VulnSea

Daily digest

Tuesday 10 February 2026

A heavy day: 53 new CVEs, well above the recent average of about 12. Severity skewed high: 33 high, 62% of the total. 3 arrived with exploitation evidence or public exploit code already attached. adobe was the most-affected vendor with 44.

53
New CVEs
0
Critical
0
KEV additions
0
Records changed

New this day, ranked by depth score

The 12 that matter most of the 53 published.

CVE-2025-68686Medium· 5.9CISA KEV
7mo ago

An Exposure of Sensitive Information to an Unauthorized Actor vulnerability [CWE-200] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.1, FortiOS 7.4.0 through 7.4.6, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all…

An Exposure of Sensitive Information to an Unauthorized Actor vulnerability [CWE-200] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.1, FortiOS 7.4.0 through 7.4.6, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all…

▾ Midnightfortinet · fortiosEPSS 30%via NVD
CVE-2026-25890High· 8.1PoC
7mo ago

File Browser has a Path-Based Access Control Bypass via Multiple Leading Slashes in URL

File Browser has a Path-Based Access Control Bypass via Multiple Leading Slashes in URL

▾ Midnightfilebrowser · github.com/filebrowser/filebrowser/v2EPSS 0.56%via OSV
CVE-2026-0651High· 7.8PoC
7mo ago

A path traversal vulnerability was identified TP-Link Tapo C260 v1, D235 v1, C211 v2 and C520WS v2.6 within the HTTP server’s handling of GET requests

A path traversal vulnerability was identified TP-Link Tapo C260 v1, D235 v1, C211 v2 and C520WS v2.6 within the HTTP server’s handling of GET requests. The server performs path normalization before fully decoding URL encoded input and fa…

▾ Midnighttp-link · tapo_c260_firmwareEPSS 0.30%via NVD
CVE-2026-25646High· 8.1
7mo ago

LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files

LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. Prior to 1.6.55, an out-of-bounds read vulnerability exists in the png_set_quantize() API functio…

▾ Twilightlibpng · libpngEPSS 0.66%via NVD
CVE-2026-21357High· 7.8
7mo ago

InDesign Desktop versions 21.1, 20.5.1 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user

InDesign Desktop versions 21.1, 20.5.1 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user inte…

▾ Twilightadobe · indesignEPSS 0.24%via NVD
CVE-2026-21353High· 7.8
7mo ago

DNG SDK versions 1.7.1 2410 and earlier are affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context of the current user

DNG SDK versions 1.7.1 2410 and earlier are affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interactio…

▾ Twilightadobe · dng_software_development_kitEPSS 0.19%via NVD
CVE-2026-21352High· 7.8
7mo ago

DNG SDK versions 1.7.1 2410 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user

DNG SDK versions 1.7.1 2410 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a…

▾ Twilightadobe · dng_software_development_kitEPSS 0.17%via NVD
CVE-2026-21351High· 7.8
7mo ago

After Effects versions 25.6 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user

After Effects versions 25.6 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victi…

▾ Twilightadobe · after_effectsEPSS 0.23%via NVD
CVE-2026-21349High· 7.8
7mo ago

Lightroom Desktop versions 15.1 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user

Lightroom Desktop versions 15.1 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in th…

▾ Twilightadobe · lightroomEPSS 0.15%via NVD
CVE-2026-21347High· 7.8
7mo ago

Bridge versions 15.1.3, 16.0.1 and earlier are affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context of the current user

Bridge versions 15.1.3, 16.0.1 and earlier are affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interac…

▾ Twilightadobe · bridgeEPSS 0.17%via NVD
CVE-2026-21346High· 7.8
7mo ago

Bridge versions 15.1.3, 16.0.1 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user

Bridge versions 15.1.3, 16.0.1 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in tha…

▾ Twilightadobe · bridgeEPSS 0.15%via NVD
CVE-2026-21345High· 7.8
7mo ago

Substance3D - Stager versions 3.1.6 and earlier are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure

Substance3D - Stager versions 3.1.6 and earlier are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this …

▾ Twilightadobe · substance_3d_stagerEPSS 0.17%via NVD

Most-affected vendors

By CVEs published in the period.