Daily digest
Tuesday 3 March 2026
A heavy day: 23 new CVEs, well above the recent average of about 10. Of those, 4 critical and 7 high. rancher was the most-affected vendor with 5.
New this day, ranked by depth score
The 12 that matter most of the 23 published.
CVE-2021-36783Critical· 9.9Rancher doesn't properly sanitize credentials in cluster template answers
Rancher doesn't properly sanitize credentials in cluster template answers
CVE-2021-25320Critical· 9.9Rancher cloud credentials can be used through proxy API by users without access
Rancher cloud credentials can be used through proxy API by users without access
CVE-2026-56315Critical· 9.8PickleScan has multiple stdlib modules with direct RCE not in blocklist
PickleScan has multiple stdlib modules with direct RCE not in blocklist
CVE-2022-31247Critical· 9.1Rancher has downstream cluster privilege escalation through cluster and project role template binding (CRTB/PRTB)
Rancher has downstream cluster privilege escalation through cluster and project role template binding (CRTB/PRTB)
CVE-2026-3437High· 8.8An improper restriction of operations within the bounds of a memory buffer vulnerability in Portwell Engineering Toolkits version 4.8.2 could allow a local authenticated attacker to read and write to arbitrary memory via the Portwell Eng…
An improper restriction of operations within the bounds of a memory buffer vulnerability in Portwell Engineering Toolkits version 4.8.2 could allow a local authenticated attacker to read and write to arbitrary memory via the Portwell Eng…
CVE-2026-27622High· 8.4OpenEXR CompositeDeepScanLine integer-overflow leads to heap OOB write
OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. In CompositeDeepScanLine::readPixels, per-pixel totals are accumulated in vector<unsigned in…
CVE-2023-22648High· 8.0Rancher's Azure AD permission changes are not reflected on active sessions
Rancher's Azure AD permission changes are not reflected on active sessions
CVE-2026-28518High· 7.8OpenViking contains a Path Traversal vulnerability
OpenViking contains a Path Traversal vulnerability
CVE-2026-27905HighBentoML Vulnerable to Arbitrary File Write via Symlink Path Traversal in Tar Extraction
BentoML Vulnerable to Arbitrary File Write via Symlink Path Traversal in Tar Extraction
CVE-2026-25673High· 7.5Django vulnerable to Uncontrolled Resource Consumption
Django vulnerable to Uncontrolled Resource Consumption
CVE-2025-62817High· 7.5An issue was discovered in Samsung Mobile Processor Exynos 1280, 2200, 1380, 1480, 2400, 1580, and 2500
An issue was discovered in Samsung Mobile Processor Exynos 1280, 2200, 1380, 1480, 2400, 1580, and 2500. A NULL pointer dereference of session->ncp_hdr_buf in __pilot_parsing_ncp() causes a denial of service.
CVE-2022-21951Medium· 6.8Rancher's weave CNI password is not configured when a cluster is created from an RKE template
Rancher's weave CNI password is not configured when a cluster is created from an RKE template
Most-affected vendors
By CVEs published in the period.