Daily digest
Monday 9 March 2026
8 new CVEs this day, in line with the recent average. Severity skewed high: 1 critical and 4 high, 63% of the total. 5 arrived with exploitation evidence or public exploit code already attached.
New this day, ranked by depth score
The 8 that matter most of the 8 published.
CVE-2025-69219High· 8.8PoCApache Airflow Providers Http has Unsafe Pickle Deserializatio leading to RCE via HttpOperator
Apache Airflow Providers Http has Unsafe Pickle Deserializatio leading to RCE via HttpOperator
CVE-2026-0846High· 8.6PoCArbitrary File Read via Absolute Path Input in nltk.util.filestring()
A vulnerability in the `filestring()` function of the `nltk.util` module in nltk version 3.9.2 allows arbitrary file read due to improper validation of input paths. The function directly opens files specified by user input without saniti…
CVE-2026-3823Critical· 9.8EHG2408 series switch developed by Atop Technologies has a Stack-based Buffer Overflow vulnerability, allowing unauthenticated remote attackers to control the program's execution flow and execute arbitrary code.
EHG2408 series switch developed by Atop Technologies has a Stack-based Buffer Overflow vulnerability, allowing unauthenticated remote attackers to control the program's execution flow and execute arbitrary code.
CVE-2026-30928HighPoCGlances Exposes Unauthenticated Configuration Secrets
Glances Exposes Unauthenticated Configuration Secrets
CVE-2026-25604Medium· 5.4PoCIn AWS Auth manager, the origin of the SAML authentication has been used as provided by the client and not verified against the actual instance URL. This allowed to gain access to different instances with potentially different access co…
In AWS Auth manager, the origin of the SAML authentication has been used as provided by the client and not verified against the actual instance URL. This allowed to gain access to different instances with potentially different access co…
CVE-2024-14027Medium· 5.5PoCIn the Linux kernel, the following vulnerability has been resolved: fs/xattr: missing fdput() in fremovexattr error path In the Linux kernel, the fremovexattr() syscall calls fdget() to acquire a file reference but returns early withou…
In the Linux kernel, the following vulnerability has been resolved: fs/xattr: missing fdput() in fremovexattr error path In the Linux kernel, the fremovexattr() syscall calls fdget() to acquire a file reference but returns early withou…
CVE-2026-30930HighGlances has SQL Injection via Process Names in TimescaleDB Export
Glances has SQL Injection via Process Names in TimescaleDB Export
CVE-2026-25960Medium· 5.4vLLM has SSRF Protection Bypass
vLLM has SSRF Protection Bypass
Most-affected vendors
By CVEs published in the period.