Daily digest
Monday 26 January 2026
A busier-than-usual day with 13 new CVEs (recent average about 11). Of those, 5 high. 2 arrived with exploitation evidence or public exploit code already attached. CISA added 3 CVEs to the Known Exploited Vulnerabilities catalog.
Added to CISA KEV
Confirmed exploitation in the wild — federal remediation deadlines attach to these.
CVE-2026-23760Critical· 9.8CISA KEVPoCSmarterTools SmarterMail versions prior to build 9511 contain an authentication bypass vulnerability in the password reset API
SmarterTools SmarterMail versions prior to build 9511 contain an authentication bypass vulnerability in the password reset API. The force-reset-password endpoint permits anonymous requests and fails to verify the existing password or a r…
CVE-2026-24061Critical· 9.8CISA KEVPoCtelnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment variable.
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment variable.
CVE-2026-21509High· 7.8CISA KEV0dayPoCReliance on untrusted inputs in a security decision in Microsoft Office allows an unauthorized attacker to bypass a security feature locally.
Reliance on untrusted inputs in a security decision in Microsoft Office allows an unauthorized attacker to bypass a security feature locally.
New this day, ranked by depth score
The 12 that matter most of the 13 published.
CVE-2026-21509High· 7.8CISA KEV0dayPoCReliance on untrusted inputs in a security decision in Microsoft Office allows an unauthorized attacker to bypass a security feature locally.
Reliance on untrusted inputs in a security decision in Microsoft Office allows an unauthorized attacker to bypass a security feature locally.
CVE-2025-14459High· 8.5A flaw was found in KubeVirt Containerized Data Importer (CDI)
A flaw was found in KubeVirt Containerized Data Importer (CDI). This vulnerability allows a user to clone PersistentVolumeClaims (PVCs) from unauthorized namespaces, resulting in unauthorized access to data via the DataImportCron PVC sou…
CVE-2026-24490High· 8.1MobSF has Stored XSS via Manifest Analysis - Dialer Code Host Field
MobSF has Stored XSS via Manifest Analysis - Dialer Code Host Field
CVE-2026-23864High· 7.5Multiple denial of service vulnerabilities exist in React Server Components, affecting the following packages: react-server-dom-parcel, react-server-dom-turbopack, react-server-dom-webpack. The vulnerabilities are triggered by sending s…
Multiple denial of service vulnerabilities exist in React Server Components, affecting the following packages: react-server-dom-parcel, react-server-dom-turbopack, react-server-dom-webpack. The vulnerabilities are triggered by sending s…
CVE-2026-24123High· 7.4BentoML has a Path Traversal via Bentofile Configuration
BentoML has a Path Traversal via Bentofile Configuration
CVE-2026-24688MediumPoCpypdf has possible Infinite Loop when processing outlines/bookmarks
pypdf has possible Infinite Loop when processing outlines/bookmarks
CVE-2025-14525Medium· 6.4A flaw was found in kubevirt
A flaw was found in kubevirt. A user within a virtual machine (VM), if the guest agent is active, can exploit this by causing the agent to report an excessive number of network interfaces. This action can overwhelm the system's ability t…
CVE-2025-11687Medium· 6.1GI-DocGen vulnerable to Reflected XSS via unescaped query strings
GI-DocGen vulnerable to Reflected XSS via unescaped query strings
CVE-2026-24489Medium· 5.3Gakido vulnerable to HTTP Header Injection (CRLF Injection)
Gakido vulnerable to HTTP Header Injection (CRLF Injection)
CVE-2025-11065Medium· 5.3A flaw was found in github.com/go-viper/mapstructure/v2, in the field processing component using mapstructure.WeakDecode
A flaw was found in github.com/go-viper/mapstructure/v2, in the field processing component using mapstructure.WeakDecode. This vulnerability allows information disclosure through detailed error messages that may leak sensitive input valu…
CVE-2025-9820Medium· 4.0A flaw was found in the GnuTLS library, specifically in the gnutls_pkcs11_token_init() function that handles PKCS#11 token initialization
A flaw was found in the GnuTLS library, specifically in the gnutls_pkcs11_token_init() function that handles PKCS#11 token initialization. When a token label longer than expected is processed, the function writes past the end of a fixed-…
CVE-2025-9615Low· 3.3A flaw was found in NetworkManager
A flaw was found in NetworkManager. The NetworkManager package allows access to files that may belong to other users. NetworkManager allows non-root users to configure the system's network. The daemon runs with root privileges and can ac…
Most-affected vendors
By CVEs published in the period.