VulnSea

Daily digest

Tuesday 17 March 2026

A quiet day: only 6 new CVEs against a recent average of about 18. Severity skewed high: 1 critical and 5 high, 100% of the total.

6
New CVEs
1
Critical
0
KEV additions
0
Records changed

New this day, ranked by depth score

The 6 that matter most of the 6 published.

CVE-2026-3564Critical· 9.0
6mo ago

A condition in the ScreenConnect server component may allow an actor with access to server-level cryptographic material used for authentication to obtain unauthorized access, including elevated privileges, in certain scenarios

A condition in the ScreenConnect server component may allow an actor with access to server-level cryptographic material used for authentication to obtain unauthorized access, including elevated privileges, in certain scenarios. ScreenCon…

▾ MidnightEPSS 0.28%via NVD
CVE-2026-21570High· 8.8
6mo ago

This High severity RCE (Remote Code Execution)  vulnerability was introduced in versions 9.6.0, 10.0.0, 10.1.0, 10.2.0, 11.0.0, 11.1.0, 12.0.0, and 12.1.0 of Bamboo Data Center. This RCE (Remote Code Execution) vulnerability, with a C…

This High severity RCE (Remote Code Execution)  vulnerability was introduced in versions 9.6.0, 10.0.0, 10.1.0, 10.2.0, 11.0.0, 11.1.0, 12.0.0, and 12.1.0 of Bamboo Data Center. This RCE (Remote Code Execution) vulnerability, with a C…

▾ Twilightatlassian · bambooEPSS 0.57%via NVD
CVE-2026-9769High
6mo ago

Uncontrolled recursion DoS in JustHTML() via deeply nested HTML

Uncontrolled recursion DoS in JustHTML() via deeply nested HTML

▾ Twilightjusthtml · justhtmlEPSS 0.49%via OSV
CVE-2026-4269High· 7.5
6mo ago

Improper S3 ownership verification in Bedrock AgentCore Starter Toolkit

Improper S3 ownership verification in Bedrock AgentCore Starter Toolkit

▾ Twilightbedrock-agentcore-starter-toolkit · bedrock-agentcore-starter-toolkitEPSS 0.42%via OSV
CVE-2026-4258High· 7.5
6mo ago

Versions of the package sjcl before 1.0.9 are vulnerable to Improper Verification of Cryptographic Signature due to missing point-on-curve validation in sjcl.ecc.basicKey.publicKey()

Versions of the package sjcl before 1.0.9 are vulnerable to Improper Verification of Cryptographic Signature due to missing point-on-curve validation in sjcl.ecc.basicKey.publicKey(). An attacker can recover a victim's ECDH private key b…

▾ Twilightbitwiseshiftleft · stanford_javascript_crypto_libraryEPSS 0.34%via NVD
CVE-2026-32981High· 7.5
6mo ago

A path traversal vulnerability was identified in Ray Dashboard (default port 8265) in Ray versions prior to 2.8.1

A path traversal vulnerability was identified in Ray Dashboard (default port 8265) in Ray versions prior to 2.8.1. Due to improper validation and sanitization of user-supplied paths in the static file handling mechanism, an attacker can …

▾ Twilightanyscale · rayEPSS 1.0%via NVD

Most-affected vendors

By CVEs published in the period.