Daily digest
Tuesday 17 February 2026
9 new CVEs this day, in line with the recent average. Of those, 3 high. 2 arrived with exploitation evidence or public exploit code already attached. CISA added one CVE to the Known Exploited Vulnerabilities catalog.
Added to CISA KEV
Confirmed exploitation in the wild — federal remediation deadlines attach to these.
New this day, ranked by depth score
The 9 that matter most of the 9 published.
CVE-2026-26731High· 8.8PoCTOTOLINK A3002RU V2.1.1-B20211108.1455 was discovered to contain a stack-based buffer overflow via the routernamer`parameter in the formDnsv6 function.
TOTOLINK A3002RU V2.1.1-B20211108.1455 was discovered to contain a stack-based buffer overflow via the routernamer`parameter in the formDnsv6 function.
CVE-2026-24126Medium· 6.6PoCWeblate has an argument injection in management console
Weblate has an argument injection in management console
CVE-2026-24734High· 7.5Improper Input Validation vulnerability in Apache Tomcat Native, Apache Tomcat. When using an OCSP responder, Tomcat Native (and Tomcat's FFM port of the Tomcat Native code) did not complete verification or freshness checks on the OCSP …
Improper Input Validation vulnerability in Apache Tomcat Native, Apache Tomcat. When using an OCSP responder, Tomcat Native (and Tomcat's FFM port of the Tomcat Native code) did not complete verification or freshness checks on the OCSP …
CVE-2026-25087High· 7.0Apache Arrow: Potential use-after-free when reading IPC file with pre-buffering
Apache Arrow: Potential use-after-free when reading IPC file with pre-buffering
CVE-2026-26057Medium· 6.5Skill-scanner Unsecured Network Binding Vulnerability
Skill-scanner Unsecured Network Binding Vulnerability
CVE-2026-25739Medium· 5.4Indico Affected by Cross-Site-Scripting via material uploads
Indico Affected by Cross-Site-Scripting via material uploads
CVE-2026-25738MediumIndico has Server-Side Request Forgery (SSRF) in multiple places
Indico has Server-Side Request Forgery (SSRF) in multiple places
MAL-2026-931NoneMalicious code in telebot-infe (PyPI)
Malicious code in telebot-infe (PyPI)
MAL-2026-930NoneMalicious code in telebot-info (PyPI)
Malicious code in telebot-info (PyPI)
Most-affected vendors
By CVEs published in the period.