Daily digest
Saturday 7 March 2026
A quiet day: only 6 new CVEs against a recent average of about 13. Severity skewed high: 3 high, 50% of the total. One arrived with exploitation evidence or public exploit code already attached.
New this day, ranked by depth score
The 6 that matter most of the 6 published.
CVE-2026-29786Medium· 6.3PoCnode-tar is a full-featured Tar for Node.js
node-tar is a full-featured Tar for Node.js. Prior to version 7.5.10, tar can be tricked into creating a hardlink that points outside the extraction directory by using a drive-relative link target such as C:../target.txt, which enables f…
CVE-2026-33010High· 8.1mcp-memory-service's Wildcard CORS with Credentials Enables Cross-Origin Memory Theft
mcp-memory-service's Wildcard CORS with Credentials Enables Cross-Origin Memory Theft
CVE-2026-24308High· 7.5⚖ disputedImproper handling of configuration values in ZKConfig in Apache ZooKeeper 3.8.5 and 3.9.4 on all platforms allows an attacker to expose sensitive information stored in client configuration in the client's logfile
Improper handling of configuration values in ZKConfig in Apache ZooKeeper 3.8.5 and 3.9.4 on all platforms allows an attacker to expose sensitive information stored in client configuration in the client's logfile. Configuration values ar…
CVE-2026-24281High· 7.4Hostname verification in Apache ZooKeeper ZKTrustManager falls back to reverse DNS (PTR) when IP SAN validation fails, allowing attackers who control or spoof PTR records to impersonate ZooKeeper servers or clients with a valid certifica…
Hostname verification in Apache ZooKeeper ZKTrustManager falls back to reverse DNS (PTR) when IP SAN validation fails, allowing attackers who control or spoof PTR records to impersonate ZooKeeper servers or clients with a valid certifica…
CVE-2026-2671Low· 3.1A vulnerability was detected in Mendi Neurofeedback Headset V4
A vulnerability was detected in Mendi Neurofeedback Headset V4. Affected by this vulnerability is an unknown functionality of the component Bluetooth Low Energy Handler. Performing a manipulation results in cleartext transmission of sens…
CVE-2026-28678NoneRejected reason: Further research determined the issue is not a vulnerability.
Rejected reason: Further research determined the issue is not a vulnerability.
Most-affected vendors
By CVEs published in the period.