Daily digest
Friday 13 February 2026
A quiet day: only 4 new CVEs against a recent average of about 17. Severity skewed high: 2 high, 50% of the total. 2 arrived with exploitation evidence or public exploit code already attached.
New this day, ranked by depth score
The 4 that matter most of the 4 published.
CVE-2026-2441High· 8.8CISA KEVPoCUse after free in CSS in Google Chrome prior to 145.0.7632.75 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page
Use after free in CSS in Google Chrome prior to 145.0.7632.75 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
CVE-2026-23111High· 7.8PoCIn the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: fix inverted genmask check in nft_map_catchall_activate() nft_map_catchall_activate() has an inverted element activity check compared to its non-…
In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: fix inverted genmask check in nft_map_catchall_activate() nft_map_catchall_activate() has an inverted element activity check compared to its non-…
GHSA-27jp-wm6q-gp25Mediumsqlparse: formatting list of tuples leads to denial of service
sqlparse: formatting list of tuples leads to denial of service
CVE-2026-0872NoneImproper Certificate Validation vulnerability in Thales SafeNet Agent for Windows Logon on Windows allows Signature Spoofing by Improper Validation. This issue affects SafeNet Agent for Windows Logon: 4.0.0, 4.1.1, 4.1.2.
Improper Certificate Validation vulnerability in Thales SafeNet Agent for Windows Logon on Windows allows Signature Spoofing by Improper Validation. This issue affects SafeNet Agent for Windows Logon: 4.0.0, 4.1.1, 4.1.2.
Most-affected vendors
By CVEs published in the period.