Newly released CVEs across every platform — sleek to read, verbose on demand, and served raw as markdown for AI and agent ingestion. Severity reads as depth: the deeper the contact, the graver the threat.
Depth = severity + exploitation
CVE-2026-76239Medium· 6.3stigmem-node has blind SSRF via unvalidated webhook subscription delivery_address
GHSA-5p3m-vhh6-9236Medium· 6.3stigmem-node has blind SSRF via unvalidated webhook subscription delivery_address
CVE-2026-76245Highstigmem (pip package stigmem-node) version 0.9.0a1 contains a timestamp-handling mismatch in federation peer-token validation that can cause valid peer tokens to be incorrectly treated as expired. This affects the availability and reliab…
CVE-2026-76236Highstigmem-node before 0.9.0a12 contains a cross-tenant broken object level authorization (BOLA) flaw in the RTBF (right-to-be-forgotten) tombstone mechanism. issue_tombstone defaulted the tenant to "default" instead of the caller's tenant,…
CVE-2026-76241Highstigmem-node 0.9.0a1 allows plugin signature enforcement to be disabled via a single configuration flag without a second explicit acknowledgment. If that setting is carried into an environment where plugin directories are writable by les…
CVE-2026-76244Criticalstigmem-node contains an insecure default configuration vulnerability that allows federation traffic to traverse networks without mTLS protection when non-loopback endpoints are enabled. Operators who explicitly disabled mTLS while bindi…
CVE-2026-76242Criticalstigmem-node 0.9.0a1 accepts federation peer key material during peer registration without a separate administrator out-of-band fingerprint approval step. On nodes that accept federation peer registration over a network where initial reg…
CVE-2026-76240Highstigmem-node 0.9.0a1 interpolates Postgres backend schema identifiers into SQL strings without defensive quoting. In the affected code path the schema value is operator-controlled, but the unsafe pattern could allow SQL injection if a sc…
CVE-2026-76237Highstistigmem-node: quarantine review surface exposes and mutates other tenants' quarantined facts (cross-tenant BOLA)
CVE-2026-76238Highstigmem-node: decay sweep expires and counts facts across all tenants (cross-tenant BOLA)
GHSA-x26h-xmv8-gxf7Highstigmem-node: RTBF tombstones are mis-attributed and suppress reads tenant-blind (cross-tenant BOLA)
GHSA-xhv3-q4xx-349rHighstistigmem-node: quarantine review surface exposes and mutates other tenants' quarantined facts (cross-tenant BOLA)
GHSA-6gqw-jqv7-v88mHighstigmem-node: decay sweep expires and counts facts across all tenants (cross-tenant BOLA)
CVE-2026-76243Criticalstigmem-node: Auth-disabled deployments may grant broad anonymous access outside loopback
A summary of everything that shipped over the last two weeks — the whole corpus is open, agents get change feeds, alias resolution and EPSS movers, and the data now includes CVE.org, vendor CSAF, aggregated exploits and per-source scores.
A step-by-step guide to plugging VulnSea into automated and agentic workflows — poll the delta, triage without burning tokens, match an SBOM, and let an MCP-native model do the reasoning.
CVE and 0day intelligence that reads like an instrument — built for analysts and AI agents alike. Here's what it does and where it's going.