Daily digest
Thursday 2 April 2026
41 new CVEs this day, in line with the recent average. Severity skewed high: 8 critical and 14 high, 54% of the total. One arrived with exploitation evidence or public exploit code already attached. endian was the most-affected vendor with 20.
New this day, ranked by depth score
The 12 that matter most of the 41 published.
CVE-2026-34976Critical· 10.0PoCDgraph: Pre-Auth Database Overwrite + SSRF + File Read via restoreTenant Missing Authorization
Dgraph: Pre-Auth Database Overwrite + SSRF + File Read via restoreTenant Missing Authorization
CVE-2026-4370Critical· 10.0Juju has Improper TLS Client/Server authentication and certificate verification on Database Cluster
Juju has Improper TLS Client/Server authentication and certificate verification on Database Cluster
CVE-2026-33107Critical· 10.0Azure Databricks Elevation of Privilege Vulnerability
Server-side request forgery (ssrf) in Azure Databricks allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-33105Critical· 10.0Microsoft Azure Kubernetes Service Elevation of Privilege Vulnerability
Improper authorization in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-32871Critical· 10.0FastMCP is a Pythonic way to build MCP servers and clients
FastMCP is a Pythonic way to build MCP servers and clients. Prior to version 3.2.0, the OpenAPIProvider in FastMCP exposes internal APIs to MCP clients by parsing OpenAPI specifications. The RequestDirector class is responsible for const…
CVE-2026-32213Critical· 10.0Azure AI Foundry Elevation of Privilege Vulnerability
Improper authorization in Azure AI Foundry allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-26135Critical· 9.6Azure Custom Locations Resource Provider (RP) Elevation of Privilege Vulnerability
Server-side request forgery (ssrf) in Azure Custom Locations Resource Provider (RP) allows an authorized attacker to elevate privileges over a network.
CVE-2026-32211Critical· 9.1Azure MCP Server Information Disclosure Vulnerability
Missing authentication for critical function in Azure MCP Server allows an unauthorized attacker to disclose information over a network.
CVE-2026-3692High· 8.8In Progress Flowmon versions prior to 12.5.8, a vulnerability exists whereby an authenticated low-privileged user may craft a request during the report generation process that results in unintended commands being executed on the server.
In Progress Flowmon versions prior to 12.5.8, a vulnerability exists whereby an authenticated low-privileged user may craft a request during the report generation process that results in unintended commands being executed on the server.
CVE-2026-34797High· 8.8Endian Firewall version 3.3.25 and prior allow authenticated users to execute arbitrary OS commands via the DATE parameter to /cgi-bin/logs_smtp.cgi
Endian Firewall version 3.3.25 and prior allow authenticated users to execute arbitrary OS commands via the DATE parameter to /cgi-bin/logs_smtp.cgi. The DATE parameter value is used to construct a file path that is passed to a Perl open…
CVE-2026-34796High· 8.8Endian Firewall version 3.3.25 and prior allow authenticated users to execute arbitrary OS commands via the DATE parameter to /cgi-bin/logs_openvpn.cgi
Endian Firewall version 3.3.25 and prior allow authenticated users to execute arbitrary OS commands via the DATE parameter to /cgi-bin/logs_openvpn.cgi. The DATE parameter value is used to construct a file path that is passed to a Perl o…
CVE-2026-34795High· 8.8Endian Firewall version 3.3.25 and prior allow authenticated users to execute arbitrary OS commands via the DATE parameter to /cgi-bin/logs_log.cgi
Endian Firewall version 3.3.25 and prior allow authenticated users to execute arbitrary OS commands via the DATE parameter to /cgi-bin/logs_log.cgi. The DATE parameter value is used to construct a file path that is passed to a Perl open(…
Most-affected vendors
By CVEs published in the period.