VulnSea

Daily digest

Friday 27 March 2026

A heavy day: 42 new CVEs, well above the recent average of about 19. Severity skewed high: 3 critical and 25 high, 67% of the total. 9 arrived with exploitation evidence or public exploit code already attached. handlebarsjs was the most-affected vendor with 5.

42
New CVEs
3
Critical
0
KEV additions
0
Records changed

New this day, ranked by depth score

The 12 that matter most of the 42 published.

CVE-2026-33937Critical· 9.8PoC
6mo ago

Handlebars provides the power necessary to let users build semantic templates

Handlebars provides the power necessary to let users build semantic templates. In versions 4.0.0 through 4.7.8, `Handlebars.compile()` accepts a pre-parsed AST object in addition to a template string. The `value` field of a `NumberLitera…

▾ Abyssalhandlebarsjs · handlebarsEPSS 1.7%via NVD
CVE-2026-33701Critical· 9.8PoC
6mo ago

OpenTelemetry Java Instrumentation provides OpenTelemetry auto-instrumentation and instrumentation libraries for Java

OpenTelemetry Java Instrumentation provides OpenTelemetry auto-instrumentation and instrumentation libraries for Java. In versions prior to 2.26.1, the RMI instrumentation registered a custom endpoint that deserialized incoming data with…

▾ Abyssallinuxfoundation · opentelemetry_instrumentation_for_javaEPSS 1.1%via NVD
CVE-2026-27876Critical· 9.1PoC
6mo ago

A chained attack via SQL Expressions and a Grafana Enterprise plugin can lead to a remote arbitrary code execution impact (RCE)

A chained attack via SQL Expressions and a Grafana Enterprise plugin can lead to a remote arbitrary code execution impact (RCE). This is enabled by a feature in Grafana (OSS), so all users are always recommended to update to avoid future…

▾ AbyssalEPSS 1.4%via NVD
CVE-2026-5027High· 8.8PoC
6mo ago

The 'POST /api/v2/files' endpoint does not sanitize the 'filename' parameter from the multipart form data, allowing an attacker to write files to arbitrary locations on the filesystem using path traversal sequences ('../').

The 'POST /api/v2/files' endpoint does not sanitize the 'filename' parameter from the multipart form data, allowing an attacker to write files to arbitrary locations on the filesystem using path traversal sequences ('../').

▾ Midnightlangflow · langflowEPSS 4.8%via NVD
CVE-2026-33980High· 8.3PoC
6mo ago

Azure Data Explorer MCP Server: KQL Injection in multiple tools allows MCP client to execute arbitrary Kusto queries

Azure Data Explorer MCP Server: KQL Injection in multiple tools allows MCP client to execute arbitrary Kusto queries

▾ Midnightadx-mcp-server · adx-mcp-serverEPSS 0.43%via OSV
CVE-2026-33941High· 8.2PoC
6mo ago

Handlebars provides the power necessary to let users build semantic templates

Handlebars provides the power necessary to let users build semantic templates. In versions 4.0.0 through 4.7.8, the Handlebars CLI precompiler (`bin/handlebars` / `lib/precompiler.js`) concatenates user-controlled strings — template file…

▾ Midnighthandlebarsjs · handlebarsEPSS 0.22%via NVD
CVE-2026-33894High· 7.5PoC
6mo ago

Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript

Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. Prior to version 1.4.0, RSASSA PKCS#1 v1.5 signature verification accepts forged signatures for low public exponent keys (e=3). Attack…

▾ Midnightdigitalbazaar · forgeEPSS 0.45%via NVD
CVE-2026-33870High· 7.5PoC
6mo ago

Netty is an asynchronous, event-driven network application framework

Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.132.Final and 4.2.10.Final, Netty incorrectly parses quoted strings in HTTP/1.1 chunked transfer encoding extension values, enabling request s…

▾ Midnightnetty · nettyEPSS 0.70%via NVD
CVE-2026-27893High· 8.8
6mo ago

vLLM is an inference and serving engine for large language models (LLMs)

vLLM is an inference and serving engine for large language models (LLMs). Starting in version 0.10.1 and prior to version 0.18.0, two model implementation files hardcode `trust_remote_code=True` when loading sub-components, bypassing the…

▾ Twilightvllm · vllmEPSS 1.8%via NVD
CVE-2026-28369High· 8.7
6mo ago

A flaw was found in Undertow

A flaw was found in Undertow. When Undertow receives an HTTP request where the first header line starts with one or more spaces, it incorrectly processes the request by stripping these leading spaces. This behavior, which violates HTTP s…

▾ Twilightredhat · build_of_apache_camel_-_hawtioEPSS 0.89%via NVD
CVE-2026-28368High· 8.7
6mo ago

A flaw was found in Undertow

A flaw was found in Undertow. This vulnerability allows a remote attacker to construct specially crafted requests where header names are parsed differently by Undertow compared to upstream proxies. This discrepancy in header interpretati…

▾ Twilightredhat · build_of_apache_camel_-_hawtioEPSS 0.89%via NVD
CVE-2026-28367High· 8.7
6mo ago

A flaw was found in Undertow

A flaw was found in Undertow. A remote attacker can exploit this vulnerability by sending `\r\r\r` as a header block terminator. This can be used for request smuggling with certain proxy servers, such as older versions of Apache Traffic …

▾ Twilightredhat · build_of_apache_camel_-_hawtioEPSS 0.89%via NVD

Most-affected vendors

By CVEs published in the period.