Daily digest
Tuesday 21 April 2026
25 new CVEs this day, in line with the recent average. Of those, 1 critical and 10 high. 2 arrived with exploitation evidence or public exploit code already attached. openbao was the most-affected vendor with 4.
New this day, ranked by depth score
The 12 that matter most of the 25 published.
CVE-2026-33626High· 7.5PoCLMDeploy has Server-Side Request Forgery (SSRF) via Vision-Language Image Loading
LMDeploy has Server-Side Request Forgery (SSRF) via Vision-Language Image Loading
CVE-2026-22016High· 7.5PoCVulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JAXP)
Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JAXP). Supported versions that are affected are Oracle Java SE: 8u481, 8u481-b50, 8u481-perf, 11.0.30, …
CVE-2026-40372Critical· 9.1Improper verification of cryptographic signature in ASP.NET Core allows an unauthorized attacker to elevate privileges over a network.
Improper verification of cryptographic signature in ASP.NET Core allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-35587High· 8.8Glances has SSRF in IP Plugin via public_api leading to credential leakage
Glances has SSRF in IP Plugin via public_api leading to credential leakage
CVE-2026-41066High· 7.5lxml: Default configuration of iterparse() and ETCompatXMLParser() allows XXE to local files
lxml: Default configuration of iterparse() and ETCompatXMLParser() allows XXE to local files
CVE-2026-40938High· 7.5Tekton Pipelines project provides k8s-style resources for declaring CI/CD-style pipelines
Tekton Pipelines project provides k8s-style resources for declaring CI/CD-style pipelines. Starting in version 1.0.0 and prior to versions 1.0.2, 1.3.4, 1.6.2, 1.9.3, and 1.11.1, the git resolver's revision parameter is passed directly a…
CVE-2026-40895High· 7.5follow-redirects is an open source, drop-in replacement for Node's `http` and `https` modules that automatically follows redirects
follow-redirects is an open source, drop-in replacement for Node's `http` and `https` modules that automatically follows redirects. Prior to 1.16.0, when an HTTP request follows a cross-domain redirect (301/302/307/308), follow-redirects…
CVE-2026-40890High· 7.5github.com/gomarkdown/markdown: github.com/gomarkdown/markdown: Denial of Service via malformed Markdown input (CVE-2026-40890)
A flaw was found in github.com/gomarkdown/markdown, a Go library for parsing Markdown text and rendering as HTML. A remote attacker could exploit this vulnerability by providing a specially crafted malformed input. Specifically, input cont…
CVE-2026-34282High· 7.5Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Networking)
Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Networking). Supported versions that are affected are Oracle Java SE: 8u481-perf, 11.0.30, 17.0.18, 21.…
CVE-2026-33813High· 7.5Parsing a WEBP image with an invalid, large size panics on 32-bit platforms.
Parsing a WEBP image with an invalid, large size panics on 32-bit platforms.
CVE-2026-40520High· 7.2FreePBX api module Command Injection via GraphQL
FreePBX api module version 17.0.8 and prior contain a command injection vulnerability in the initiateGqlAPIProcess() function where GraphQL mutation input fields are passed directly to shell_exec() without sanitization or escaping. An au…
CVE-2026-39378Medium· 6.5nbconvert has an Arbitrary File Read via Path Traversal in HTMLExporter Image Embedding
nbconvert has an Arbitrary File Read via Path Traversal in HTMLExporter Image Embedding
Most-affected vendors
By CVEs published in the period.