{
  "day": "2026-06-28",
  "boundary": "UTC calendar day",
  "published_count": 44,
  "by_severity": {
    "CRITICAL": 1,
    "HIGH": 8,
    "MEDIUM": 12,
    "LOW": 23
  },
  "kev_count": 0,
  "exploit_reference_count": 6,
  "awaiting_enrichment_count": 0,
  "ranking": "Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.",
  "results": [
    {
      "rank": 1,
      "cve_id": "CVE-2026-58057",
      "cvss_base": 2.3,
      "cvss_severity": "LOW",
      "epss_score": 0.01269,
      "epss_percentile": 0.67464,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Flowise",
      "product": "Flowise",
      "cwe": "CWE-178",
      "title": "Flowise - Custom MCP Environment Variable Denylist Bypass via Case Sensitivity",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58057"
    },
    {
      "rank": 2,
      "cve_id": "CVE-2026-58058",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00878,
      "epss_percentile": 0.5626,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Nmap",
      "product": "Nmap",
      "cwe": "CWE-191",
      "title": "Nmap - Integer Underflow in IPv6 Extension Header Parsing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58058"
    },
    {
      "rank": 3,
      "cve_id": "CVE-2026-58050",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00706,
      "epss_percentile": 0.5058,
      "kev": false,
      "kev_due_at": null,
      "vendor": "libssh2",
      "product": "libssh2",
      "cwe": "CWE-190",
      "title": "libssh2 - Integer Overflow in publickey Subsystem Attribute Allocation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58050"
    },
    {
      "rank": 4,
      "cve_id": "CVE-2026-13501",
      "cvss_base": 1.9,
      "cvss_severity": "LOW",
      "epss_score": 0.00679,
      "epss_percentile": 0.49561,
      "kev": false,
      "kev_due_at": null,
      "vendor": "antlr",
      "product": "ANTLR4",
      "cwe": "CWE-74",
      "title": "antlr ANTLR4 gofmt GoTarget.java GoTarget command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13501"
    },
    {
      "rank": 5,
      "cve_id": "CVE-2026-13503",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00551,
      "epss_percentile": 0.43713,
      "kev": false,
      "kev_due_at": null,
      "vendor": "antlr",
      "product": "ANTLR4",
      "cwe": "CWE-22",
      "title": "antlr ANTLR4 tokenVocab Grammar Option TokenVocabParser.java getImportedVocabFile path traversal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13503"
    },
    {
      "rank": 6,
      "cve_id": "CVE-2026-49048",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00505,
      "epss_percentile": 0.41076,
      "kev": false,
      "kev_due_at": null,
      "vendor": "joomcoder.com",
      "product": "JoomCCK extension for Joomla",
      "cwe": "CWE-89",
      "title": "Joomla Extension - joomcoder.com - Unauthenticated SQL Injection in JoomCCK extension for Joomla < 6.4.1",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49048"
    },
    {
      "rank": 7,
      "cve_id": "CVE-2026-13515",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00476,
      "epss_percentile": 0.39302,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Tenda",
      "product": "JD12L",
      "cwe": "CWE-119",
      "title": "Tenda JD12L SetPptpServerCfg formSetPPTPServer stack-based overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13515"
    },
    {
      "rank": 8,
      "cve_id": "CVE-2026-13516",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00466,
      "epss_percentile": 0.38646,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Tenda",
      "product": "JD12L",
      "cwe": "CWE-119",
      "title": "Tenda JD12L WifiGuestSet fromSetWifiGusetBasic stack-based overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13516"
    },
    {
      "rank": 9,
      "cve_id": "CVE-2026-58051",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.0044,
      "epss_percentile": 0.36781,
      "kev": false,
      "kev_due_at": null,
      "vendor": "libssh2",
      "product": "libssh2",
      "cwe": "CWE-908",
      "title": "libssh2 - Free of Uninitialized Pointer in publickey List Cleanup",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58051"
    },
    {
      "rank": 10,
      "cve_id": "CVE-2026-13491",
      "cvss_base": 2.9,
      "cvss_severity": "LOW",
      "epss_score": 0.00411,
      "epss_percentile": 0.3447,
      "kev": false,
      "kev_due_at": null,
      "vendor": "78",
      "product": "xiaozhi-esp32",
      "cwe": "CWE-404",
      "title": "78 xiaozhi-esp32 MQTT Goodbye mqtt_protocol.cc GetInstance denial of service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13491"
    },
    {
      "rank": 11,
      "cve_id": "CVE-2026-10646",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.0032,
      "epss_percentile": 0.24858,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zephyrproject",
      "product": "zephyr",
      "cwe": "CWE-416",
      "title": "Use-after-return in `zsock_getaddrinfo()` when a timed-out DNS query is retried without cancellation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10646"
