Daily digest
Tuesday 24 February 2026
A heavy day: 13 new CVEs, well above the recent average of about 8. Of those, 1 critical and 5 high. 2 arrived with exploitation evidence or public exploit code already attached. apache-superset was the most-affected vendor with 5.
New this day, ranked by depth score
The 12 that matter most of the 13 published.
CVE-2026-27483High· 8.8PoCMindsDB: Path Traversal in /api/files Leading to Remote Code Execution
MindsDB: Path Traversal in /api/files Leading to Remote Code Execution
CVE-2026-2771Critical· 9.8Undefined behavior in the DOM: Core & HTML component
Undefined behavior in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.
CVE-2024-56373High· 8.4Apache Airflow vulnerable to Code Injection in the web-server context via LogTemplate table
Apache Airflow vulnerable to Code Injection in the web-server context via LogTemplate table
CVE-2026-25968High· 7.4ImageMagick is free and open-source software used for editing and manipulating digital images
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, a stack buffer overflow occurs when processing the an attribute in msl.c. A long value overflows a f…
CVE-2026-23984HighApache Superset: Read-Only Bypass via Improper Input Validation on PostgreSQL Connections
Apache Superset: Read-Only Bypass via Improper Input Validation on PostgreSQL Connections
CVE-2026-23982HighApache Superset Improper Authorization allows low-privileged users to bypass access controls
Apache Superset Improper Authorization allows low-privileged users to bypass access controls
CVE-2026-23980MediumPoCApache Superset allows privileged users to conduct error-based SQL Injection
Apache Superset allows privileged users to conduct error-based SQL Injection
CVE-2025-27555Medium· 6.5Apache Airflow exposes sensitive information in its log files
Apache Airflow exposes sensitive information in its log files
CVE-2026-27469Medium· 6.1Isso affected by Stored XSS via comment website field
Isso affected by Stored XSS via comment website field
CVE-2026-27156Medium· 6.1NiceGUI vulnerable to XSS via Code Injection during client-side element function execution
NiceGUI vulnerable to XSS via Code Injection during client-side element function execution
CVE-2026-25969Medium· 5.3ImageMagick is free and open-source software used for editing and manipulating digital images
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.2-15, a memory leak exists in `coders/ashlar.c`. The `WriteASHLARImage` allocates a structure. However, when an exceptio…
CVE-2026-23969MediumApache Superset: Incomplete DISALLOWED_SQL_FUNCTIONS default list for ClickHouse engine
Apache Superset: Incomplete DISALLOWED_SQL_FUNCTIONS default list for ClickHouse engine
Most-affected vendors
By CVEs published in the period.