VulnSea

Daily digest

Tuesday 17 February 2026

9 new CVEs this day, in line with the recent average. Of those, 3 high. 2 arrived with exploitation evidence or public exploit code already attached. CISA added one CVE to the Known Exploited Vulnerabilities catalog.

9
New CVEs
0
Critical
1
KEV additions
0
Records changed

Added to CISA KEV

Confirmed exploitation in the wild — federal remediation deadlines attach to these.

New this day, ranked by depth score

The 9 that matter most of the 9 published.

CVE-2026-26731High· 8.8PoC
7mo ago

TOTOLINK A3002RU V2.1.1-B20211108.1455 was discovered to contain a stack-based buffer overflow via the routernamer`parameter in the formDnsv6 function.

TOTOLINK A3002RU V2.1.1-B20211108.1455 was discovered to contain a stack-based buffer overflow via the routernamer`parameter in the formDnsv6 function.

▾ Midnighttotolink · a3002ru_firmwareEPSS 1.3%via NVD
CVE-2026-24126Medium· 6.6PoC
7mo ago

Weblate has an argument injection in management console

Weblate has an argument injection in management console

▾ Twilightweblate · weblateEPSS 0.47%via OSV
CVE-2026-24734High· 7.5
7mo ago

Improper Input Validation vulnerability in Apache Tomcat Native, Apache Tomcat. When using an OCSP responder, Tomcat Native (and Tomcat's FFM port of the Tomcat Native code) did not complete verification or freshness checks on the OCSP …

Improper Input Validation vulnerability in Apache Tomcat Native, Apache Tomcat. When using an OCSP responder, Tomcat Native (and Tomcat's FFM port of the Tomcat Native code) did not complete verification or freshness checks on the OCSP …

▾ Twilightapache · tomcatEPSS 0.52%via NVD
CVE-2026-25087High· 7.0
7mo ago

Apache Arrow: Potential use-after-free when reading IPC file with pre-buffering

Apache Arrow: Potential use-after-free when reading IPC file with pre-buffering

▾ Twilightpyarrow · pyarrowEPSS 0.82%via OSV
CVE-2026-26057Medium· 6.5
7mo ago

Skill-scanner Unsecured Network Binding Vulnerability

Skill-scanner Unsecured Network Binding Vulnerability

▾ Sunlitcisco-ai-skill-scanner · cisco-ai-skill-scannerEPSS 0.45%via OSV
CVE-2026-25739Medium· 5.4
7mo ago

Indico Affected by Cross-Site-Scripting via material uploads

Indico Affected by Cross-Site-Scripting via material uploads

▾ Sunlitindico · indicoEPSS 0.29%via OSV
CVE-2026-25738Medium
7mo ago

Indico has Server-Side Request Forgery (SSRF) in multiple places

Indico has Server-Side Request Forgery (SSRF) in multiple places

▾ Sunlitindico · indicoEPSS 0.33%via OSV
MAL-2026-931None
7mo ago

Malicious code in telebot-infe (PyPI)

Malicious code in telebot-infe (PyPI)

▾ Sunlittelebot-infe · telebot-infevia OSV
MAL-2026-930None
7mo ago

Malicious code in telebot-info (PyPI)

Malicious code in telebot-info (PyPI)

▾ Sunlittelebot-info · telebot-infovia OSV

Most-affected vendors

By CVEs published in the period.