Daily digest
Thursday 19 March 2026
17 new CVEs this day, in line with the recent average. Of those, 1 critical and 6 high. 5 arrived with exploitation evidence or public exploit code already attached. bmc was the most-affected vendor with 4.
New this day, ranked by depth score
The 12 that matter most of the 17 published.
CVE-2025-71257High· 7.3PoCBMC FootPrints ITSM versions 20.20.02 through 20.24.01.001 contain an authentication bypass vulnerability due to improper enforcement of security filters on restricted REST API endpoints and servlets
BMC FootPrints ITSM versions 20.20.02 through 20.24.01.001 contain an authentication bypass vulnerability due to improper enforcement of security filters on restricted REST API endpoints and servlets. Unauthenticated remote attackers can…
CVE-2026-33310High· 8.8PoCIntake has a Command Injection via shell() Expansion in Parameter Defaults
Intake has a Command Injection via shell() Expansion in Parameter Defaults
CVE-2025-71260High· 8.8BMC FootPrints ITSM versions 20.20.02 through 20.24.01.001 contain a deserialization of untrusted data vulnerability in the ASP.NET servlet's VIEWSTATE handling that allows authenticated attackers to execute arbitrary code
BMC FootPrints ITSM versions 20.20.02 through 20.24.01.001 contain a deserialization of untrusted data vulnerability in the ASP.NET servlet's VIEWSTATE handling that allows authenticated attackers to execute arbitrary code. Attackers can…
CVE-2026-33322CriticalMinIO has JWT Algorithm Confusion in OIDC Authentication
MinIO has JWT Algorithm Confusion in OIDC Authentication
CVE-2026-33320Medium· 6.2PoCDasel has unbounded YAML alias expansion in dasel leads to CPU/memory denial of service
Dasel has unbounded YAML alias expansion in dasel leads to CPU/memory denial of service
CVE-2025-15031High· 8.1Arbitrary file write via tar traversal in mlflow
Arbitrary file write via tar traversal in mlflow
CVE-2026-4424High· 7.5A flaw was found in libarchive
A flaw was found in libarchive. This heap out-of-bounds read vulnerability exists in the RAR archive processing logic due to improper validation of the LZSS sliding window size after transitions between compression methods. A remote atta…
CVE-2026-27953High· 7.1ormar Pydantic Validation Bypass via __pk_only__ and __excluded__ Kwargs Injection in Model Constructor
ormar Pydantic Validation Bypass via __pk_only__ and __excluded__ Kwargs Injection in Model Constructor
CVE-2025-71258Medium· 4.3PoCBMC FootPrints ITSM versions 20.20.02 through 20.24.01.001 contain a blind server-side request forgery vulnerability in the searchWeb API component that allows authenticated attackers to cause the server to initiate arbitrary outbound re…
BMC FootPrints ITSM versions 20.20.02 through 20.24.01.001 contain a blind server-side request forgery vulnerability in the searchWeb API component that allows authenticated attackers to cause the server to initiate arbitrary outbound re…
CVE-2025-71259Medium· 4.3PoCBMC FootPrints ITSM versions 20.20.02 through 20.24.01.001 contain a blind server-side request forgery vulnerability in the externalfeed/RSS API component that allows authenticated attackers to trigger arbitrary outbound requests from th…
BMC FootPrints ITSM versions 20.20.02 through 20.24.01.001 contain a blind server-side request forgery vulnerability in the externalfeed/RSS API component that allows authenticated attackers to trigger arbitrary outbound requests from th…
CVE-2026-4426Medium· 6.5A flaw was found in libarchive
A flaw was found in libarchive. An Undefined Behavior vulnerability exists in the zisofs decompression logic, caused by improper validation of a field (`pz_log2_bs`) read from ISO9660 Rock Ridge extensions. A remote attacker can exploit …
CVE-2026-32889Medium· 6.5Denial of service via non-terminating SYLT frame parsing loop in tinytag
Denial of service via non-terminating SYLT frame parsing loop in tinytag
Most-affected vendors
By CVEs published in the period.