Daily digest
Wednesday 21 January 2026
16 new CVEs this day, in line with the recent average. Of those, 1 critical and 5 high. 3 arrived with exploitation evidence or public exploit code already attached.
New this day, ranked by depth score
The 12 that matter most of the 16 published.
CVE-2026-24061Critical· 9.8CISA KEVPoCtelnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment variable.
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment variable.
CVE-2026-22807High· 8.8PoCvLLM is an inference and serving engine for large language models (LLMs)
vLLM is an inference and serving engine for large language models (LLMs). Starting in version 0.10.1 and prior to version 0.14.0, vLLM loads Hugging Face `auto_map` dynamic modules during model resolution without gating on `trust_remote_…
CVE-2026-22822High· 8.8External Secrets Operator reads information from a third-party service and automatically injects the values as Kubernetes Secrets
External Secrets Operator reads information from a third-party service and automatically injects the values as Kubernetes Secrets. Starting in version 0.20.2 and prior to version 1.2.0, the `getSecretKey` template function, while introd…
CVE-2025-13878High· 7.5Malformed BRID/HHIT records can cause `named` to terminate unexpectedly. This issue affects BIND 9 versions 9.18.40 through 9.18.43, 9.20.13 through 9.20.17, 9.21.12 through 9.21.16, 9.18.40-S1 through 9.18.43-S1, and 9.20.13-S1 through …
Malformed BRID/HHIT records can cause `named` to terminate unexpectedly. This issue affects BIND 9 versions 9.18.40 through 9.18.43, 9.20.13 through 9.20.17, 9.21.12 through 9.21.16, 9.18.40-S1 through 9.18.43-S1, and 9.20.13-S1 through …
CVE-2025-13465Medium· 5.3PoCLodash versions 4.0.0 through 4.17.22 are vulnerable to prototype pollution in the _.unset and _.omit functions
Lodash versions 4.0.0 through 4.17.22 are vulnerable to prototype pollution in the _.unset and _.omit functions. An attacker can pass crafted paths which cause Lodash to delete methods from global prototypes. The issue permits deletion …
CVE-2026-24046High· 7.1Backstage is an open framework for building developer portals
Backstage is an open framework for building developer portals. Multiple Scaffolder actions and archive extraction utilities were vulnerable to symlink-based path traversal attacks. An attacker with access to create and execute Scaffolder…
CVE-2026-23986High· 7.1Copier safe template has arbitrary filesystem write access via directory symlinks when _preserve_symlinks: true
Copier safe template has arbitrary filesystem write access via directory symlinks when _preserve_symlinks: true
CVE-2026-23946Medium· 6.8Tendenci Affected by Authenticated Remote Code Execution via Pickle Deserialization
Tendenci Affected by Authenticated Remote Code Execution via Pickle Deserialization
CVE-2026-23968Medium· 5.5Copier safe template has arbitrary filesystem read access via symlinks when _preserve_symlinks: false
Copier safe template has arbitrary filesystem read access via symlinks when _preserve_symlinks: false
CVE-2026-23960Medium· 5.4Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes
Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. Prior to versions 3.6.17 and 3.7.8, stored XSS in the artifact directory listing allows any workflow author to execute arbit…
CVE-2026-23990Medium· 5.3Flux Operator Web UI Impersonation Bypass via Empty OIDC Claims
Flux Operator Web UI Impersonation Bypass via Empty OIDC Claims
CVE-2026-23849Medium· 5.3File Browser Vulnerable to Username Enumeration via Timing Attack in /api/login
File Browser Vulnerable to Username Enumeration via Timing Attack in /api/login
Most-affected vendors
By CVEs published in the period.