    },
    {
      "rank": 12,
      "cve_id": "CVE-2026-13500",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00311,
      "epss_percentile": 0.23882,
      "kev": false,
      "kev_due_at": null,
      "vendor": "antlr",
      "product": "ANTLR4",
      "cwe": "CWE-74",
      "title": "antlr ANTLR4 Grammar Action Block OutputFile.java code injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13500"
    },
    {
      "rank": 13,
      "cve_id": "CVE-2026-13490",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00309,
      "epss_percentile": 0.23629,
      "kev": false,
      "kev_due_at": null,
      "vendor": "glpi-project",
      "product": "glpi",
      "cwe": "CWE-285",
      "title": "glpi-project glpi Document document.send.php canViewFile authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13490"
    },
    {
      "rank": 14,
      "cve_id": "CVE-2026-13484",
      "cvss_base": 1.3,
      "cvss_severity": "LOW",
      "epss_score": 0.00306,
      "epss_percentile": 0.23282,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "MLflow",
      "cwe": "CWE-862",
      "title": "MLflow Experiment-scoped Label Schema CRUD API authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13484"
    },
    {
      "rank": 15,
      "cve_id": "CVE-2026-13509",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00294,
      "epss_percentile": 0.22041,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "RAGapp",
      "cwe": "CWE-22",
      "title": "RAGapp Knowledge File files.py FileHandler.remove_file path traversal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13509"
    },
    {
      "rank": 16,
      "cve_id": "CVE-2026-10593",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00282,
      "epss_percentile": 0.20782,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zephyrproject",
      "product": "zephyr",
      "cwe": "CWE-476",
      "title": "Remotely triggerable NULL-pointer dereference in Bluetooth LE Audio BAP unicast client QoS-state handling",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10593"
    },
    {
      "rank": 17,
      "cve_id": "CVE-2026-13499",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00278,
      "epss_percentile": 0.20383,
      "kev": false,
      "kev_due_at": null,
      "vendor": "yashpokharna2555",
      "product": "restaurent-management-system",
      "cwe": "CWE-79",
      "title": "yashpokharna2555 restaurent-management-system Registration login_register.php cross site scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13499"
    },
    {
      "rank": 18,
      "cve_id": "CVE-2026-58049",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00275,
      "epss_percentile": 0.19983,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FFmpeg",
      "product": "FFmpeg",
      "cwe": "CWE-787",
      "title": "FFmpeg - Out-of-Bounds Write in RASC Decoder decode_dlta()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58049"
    },
    {
      "rank": 19,
      "cve_id": "CVE-2026-13485",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00269,
      "epss_percentile": 0.19114,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SourceCodester",
      "product": "Class and Exam Timetabling System",
      "cwe": "CWE-74",
      "title": "SourceCodester Class and Exam Timetabling System preview.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13485"
    },
    {
      "rank": 20,
      "cve_id": "CVE-2026-13486",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00269,
      "epss_percentile": 0.19122,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SourceCodester",
      "product": "Class and Exam Timetabling System",
      "cwe": "CWE-74",
      "title": "SourceCodester Class and Exam Timetabling System preview6.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13486"
    },
    {
      "rank": 21,
      "cve_id": "CVE-2026-13487",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00269,
      "epss_percentile": 0.19119,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SourceCodester",
      "product": "Class and Exam Timetabling System",
      "cwe": "CWE-74",
      "title": "SourceCodester Class and Exam Timetabling System archive.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13487"
    },
    {
      "rank": 22,
      "cve_id": "CVE-2026-13488",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00269,
      "epss_percentile": 0.19123,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SourceCodester",
      "product": "Class and Exam Timetabling System",
      "cwe": "CWE-74",
      "title": "SourceCodester Class and Exam Timetabling System preview7.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13488"
    },
    {
      "rank": 23,
      "cve_id": "CVE-2026-13498",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00269,
      "epss_percentile": 0.19123,
      "kev": false,
      "kev_due_at": null,
      "vendor": "yashpokharna2555",
      "product": "restaurent-management-system",
