Daily digest
Friday 27 February 2026
A quiet day: only 5 new CVEs against a recent average of about 11. Severity skewed high: 2 critical and 1 high, 60% of the total.
New this day, ranked by depth score
The 5 that matter most of the 5 published.
CVE-2026-21660Critical· 9.8A Hardcoded Email Credentials Saved as Plaintext in Firmware (CWE-256: Plaintext Storage of a Password) vulnerability in Frick Controls Quantum HD version 10.22 and prior lead to unauthorized access, exposure of sensitive information, an…
A Hardcoded Email Credentials Saved as Plaintext in Firmware (CWE-256: Plaintext Storage of a Password) vulnerability in Frick Controls Quantum HD version 10.22 and prior lead to unauthorized access, exposure of sensitive information, an…
CVE-2026-28231Critical· 9.1pillow_heif is a Python library for working with HEIF images and plugin for Pillow. Prior to version 1.3.0, an integer overflow in the en…
pillow_heif is a Python library for working with HEIF images and plugin for Pillow. Prior to version 1.3.0, an integer overflow in the encode path buffer validation of `_pillow_heif.c` allows an attacker to bypass bounds checks by provid…
CVE-2025-10990High· 7.5A flaw was found in REXML
A flaw was found in REXML. A remote attacker could exploit inefficient regular expression (regex) parsing when processing hex numeric character references (&#x...;) in XML documents. This could lead to a Regular Expression Denial of Serv…
GHSA-747p-wmpv-9c78Medium· 5.9AWS CLI: cli_history database does not restrict file permissions on Unix systems
AWS CLI: cli_history database does not restrict file permissions on Unix systems
CVE-2025-12150Low· 3.1A flaw was found in Keycloak’s WebAuthn registration component
A flaw was found in Keycloak’s WebAuthn registration component. This vulnerability allows an attacker to bypass the configured attestation policy and register untrusted or forged authenticators via submission of an attestation object wit…
Most-affected vendors
By CVEs published in the period.