Daily digest
Friday 6 February 2026
9 new CVEs this day, in line with the recent average. Severity skewed high: 2 critical and 4 high, 67% of the total. 2 arrived with exploitation evidence or public exploit code already attached.
New this day, ranked by depth score
The 9 that matter most of the 9 published.
CVE-2026-1709Critical· 9.4A flaw was found in Keylime
A flaw was found in Keylime. The Keylime registrar, since version 7.12.0, does not enforce client-side Transport Layer Security (TLS) authentication. This authentication bypass vulnerability allows unauthenticated clients with network ac…
GHSA-4f84-67cv-qrv3CriticalA single post-release of dydx-v4-client contained obfuscated multi-stage loader
A single post-release of dydx-v4-client contained obfuscated multi-stage loader
CVE-2026-25580High· 8.6Pydantic AI is a Python agent framework for building applications and workflows with Generative AI
Pydantic AI is a Python agent framework for building applications and workflows with Generative AI. From 0.0.26 to before 1.56.0, aServer-Side Request Forgery (SSRF) vulnerability exists in Pydantic AI's URL download functionality. When …
CVE-2026-2015Medium· 6.3PoCA weakness has been identified in Portabilis i-Educar up to 2.10
A weakness has been identified in Portabilis i-Educar up to 2.10. Affected is an unknown function of the file FinalStatusImportService.php of the component Final Status Import. Executing a manipulation of the argument school_id can lead …
CVE-2026-1337Medium· 5.4PoCInsufficient escaping of unicode characters in query log in Neo4j Enterprise and Community editions prior to 2026.01 can lead to XSS if the user opens the logs in a tool that treats them as HTML
Insufficient escaping of unicode characters in query log in Neo4j Enterprise and Community editions prior to 2026.01 can lead to XSS if the user opens the logs in a tool that treats them as HTML. There is no security impact on Neo4j prod…
CVE-2026-25793HighBlocklist Bypass possible via ECDSA Signature Malleability
Blocklist Bypass possible via ECDSA Signature Malleability
CVE-2026-25650HighMCP-Salesforce's arbitrary attribute access leads to disclosure of Salesforce auth token
MCP-Salesforce's arbitrary attribute access leads to disclosure of Salesforce auth token
CVE-2026-25640High· 7.1Pydantic AI is a Python agent framework for building applications and workflows with Generative AI
Pydantic AI is a Python agent framework for building applications and workflows with Generative AI. From 1.34.0 to before 1.51.0, a path traversal vulnerability in the Pydantic AI web UI allows an attacker to serve arbitrary JavaScript …
CVE-2025-13818Medium· 6.7Local privilege escalation vulnerability via insecure temporary batch file execution in ESET Management Agent
Local privilege escalation vulnerability via insecure temporary batch file execution in ESET Management Agent
Most-affected vendors
By CVEs published in the period.