Daily digest
Thursday 7 May 2026
A heavy day: 62 new CVEs, well above the recent average of about 26. Severity skewed high: 7 critical and 30 high, 60% of the total. 5 arrived with exploitation evidence or public exploit code already attached. Red Hat was the most-affected vendor with 10.
New this day, ranked by depth score
The 12 that matter most of the 62 published.
CVE-2026-42880Critical· 9.6PoCArgoCD ServerSideDiff is vulnerable to Kubernetes Secret Extraction
ArgoCD ServerSideDiff is vulnerable to Kubernetes Secret Extraction
CVE-2026-42216Critical· 9.1PoCOpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry
OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From versions 3.0.0 to before 3.2.9, 3.3.0 to before 3.3.11, and 3.4.0 to before 3.4.11, IDM…
CVE-2026-8094Critical· 9.8Other issue in the WebRTC component
Other issue in the WebRTC component. This vulnerability was fixed in Firefox ESR 140.10.2 and Thunderbird 140.10.2.
CVE-2026-8091Critical· 9.8Incorrect boundary conditions in the Audio/Video: Playback component
Incorrect boundary conditions in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 150, Thunderbird 150, Firefox ESR 140.10.1, Thunderbird 140.10.1, and Firefox ESR 115.35.2.
CVE-2026-44484Critical· 9.8Compromise of PyTorch Lightning PyPi Package Versions
Compromise of PyTorch Lightning PyPi Package Versions
CVE-2026-41586Critical· 9.8Hyperledger Fabric is an enterprise-grade permissioned distributed ledger framework for developing solutions and applications
Hyperledger Fabric is an enterprise-grade permissioned distributed ledger framework for developing solutions and applications. From versions 1.0.0 to 2.2.26, Channel.java implements readObject() and exposes deSerializeChannel() which cal…
CVE-2026-41674High· 7.5PoCxmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) `DOMParser` and `XMLSerializer` module
xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) `DOMParser` and `XMLSerializer` module. In @xmldom/xmldom prior to versions 0.9.10 and 0.8.13 and xmldom version 0.6.0 and prior, the package serializes DocumentType n…
CVE-2026-7891Critical· 9.1Rejected reason: This CVE has been retracted
Rejected reason: This CVE has been retracted. Re-investigation confirmed the reported behavior is expected platform configuration and does not expose the protected attribute.
CVE-2026-32686Medium· 6.9PoCUncontrolled Resource Consumption vulnerability in ericmj decimal allows unauthenticated remote Denial of Service. The decimal library does not bound the exponent on parsed input
Uncontrolled Resource Consumption vulnerability in ericmj decimal allows unauthenticated remote Denial of Service. The decimal library does not bound the exponent on parsed input. Storing a decimal with a very large exponent (e.g. Decim…
CVE-2026-41142High· 8.8OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry
OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From versions 3.0.0 to before 3.2.9, 3.3.0 to before 3.3.11, and 3.4.0 to before 3.4.11, the…
CVE-2026-25705High· 8.4Rancher Extensions have arbitrary file access via path traversal
Rancher Extensions have arbitrary file access via path traversal
CVE-2026-8092High· 8.1Memory safety bugs present in Firefox ESR 115.35.1, Firefox ESR 140.10.1 and Firefox 150.0.1
Memory safety bugs present in Firefox ESR 115.35.1, Firefox ESR 140.10.1 and Firefox 150.0.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run a…
Most-affected vendors
By CVEs published in the period.