56304",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-56304 (picklescan). Public exploit reference added."
    },
    {
      "type": "DUE_DATE_PASSED",
      "cve_id": "CVE-2026-28318",
      "detail": "DUE DATE PASSED — CVE-2026-28318 (SolarWinds Serv-U). CISA remediation deadline was June 19, 2026; still in catalog."
    },
    {
      "type": "DUE_DATE_PASSED",
      "cve_id": "CVE-2026-48907",
      "detail": "DUE DATE PASSED — CVE-2026-48907 (joomlacontenteditor.net Joomla Content Editor (JCE) extension for Joomla). CISA remediation deadline was June 19, 2026; still in catalog."
    }
  ],
  "attribution": "CVE Program, NVD (NIST), CISA KEV, FIRST EPSS, OSV. See /security/methodology/."
}
