Daily digest
Tuesday 14 April 2026
A heavy day: 215 new CVEs, well above the recent average of about 57. Severity skewed high: 4 critical and 152 high, 73% of the total. 12 arrived with exploitation evidence or public exploit code already attached. CISA added one CVE to the Known Exploited Vulnerabilities catalog. Microsoft was the most-affected vendor with 163.
Added to CISA KEV
Confirmed exploitation in the wild — federal remediation deadlines attach to these.
New this day, ranked by depth score
The 12 that matter most of the 215 published.
CVE-2026-39808Critical· 9.8CISA KEVPoCA improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.8 may allow attacker to execute unauthorized code or commands via <insert attack vector…
A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.8 may allow attacker to execute unauthorized code or commands via <insert attack vector…
CVE-2026-33824Critical· 9.8CISA KEVPoCDouble free in Windows IKE Extension allows an unauthorized attacker to execute code over a network.
Double free in Windows IKE Extension allows an unauthorized attacker to execute code over a network.
CVE-2026-33825High· 7.8CISA KEVPoCMicrosoft Defender Elevation of Privilege Vulnerability
Insufficient granularity of access control in Microsoft Defender allows an authorized attacker to elevate privileges locally.
CVE-2026-32201Medium· 6.5CISA KEV0dayPoCMicrosoft SharePoint Server Spoofing Vulnerability
Improper input validation in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.
CVE-2026-33827High· 8.1PoCWindows TCP/IP Remote Code Execution Vulnerability
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows TCP/IP allows an unauthorized attacker to execute code over a network.
CVE-2026-33826High· 8.0PoCWindows Active Directory Remote Code Execution Vulnerability
Improper input validation in Windows Active Directory allows an authorized attacker to execute code over an adjacent network.
CVE-2026-27912High· 8.0PoCWindows Kerberos Elevation of Privilege Vulnerability
Improper authorization in Windows Kerberos allows an authorized attacker to elevate privileges over an adjacent network.
CVE-2026-26179High· 7.8PoCWindows Kernel Elevation of Privilege Vulnerability
Double free in Windows Kernel allows an authorized attacker to elevate privileges locally.
CVE-2026-2332High· 7.4PoCIn Eclipse Jetty, the HTTP/1.1 parser is vulnerable to request smuggling when chunk extensions are used, similar to the "funky chunks" techniques outlined here: * https://w4ke.info/2025/06/18/funky-chunks.html * https://w4ke.info/…
In Eclipse Jetty, the HTTP/1.1 parser is vulnerable to request smuggling when chunk extensions are used, similar to the "funky chunks" techniques outlined here: * https://w4ke.info/2025/06/18/funky-chunks.html * https://w4ke.info/…
CVE-2026-27304Critical· 9.3ColdFusion versions 2023.18, 2025.6 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user
ColdFusion versions 2023.18, 2025.6 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user…
CVE-2026-32223Medium· 6.8PoCHeap-based buffer overflow in Windows USB Print Driver allows an unauthorized attacker to elevate privileges with a physical attack.
Heap-based buffer overflow in Windows USB Print Driver allows an unauthorized attacker to elevate privileges with a physical attack.
CVE-2026-32202Medium· 4.3CISA KEVPoCProtection mechanism failure in Windows Shell allows an unauthorized attacker to perform spoofing over a network.
Protection mechanism failure in Windows Shell allows an unauthorized attacker to perform spoofing over a network.
Most-affected vendors
By CVEs published in the period.