VulnSea

Daily digest

Tuesday 28 April 2026

A busier-than-usual day with 27 new CVEs (recent average about 22). Severity skewed high: 1 critical and 14 high, 56% of the total. 2 arrived with exploitation evidence or public exploit code already attached. CISA added one CVE to the Known Exploited Vulnerabilities catalog. apache was the most-affected vendor with 7.

27
New CVEs
1
Critical
1
KEV additions
0
Records changed

Added to CISA KEV

Confirmed exploitation in the wild — federal remediation deadlines attach to these.

New this day, ranked by depth score

The 12 that matter most of the 27 published.

CVE-2026-42167High· 8.1PoC
5mo ago

mod_sql in ProFTPD before 1.3.9a allows remote attackers to execute arbitrary code via a username, in scenarios where there is logging of USER requests with an expansion such as %U, and the SQL backend allows commands (e.g., COPY TO PROG…

mod_sql in ProFTPD before 1.3.9a allows remote attackers to execute arbitrary code via a username, in scenarios where there is logging of USER requests with an expansion such as %U, and the SQL backend allows commands (e.g., COPY TO PROG…

▾ Midnightproftpd · proftpdEPSS 7.3%via NVD
CVE-2026-32644Critical· 9.8
5mo ago

Specific firmware versions of Milesight AIOT cameras use SSL certificates with default private keys.

Specific firmware versions of Milesight AIOT cameras use SSL certificates with default private keys.

▾ MidnightEPSS 0.39%via NVD
CVE-2026-27785High· 8.8
5mo ago

Specific firmware versions of Milesight AIOT camera firmware contain hard-coded credentials.

Specific firmware versions of Milesight AIOT camera firmware contain hard-coded credentials.

▾ TwilightEPSS 0.35%via NVD
CVE-2024-54013High· 8.8
5mo ago

Penetration Testing engineers at Amazon have identified a security flaw related to request handling in the web server component that could, under certain conditions, lead to unintended access to protected functions

Penetration Testing engineers at Amazon have identified a security flaw related to request handling in the web server component that could, under certain conditions, lead to unintended access to protected functions. The manufacturer has …

▾ TwilightEPSS 0.19%via NVD
CVE-2026-41604High· 8.2
5mo ago

Out-of-bounds Read vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issue.

Out-of-bounds Read vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issue.

▾ Twilightapache · thriftEPSS 1.2%via NVD
CVE-2026-40355Medium· 5.9PoC
5mo ago

In MIT Kerberos 5 (aka krb5) before 1.22.3, there is a NULL pointer dereference if an application calls gss_accept_sec_context() on a system with a NegoEx mechanism registered in /etc/gss/mech

In MIT Kerberos 5 (aka krb5) before 1.22.3, there is a NULL pointer dereference if an application calls gss_accept_sec_context() on a system with a NegoEx mechanism registered in /etc/gss/mech. An unauthenticated remote attacker can trig…

▾ Twilightmit · kerberos_5EPSS 0.79%via NVD
CVE-2026-41602High· 7.5
5mo ago

Integer Overflow or Wraparound vulnerability in Apache Thrift TFramedTransport Go language implementation This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issue.

Integer Overflow or Wraparound vulnerability in Apache Thrift TFramedTransport Go language implementation This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issue.

▾ Twilightapache · thriftEPSS 1.4%via NVD
CVE-2026-41603High· 7.4
5mo ago

Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issue.

Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issue.

▾ Twilightapache · thriftEPSS 0.57%via NVD
CVE-2026-32936High· 7.5
5mo ago

CoreDNS DoH GET oversized dns= query parameter causes pre-validation CPU and memory amplification

CoreDNS DoH GET oversized dns= query parameter causes pre-validation CPU and memory amplification

▾ Twilightcoredns · github.com/coredns/corednsEPSS 0.61%via OSV
CVE-2026-32934High· 7.5
5mo ago

CoreDNS' DoQ worker pool does not bound stream backlog

CoreDNS' DoQ worker pool does not bound stream backlog

▾ Twilightcoredns · github.com/coredns/corednsEPSS 0.63%via OSV
CVE-2025-48431High· 7.5
5mo ago

Mismatched Memory Management Routines vulnerability in Apache Thrift c_glib language bindings. This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issue. Description: Sp…

Mismatched Memory Management Routines vulnerability in Apache Thrift c_glib language bindings. This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issue. Description: Sp…

▾ Twilightapache · thriftEPSS 1.1%via NVD
CVE-2026-7212High· 7.3
5mo ago

notes-mcp has a Path Traversal issue

notes-mcp has a Path Traversal issue

▾ Twilightnotes-mcp · notes-mcpEPSS 0.59%via OSV

Most-affected vendors

By CVEs published in the period.