Daily digest
Monday 23 February 2026
6 new CVEs this day, in line with the recent average. Severity skewed high: 4 high, 67% of the total. 2 arrived with exploitation evidence or public exploit code already attached.
New this day, ranked by depth score
The 6 that matter most of the 6 published.
CVE-2026-26331High· 8.8PoCyt-dlp: Arbitrary Command Injection when using the `--netrc-cmd` option
yt-dlp: Arbitrary Command Injection when using the `--netrc-cmd` option
CVE-2026-25747High· 8.8PoCDeserialization of Untrusted Data vulnerability in Apache Camel LevelDB component. The Camel-LevelDB DefaultLevelDBSerializer class deserializes data read from the LevelDB aggregation repository using java.io.ObjectInputStream without a…
Deserialization of Untrusted Data vulnerability in Apache Camel LevelDB component. The Camel-LevelDB DefaultLevelDBSerializer class deserializes data read from the LevelDB aggregation repository using java.io.ObjectInputStream without a…
CVE-2026-2998High· 7.8ERP developed by eAI Technologies has a DLL Hijacking vulnerability, allowing authenticated local attackers to place a crafted DLL file in the same directory as the program, thereby executing arbitrary code.
ERP developed by eAI Technologies has a DLL Hijacking vulnerability, allowing authenticated local attackers to place a crafted DLL file in the same directory as the program, thereby executing arbitrary code.
CVE-2025-14905High· 7.2A flaw was found in the 389-ds-base server
A flaw was found in the 389-ds-base server. A heap buffer overflow vulnerability exists in the `schema_attr_enum_callback` function within the `schema.c` file. This occurs because the code incorrectly calculates the buffer size by summin…
CVE-2026-2970Medium· 4.6datapizza-ai has unsafe deserialization via pickle.loads() in RedisCache
datapizza-ai has unsafe deserialization via pickle.loads() in RedisCache
CVE-2026-2969Medium· 4.7datapizza-ai: Server-Side Template Injection in ChatPromptTemplate via Jinja2 Template Handler
datapizza-ai: Server-Side Template Injection in ChatPromptTemplate via Jinja2 Template Handler
Most-affected vendors
By CVEs published in the period.