Daily digest
Thursday 23 April 2026
19 new CVEs this day, in line with the recent average. Severity skewed high: 8 critical and 5 high, 68% of the total. One arrived with exploitation evidence or public exploit code already attached. Microsoft was the most-affected vendor with 7.
New this day, ranked by depth score
The 12 that matter most of the 19 published.
CVE-2026-41176Critical· 9.8PoCRclone is a command-line program to sync files and directories to and from different cloud storage providers
Rclone is a command-line program to sync files and directories to and from different cloud storage providers. The RC endpoint `options/set` is exposed without `AuthRequired: true`, but it can mutate global runtime configuration, includin…
CVE-2026-35431Critical· 10.0Microsoft Entra ID Entitlement Management Spoofing Vulnerability
Server-side request forgery (ssrf) in Microsoft Entra ID Entitlement Management allows an unauthorized attacker to perform spoofing over a network.
CVE-2026-33819Critical· 10.0Microsoft Bing Remote Code Execution Vulnerability
Deserialization of untrusted data in Microsoft Bing allows an unauthorized attacker to execute code over a network.
CVE-2026-3960Critical· 9.8A critical remote code execution vulnerability exists in the unauthenticated REST API endpoint /99/ImportSQLTable in H2O-3 version 3.46.0…
A critical remote code execution vulnerability exists in the unauthenticated REST API endpoint /99/ImportSQLTable in H2O-3 version 3.46.0.9 and prior. The vulnerability arises due to insufficient security controls in the parameter blackl…
CVE-2026-31533Critical· 9.8net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption
In the Linux kernel, the following vulnerability has been resolved: net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption The -EBUSY handling in tls_do_encryption(), introduced by commit 859054147318 ("net: tls: handle …
CVE-2026-24303Critical· 9.6Microsoft Partner Center Elevation of Privilege Vulnerability
Improper access control in Microsoft Partner Center allows an authorized attacker to elevate privileges over a network.
CVE-2026-33102Critical· 9.3Microsoft 365 Copilot Elevation of Privilege Vulnerability
Url redirection to untrusted site ('open redirect') in M365 Copilot allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-32210Critical· 9.3Microsoft Dynamics 365 (online) Spoofing Vulnerability
Server-side request forgery (ssrf) in Microsoft Dynamics 365 (Online) allows an unauthorized attacker to perform spoofing over a network.
CVE-2026-26150High· 8.6Microsoft Purview eDiscovery Elevation of Privilege Vulnerability
Server-side request forgery (ssrf) in Microsoft Purview allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-32172High· 8.0Microsoft Power Apps Remote Code Execution Vulnerability
Uncontrolled search path element in Microsoft Power Apps allows an unauthorized attacker to execute code over a network.
CVE-2026-33694High· 7.8This vulnerability allows an attacker to create a junction, enabling the deletion of arbitrary files with SYSTEM privileges
This vulnerability allows an attacker to create a junction, enabling the deletion of arbitrary files with SYSTEM privileges. As a result, this condition potentially facilitates arbitrary code execution, whereby an attacker may exploit th…
CVE-2026-40886High· 7.7Argo Workflows: Unchecked annotation parsing in pod informer crashes Argo Workflows Controller
Argo Workflows: Unchecked annotation parsing in pod informer crashes Argo Workflows Controller
Most-affected vendors
By CVEs published in the period.