VulnSea

Daily digest

Thursday 7 May 2026

A heavy day: 62 new CVEs, well above the recent average of about 26. Severity skewed high: 7 critical and 30 high, 60% of the total. 5 arrived with exploitation evidence or public exploit code already attached. Red Hat was the most-affected vendor with 10.

62
New CVEs
7
Critical
0
KEV additions
0
Records changed

New this day, ranked by depth score

The 12 that matter most of the 62 published.

CVE-2026-42880Critical· 9.6PoC
4mo ago

ArgoCD ServerSideDiff is vulnerable to Kubernetes Secret Extraction

ArgoCD ServerSideDiff is vulnerable to Kubernetes Secret Extraction

▾ Abyssalargoproj · github.com/argoproj/argo-cd/v3EPSS 0.56%via OSV
CVE-2026-42216Critical· 9.1PoC
4mo ago

OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry

OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From versions 3.0.0 to before 3.2.9, 3.3.0 to before 3.3.11, and 3.4.0 to before 3.4.11, IDM…

▾ Abyssalopenexr · openexrEPSS 0.71%via NVD
CVE-2026-8094Critical· 9.8
4mo ago

Other issue in the WebRTC component

Other issue in the WebRTC component. This vulnerability was fixed in Firefox ESR 140.10.2 and Thunderbird 140.10.2.

▾ Midnightmozilla · firefoxEPSS 0.63%via NVD
CVE-2026-8091Critical· 9.8
4mo ago

Incorrect boundary conditions in the Audio/Video: Playback component

Incorrect boundary conditions in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 150, Thunderbird 150, Firefox ESR 140.10.1, Thunderbird 140.10.1, and Firefox ESR 115.35.2.

▾ Midnightmozilla · firefoxEPSS 0.60%via NVD
CVE-2026-44484Critical· 9.8
4mo ago

Compromise of PyTorch Lightning PyPi Package Versions

Compromise of PyTorch Lightning PyPi Package Versions

▾ Midnightpytorch-lightning · pytorch-lightningEPSS 0.67%via OSV
CVE-2026-41586Critical· 9.8
4mo ago

Hyperledger Fabric is an enterprise-grade permissioned distributed ledger framework for developing solutions and applications

Hyperledger Fabric is an enterprise-grade permissioned distributed ledger framework for developing solutions and applications. From versions 1.0.0 to 2.2.26, Channel.java implements readObject() and exposes deSerializeChannel() which cal…

▾ Midnighthyperledger · fabricEPSS 0.63%via NVD
CVE-2026-41674High· 7.5PoC
4mo ago

xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) `DOMParser` and `XMLSerializer` module

xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) `DOMParser` and `XMLSerializer` module. In @xmldom/xmldom prior to versions 0.9.10 and 0.8.13 and xmldom version 0.6.0 and prior, the package serializes DocumentType n…

▾ Midnightxmldom · xmldomEPSS 0.65%via NVD
CVE-2026-7891Critical· 9.1
4mo ago

Rejected reason: This CVE has been retracted

Rejected reason: This CVE has been retracted. Re-investigation confirmed the reported behavior is expected platform configuration and does not expose the protected attribute.

▾ MidnightEPSS 0.27%via NVD
CVE-2026-32686Medium· 6.9PoC
4mo ago

Uncontrolled Resource Consumption vulnerability in ericmj decimal allows unauthenticated remote Denial of Service. The decimal library does not bound the exponent on parsed input

Uncontrolled Resource Consumption vulnerability in ericmj decimal allows unauthenticated remote Denial of Service. The decimal library does not bound the exponent on parsed input. Storing a decimal with a very large exponent (e.g. Decim…

▾ Twilightericmj · decimalEPSS 0.34%via NVD
CVE-2026-41142High· 8.8
4mo ago

OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry

OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From versions 3.0.0 to before 3.2.9, 3.3.0 to before 3.3.11, and 3.4.0 to before 3.4.11, the…

▾ Twilightopenexr · openexrEPSS 0.73%via NVD
CVE-2026-25705High· 8.4
4mo ago

Rancher Extensions have arbitrary file access via path traversal

Rancher Extensions have arbitrary file access via path traversal

▾ Twilightrancher · github.com/rancher/rancherEPSS 0.49%via OSV
CVE-2026-8092High· 8.1
4mo ago

Memory safety bugs present in Firefox ESR 115.35.1, Firefox ESR 140.10.1 and Firefox 150.0.1

Memory safety bugs present in Firefox ESR 115.35.1, Firefox ESR 140.10.1 and Firefox 150.0.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run a…

▾ Twilightmozilla · firefoxEPSS 0.54%via NVD

Most-affected vendors

By CVEs published in the period.