VulnSea

Daily digest

Thursday 26 March 2026

21 new CVEs this day, in line with the recent average. Severity skewed high: 4 critical and 7 high, 52% of the total. 5 arrived with exploitation evidence or public exploit code already attached. CISA added one CVE to the Known Exploited Vulnerabilities catalog. libssh was the most-affected vendor with 5.

21
New CVEs
4
Critical
1
KEV additions
0
Records changed

Added to CISA KEV

Confirmed exploitation in the wild — federal remediation deadlines attach to these.

New this day, ranked by depth score

The 12 that matter most of the 21 published.

CVE-2026-1961High· 8.0PoC
6mo ago

A flaw was found in Foreman

A flaw was found in Foreman. A remote attacker could exploit a command injection vulnerability in Foreman's WebSocket proxy implementation. This vulnerability arises from the system's use of unsanitized hostname values from compute resou…

▾ MidnightEPSS 1.4%via NVD
CVE-2026-4809Critical· 9.8
6mo ago

plank/laravel-mediable through version 6.4.0 can allow upload of a dangerous file type when an application using the package accepts or prefers a client-supplied MIME type during file upload handling

plank/laravel-mediable through version 6.4.0 can allow upload of a dangerous file type when an application using the package accepts or prefers a client-supplied MIME type during file upload handling. In that configuration, a remote atta…

▾ MidnightEPSS 1.1%via NVD
CVE-2026-33757Critical· 9.6
6mo ago

OpenBao lacks user confirmation for OIDC direct callback mode

OpenBao lacks user confirmation for OIDC direct callback mode

▾ Midnightopenbao · github.com/openbao/openbaoEPSS 0.61%via OSV
CVE-2026-33487High· 7.5PoC
6mo ago

goxmlsig provides XML Digital Signatures implemented in Go

goxmlsig provides XML Digital Signatures implemented in Go. Prior to version 1.6.0, the `validateSignature` function in `validate.go` goes through the references in the `SignedInfo` block to find one that matches the signed element's ID.…

▾ Midnightgoxmldsig_project · goxmldsigEPSS 0.42%via NVD
CVE-2026-32286High· 7.5PoC
6mo ago

The DataRow.Decode function fails to properly validate field lengths

The DataRow.Decode function fails to properly validate field lengths. A malicious or compromised PostgreSQL server can send a DataRow message with a negative field length, causing a slice bounds out of range panic.

▾ Midnightjackc · pgproto3EPSS 0.92%via NVD
CVE-2026-32285High· 7.5PoC
6mo ago

The Delete function fails to properly validate offsets when processing malformed JSON input

The Delete function fails to properly validate offsets when processing malformed JSON input. This can lead to a negative slice index and a runtime panic, allowing a denial of service attack.

▾ Midnightjsonparser_project · jsonparserEPSS 0.97%via NVD
CVE-2026-33758Critical
6mo ago

OpenBao has Reflected XSS in its OIDC authentication error message

OpenBao has Reflected XSS in its OIDC authentication error message

▾ Midnightopenbao · github.com/openbao/openbaoEPSS 0.45%via OSV
CVE-2026-56765Critical· 9.1
6mo ago

Vikunja: Unauthenticated Instance-Wide Data Breach via Link Share Hash Disclosure Chained with Cross-Project Attachment IDOR

Vikunja: Unauthenticated Instance-Wide Data Breach via Link Share Hash Disclosure Chained with Cross-Project Attachment IDOR

▾ Midnightapi · code.vikunja.io/apiEPSS 0.51%via OSV
CVE-2026-0966High· 8.2
6mo ago

A flaw was found in libssh

A flaw was found in libssh. The API function `ssh_get_hexa()` is vulnerable to a denial of service when processing zero-length input. This can be exploited remotely by an attacker during GSSAPI (Generic Security Service Application Progr…

▾ Twilightlibssh · libsshEPSS 0.58%via NVD
GHSA-wcjx-v2wj-xg87High· 7.5
6mo ago

C2C CI utils is vulnerable to DoS via pyasn dependency (CVE-2026-30922)

C2C CI utils is vulnerable to DoS via pyasn dependency (CVE-2026-30922)

▾ Twilightc2cciutils · c2cciutilsvia OSV
CVE-2026-4926High· 7.5
6mo ago

Impact: A bad regular expression is generated any time you have multiple sequential optional groups (curly brace syntax), such as `{a}{b}{c}:z`

Impact: A bad regular expression is generated any time you have multiple sequential optional groups (curly brace syntax), such as `{a}{b}{c}:z`. The generated regex grows exponentially with the number of groups, causing denial of servic…

▾ Twilightpillarjs · path-to-regexpEPSS 0.89%via NVD
CVE-2026-0964Medium· 6.3
6mo ago

A malicious SCP server can send unexpected paths that could make the client application override local files outside of working directory. This could be misused to create malicious executable or configuration files and make the user exec…

A malicious SCP server can send unexpected paths that could make the client application override local files outside of working directory. This could be misused to create malicious executable or configuration files and make the user exec…

▾ Sunlitlibssh · libsshEPSS 0.41%via NVD

Most-affected vendors

By CVEs published in the period.