Daily digest
Wednesday 1 April 2026
A busier-than-usual day with 56 new CVEs (recent average about 38). Of those, 3 critical and 16 high. One arrived with exploitation evidence or public exploit code already attached. CISA added one CVE to the Known Exploited Vulnerabilities catalog. cisco was the most-affected vendor with 14.
Added to CISA KEV
Confirmed exploitation in the wild — federal remediation deadlines attach to these.
New this day, ranked by depth score
The 12 that matter most of the 56 published.
CVE-2026-5281High· 8.8CISA KEV0dayPoCUse after free in Dawn in Google Chrome prior to 146.0.7680.178 allowed a remote attacker who had compromised the renderer process to execute arbitrary code via a crafted HTML page
Use after free in Dawn in Google Chrome prior to 146.0.7680.178 allowed a remote attacker who had compromised the renderer process to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)
CVE-2026-20160Critical· 9.8A vulnerability in Cisco Smart Software Manager On-Prem (SSM On-Prem) could allow an unauthenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected SSM On-Prem host. This vulnerability…
A vulnerability in Cisco Smart Software Manager On-Prem (SSM On-Prem) could allow an unauthenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected SSM On-Prem host. This vulnerability…
CVE-2026-4374Critical· 9.1Improper Restriction of XML External Entity Reference vulnerability in RTI Connext Professional (Recording Service,Routing Service,Queueing Service,Cloud Discovery Service,Observability Collector) allows Serialized Data External Linking,…
Improper Restriction of XML External Entity Reference vulnerability in RTI Connext Professional (Recording Service,Routing Service,Queueing Service,Cloud Discovery Service,Observability Collector) allows Serialized Data External Linking,…
CVE-2026-34520Critical· 9.1AIOHTTP's C parser (llhttp) accepts null bytes and control characters in response header values - header injection/security bypass
AIOHTTP's C parser (llhttp) accepts null bytes and control characters in response header values - header injection/security bypass
CVE-2026-20094High· 8.8A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with read-only privileges to perform command injection attacks on an affected system and execute arbitrary commands as the r…
A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with read-only privileges to perform command injection attacks on an affected system and execute arbitrary commands as the r…
CVE-2026-34955High· 8.8PraisonAI Has Sandbox Escape via shell=True and Bypassable Blocklist in SubprocessSandbox
PraisonAI Has Sandbox Escape via shell=True and Bypassable Blocklist in SubprocessSandbox
CVE-2026-34954High· 8.6PraisonAI Has SSRF in FileTools.download_file() via Unvalidated URL
PraisonAI Has SSRF in FileTools.download_file() via Unvalidated URL
CVE-2026-34445High· 8.6ONNX: Malicious ONNX models can crash servers by exploiting unprotected object settings.
ONNX: Malicious ONNX models can crash servers by exploiting unprotected object settings.
CVE-2026-35091High· 8.2A flaw was found in Corosync
A flaw was found in Corosync. A remote unauthenticated attacker can exploit a wrong return value vulnerability in the Corosync membership commit token sanity check by sending a specially crafted User Datagram Protocol (UDP) packet. This …
CVE-2026-34783High· 8.1Ferret: Path Traversal in IO::FS::WRITE allows arbitrary file write when scraping malicious websites
Ferret: Path Traversal in IO::FS::WRITE allows arbitrary file write when scraping malicious websites
CVE-2026-34742High· 8.1DNS Rebinding Protection Disabled by Default in Model Context Protocol Go SDK for Servers Running on Localhost
DNS Rebinding Protection Disabled by Default in Model Context Protocol Go SDK for Servers Running on Localhost
CVE-2026-20155High· 8.0A vulnerability in the web-based management interface of Cisco Evolved Programmable Network Manager (EPNM) could allow an authenticated, remote attacker with low privileges to access sensitive information that they are not authorized to …
A vulnerability in the web-based management interface of Cisco Evolved Programmable Network Manager (EPNM) could allow an authenticated, remote attacker with low privileges to access sensitive information that they are not authorized to …
Most-affected vendors
By CVEs published in the period.