Daily digest
Friday 17 April 2026
A quiet day: only 20 new CVEs against a recent average of about 50. Severity skewed high: 4 critical and 9 high, 65% of the total. One arrived with exploitation evidence or public exploit code already attached. hashicorp was the most-affected vendor with 3.
New this day, ranked by depth score
The 12 that matter most of the 20 published.
CVE-2026-40477Critical· 9.0PoCThymeleaf is a server-side Java template engine for web and standalone environments
Thymeleaf is a server-side Java template engine for web and standalone environments. Versions 3.1.3.RELEASE and prior contain a security bypass vulnerability in the expression execution mechanisms. Although the library provides mechanism…
CVE-2026-5720Critical· 9.1miniupnpd contains an integer underflow vulnerability in SOAPAction header parsing that allows remote attackers to cause a denial of service or information disclosure by sending a malformed SOAPAction header with a single quote
miniupnpd contains an integer underflow vulnerability in SOAPAction header parsing that allows remote attackers to cause a denial of service or information disclosure by sending a malformed SOAPAction header with a single quote. Attacker…
CVE-2026-40525Critical· 9.1OpenViking: Unauthenticated remote bot control via OpenAPI HTTP routes
OpenViking: Unauthenticated remote bot control via OpenAPI HTTP routes
CVE-2026-40478Critical· 9.0Thymeleaf is a server-side Java template engine for web and standalone environments
Thymeleaf is a server-side Java template engine for web and standalone environments. Versions 3.1.3.RELEASE and prior contain a security bypass vulnerability in the the expression execution mechanisms. Although the library provides mecha…
CVE-2026-40066High· 8.8Anviz CX2 Lite and CX7 are vulnerable to unverified update packages that can be uploaded
Anviz CX2 Lite and CX7 are vulnerable to unverified update packages that can be uploaded. The device unpacks and executes a script resulting in unauthenticated remote code execution.
CVE-2026-41496High· 8.1PraisonAI: SQL Injection via unvalidated `table_prefix` in 9 conversation store backends (incomplete fix for CVE-2026-40315)
PraisonAI: SQL Injection via unvalidated `table_prefix` in 9 conversation store backends (incomplete fix for CVE-2026-40315)
CVE-2026-41491High· 8.1Dapr: Service Invocation path traversal ACL bypass
Dapr: Service Invocation path traversal ACL bypass
CVE-2026-6507High· 7.5A flaw was found in dnsmasq
A flaw was found in dnsmasq. A remote attacker could exploit an out-of-bounds write vulnerability by sending a specially crafted BOOTREPLY (Bootstrap Protocol Reply) packet to a dnsmasq server configured with the `--dhcp-split-relay` opt…
CVE-2026-5807High· 7.5HashiCorp Vault Vulnerable to Denial-of-Service via Unauthenticated Root Token Generation/Rekey Operations
HashiCorp Vault Vulnerable to Denial-of-Service via Unauthenticated Root Token Generation/Rekey Operations
CVE-2026-4525High· 7.5HashiCorp Vault May Expose Tokens to Auth Plugins Due to Incorrect Header Sanitization
HashiCorp Vault May Expose Tokens to Auth Plugins Due to Incorrect Header Sanitization
CVE-2026-40476High· 7.5graphql-go is a Go implementation of GraphQL
graphql-go is a Go implementation of GraphQL. In versions 15.31.4 and below, the OverlappingFieldsCanBeMerged validation rule performs O(n²) pairwise comparisons of fields sharing the same response name. An attacker can send a query with…
CVE-2026-40293High· 7.5OpenFGA: github.com/openfga/openfga: OpenFGA: Information disclosure of preshared API key via playground endpoint (CVE-2026-40293)
A flaw was found in OpenFGA, an authorization/permission engine. When OpenFGA is configured to use preshared-key authentication and the built-in playground is enabled and accessible beyond localhost or trusted networks, a remote attacker c…
Most-affected vendors
By CVEs published in the period.