      "cwe": "CWE-74",
      "title": "yashpokharna2555 restaurent-management-system POST Parameter forgotpassword.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13498"
    },
    {
      "rank": 24,
      "cve_id": "CVE-2026-58053",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00265,
      "epss_percentile": 0.18567,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Gitea",
      "product": "act_runner",
      "cwe": "CWE-269",
      "title": "Gitea act_runner - Container Hardening Bypass via Workflow Container Options",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58053"
    },
    {
      "rank": 25,
      "cve_id": "CVE-2026-58055",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00263,
      "epss_percentile": 0.18255,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nghttp2",
      "product": "nghttp2",
      "cwe": "CWE-444",
      "title": "nghttp2 nghttpx - HTTP Request/Response Smuggling via Upgrade Request with Content-Length",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58055"
    },
    {
      "rank": 26,
      "cve_id": "CVE-2026-13493",
      "cvss_base": 1.3,
      "cvss_severity": "LOW",
      "epss_score": 0.00232,
      "epss_percentile": 0.14277,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AIDC-AI",
      "product": "ComfyUI-Copilot",
      "cwe": "CWE-99",
      "title": "AIDC-AI ComfyUI-Copilot Workflow Checkpoint Restore conversation_api.py resource injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13493"
    },
    {
      "rank": 27,
      "cve_id": "CVE-2026-10644",
      "cvss_base": 3.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00229,
      "epss_percentile": 0.1397,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zephyrproject",
      "product": "zephyr",
      "cwe": "CWE-787",
      "title": "Out-of-bounds write in Microchip SERCOM-G1 (PIC32CM-JH) async UART RX with 1-byte buffer",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10644"
    },
    {
      "rank": 28,
      "cve_id": "CVE-2026-13489",
      "cvss_base": 1.3,
      "cvss_severity": "LOW",
      "epss_score": 0.00228,
      "epss_percentile": 0.13816,
      "kev": false,
      "kev_due_at": null,
      "vendor": "78",
      "product": "xiaozhi-esp32",
      "cwe": "CWE-662",
      "title": "78 xiaozhi-esp32 MCP Response mcp_server.cc ParseMessage improper synchronization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13489"
    },
    {
      "rank": 29,
      "cve_id": "CVE-2026-13512",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.0022,
      "epss_percentile": 0.12778,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "Databend",
      "cwe": "CWE-285",
      "title": "Databend Tenant client_session_manager.rs state_key authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13512"
    },
    {
      "rank": 30,
      "cve_id": "CVE-2026-13511",
      "cvss_base": 1.3,
      "cvss_severity": "LOW",
      "epss_score": 0.0022,
      "epss_percentile": 0.12846,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "VoltAgent",
      "cwe": "CWE-266",
      "title": "VoltAgent Memory REST API memory.handlers.ts handleGetMemoryConversation improper authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13511"
    },
    {
      "rank": 31,
      "cve_id": "CVE-2026-13510",
      "cvss_base": 2.9,
      "cvss_severity": "LOW",
      "epss_score": 0.00216,
      "epss_percentile": 0.12314,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SimStudioAI",
      "product": "sim",
      "cwe": "CWE-327",
      "title": "SimStudioAI sim Password Protection deployment.ts weak hash",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13510"
    },
    {
      "rank": 32,
      "cve_id": "CVE-2026-13495",
      "cvss_base": 2,
      "cvss_severity": "LOW",
      "epss_score": 0.00214,
      "epss_percentile": 0.12086,
      "kev": false,
      "kev_due_at": null,
      "vendor": "itsourcecode",
      "product": "Hospital Management System",
      "cwe": "CWE-74",
      "title": "itsourcecode Hospital Management System adminprofile.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13495"
    },
    {
      "rank": 33,
      "cve_id": "CVE-2026-13496",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00204,
      "epss_percentile": 0.10763,
      "kev": false,
      "kev_due_at": null,
      "vendor": "itsourcecode",
      "product": "Hospital Management System",
      "cwe": "CWE-74",
      "title": "itsourcecode Hospital Management System ajaxmedicine.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13496"
    },
    {
      "rank": 34,
      "cve_id": "CVE-2026-13497",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00204,
      "epss_percentile": 0.10763,
      "kev": false,
      "kev_due_at": null,
      "vendor": "itsourcecode",
      "product": "Hospital Management System",
      "cwe": "CWE-74",
      "title": "itsourcecode Hospital Management System appointment.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13497"
    },
    {
      "rank": 35,
      "cve_id": "CVE-2026-13504",
