VulnSea

Daily digest

Wednesday 1 April 2026

A busier-than-usual day with 56 new CVEs (recent average about 38). Of those, 3 critical and 16 high. One arrived with exploitation evidence or public exploit code already attached. CISA added one CVE to the Known Exploited Vulnerabilities catalog. cisco was the most-affected vendor with 14.

56
New CVEs
3
Critical
1
KEV additions
0
Records changed

Added to CISA KEV

Confirmed exploitation in the wild — federal remediation deadlines attach to these.

New this day, ranked by depth score

The 12 that matter most of the 56 published.

CVE-2026-5281High· 8.8CISA KEV0dayPoC
6mo ago

Use after free in Dawn in Google Chrome prior to 146.0.7680.178 allowed a remote attacker who had compromised the renderer process to execute arbitrary code via a crafted HTML page

Use after free in Dawn in Google Chrome prior to 146.0.7680.178 allowed a remote attacker who had compromised the renderer process to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)

▾ Abyssalgoogle · chromeEPSS 0.70%via NVD
CVE-2026-20160Critical· 9.8
6mo ago

A vulnerability in Cisco Smart Software Manager On-Prem (SSM On-Prem) could allow an unauthenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected SSM On-Prem host. This vulnerability…

A vulnerability in Cisco Smart Software Manager On-Prem (SSM On-Prem) could allow an unauthenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected SSM On-Prem host. This vulnerability…

▾ Midnightcisco · smart_software_manager_on-premEPSS 0.91%via NVD
CVE-2026-4374Critical· 9.1
6mo ago

Improper Restriction of XML External Entity Reference vulnerability in RTI Connext Professional (Recording Service,Routing Service,Queueing Service,Cloud Discovery Service,Observability Collector) allows Serialized Data External Linking,…

Improper Restriction of XML External Entity Reference vulnerability in RTI Connext Professional (Recording Service,Routing Service,Queueing Service,Cloud Discovery Service,Observability Collector) allows Serialized Data External Linking,…

▾ Midnightrti · connext_professionalEPSS 0.39%via NVD
CVE-2026-34520Critical· 9.1
6mo ago

AIOHTTP's C parser (llhttp) accepts null bytes and control characters in response header values - header injection/security bypass

AIOHTTP's C parser (llhttp) accepts null bytes and control characters in response header values - header injection/security bypass

▾ Midnightaiohttp · aiohttpEPSS 0.68%via OSV
CVE-2026-20094High· 8.8
6mo ago

A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with read-only privileges to perform command injection attacks on an affected system and execute arbitrary commands as the r…

A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with read-only privileges to perform command injection attacks on an affected system and execute arbitrary commands as the r…

▾ Twilightcisco · unified_computing_systemEPSS 1.1%via NVD
CVE-2026-34955High· 8.8
6mo ago

PraisonAI Has Sandbox Escape via shell=True and Bypassable Blocklist in SubprocessSandbox

PraisonAI Has Sandbox Escape via shell=True and Bypassable Blocklist in SubprocessSandbox

▾ Twilightpraisonai · praisonaiEPSS 0.39%via OSV
CVE-2026-34954High· 8.6
6mo ago

PraisonAI Has SSRF in FileTools.download_file() via Unvalidated URL

PraisonAI Has SSRF in FileTools.download_file() via Unvalidated URL

▾ Twilightpraisonaiagents · praisonaiagentsEPSS 0.41%via OSV
CVE-2026-34445High· 8.6
6mo ago

ONNX: Malicious ONNX models can crash servers by exploiting unprotected object settings.

ONNX: Malicious ONNX models can crash servers by exploiting unprotected object settings.

▾ Twilightonnx · onnxEPSS 0.51%via OSV
CVE-2026-35091High· 8.2
6mo ago

A flaw was found in Corosync

A flaw was found in Corosync. A remote unauthenticated attacker can exploit a wrong return value vulnerability in the Corosync membership commit token sanity check by sending a specially crafted User Datagram Protocol (UDP) packet. This …

▾ Twilightcorosync · corosyncEPSS 1.1%via NVD
CVE-2026-34783High· 8.1
6mo ago

Ferret: Path Traversal in IO::FS::WRITE allows arbitrary file write when scraping malicious websites

Ferret: Path Traversal in IO::FS::WRITE allows arbitrary file write when scraping malicious websites

▾ TwilightMontFerret · github.com/MontFerret/ferret/v2EPSS 0.71%via OSV
CVE-2026-34742High· 8.1
6mo ago

DNS Rebinding Protection Disabled by Default in Model Context Protocol Go SDK for Servers Running on Localhost

DNS Rebinding Protection Disabled by Default in Model Context Protocol Go SDK for Servers Running on Localhost

▾ Twilightmodelcontextprotocol · github.com/modelcontextprotocol/go-sdkEPSS 0.66%via OSV
CVE-2026-20155High· 8.0
6mo ago

A vulnerability in the web-based management interface of Cisco Evolved Programmable Network Manager (EPNM) could allow an authenticated, remote attacker with low privileges to access sensitive information that they are not authorized to …

A vulnerability in the web-based management interface of Cisco Evolved Programmable Network Manager (EPNM) could allow an authenticated, remote attacker with low privileges to access sensitive information that they are not authorized to …

▾ Twilightcisco · evolved_programmable_network_managerEPSS 0.27%via NVD

Most-affected vendors

By CVEs published in the period.