VulnSea

Daily digest

Friday 1 May 2026

A heavy day: 30 new CVEs, well above the recent average of about 18. Severity skewed high: 3 critical and 15 high, 60% of the total. One arrived with exploitation evidence or public exploit code already attached. CISA added one CVE to the Known Exploited Vulnerabilities catalog. linux was the most-affected vendor with 23.

30
New CVEs
3
Critical
1
KEV additions
0
Records changed

Added to CISA KEV

Confirmed exploitation in the wild — federal remediation deadlines attach to these.

New this day, ranked by depth score

The 12 that matter most of the 30 published.

CVE-2026-31694High· 7.8PoC
5mo ago

In the Linux kernel, the following vulnerability has been resolved: fuse: reject oversized dirents in page cache fuse_add_dirent_to_cache() computes a serialized dirent size from the server-controlled namelen field and copies the diren…

In the Linux kernel, the following vulnerability has been resolved: fuse: reject oversized dirents in page cache fuse_add_dirent_to_cache() computes a serialized dirent size from the server-controlled namelen field and copies the diren…

▾ Midnightlinux · linux_kernelEPSS 0.17%via NVD
CVE-2026-43038Critical· 9.8
5mo ago

In the Linux kernel, the following vulnerability has been resolved: ipv6: icmp: clear skb2->cb[] in ip6_err_gen_icmpv6_unreach() Sashiko AI-review observed: In ip6_err_gen_icmpv6_unreach(), the skb is an outer IPv4 ICMP error packet…

In the Linux kernel, the following vulnerability has been resolved: ipv6: icmp: clear skb2->cb[] in ip6_err_gen_icmpv6_unreach() Sashiko AI-review observed: In ip6_err_gen_icmpv6_unreach(), the skb is an outer IPv4 ICMP error packet…

▾ Midnightlinux · linux_kernelEPSS 0.44%via NVD
CVE-2026-43037Critical· 9.8
5mo ago

In the Linux kernel, the following vulnerability has been resolved: ip6_tunnel: clear skb2->cb[] in ip4ip6_err() Oskar Kjos reported the following problem. ip4ip6_err() calls icmp_send() on a cloned skb whose cb[] was written by the I…

In the Linux kernel, the following vulnerability has been resolved: ip6_tunnel: clear skb2->cb[] in ip4ip6_err() Oskar Kjos reported the following problem. ip4ip6_err() calls icmp_send() on a cloned skb whose cb[] was written by the I…

▾ MidnightEPSS 0.83%via NVD
CVE-2026-43011Critical· 9.8
5mo ago

net/x25: Fix potential double free of skb

In the Linux kernel, the following vulnerability has been resolved: net/x25: Fix potential double free of skb When alloc_skb fails in x25_queue_rx_frame it calls kfree_skb(skb) at line 48 and returns 1 (error). This error propagates ba…

▾ MidnightLinux · LinuxEPSS 0.87%via CVEORG
CVE-2026-37552High· 8.4
5mo ago

Unsafe deserialization vulnerability in MixPHP Framework 2.x thru 2.2.17

Unsafe deserialization vulnerability in MixPHP Framework 2.x thru 2.2.17. The sync-invoke TCP server (Server.php:87) receives data from a TCP socket, passes it directly to Opis\Closure\unserialize(), then executes the result via call_use…

▾ Twilightopenmix · mix_phpEPSS 0.48%via NVD
CVE-2026-43003High· 8.0
5mo ago

An issue was discovered in OpenStack ironic-python-agent 1.0.0 through 11.5.0

An issue was discovered in OpenStack ironic-python-agent 1.0.0 through 11.5.0. Ironic Python Agent (IPA) sometimes executes grub-install from within a chroot of the deployed partition image, leading to code execution in the case of a mal…

▾ Twilightopenstack · ironic_python_agentEPSS 1.1%via NVD
CVE-2026-43001High· 8.0
5mo ago

OpenStack Keystone: OpenStack Keystone: Unauthorized cross-project access due to improper validation in EC2 credential creation (CVE-2026-4…

A flaw was found in OpenStack Keystone. An attacker holding an unrestricted application credential could exploit a vulnerability in the POST /v3/credentials endpoint where the caller-supplied project_id for an EC2-type credential was not v…

▾ TwilightRed Hat · Red Hat OpenStack Platform 17.1EPSS 0.59%via CSAF
CVE-2026-43033High· 7.8
5mo ago

crypto: authencesn - Do not place hiseq at end of dst for out-of-place decryption

In the Linux kernel, the following vulnerability has been resolved: crypto: authencesn - Do not place hiseq at end of dst for out-of-place decryption When decrypting data that is not in-place (src != dst), there is no need to save the …

▾ TwilightLinux · LinuxEPSS 0.18%via CVEORG
CVE-2026-43030High· 7.8
5mo ago

bpf: Fix regsafe() for pointers to packet

In the Linux kernel, the following vulnerability has been resolved: bpf: Fix regsafe() for pointers to packet In case rold->reg->range == BEYOND_PKT_END && rcur->reg->range == N regsafe() may return true which may lead to current state…

▾ TwilightLinux · LinuxEPSS 0.18%via CVEORG
CVE-2026-43009High· 7.8
5mo ago

In the Linux kernel, the following vulnerability has been resolved: bpf: Fix incorrect pruning due to atomic fetch precision tracking When backtrack_insn encounters a BPF_STX instruction with BPF_ATOMIC and BPF_FETCH, the src register …

In the Linux kernel, the following vulnerability has been resolved: bpf: Fix incorrect pruning due to atomic fetch precision tracking When backtrack_insn encounters a BPF_STX instruction with BPF_ATOMIC and BPF_FETCH, the src register …

▾ Twilightlinux · linux_kernelEPSS 0.17%via NVD
CVE-2026-31768High· 7.8
5mo ago

iio: adc: ti-adc161s626: use DMA-safe memory for spi_read()

In the Linux kernel, the following vulnerability has been resolved: iio: adc: ti-adc161s626: use DMA-safe memory for spi_read() Add a DMA-safe buffer and use it for spi_read() instead of a stack memory. All SPI buffers must be DMA-safe…

▾ TwilightLinux · LinuxEPSS 0.18%via CVEORG
CVE-2026-31761High· 7.8
5mo ago

iio: gyro: mpu3050: Move iio_device_register() to correct location

In the Linux kernel, the following vulnerability has been resolved: iio: gyro: mpu3050: Move iio_device_register() to correct location iio_device_register() should be at the end of the probe function to prevent race conditions. Place …

▾ TwilightLinux · LinuxEPSS 0.14%via CVEORG

Most-affected vendors

By CVEs published in the period.