VulnSea

Daily digest

Wednesday 22 April 2026

42 new CVEs this day, in line with the recent average. Of those, 3 critical and 16 high. 3 arrived with exploitation evidence or public exploit code already attached. CISA added one CVE to the Known Exploited Vulnerabilities catalog. Linux was the most-affected vendor with 21.

42
New CVEs
3
Critical
1
KEV additions
0
Records changed

Added to CISA KEV

Confirmed exploitation in the wild — federal remediation deadlines attach to these.

New this day, ranked by depth score

The 12 that matter most of the 42 published.

CVE-2026-31431High· 7.8CISA KEVPoC
5mo ago

In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commit 72548b093ee3 except for the copying of the associated data. There is no benefit in op…

In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commit 72548b093ee3 except for the copying of the associated data. There is no benefit in op…

▾ Abyssalredhat · openshift_container_platformEPSS 3.4%via NVD
CVE-2026-41179Critical· 9.8PoC
5mo ago

RClone: Unauthenticated operations/fsinfo allows attacker-controlled backend instantiation and local command execution

RClone: Unauthenticated operations/fsinfo allows attacker-controlled backend instantiation and local command execution

▾ Abyssalrclone · github.com/rclone/rcloneEPSS 5.3%via OSV
CVE-2026-6235Critical· 9.8
5mo ago

The Sendmachine for WordPress plugin for WordPress is vulnerable to authorization bypass via the 'manage_admin_requests' function in all versions up to, and including, 1.0.20

The Sendmachine for WordPress plugin for WordPress is vulnerable to authorization bypass via the 'manage_admin_requests' function in all versions up to, and including, 1.0.20. This is due to the plugin not properly verifying that a user …

▾ MidnightEPSS 0.67%via NVD
CVE-2026-6857High· 7.5PoC
5mo ago

A flaw was found in camel-infinispan

A flaw was found in camel-infinispan. This vulnerability involves unsafe deserialization in the ProtoStream remote aggregation repository. A remote attacker with low privileges could exploit this by sending specially crafted data, leadin…

▾ MidnightRed Hat · camel-infinispanEPSS 1.2%via NVD
CVE-2026-31448Critical· 9.4
5mo ago

ext4: avoid infinite loops caused by residual data

In the Linux kernel, the following vulnerability has been resolved: ext4: avoid infinite loops caused by residual data On the mkdir/mknod path, when mapping logical blocks to physical blocks, if inserting a new extent into the extent t…

▾ MidnightLinux · LinuxEPSS 0.65%via CVEORG
CVE-2026-6859High· 8.8
5mo ago

InstructLab Includes Functionality from Untrusted Control Sphere

InstructLab Includes Functionality from Untrusted Control Sphere

▾ Twilightinstructlab · instructlabEPSS 0.77%via OSV
CVE-2026-31450High· 8.8
5mo ago

ext4: publish jinode after initialization

In the Linux kernel, the following vulnerability has been resolved: ext4: publish jinode after initialization ext4_inode_attach_jinode() publishes ei->jinode to concurrent users. It used to set ei->jinode before jbd2_journal_init_jbd_i…

▾ TwilightLinux · LinuxEPSS 0.77%via CVEORG
CVE-2026-6846High· 7.8
5mo ago

A flaw was found in binutils

A flaw was found in binutils. A heap-buffer-overflow vulnerability exists when processing a specially crafted XCOFF (Extended Common Object File Format) object file during linking. A local attacker could trick a user into processing this…

▾ Twilightgnu · binutilsEPSS 0.20%via NVD
CVE-2026-41134High· 7.8
5mo ago

Kiota is an OpenAPI based HTTP Client code generator

Kiota is an OpenAPI based HTTP Client code generator. Versions prior to 1.29.1 and 1.31.1 are affected by a code-generation literal injection vulnerability in multiple writer sinks (for example: serialization/deserialization keys, path/q…

▾ Twilightmicrosoft · kiotaEPSS 0.35%via NVD
CVE-2026-31508High· 7.8
5mo ago

net: openvswitch: Avoid releasing netdev before teardown completes

In the Linux kernel, the following vulnerability has been resolved: net: openvswitch: Avoid releasing netdev before teardown completes The patch cited in the Fixes tag below changed the teardown code for OVS ports to no longer uncondit…

▾ TwilightLinux · LinuxEPSS 0.18%via CVEORG
CVE-2026-31507High· 7.8
5mo ago

net/smc: fix double-free of smc_spd_priv when tee() duplicates splice pipe buffer

In the Linux kernel, the following vulnerability has been resolved: net/smc: fix double-free of smc_spd_priv when tee() duplicates splice pipe buffer smc_rx_splice() allocates one smc_spd_priv per pipe_buffer and stores the pointer in …

▾ TwilightLinux · LinuxEPSS 0.18%via CVEORG
CVE-2026-31504High· 7.8
5mo ago

net: fix fanout UAF in packet_release() via NETDEV_UP race

In the Linux kernel, the following vulnerability has been resolved: net: fix fanout UAF in packet_release() via NETDEV_UP race `packet_release()` has a race window where `NETDEV_UP` can re-register a socket into a fanout group's `arr[]…

▾ TwilightLinux · LinuxEPSS 0.18%via CVEORG

Most-affected vendors

By CVEs published in the period.