Daily digest
Monday 2 March 2026
A heavy day: 15 new CVEs, well above the recent average of about 9. Severity skewed high: 1 critical and 8 high, 60% of the total. 4 arrived with exploitation evidence or public exploit code already attached. google was the most-affected vendor with 7.
New this day, ranked by depth score
The 12 that matter most of the 15 published.
CVE-2026-0013High· 8.4PoCIn setupLayout of PickActivity.java, there is a possible way to start any activity as a DocumentsUI app due to a confused deputy
In setupLayout of PickActivity.java, there is a possible way to start any activity as a DocumentsUI app due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User inter…
CVE-2026-0010High· 8.4PoCIn onTransact of IDrmManagerService.cpp, there is a possible out of bounds write due to a missing bounds check
In onTransact of IDrmManagerService.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not need…
CVE-2026-23600Critical· 9.8A remote authentication bypass vulnerability exists in HPE AutoPass License Server (APLS).
A remote authentication bypass vulnerability exists in HPE AutoPass License Server (APLS).
CVE-2026-2256Medium· 6.5PoCMS-Agent vulnerable to Command Injection
MS-Agent vulnerable to Command Injection
CVE-2026-0014Medium· 6.2PoCIn isPackageNullOrSystem of AppOpsService.java, there is a possible persistent denial of service due to improper input validation
In isPackageNullOrSystem of AppOpsService.java, there is a possible persistent denial of service due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User interactio…
CVE-2026-0011High· 8.4In enableSystemPackageLPw of Settings.java, there is a possible way to prevent location access from working due to a logic error in the code
In enableSystemPackageLPw of Settings.java, there is a possible way to prevent location access from working due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed…
CVE-2026-0008High· 8.4In multiple functions of FaceEnroll.kt, there is a possible privilege escalation due to a confused deputy
In multiple functions of FaceEnroll.kt, there is a possible privilege escalation due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed fo…
CVE-2026-0017High· 7.7In onChange of BiometricService.java, there is a possible way to enable fingerprint unlock due to a logic error in the code
In onChange of BiometricService.java, there is a possible way to enable fingerprint unlock due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interactio…
CVE-2026-28795HighOpenChatBI has a Path Traversal Vulnerability in save_report Tool
OpenChatBI has a Path Traversal Vulnerability in save_report Tool
CVE-2026-28438HighCocoIndex Doris target connector didn't verify table name when constructing ALTER TABLE statements
CocoIndex Doris target connector didn't verify table name when constructing ALTER TABLE statements
CVE-2026-27932High· 7.5joserfc's PBES2 p2c Unbounded Iteration Count enables Denial of Service (DoS)
joserfc's PBES2 p2c Unbounded Iteration Count enables Denial of Service (DoS)
CVE-2026-28350Medium· 6.1lxml-html-clean has <base> tag injection through default Cleaner configuration
lxml-html-clean has <base> tag injection through default Cleaner configuration
Most-affected vendors
By CVEs published in the period.