Daily digest
Friday 20 February 2026
7 new CVEs this day, in line with the recent average. Severity skewed high: 1 critical and 4 high, 71% of the total. 2 arrived with exploitation evidence or public exploit code already attached.
New this day, ranked by depth score
The 7 that matter most of the 7 published.
CVE-2026-2635High· 7.30day⚖ disputedMLflow Use of Default Password Authentication Bypass Vulnerability
MLflow Use of Default Password Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of MLflow. Authentication is not required to exploit this vulnerability. T…
CVE-2026-25896Critical· 9.3PoC⚖ disputedfast-xml-parser allows users to validate XML, parse XML to JS object, or build XML from JS object without C/C++ based libraries and no callback
fast-xml-parser allows users to validate XML, parse XML to JS object, or build XML from JS object without C/C++ based libraries and no callback. From 4.1.3to before 5.3.5, a dot (.) in a DOCTYPE entity name is treated as a regex wildcard…
CVE-2026-2472HighPoCGoogle Cloud Vertex AI SDK affected by Stored Cross-Site Scripting (XSS)
Google Cloud Vertex AI SDK affected by Stored Cross-Site Scripting (XSS)
CVE-2026-2473HighGoogle Cloud Vertex AI has a a vulnerability involving predictable bucket naming
Google Cloud Vertex AI has a a vulnerability involving predictable bucket naming
CVE-2019-25434High· 7.5SpotAuditor 5.3.1.0 contains a denial of service vulnerability that allows unauthenticated attackers to crash the application by submitting excessive data in the registration name field
SpotAuditor 5.3.1.0 contains a denial of service vulnerability that allows unauthenticated attackers to crash the application by submitting excessive data in the registration name field. Attackers can enter a large string of characters (…
CVE-2026-27482Medium· 5.9Ray dashboard DELETE endpoints allow unauthenticated browser-triggered DoS (Serve shutdown / job deletion)
Ray dashboard DELETE endpoints allow unauthenticated browser-triggered DoS (Serve shutdown / job deletion)
CVE-2026-21620NoneRelative Path Traversal, Improper Isolation or Compartmentalization vulnerability in erlang otp erlang/otp (tftp_file modules), erlang otp inets (tftp_file modules), erlang otp tftp (tftp_file modules) allows Relative Path Traversal
Relative Path Traversal, Improper Isolation or Compartmentalization vulnerability in erlang otp erlang/otp (tftp_file modules), erlang otp inets (tftp_file modules), erlang otp tftp (tftp_file modules) allows Relative Path Traversal. Thi…
Most-affected vendors
By CVEs published in the period.