VulnSea

Daily digest

Monday 13 April 2026

A quiet day: only 27 new CVEs against a recent average of about 55. Of those, 2 critical and 9 high. One arrived with exploitation evidence or public exploit code already attached. Linux was the most-affected vendor with 13.

27
New CVEs
2
Critical
0
KEV additions
0
Records changed

New this day, ranked by depth score

The 12 that matter most of the 27 published.

CVE-2026-31414Critical· 9.8
5mo ago

netfilter: nf_conntrack_expect: use expect->helper

In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conntrack_expect: use expect->helper Use expect->helper in ctnetlink and /proc to dump the helper name. Using nfct_help() without holding a reference to …

▾ MidnightLinux · LinuxEPSS 0.76%via CVEORG
CVE-2026-0234Critical· 9.1
5mo ago

An improper verification of cryptographic signature vulnerability exists in Cortex XSOAR and Cortex XSIAM platforms during integration of Microsoft Teams that enables an unauthenticated user to access and modify protected resources.

An improper verification of cryptographic signature vulnerability exists in Cortex XSOAR and Cortex XSIAM platforms during integration of Microsoft Teams that enables an unauthenticated user to access and modify protected resources.

▾ Midnightpaloaltonetworks · cortex_xsiamEPSS 0.23%via NVD
CVE-2026-0233High· 8.8
5mo ago

A certificate validation vulnerability in Palo Alto Networks Autonomous Digital Experience Manager on Windows allows an unauthenticated attacker with adjacent network access to execute arbitrary code with NT AUTHORITY\SYSTEM privileges.

A certificate validation vulnerability in Palo Alto Networks Autonomous Digital Experience Manager on Windows allows an unauthenticated attacker with adjacent network access to execute arbitrary code with NT AUTHORITY\SYSTEM privileges.

▾ Twilightpaloaltonetworks · autonomous_digital_experience_managerEPSS 0.18%via NVD
CVE-2026-5936High· 8.5
5mo ago

An attacker can control a server-side HTTP request by supplying a crafted URL, causing the server to initiate requests to arbitrary destinations

An attacker can control a server-side HTTP request by supplying a crafted URL, causing the server to initiate requests to arbitrary destinations. This behavior may be exploited to probe internal network services, access otherwise unreach…

▾ Twilightfoxit · pdf_services_apiEPSS 0.34%via NVD
CVE-2026-6100High· 8.1
5mo ago

Use-after-free (UAF) was possible in the `lzma.LZMADecompressor`, `bz2.BZ2Decompressor`, and `gzip.GzipFile` when a memory allocation fails with a `MemoryError` and the decompression instance is re-used

Use-after-free (UAF) was possible in the `lzma.LZMADecompressor`, `bz2.BZ2Decompressor`, and `gzip.GzipFile` when a memory allocation fails with a `MemoryError` and the decompression instance is re-used. This scenario can be triggered if…

▾ TwilightEPSS 0.76%via NVD
CVE-2026-31419High· 7.8
5mo ago

In the Linux kernel, the following vulnerability has been resolved: net: bonding: fix use-after-free in bond_xmit_broadcast() bond_xmit_broadcast() reuses the original skb for the last slave (determined by bond_is_last_slave()) and clo…

In the Linux kernel, the following vulnerability has been resolved: net: bonding: fix use-after-free in bond_xmit_broadcast() bond_xmit_broadcast() reuses the original skb for the last slave (determined by bond_is_last_slave()) and clo…

▾ Twilightlinux · linux_kernelEPSS 0.18%via NVD
CVE-2026-1462High· 7.8
5mo ago

A vulnerability in the `TFSMLayer` class of the `keras` package, version 3.13.0, allows attacker-controlled TensorFlow SavedModels to be loaded during deserialization of `.keras` models, even when `safe_mode=True`

A vulnerability in the `TFSMLayer` class of the `keras` package, version 3.13.0, allows attacker-controlled TensorFlow SavedModels to be loaded during deserialization of `.keras` models, even when `safe_mode=True`. This bypasses the secu…

▾ Twilightkeras · kerasEPSS 0.40%via NVD
CVE-2026-31417High· 7.5
5mo ago

net/x25: Fix overflow when accumulating packets

In the Linux kernel, the following vulnerability has been resolved: net/x25: Fix overflow when accumulating packets Add a check to ensure that `x25_sock.fraglen` does not overflow. The `fraglen` also needs to be resetted when purging …

▾ TwilightLinux · LinuxEPSS 0.83%via CVEORG
CVE-2025-66236High· 7.5
5mo ago

Apache Airflow: Secrets from Airflow config file logged in plain text in DAG run logs UI

Before Airflow 3.2.0, it was unclear that secure Airflow deployments require the Deployment Manager to take appropriate actions and pay attention to security details and security model of Airflow. Some assumptions the Deployment Manager …

▾ TwilightApache Software Foundation · apache-airflowEPSS 0.44%via CVEORG
CVE-2026-4786High· 7.1
5mo ago

Mitgation of CVE-2026-4519 was incomplete

Mitgation of CVE-2026-4519 was incomplete. If the URL contained "%action" the mitigation could be bypassed for certain browser types the "webbrowser.open()" API could have commands injected into the underlying shell. See CVE-2026-4519 fo…

▾ TwilightEPSS 0.48%via NVD
CVE-2026-34476High· 7.1
5mo ago

Apache SkyWalking MCP: Server-Side Request Forgery via SW-URL Header in MCP Server

Apache SkyWalking MCP: Server-Side Request Forgery via SW-URL Header in MCP Server

▾ Twilightapache · github.com/apache/skywalking-mcpEPSS 0.54%via OSV
CVE-2025-31991Medium· 6.8
5mo ago

Rate Limiting for attempting a user login is not being properly enforced, making HCL DevOps Velocity susceptible to brute-force attacks past the unsuccessful login attempt limit.  This vulnerability is fixed in 5.1.7.

Rate Limiting for attempting a user login is not being properly enforced, making HCL DevOps Velocity susceptible to brute-force attacks past the unsuccessful login attempt limit.  This vulnerability is fixed in 5.1.7.

▾ Sunlithcltech · devops_velocityEPSS 0.23%via NVD

Most-affected vendors

By CVEs published in the period.