Daily digest
Tuesday 24 March 2026
A busier-than-usual day with 19 new CVEs (recent average about 15). Severity skewed high: 2 critical and 8 high, 53% of the total. 3 arrived with exploitation evidence or public exploit code already attached. zabbix was the most-affected vendor with 5.
New this day, ranked by depth score
The 12 that matter most of the 19 published.
CVE-2026-33634CriticalCISA KEVPoCTrivy ecosystem supply chain was briefly compromised
Trivy ecosystem supply chain was briefly compromised
CVE-2026-23921High· 8.8PoCA low privilege Zabbix user with API access can exploit a blind SQL injection vulnerability in include/classes/api/CApiService.php to execute arbitrary SQL selects via the sortfield parameter
A low privilege Zabbix user with API access can exploit a blind SQL injection vulnerability in include/classes/api/CApiService.php to execute arbitrary SQL selects via the sortfield parameter. Although query results are not returned dire…
CVE-2026-22739High· 8.6PoCVulnerability in Spring Cloud when substituting the profile parameter from a request made to the Spring Cloud Config Server configured to the native file system as a backend, because it was possible to access files outside of the configu…
Vulnerability in Spring Cloud when substituting the profile parameter from a request made to the Spring Cloud Config Server configured to the native file system as a backend, because it was possible to access files outside of the configu…
CVE-2026-33211Critical· 9.6Tekton Pipelines project provides k8s-style resources for declaring CI/CD-style pipelines
Tekton Pipelines project provides k8s-style resources for declaring CI/CD-style pipelines. Starting in version 1.0.0 and prior to versions 1.0.1, 1.3.3, 1.6.1, 1.9.2, and 1.10.2, the Tekton Pipelines git resolver is vulnerable to path tr…
CVE-2026-23920High· 8.8Host and event action script input is validated with a regex (set by the administrator), but the validation runs in multiline mode
Host and event action script input is validated with a regex (set by the administrator), but the validation runs in multiline mode. If ^ and $ anchors are used in user input validation, an injected newline lets authenticated users bypass…
CVE-2026-4775High· 7.8A flaw was found in the libtiff library
A flaw was found in the libtiff library. A remote attacker could exploit a signed integer overflow vulnerability in the putcontig8bitYCbCr44tile function by providing a specially crafted TIFF file. This flaw can lead to an out-of-bounds …
CVE-2026-24159High· 7.8NVIDIA NeMo Framework contains a vulnerability leading to Remote Code Execution
NVIDIA NeMo Framework contains a vulnerability leading to Remote Code Execution
CVE-2026-24157High· 7.8NVIDIA NeMo Framework contains an RCE vulnerability in checkpoint loading
NVIDIA NeMo Framework contains an RCE vulnerability in checkpoint loading
CVE-2026-1995High· 7.8In versions before 7.0.0.64, IDrive’s id_service.exe process runs with elevated privileges and regularly reads from several files under the C:\ProgramData\IDrive\ directory
In versions before 7.0.0.64, IDrive’s id_service.exe process runs with elevated privileges and regularly reads from several files under the C:\ProgramData\IDrive\ directory. The UTF16-LE encoded contents of these files are used as argume…
CVE-2026-5389HighJustHTML is vulnerable to XSS via code fence breakout in <pre> content
JustHTML is vulnerable to XSS via code fence breakout in <pre> content
CVE-2026-33246Medium· 6.4NATS: Leafnode connections allow spoofing of Nats-Request-Info identity headers
NATS: Leafnode connections allow spoofing of Nats-Request-Info identity headers
CVE-2026-23919Medium· 6.0For performance reasons Zabbix Server/Proxy reuses JavaScript (Duktape) contexts (used in script items, JavaScript reprocessing, Webhooks)
For performance reasons Zabbix Server/Proxy reuses JavaScript (Duktape) contexts (used in script items, JavaScript reprocessing, Webhooks). This can lead to confidentiality loss where a regular (non-super) Zabbix administrator leaks data…
Most-affected vendors
By CVEs published in the period.