Daily digest
Monday 4 May 2026
A heavy day: 34 new CVEs, well above the recent average of about 14. Severity skewed high: 6 critical and 16 high, 65% of the total. 2 arrived with exploitation evidence or public exploit code already attached. openc3 was the most-affected vendor with 4.
New this day, ranked by depth score
The 12 that matter most of the 34 published.
CVE-2026-7482Critical· 9.1PoCOllama contains a heap out-of-bounds read vulnerability in the GGUF model loader
Ollama contains a heap out-of-bounds read vulnerability in the GGUF model loader
CVE-2026-42601Critical· 9.8ArchiveBox Vulnerable to RCE via unvalidated per-crawl config overrides in AddView
ArchiveBox Vulnerable to RCE via unvalidated per-crawl config overrides in AddView
CVE-2026-42027Critical· 9.8⚖ disputedArbitrary Class Instantiation via Model Manifest in Apache OpenNLP ExtensionLoader Versions Affected: before 1.9.5, before 2.5.9, before 3.0.0-M3 Description: The ExtensionLoader.instantiateExtension(Class, String) method loa…
Arbitrary Class Instantiation via Model Manifest in Apache OpenNLP ExtensionLoader Versions Affected: before 1.9.5, before 2.5.9, before 3.0.0-M3 Description: The ExtensionLoader.instantiateExtension(Class, String) method loa…
CVE-2026-24781Critical· 9.8vm2 is an open source vm/sandbox for Node.js
vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.0, VM2 suffers from a sandbox breakout vulnerability through the inspect function. This allows attackers to write code which can escape from the VM2 sandbox and execute …
CVE-2026-42154High· 7.5PoCPrometheus is an open-source monitoring system and time series database
Prometheus is an open-source monitoring system and time series database. Prior to versions 3.5.3 and 3.11.3, the remote read endpoint (/api/v1/read) does not validate the declared decoded length in a snappy-compressed request body before…
CVE-2026-42087Critical· 9.6OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. From version 6.7.…
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. From version 6.7.0 to before version 7.0.0-rc3, a SQL injection vulnerability exists in the Time-Series Database (TSD…
CVE-2026-40682Critical· 9.1XML External Entity (XXE) via Unsanitized Dictionary Parsing in Apache OpenNLP DictionaryEntryPersistor Versions Affected: before 2.5.9, before 3.0.0-M3 Description: The DictionaryEntryPersistor class initializes a static SAXParserFa…
XML External Entity (XXE) via Unsanitized Dictionary Parsing in Apache OpenNLP DictionaryEntryPersistor Versions Affected: before 2.5.9, before 3.0.0-M3 Description: The DictionaryEntryPersistor class initializes a static SAXParserFa…
CVE-2026-6266High· 8.3A flaw was found in the AAP gateway
A flaw was found in the AAP gateway. The user auto-link strategy, introduced in AAP 2.6, automatically links an external Identity Provider (IDP) identity to an existing AAP user account based on email matching without verifying email own…
CVE-2026-42088High· 8.1OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to version …
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to version 7.0.0-rc3, the Script Runner widget allows users to execute Python and Ruby scripts directly from th…
CVE-2026-42084High· 8.1OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to versions…
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to versions 6.10.5 and 7.0.0-rc3, the OpenC3 password change functionality allows a user to change their passwo…
CVE-2025-67796High· 8.1IKUS Rdiffweb allows an attacker with any valid or stolen access token to act as other users
IKUS Rdiffweb allows an attacker with any valid or stolen access token to act as other users
CVE-2026-24082High· 7.8Memory Corruption when copying data from a freed source while executing performance counter deselect operation.
Memory Corruption when copying data from a freed source while executing performance counter deselect operation.
Most-affected vendors
By CVEs published in the period.