Daily digest
Thursday 16 April 2026
A quiet day: only 31 new CVEs against a recent average of about 71. Of those, 2 critical and 10 high. One arrived with exploitation evidence or public exploit code already attached. CISA added one CVE to the Known Exploited Vulnerabilities catalog. weblate was the most-affected vendor with 5.
Added to CISA KEV
Confirmed exploitation in the wild — federal remediation deadlines attach to these.
New this day, ranked by depth score
The 12 that matter most of the 31 published.
CVE-2026-31843Critical· 9.8The goodoneuz/pay-uz Laravel package (<= 2.2.24) contains a critical vulnerability in the /payment/api/editable/update endpoint that allows unauthenticated attackers to overwrite existing PHP payment hook files
The goodoneuz/pay-uz Laravel package (<= 2.2.24) contains a critical vulnerability in the /payment/api/editable/update endpoint that allows unauthenticated attackers to overwrite existing PHP payment hook files. The endpoint is exposed v…
CVE-2026-40173Critical· 9.4Dgraph: Unauthenticated /debug/pprof/cmdline discloses admin auth token, enabling unauthorized access to protected Alpha admin endpoints
Dgraph: Unauthenticated /debug/pprof/cmdline discloses admin auth token, enabling unauthorized access to protected Alpha admin endpoints
CVE-2026-40611High· 8.8ACME Lego: Arbitrary File Write via Path Traversal in Webroot HTTP-01 Provider
ACME Lego: Arbitrary File Write via Path Traversal in Webroot HTTP-01 Provider
CVE-2026-2336High· 8.8A privilege escalation vulnerability in Microchip IStaX allows an authenticated low-privileged user to recover a shared per-device cookie secret from their own webstax_auth session cookie and forge a new cookie with administrative privil…
A privilege escalation vulnerability in Microchip IStaX allows an authenticated low-privileged user to recover a shared per-device cookie secret from their own webstax_auth session cookie and forge a new cookie with administrative privil…
CVE-2025-54550High· 8.1Apache Airflow: RCE by race condition in example_xcom dag
Apache Airflow: RCE by race condition in example_xcom dag
CVE-2026-41068High· 7.7Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix)
Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix)
CVE-2026-40474High· 7.6wger has Broken Access Control in Global Gym Configuration Update Endpoint
wger has Broken Access Control in Global Gym Configuration Update Endpoint
CVE-2026-34242High· 7.7Weblate: Arbitrary File Read via Symlink
Weblate: Arbitrary File Read via Symlink
CVE-2026-1880Medium· 5.4PoCAn Incorrect Permission Assignment for Critical Resource vulnerability in the ASUS DriverHub update process allows privilege escalation due to improper protection of required execution resources during the validation phase, permitting a …
An Incorrect Permission Assignment for Critical Resource vulnerability in the ASUS DriverHub update process allows privilege escalation due to improper protection of required execution resources during the validation phase, permitting a …
CVE-2026-41205High· 7.5Mako: Path traversal via double-slash URI prefix in TemplateLookup
Mako: Path traversal via double-slash URI prefix in TemplateLookup
CVE-2026-41035High· 7.4In rsync 3.0.1 through 3.4.1, receive_xattr relies on an untrusted length value during a qsort call, leading to a receiver use-after-free
In rsync 3.0.1 through 3.4.1, receive_xattr relies on an untrusted length value during a qsort call, leading to a receiver use-after-free. The victim must run rsync with -X (aka --xattrs). On Linux, many (but not all) common configuratio…
CVE-2026-31987High· 7.5Apache Airflow: JWT token appearing in logs
Apache Airflow: JWT token appearing in logs
Most-affected vendors
By CVEs published in the period.