VulnSea

Daily digest

Thursday 26 February 2026

A heavy day: 20 new CVEs, well above the recent average of about 11. Of those, 1 critical and 3 high. One arrived with exploitation evidence or public exploit code already attached. arcinfo was the most-affected vendor with 7.

20
New CVEs
1
Critical
0
KEV additions
0
Records changed

New this day, ranked by depth score

The 12 that matter most of the 20 published.

CVE-2026-27941Critical· 9.9PoC
7mo ago

OpenLIT is an open source platform for AI engineering. Prior to version 1.37.1, several GitHub Actions workflows in OpenLIT's GitHub repo…

OpenLIT is an open source platform for AI engineering. Prior to version 1.37.1, several GitHub Actions workflows in OpenLIT's GitHub repository use the `pull_request_target` event while checking out and executing untrusted code from fork…

▾ Abyssalopenlit · openlitEPSS 0.57%via OSV
CVE-2026-27830High· 8.0
7mo ago

c3p0, a JDBC Connection pooling library, is vulnerable to attack via maliciously crafted Java-serialized objects and `javax.naming.Reference` instances

c3p0, a JDBC Connection pooling library, is vulnerable to attack via maliciously crafted Java-serialized objects and `javax.naming.Reference` instances. Several c3p0 `ConnectionPoolDataSource` implementations have a property called `user…

▾ Twilightswaldman · c3p0EPSS 2.1%via NVD
CVE-2026-1693High· 7.5
7mo ago

The OAuth grant type Resource Owner Password Credentials (ROPC) flow is still used by the werbservices used by the WebVue, WebScheduler, TouchVue and Snapvue features of PcVue in version 12.0.0 through 16.3.3 included despite being depre…

The OAuth grant type Resource Owner Password Credentials (ROPC) flow is still used by the werbservices used by the WebVue, WebScheduler, TouchVue and Snapvue features of PcVue in version 12.0.0 through 16.3.3 included despite being depre…

▾ Twilightarcinfo · pcvueEPSS 0.32%via NVD
CVE-2026-27896High· 7.0
7mo ago

MCP Go SDK Vulnerable to Improper Handling of Case Sensitivity

The Go MCP SDK used Go's standard encoding/json.Unmarshal for JSON-RPC and MCP protocol message parsing in versions prior to 1.3.1. Go's standard library performs case-insensitive matching of JSON keys to struct field tags — a field tagg…

▾ Twilightmodelcontextprotocol · go-sdkEPSS 0.46%via CVEORG
CVE-2026-23939Medium· 6.9
7mo ago

Path Traversal in Local File Store Backend

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in hexpm hexpm/hexpm ('Elixir.Hexpm.Store.Local' module) allows Relative Path Traversal. This vulnerability is associated with program files lib…

▾ Sunlithexpm · hexpm/hexpmEPSS 0.43%via CVEORG
CVE-2026-1697Medium· 6.5
7mo ago

The Secure and SameSite attribute are missing in the GraphicalData web services and WebClient web app of PcVue in version 12.0.0 through 16.3.3 included.

The Secure and SameSite attribute are missing in the GraphicalData web services and WebClient web app of PcVue in version 12.0.0 through 16.3.3 included.

▾ Sunlitarcinfo · pcvueEPSS 0.12%via NVD
CVE-2026-1698Medium· 6.1
7mo ago

A HTTP Host header attack vulnerability affects WebClient and the WebScheduler web apps of PcVue in version 15.0.0 through 16.3.3 included, allowing a remote attacker to inject harmful payloads that manipulate server-side behavior. This…

A HTTP Host header attack vulnerability affects WebClient and the WebScheduler web apps of PcVue in version 15.0.0 through 16.3.3 included, allowing a remote attacker to inject harmful payloads that manipulate server-side behavior. This…

▾ Sunlitarcinfo · pcvueEPSS 0.21%via NVD
CVE-2026-1696Medium· 6.1
7mo ago

Some HTTP security headers are not properly set by the web server when sending responses to the client application.

Some HTTP security headers are not properly set by the web server when sending responses to the client application.

▾ Sunlitarcinfo · pcvueEPSS 0.15%via NVD
CVE-2026-1695Medium· 6.1
7mo ago

An XSS vulnerability affects the OAuth web services used by the WebVue, WebScheduler, TouchVue and SnapVue features of PcVue in version 12.0.0 through 16.3.3 included

An XSS vulnerability affects the OAuth web services used by the WebVue, WebScheduler, TouchVue and SnapVue features of PcVue in version 12.0.0 through 16.3.3 included. It might allow a remote attacker to trick a legitimate user into load…

▾ Sunlitarcinfo · pcvueEPSS 0.21%via NVD
CVE-2026-1692Medium· 6.1
7mo ago

A missing origin validation in WebSockets vulnerability affects the GraphicalData web services used by the WebVue, WebScheduler, TouchVue and SnapVue features of PcVue in version 12.0.0 through 16.3.3 included

A missing origin validation in WebSockets vulnerability affects the GraphicalData web services used by the WebVue, WebScheduler, TouchVue and SnapVue features of PcVue in version 12.0.0 through 16.3.3 included. It might allow a remote at…

▾ Sunlitarcinfo · pcvueEPSS 0.11%via NVD
CVE-2026-27948Medium· 5.4
7mo ago

Copyparty vulnerable to reflected XSS via setck parameter

Copyparty vulnerable to reflected XSS via setck parameter

▾ Sunlitcopyparty · copypartyEPSS 0.27%via OSV
CVE-2026-27888Medium
7mo ago

pypdf: Manipulated FlateDecode XFA streams can exhaust RAM

pypdf: Manipulated FlateDecode XFA streams can exhaust RAM

▾ Sunlitpypdf · pypdfEPSS 0.64%via OSV

Most-affected vendors

By CVEs published in the period.