Daily digest
Friday 20 March 2026
A busier-than-usual day with 21 new CVEs (recent average about 14). Severity skewed high: 5 critical and 12 high, 81% of the total. 3 arrived with exploitation evidence or public exploit code already attached. CISA added 3 CVEs to the Known Exploited Vulnerabilities catalog. Linux was the most-affected vendor with 6.
Added to CISA KEV
Confirmed exploitation in the wild — federal remediation deadlines attach to these.
CVE-2025-32432Critical· 10.0CISA KEVPoCCraft is a flexible, user-friendly CMS for creating custom digital experiences on the web and beyond
Craft is a flexible, user-friendly CMS for creating custom digital experiences on the web and beyond. Starting from version 3.0.0-RC1 to before 3.9.15, 4.0.0-RC1 to before 4.14.15, and 5.0.0-RC1 to before 5.6.17, Craft is vulnerable to r…
CVE-2025-31277High· 8.8CISA KEVPoCThe issue was addressed with improved memory handling
The issue was addressed with improved memory handling. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6, watchOS 11.6. Processing maliciously crafted web content may lead to memory…
CVE-2025-43520Medium· 5.5CISA KEVPoCA memory corruption issue was addressed with improved memory handling
A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe 26.1, tvOS 26.1, visionOS 26.1, …
New this day, ranked by depth score
The 12 that matter most of the 21 published.
CVE-2026-33186Critical· 9.1PoCgRPC-Go is the Go language implementation of gRPC
gRPC-Go is the Go language implementation of gRPC. Versions prior to 1.79.3 have an authorization bypass resulting from improper input validation of the HTTP/2 `:path` pseudo-header. The gRPC-Go server was too lenient in its routing logi…
CVE-2026-22172Critical· 9.9OpenClaw < 2026.3.12 - Scope Elevation in WebSocket Shared-Auth Connections
OpenClaw versions prior to 2026.3.12 contain an authorization bypass vulnerability in the WebSocket connect path that allows shared-token or password-authenticated connections to self-declare elevated scopes without server-side binding. …
CVE-2026-33231High· 7.5PoCNLTK (Natural Language Toolkit) is a suite of open source Python modules, data sets, and tutorials supporting research and development in Natural Language Processing
NLTK (Natural Language Toolkit) is a suite of open source Python modules, data sets, and tutorials supporting research and development in Natural Language Processing. In versions 3.9.3 and prior, `nltk.app.wordnet_app` allows unauthentic…
CVE-2026-33228Critical· 9.8flatted is a circular JSON parser
flatted is a circular JSON parser. Prior to version 3.4.2, the parse() function in flatted can use attacker-controlled string values from the parsed JSON as direct array index keys, without validating that they are numeric. Since the int…
CVE-2025-15608Critical· 9.8This vulnerability in AX53 v1, AX55 v4 and AX55 v4.6 results from insufficient input sanitization in the device’s probe handling logic, where unvalidated parameters can trigger a stack-based buffer overflow that causes the affected servi…
This vulnerability in AX53 v1, AX55 v4 and AX55 v4.6 results from insufficient input sanitization in the device’s probe handling logic, where unvalidated parameters can trigger a stack-based buffer overflow that causes the affected servi…
CVE-2026-33154High· 7.5PoCdynaconf: jinja2: Dynaconf: Arbitrary code execution via Server-Side Template Injection (CVE-2026-33154)
A flaw was found in dynaconf, a Python configuration management tool. This Server-Side Template Injection (SSTI) vulnerability occurs due to unsafe template evaluation in the @Jinja resolver when the jinja2 package is installed. A remote a…
CVE-2026-33210Critical· 9.1Ruby JSON is a JSON implementation for Ruby
Ruby JSON is a JSON implementation for Ruby. From version 2.14.0 to before versions 2.15.2.1, 2.17.1.2, and 2.19.2, a format string injection vulnerability can lead to denial of service attacks or information disclosure, when the allow_d…
CVE-2026-33243High· 8.2barebox is a bootloader
barebox is a bootloader. In barebox from version 2016.03.0 to before version 2026.03.1 (and the corresponding backport to 2025.09.3), an attacker could exploit a FIT signature verification vulnerability to trick the bootloader into booti…
CVE-2026-33236High· 8.1NLTK (Natural Language Toolkit) is a suite of open source Python modules, data sets, and tutorials supporting research and development in Natural Language Processing
NLTK (Natural Language Toolkit) is a suite of open source Python modules, data sets, and tutorials supporting research and development in Natural Language Processing. In versions 3.9.3 and prior, the NLTK downloader does not validate the…
CVE-2026-32711High· 7.8pydicom has a path traversal in FileSet/DICOMDIR ReferencedFileID allows file access outside the File-set root
pydicom has a path traversal in FileSet/DICOMDIR ReferencedFileID allows file access outside the File-set root
CVE-2026-23278High· 7.8In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: always walk all pending catchall elements During transaction processing we might have more than one catchall element: 1 live catchall element and…
In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: always walk all pending catchall elements During transaction processing we might have more than one catchall element: 1 live catchall element and…
CVE-2026-23274High· 7.8netfilter: xt_IDLETIMER: reject rev0 reuse of ALARM timer labels
In the Linux kernel, the following vulnerability has been resolved: netfilter: xt_IDLETIMER: reject rev0 reuse of ALARM timer labels IDLETIMER revision 0 rules reuse existing timers by label and always call mod_timer() on timer->timer.…
Most-affected vendors
By CVEs published in the period.