VulnSea

Daily digest

Tuesday 14 April 2026

A heavy day: 215 new CVEs, well above the recent average of about 57. Severity skewed high: 4 critical and 152 high, 73% of the total. 12 arrived with exploitation evidence or public exploit code already attached. CISA added one CVE to the Known Exploited Vulnerabilities catalog. Microsoft was the most-affected vendor with 163.

215
New CVEs
4
Critical
1
KEV additions
0
Records changed

Added to CISA KEV

Confirmed exploitation in the wild — federal remediation deadlines attach to these.

New this day, ranked by depth score

The 12 that matter most of the 215 published.

CVE-2026-39808Critical· 9.8CISA KEVPoC
5mo ago

A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.8 may allow attacker to execute unauthorized code or commands via <insert attack vector…

A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.8 may allow attacker to execute unauthorized code or commands via <insert attack vector…

▾ Hadalfortinet · fortisandboxEPSS 47%via NVD
CVE-2026-33824Critical· 9.8CISA KEVPoC
5mo ago

Double free in Windows IKE Extension allows an unauthorized attacker to execute code over a network.

Double free in Windows IKE Extension allows an unauthorized attacker to execute code over a network.

▾ Hadalmicrosoft · windows_10_1607EPSS 1.6%via NVD
CVE-2026-33825High· 7.8CISA KEVPoC
5mo ago

Microsoft Defender Elevation of Privilege Vulnerability

Insufficient granularity of access control in Microsoft Defender allows an authorized attacker to elevate privileges locally.

▾ AbyssalMicrosoft · Microsoft Defender Antimalware PlatformEPSS 0.40%via CVEORG
CVE-2026-32201Medium· 6.5CISA KEV0dayPoC
5mo ago

Microsoft SharePoint Server Spoofing Vulnerability

Improper input validation in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.

▾ MidnightMicrosoft · Microsoft SharePoint Enterprise Server 2016EPSS 0.98%via CVEORG
CVE-2026-33827High· 8.1PoC
5mo ago

Windows TCP/IP Remote Code Execution Vulnerability

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows TCP/IP allows an unauthorized attacker to execute code over a network.

▾ MidnightMicrosoft · Windows 10 Version 1607EPSS 0.54%via CVEORG
CVE-2026-33826High· 8.0PoC
5mo ago

Windows Active Directory Remote Code Execution Vulnerability

Improper input validation in Windows Active Directory allows an authorized attacker to execute code over an adjacent network.

▾ MidnightMicrosoft · Windows Server 2012 R2EPSS 0.54%via CVEORG
CVE-2026-27912High· 8.0PoC
5mo ago

Windows Kerberos Elevation of Privilege Vulnerability

Improper authorization in Windows Kerberos allows an authorized attacker to elevate privileges over an adjacent network.

▾ MidnightMicrosoft · Windows Server 2012EPSS 0.43%via CVEORG
CVE-2026-26179High· 7.8PoC
5mo ago

Windows Kernel Elevation of Privilege Vulnerability

Double free in Windows Kernel allows an authorized attacker to elevate privileges locally.

▾ MidnightMicrosoft · Windows 11 version 22H3EPSS 0.33%via CVEORG
CVE-2026-2332High· 7.4PoC
5mo ago

In Eclipse Jetty, the HTTP/1.1 parser is vulnerable to request smuggling when chunk extensions are used, similar to the "funky chunks" techniques outlined here: * https://w4ke.info/2025/06/18/funky-chunks.html * https://w4ke.info/…

In Eclipse Jetty, the HTTP/1.1 parser is vulnerable to request smuggling when chunk extensions are used, similar to the "funky chunks" techniques outlined here: * https://w4ke.info/2025/06/18/funky-chunks.html * https://w4ke.info/…

▾ Midnighteclipse · jettyEPSS 1.3%via NVD
CVE-2026-27304Critical· 9.3
5mo ago

ColdFusion versions 2023.18, 2025.6 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user

ColdFusion versions 2023.18, 2025.6 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user…

▾ Midnightadobe · coldfusionEPSS 0.46%via NVD
CVE-2026-32223Medium· 6.8PoC
5mo ago

Heap-based buffer overflow in Windows USB Print Driver allows an unauthorized attacker to elevate privileges with a physical attack.

Heap-based buffer overflow in Windows USB Print Driver allows an unauthorized attacker to elevate privileges with a physical attack.

▾ Twilightmicrosoft · windows_11_24h2EPSS 0.56%via NVD
CVE-2026-32202Medium· 4.3CISA KEVPoC
5mo ago

Protection mechanism failure in Windows Shell allows an unauthorized attacker to perform spoofing over a network.

Protection mechanism failure in Windows Shell allows an unauthorized attacker to perform spoofing over a network.

▾ Midnightmicrosoft · windows_10_1607EPSS 4.9%via NVD

Most-affected vendors

By CVEs published in the period.