VulnSea

Daily digest

Tuesday 10 March 2026

A heavy day: 40 new CVEs, well above the recent average of about 13. Severity skewed high: 1 critical and 20 high, 53% of the total. 5 arrived with exploitation evidence or public exploit code already attached. adobe was the most-affected vendor with 24.

40
New CVEs
1
Critical
0
KEV additions
0
Records changed

New this day, ranked by depth score

The 12 that matter most of the 40 published.

CVE-2026-26118High· 8.8PoC
6mo ago

Azure MCP Server has Server-Side Request Forgery issue that allows authorized attacker to elevate privileges over a network

Azure MCP Server has Server-Side Request Forgery issue that allows authorized attacker to elevate privileges over a network

▾ MidnightAzure · Azure.McpEPSS 0.86%via OSV
CVE-2026-27826High· 8.2PoC
6mo ago

MCP Atlassian has SSRF via unvalidated X-Atlassian-Jira-Url / X-Atlassian-Confluence-Url headers

MCP Atlassian has SSRF via unvalidated X-Atlassian-Jira-Url / X-Atlassian-Confluence-Url headers

▾ Midnightmcp-atlassian · mcp-atlassianEPSS 1.0%via OSV
CVE-2026-24294High· 7.8PoC
6mo ago

Improper authentication in Windows SMB Server allows an authorized attacker to elevate privileges locally.

Improper authentication in Windows SMB Server allows an authorized attacker to elevate privileges locally.

▾ Midnightmicrosoft · windows_10_1607EPSS 4.7%via NVD
CVE-2026-27280High· 7.8PoC
6mo ago

DNG SDK versions 1.7.1 2471 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user

DNG SDK versions 1.7.1 2471 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a…

▾ Midnightadobe · dng_software_development_kitEPSS 0.26%via NVD
CVE-2026-3843Critical· 9.8
6mo ago

Nefteprodukttekhnika BUK TS-G Gas Station Automation System 2.9.1 on Linux contains a SQL Injection vulnerability (CWE-89) in the system configuration module

Nefteprodukttekhnika BUK TS-G Gas Station Automation System 2.9.1 on Linux contains a SQL Injection vulnerability (CWE-89) in the system configuration module. A remote attacker can send specially crafted HTTP POST requests to the /php/re…

▾ Midnightbukts · buk_ts-g_gas_station_automation_systemEPSS 0.94%via NVD
CVE-2026-21262High· 8.8
6mo ago

Improper access control in SQL Server allows an authorized attacker to elevate privileges over a network.

Improper access control in SQL Server allows an authorized attacker to elevate privileges over a network.

▾ Twilightmicrosoft · sql_server_2016EPSS 2.0%via NVD
CVE-2026-21333High· 8.6
6mo ago

Illustrator versions 29.8.4, 30.1 and earlier are affected by an Untrusted Search Path vulnerability that might allow attackers to execute arbitrary code in the context of the current user

Illustrator versions 29.8.4, 30.1 and earlier are affected by an Untrusted Search Path vulnerability that might allow attackers to execute arbitrary code in the context of the current user. Exploitation of this issue requires user intera…

▾ Twilightadobe · illustratorEPSS 0.16%via NVD
CVE-2026-2273High· 8.2
6mo ago

CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability exist that could cause execution of untrusted commands on the engineering workstation which could result in a limited compromise of the workstation and a pot…

CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability exist that could cause execution of untrusted commands on the engineering workstation which could result in a limited compromise of the workstation and a pot…

▾ TwilightEPSS 0.23%via NVD
CVE-2026-27279High· 7.8
6mo ago

Substance3D - Stager versions 3.1.7 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user

Substance3D - Stager versions 3.1.7 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction i…

▾ Twilightadobe · substance_3d_stagerEPSS 0.26%via NVD
CVE-2026-27278High· 7.8
6mo ago

Acrobat Reader versions 24.001.30307, 24.001.30308, 25.001.21265 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user

Acrobat Reader versions 24.001.30307, 24.001.30308, 25.001.21265 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requ…

▾ Twilightadobe · acrobat_dcEPSS 0.38%via NVD
CVE-2026-27277High· 7.8
6mo ago

Substance3D - Stager versions 3.1.7 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user

Substance3D - Stager versions 3.1.7 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that…

▾ Twilightadobe · substance_3d_stagerEPSS 0.38%via NVD
CVE-2026-27276High· 7.8
6mo ago

Substance3D - Stager versions 3.1.7 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user

Substance3D - Stager versions 3.1.7 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that…

▾ Twilightadobe · substance_3d_stagerEPSS 0.38%via NVD

Most-affected vendors

By CVEs published in the period.