Daily digest
Thursday 26 March 2026
21 new CVEs this day, in line with the recent average. Severity skewed high: 4 critical and 7 high, 52% of the total. 5 arrived with exploitation evidence or public exploit code already attached. CISA added one CVE to the Known Exploited Vulnerabilities catalog. libssh was the most-affected vendor with 5.
Added to CISA KEV
Confirmed exploitation in the wild — federal remediation deadlines attach to these.
New this day, ranked by depth score
The 12 that matter most of the 21 published.
CVE-2026-1961High· 8.0PoCA flaw was found in Foreman
A flaw was found in Foreman. A remote attacker could exploit a command injection vulnerability in Foreman's WebSocket proxy implementation. This vulnerability arises from the system's use of unsanitized hostname values from compute resou…
CVE-2026-4809Critical· 9.8plank/laravel-mediable through version 6.4.0 can allow upload of a dangerous file type when an application using the package accepts or prefers a client-supplied MIME type during file upload handling
plank/laravel-mediable through version 6.4.0 can allow upload of a dangerous file type when an application using the package accepts or prefers a client-supplied MIME type during file upload handling. In that configuration, a remote atta…
CVE-2026-33757Critical· 9.6OpenBao lacks user confirmation for OIDC direct callback mode
OpenBao lacks user confirmation for OIDC direct callback mode
CVE-2026-33487High· 7.5PoCgoxmlsig provides XML Digital Signatures implemented in Go
goxmlsig provides XML Digital Signatures implemented in Go. Prior to version 1.6.0, the `validateSignature` function in `validate.go` goes through the references in the `SignedInfo` block to find one that matches the signed element's ID.…
CVE-2026-32286High· 7.5PoCThe DataRow.Decode function fails to properly validate field lengths
The DataRow.Decode function fails to properly validate field lengths. A malicious or compromised PostgreSQL server can send a DataRow message with a negative field length, causing a slice bounds out of range panic.
CVE-2026-32285High· 7.5PoCThe Delete function fails to properly validate offsets when processing malformed JSON input
The Delete function fails to properly validate offsets when processing malformed JSON input. This can lead to a negative slice index and a runtime panic, allowing a denial of service attack.
CVE-2026-33758CriticalOpenBao has Reflected XSS in its OIDC authentication error message
OpenBao has Reflected XSS in its OIDC authentication error message
CVE-2026-56765Critical· 9.1Vikunja: Unauthenticated Instance-Wide Data Breach via Link Share Hash Disclosure Chained with Cross-Project Attachment IDOR
Vikunja: Unauthenticated Instance-Wide Data Breach via Link Share Hash Disclosure Chained with Cross-Project Attachment IDOR
CVE-2026-0966High· 8.2A flaw was found in libssh
A flaw was found in libssh. The API function `ssh_get_hexa()` is vulnerable to a denial of service when processing zero-length input. This can be exploited remotely by an attacker during GSSAPI (Generic Security Service Application Progr…
GHSA-wcjx-v2wj-xg87High· 7.5C2C CI utils is vulnerable to DoS via pyasn dependency (CVE-2026-30922)
C2C CI utils is vulnerable to DoS via pyasn dependency (CVE-2026-30922)
CVE-2026-4926High· 7.5Impact: A bad regular expression is generated any time you have multiple sequential optional groups (curly brace syntax), such as `{a}{b}{c}:z`
Impact: A bad regular expression is generated any time you have multiple sequential optional groups (curly brace syntax), such as `{a}{b}{c}:z`. The generated regex grows exponentially with the number of groups, causing denial of servic…
CVE-2026-0964Medium· 6.3A malicious SCP server can send unexpected paths that could make the client application override local files outside of working directory. This could be misused to create malicious executable or configuration files and make the user exec…
A malicious SCP server can send unexpected paths that could make the client application override local files outside of working directory. This could be misused to create malicious executable or configuration files and make the user exec…
Most-affected vendors
By CVEs published in the period.