Daily digest
Tuesday 17 March 2026
A quiet day: only 6 new CVEs against a recent average of about 18. Severity skewed high: 1 critical and 5 high, 100% of the total.
New this day, ranked by depth score
The 6 that matter most of the 6 published.
CVE-2026-3564Critical· 9.0A condition in the ScreenConnect server component may allow an actor with access to server-level cryptographic material used for authentication to obtain unauthorized access, including elevated privileges, in certain scenarios
A condition in the ScreenConnect server component may allow an actor with access to server-level cryptographic material used for authentication to obtain unauthorized access, including elevated privileges, in certain scenarios. ScreenCon…
CVE-2026-21570High· 8.8This High severity RCE (Remote Code Execution) vulnerability was introduced in versions 9.6.0, 10.0.0, 10.1.0, 10.2.0, 11.0.0, 11.1.0, 12.0.0, and 12.1.0 of Bamboo Data Center. This RCE (Remote Code Execution) vulnerability, with a C…
This High severity RCE (Remote Code Execution) vulnerability was introduced in versions 9.6.0, 10.0.0, 10.1.0, 10.2.0, 11.0.0, 11.1.0, 12.0.0, and 12.1.0 of Bamboo Data Center. This RCE (Remote Code Execution) vulnerability, with a C…
CVE-2026-9769HighUncontrolled recursion DoS in JustHTML() via deeply nested HTML
Uncontrolled recursion DoS in JustHTML() via deeply nested HTML
CVE-2026-4269High· 7.5Improper S3 ownership verification in Bedrock AgentCore Starter Toolkit
Improper S3 ownership verification in Bedrock AgentCore Starter Toolkit
CVE-2026-4258High· 7.5Versions of the package sjcl before 1.0.9 are vulnerable to Improper Verification of Cryptographic Signature due to missing point-on-curve validation in sjcl.ecc.basicKey.publicKey()
Versions of the package sjcl before 1.0.9 are vulnerable to Improper Verification of Cryptographic Signature due to missing point-on-curve validation in sjcl.ecc.basicKey.publicKey(). An attacker can recover a victim's ECDH private key b…
CVE-2026-32981High· 7.5A path traversal vulnerability was identified in Ray Dashboard (default port 8265) in Ray versions prior to 2.8.1
A path traversal vulnerability was identified in Ray Dashboard (default port 8265) in Ray versions prior to 2.8.1. Due to improper validation and sanitization of user-supplied paths in the static file handling mechanism, an attacker can …
Most-affected vendors
By CVEs published in the period.