Daily digest
Wednesday 25 February 2026
A heavy day: 22 new CVEs, well above the recent average of about 10. Of those, 3 critical and 6 high. 6 arrived with exploitation evidence or public exploit code already attached. rucio-webui was the most-affected vendor with 6.
New this day, ranked by depth score
The 12 that matter most of the 22 published.
CVE-2026-27577Critical· 9.9PoCn8n is an open source workflow automation platform
n8n is an open source workflow automation platform. Prior to versions 2.10.1, 2.9.3, and 1.123.22, additional exploits in the expression evaluation of n8n have been identified and patched following CVE-2025-68613. An authenticated user w…
CVE-2026-27727Critical· 9.8PoCmchange-commons-java, a library that provides Java utilities, includes code that mirrors early implementations of JNDI functionality, including support for remote `factoryClassLocation` values, by which code can be downloaded and invoked…
mchange-commons-java, a library that provides Java utilities, includes code that mirrors early implementations of JNDI functionality, including support for remote `factoryClassLocation` values, by which code can be downloaded and invoked…
CVE-2026-27606Critical· 9.8PoCRollup is a module bundler for JavaScript
Rollup is a module bundler for JavaScript. Versions prior to 2.80.0, 3.30.0, and 4.59.0 of the Rollup module bundler (specifically v4.x and present in current source) is vulnerable to an Arbitrary File Write via Path Traversal. Insecure …
CVE-2026-27696High· 8.6changedetection.io is Vulnerable to SSRF via Watch URLs
changedetection.io is Vulnerable to SSRF via Watch URLs
CVE-2026-27645Medium· 6.1PoCchangedetection.io Vulnerable to Reflected XSS in RSS Single Watch Error Response
changedetection.io Vulnerable to Reflected XSS in RSS Single Watch Error Response
CVE-2026-27608High· 8.1Parse Dashboard is a standalone dashboard for managing Parse Server apps
Parse Dashboard is a standalone dashboard for managing Parse Server apps. In versions 7.3.0-alpha.42 through 9.0.0-alpha.7, the AI Agent API endpoint (`POST /apps/:appId/agent`) does not enforce authorization. Authenticated users scoped …
CVE-2026-25136High· 8.1Rucio WebUI has a Reflected Cross-site Scripting Vulnerability
Rucio WebUI has a Reflected Cross-site Scripting Vulnerability
CVE-2026-26986Medium· 5.5PoCFreeRDP has heap-use-after-free in rail_window_free
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.23.0, `rail_window_free` dereferences a freed `xfAppWindow` pointer during `HashTable_Free` cleanup because `xf_rail_window_common` calls `free(appWindow…
CVE-2026-27628High· 7.5pypdf: possible infinite loop when loading circular /Prev entries in cross-reference streams (CVE-2026-27628)
A flaw was found in pypdf. Processing a specially crafted PDF document, specifically with circular /Prev references in the cross-reference (xref) chain, can cause an infinite loop and a high consumption of CPU, resulting in a denial of ser…
CVE-2026-27595High· 7.5Parse Dashboard is a standalone dashboard for managing Parse Server apps
Parse Dashboard is a standalone dashboard for managing Parse Server apps. In versions 7.3.0-alpha.42 through 9.0.0-alpha.7, the AI Agent API endpoint (POST `/apps/:appId/agent`) has multiple security vulnerabilities that, when chained, a…
CVE-2026-25733High· 7.3Rucio WebUI Vulnerable to Stored Cross-site Scripting (XSS) through Custom Rule Function
Rucio WebUI Vulnerable to Stored Cross-site Scripting (XSS) through Custom Rule Function
CVE-2026-26717Medium· 4.8PoCOpenFUN Richie Observable Timing Discrepancy in its sync_course_run_from_request function
OpenFUN Richie Observable Timing Discrepancy in its sync_course_run_from_request function
Most-affected vendors
By CVEs published in the period.