      "cvss_base": 2,
      "cvss_severity": "LOW",
      "epss_score": 0.00203,
      "epss_percentile": 0.1058,
      "kev": false,
      "kev_due_at": null,
      "vendor": "code-projects",
      "product": "Project Management System",
      "cwe": "CWE-79",
      "title": "code-projects Project Management System Mail Compose mail.php cross site scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13504"
    },
    {
      "rank": 36,
      "cve_id": "CVE-2026-58056",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00191,
      "epss_percentile": 0.09163,
      "kev": false,
      "kev_due_at": null,
      "vendor": "RustDesk",
      "product": "RustDesk",
      "cwe": "CWE-863",
      "title": "RustDesk - FileTransfer Session Authorization Scope Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58056"
    },
    {
      "rank": 37,
      "cve_id": "CVE-2026-13482",
      "cvss_base": 2.9,
      "cvss_severity": "LOW",
      "epss_score": 0.00189,
      "epss_percentile": 0.08887,
      "kev": false,
      "kev_due_at": null,
      "vendor": "skypilot-org",
      "product": "skypilot",
      "cwe": "CWE-327",
      "title": "skypilot-org skypilot User ID server.py username.encode weak hash",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13482"
    },
    {
      "rank": 38,
      "cve_id": "CVE-2026-13508",
      "cvss_base": 2,
      "cvss_severity": "LOW",
      "epss_score": 0.00165,
      "epss_percentile": 0.06182,
      "kev": false,
      "kev_due_at": null,
      "vendor": "khoj-ai",
      "product": "khoj",
      "cwe": "CWE-285",
      "title": "khoj-ai khoj Conversation Sharing api_chat.py authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13508"
    },
    {
      "rank": 39,
      "cve_id": "CVE-2026-13507",
      "cvss_base": 2.3,
      "cvss_severity": "LOW",
      "epss_score": 0.00138,
      "epss_percentile": 0.03669,
      "kev": false,
      "kev_due_at": null,
      "vendor": "volcengine",
      "product": "OpenViking",
      "cwe": "CWE-345",
      "title": "volcengine OpenViking Local VectorDB Primary-key Label str_to_uint64.py str_to_uint64 data authenticity",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13507"
    },
    {
      "rank": 40,
      "cve_id": "CVE-2026-13513",
      "cvss_base": 1.3,
      "cvss_severity": "LOW",
      "epss_score": 0.00133,
      "epss_percentile": 0.03293,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MyScale",
      "product": "MyScaleDB",
      "cwe": "CWE-345",
      "title": "MyScale MyScaleDB SegmentId.h getCacheKey data authenticity",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13513"
    },
    {
      "rank": 41,
      "cve_id": "CVE-2026-13514",
      "cvss_base": 0.9,
      "cvss_severity": "LOW",
      "epss_score": 0.00133,
      "epss_percentile": 0.03258,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Chess",
      "product": "Play and Learn App",
      "cwe": "CWE-285",
      "title": "Chess Play and Learn App com.chess AndroidManifest.xml backup",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13514"
    },
    {
      "rank": 42,
      "cve_id": "CVE-2026-58052",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00117,
      "epss_percentile": 0.0197,
      "kev": false,
      "kev_due_at": null,
      "vendor": "7-Zip",
      "product": "7-Zip",
      "cwe": "CWE-693",
      "title": "7-Zip - Mark-of-the-Web Bypass via RAR5 Alternate Data Stream Name Collision",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58052"
    },
    {
      "rank": 43,
      "cve_id": "CVE-2026-13483",
      "cvss_base": 1.3,
      "cvss_severity": "LOW",
      "epss_score": 0.00097,
      "epss_percentile": 0.0085,
      "kev": false,
      "kev_due_at": null,
      "vendor": "arc53",
      "product": "DocsGPT",
      "cwe": "CWE-345",
      "title": "arc53 DocsGPT Credential Storage encryption.py encrypt_credentials data authenticity",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13483"
    },
    {
      "rank": 44,
      "cve_id": "CVE-2026-13502",
      "cvss_base": 1.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00091,
      "epss_percentile": 0.00579,
      "kev": false,
      "kev_due_at": null,
      "vendor": "antlr",
      "product": "ANTLR4",
      "cwe": "CWE-362",
      "title": "antlr ANTLR4 Maven Plugin GrammarDependencies.java ObjectInputStream.readObject toctou",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13502"
    }
  ],
  "transactions": [
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-10593",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-10593 (zephyrproject zephyr). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-10644",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-10644 (zephyrproject zephyr). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-10646",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-10646 (zephyrproject zephyr). Public exploit reference added."
    }
  ],
  "attribution": "CVE Program, NVD (NIST), CISA KEV, FIRST EPSS, OSV. See /security/methodology/."
}
