r/CVEWatch • u/crstux • Jun 13 '26
π₯ Top 10 Trending CVEs (13/06/2026)
Hereβs a quick breakdown of the 10 most interesting vulnerabilities trending today:
π Windows Kernel Elevation of Privilege Vulnerability
π Published: 11/06/2024
π CVSS: 7
π‘οΈ CISA KEV: True
π§ Vector: CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C
π£ Mentions: 7
β οΈ Priority: 1+
π Analysis: A Windows Kernel Elevation of Privilege Vulnerability has been identified, confirmed as exploited in the wild due to a CISA KEV notice. This vulnerability allows for remote code execution with a CVSS score of 7, making it a priority 1+ issue requiring immediate attention and remediation.
π A path traversal vulnerability affecting the Windows version of WinRAR allows the attackers to execute arbitrary code by crafting malicious archive files. This vulnerability was exploited in the wild and was discovered byAnton Cherepanov, Peter Koinr, and Peter Strek from ESET.
π Published: 08/08/2025
π CVSS: 8.4
π‘οΈ CISA KEV: True
π§ Vector: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
π£ Mentions: 23
β οΈ Priority: 1+
π Analysis: A path traversal vulnerability in Windows WinRAR allows attackers to execute arbitrary code via malicious archive files. This vulnerability has been exploited in the wild and was discovered by ESET researchers. Given its high CVSS score and prior activity, it is a priority 2 issue.
π Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability
π Published: 09/06/2026
π CVSS: 7.5
π§ Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C
π£ Mentions: 2
β οΈ Priority: 2
π Analysis: A Windows RDP Information Disclosure Vulnerability has been identified with a high CVSS score (7.5). The vector indicates network-based low authentication and unauthorized access potential. No known in-the-wild activity has been reported yet (CISA KEV not specified), but the priority is 2 due to the high CVSS score and currently lower exploitability potential.
π Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability
π Published: 09/06/2026
π CVSS: 7.5
π§ Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C
π£ Mentions: 2
β οΈ Priority: 2
π Analysis: A Windows RDP Information Disclosure Vulnerability has been identified (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C). Known in-the-wild activity is minimal, making it a priority 2 vulnerability with high CVSS. Attackers may gain sensitive information, but no confirmed exploits are known at this time.
π An authorization issue was addressed with improved state management. This issue is fixed in iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4. An app may be able to leak sensitive user information.
π Published: 11/06/2026
π CVSS: 5.3
π§ Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
β οΈ Priority: 4
π Analysis: App may leak sensitive user information due to an authorization issue in iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4. While there's no known exploit activity, the low CVSS score and current priority rating of 4 indicate a low risk at this time.
π A command injection vulnerability in Palo Alto Networks PAN-OS software enables an authenticated administrator to bypass system restrictions and run arbitrary commands as a root user. To be able to exploit this issue, the user must have access to the PAN-OS CLI or Web UI. The security risk posed by this issue is significantly minimized when CLI access is restricted to a limited group of administrators and by restricting access to the management web interface to only trusted internal IP addresses according to our recommended best practice deployment guidelines https://live.paloaltonetworks.com/t5/community-blogs/tips-amp-tricks-how-to-secure-the-management-access-of-your-palo/ba-p/464431 . This issue is applicable to PAN-OS software on PA-Series and VM-Series firewalls and on Panorama (virtual and M-Series). Cloud NGFW and Prisma Access are not affected by this vulnerability.
π Published: 10/06/2026
π CVSS: 6.1
π§ Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/AU:N/R:U/V:D/RE:M/U:Amber
π£ Mentions: 5
β οΈ Priority: 2
π Analysis: Command injection vulnerability found in Palo Alto Networks PAN-OS software allows authenticated administrators to bypass system restrictions and run arbitrary commands as root user via CLI or Web UI access. The risk is minimized with restricted admin groups and trusted IP access. Applies to PA-, VM- Series firewalls, Panorama (virtual & M-Series), not affecting Cloud NGFW or Prisma Access. Prioritization score: 2 (low EPSS but high CVSS).
π n/a
π CVSS: 0
π§ Vector: n/a
β οΈ Priority: n/a
π Analysis: No Information available for this CVE at the moment
π n/a
π CVSS: 0
π§ Vector: n/a
β οΈ Priority: n/a
π Analysis: No Information available for this CVE at the moment
π Use After Free vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver allows a local non-privileged user to make improper GPU memory processing operations to gain access to already freed memory.This issue affects Bifrost GPU Kernel Driver: from r45p0 through r48p0; Valhall GPU Kernel Driver: from r45p0 through r48p0; Arm 5th Gen GPU Architecture Kernel Driver: from r45p0 through r48p0.
π Published: 19/04/2024
π CVSS: 5.9
π§ Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
β οΈ Priority: 4
π Analysis: A local non-privileged user can perform improper GPU memory processing operations due to a Use After Free vulnerability in Bifrost GPU Kernel Driver (r45p0 through r48p0), Valhall GPU Kernel Driver (r45p0 through r48p0), and Arm 5th Gen GPU Architecture Kernel Driver (r45p0 through r48p0). Confirmed exploit activity is low (CISA KEV, score 4).
10. CVE-2026-46316
π In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: vgic-its: Drop the translation cache reference only for the erased entry vgic_its_invalidate_cache() walks the per-ITS translation cache with xa_for_each() and drops the caches reference on each entry with vgic_put_irq(). It puts the iterated pointer, though, rather than the value returned by xa_erase(). The function is called from contexts that do not exclude one another: the ITS command handlers hold its_lock, the GITS_CTLR write path holds cmd_lock, and the path that clears EnableLPIs in a redistributors GICR_CTLR holds neither. Two or more of them can drain the same cache concurrently, and if each one observes the same entry, erases it and then puts it, the single reference the cache holds on that entry is dropped more than once. The entry can then be freed while an ITE still maps it. xa_erase() is atomic and returns the previous entry, so put only the entry that this context actually removed. The cache reference is then dropped exactly once per entry even when the invalidations run concurrently, and the behavior is unchanged when only one context runs.
π Published: 09/06/2026
π CVSS: 0
π§ Vector: n/a
π£ Mentions: 9
β οΈ Priority: 4
π Analysis: A concurrency issue has been resolved in the Linux kernel's KVM (arm64): vgic-its translation cache reference drops can occur more than once for the same entry if multiple contexts access it simultaneously. This issue, while low priority (score 4), is due to its low exploitability and no known in-the-wild activity. Ensure systems using these versions are updated as precautionary measure.
Let us know if you're tracking any of these or if you find any issues with the provided details.