Daily digest
Monday 2 February 2026
A heavy day: 22 new CVEs, well above the recent average of about 7. Severity skewed high: 2 critical and 12 high, 64% of the total. One arrived with exploitation evidence or public exploit code already attached. tp-link was the most-affected vendor with 3.
New this day, ranked by depth score
The 12 that matter most of the 22 published.
CVE-2026-22778Critical· 9.8PoCvLLM is an inference and serving engine for large language models (LLMs)
vLLM is an inference and serving engine for large language models (LLMs). From 0.8.3 to before 0.14.1, when an invalid image is sent to vLLM's multimodal endpoint, PIL throws an error. vLLM returns this error to the client, leaking a hea…
CVE-2026-25481CriticalLangroid has WAF Bypass Leading to RCE in TableChatAgent
Langroid has WAF Bypass Leading to RCE in TableChatAgent
CVE-2026-1761High· 8.6A flaw was found in libsoup
A flaw was found in libsoup. This stack-based buffer overflow vulnerability occurs during the parsing of multipart HTTP responses due to an incorrect length calculation. A remote attacker can exploit this by sending a specially crafted m…
CVE-2026-0599High· 7.5Hugging Face Text Generation Inference vulnerable to Uncontrolled Resource Consumption
Hugging Face Text Generation Inference vulnerable to Uncontrolled Resource Consumption
CVE-2026-24737High· 8.1jsPDF is a library to generate PDFs in JavaScript
jsPDF is a library to generate PDFs in JavaScript. Prior to 4.1.0, user control of properties and methods of the Acroform module allows users to inject arbitrary PDF objects, such as JavaScript actions. If given the possibility to pass u…
CVE-2026-1531High· 8.1A flaw was found in foreman_kubevirt
A flaw was found in foreman_kubevirt. When configuring the connection to OpenShift, the system disables SSL verification if a Certificate Authority (CA) certificate is not explicitly set. This insecure default allows a remote attacker, c…
CVE-2026-1530High· 8.1A flaw was found in fog-kubevirt
A flaw was found in fog-kubevirt. This vulnerability allows a remote attacker to perform a Man-in-the-Middle (MITM) attack due to disabled certificate validation. This enables the attacker to intercept and potentially alter sensitive com…
CVE-2026-1117High· 8.2Lollms has an Improper Access Control vulnerability
Lollms has an Improper Access Control vulnerability
CVE-2026-22223High· 8.0An OS Command Injection vulnerability in TP-Link Archer BE230 v1.2 and BE3600 v1 (vpn modules) allows adjacent authenticated attacker execute arbitrary code. Successful exploitation could allow an attacker to gain full administrati…
An OS Command Injection vulnerability in TP-Link Archer BE230 v1.2 and BE3600 v1 (vpn modules) allows adjacent authenticated attacker execute arbitrary code. Successful exploitation could allow an attacker to gain full administrati…
CVE-2026-22221High· 8.0An OS Command Injection vulnerability in TP-Link Archer BE230 v1.2(vpn modules) and BE3600 v1 allows adjacent authenticated attacker execute arbitrary code. Successful exploitation could allow an attacker to gain full administrativ…
An OS Command Injection vulnerability in TP-Link Archer BE230 v1.2(vpn modules) and BE3600 v1 allows adjacent authenticated attacker execute arbitrary code. Successful exploitation could allow an attacker to gain full administrativ…
CVE-2026-0631High· 8.0An OS Command Injection vulnerability in OpenVPN modules in TP-Link Archer BE230 v1.2, BE3600v1 and AXE75 v1 allows an adjacent authenticated attacker to execute arbitrary code. Successful exploitation could allow an attacker to gain…
An OS Command Injection vulnerability in OpenVPN modules in TP-Link Archer BE230 v1.2, BE3600v1 and AXE75 v1 allows an adjacent authenticated attacker to execute arbitrary code. Successful exploitation could allow an attacker to gain…
CVE-2026-53874Highpicklescan missing detection by simple obfuscation of a `builtins.eval` call
picklescan missing detection by simple obfuscation of a `builtins.eval` call
Most-affected vendors
By CVEs published in the period.