VulnSea

Daily digest

Tuesday 19 May 2026

A busier-than-usual day with 49 new CVEs (recent average about 42). Severity skewed high: 5 critical and 22 high, 55% of the total. 2 arrived with exploitation evidence or public exploit code already attached. mozilla was the most-affected vendor with 17.

49
New CVEs
5
Critical
0
KEV additions
0
Records changed

New this day, ranked by depth score

The 12 that matter most of the 49 published.

CVE-2026-2587Critical· 9.6PoC
4mo ago

A critical Remote Code Execution (RCE) vulnerability was identified in the server-side template rendering mechanism used by the Glassfish gadget handler

A critical Remote Code Execution (RCE) vulnerability was identified in the server-side template rendering mechanism used by the Glassfish gadget handler. The application processes .xml files and evaluates user-supplied values within a co…

▾ AbyssalEPSS 0.67%via NVD
CVE-2026-2586Critical· 9.1PoC
4mo ago

An authenticated Remote Code Execution (RCE) vulnerability was identified in GlassFish's Administration Console

An authenticated Remote Code Execution (RCE) vulnerability was identified in GlassFish's Administration Console. A user with access to the panel can send crafted requests that allow the execution of arbitrary operating system commands wi…

▾ AbyssalEPSS 0.83%via NVD
CVE-2026-8603Critical· 9.8
4mo ago

In ScadaBR version 1.2.0, an OS Command Injection vulnerability could allow an attacker to execute commands as root on the SCADA system.

In ScadaBR version 1.2.0, an OS Command Injection vulnerability could allow an attacker to execute commands as root on the SCADA system.

▾ Midnightscadabr · scadabrEPSS 2.1%via NVD
GHSA-g53w-w6mj-hrppCritical
4mo ago

MCP Gateway: Authority-injection and JWT/session bypass via the unauthenticated router hair-pin "router-key" / "mcp-init-host" path

MCP Gateway: Authority-injection and JWT/session bypass via the unauthenticated router hair-pin "router-key" / "mcp-init-host" path

▾ MidnightKuadrant · github.com/Kuadrant/mcp-gatewayvia OSV
CVE-2026-8602Critical· 9.1
4mo ago

In ScadaBR version 1.2.0, a Missing Authentication for Critical Function vulnerability could allow an unauthenticated attacker to send a HTTP GET requests to the SCADA system and inject arbitrary sensor readings.

In ScadaBR version 1.2.0, a Missing Authentication for Critical Function vulnerability could allow an unauthenticated attacker to send a HTTP GET requests to the SCADA system and inject arbitrary sensor readings.

▾ Midnightscadabr · scadabrEPSS 0.58%via NVD
CVE-2026-8975High· 8.8
4mo ago

Memory safety bugs present in Firefox ESR 115.35, Firefox ESR 140.10 and Firefox 150

Memory safety bugs present in Firefox ESR 115.35, Firefox ESR 140.10 and Firefox 150. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary…

▾ Twilightmozilla · firefoxEPSS 0.59%via NVD
CVE-2026-8974High· 8.8
4mo ago

Memory safety bugs present in Firefox ESR 140.10 and Firefox 150

Memory safety bugs present in Firefox ESR 140.10 and Firefox 150. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerab…

▾ Twilightmozilla · firefoxEPSS 0.45%via NVD
CVE-2026-8973High· 8.8
4mo ago

Memory safety bugs present in Firefox 150

Memory safety bugs present in Firefox 150. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Fire…

▾ Twilightmozilla · firefoxEPSS 0.46%via NVD
CVE-2026-8972High· 8.8
4mo ago

Privilege escalation in the WebRTC: Audio/Video component

Privilege escalation in the WebRTC: Audio/Video component. This vulnerability was fixed in Firefox 151 and Thunderbird 151.

▾ Twilightmozilla · firefoxEPSS 0.44%via NVD
CVE-2026-8970High· 8.8
4mo ago

Privilege escalation in the Security component

Privilege escalation in the Security component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11.

▾ Twilightmozilla · firefoxEPSS 0.41%via NVD
CVE-2026-8604High· 8.8
4mo ago

In ScadaBR version 1.2.0, a CSRF vulnerability could allow an attacker to trigger any authenticated action through a victim's session by luring any logged-in user to a malicious webpage.

In ScadaBR version 1.2.0, a CSRF vulnerability could allow an attacker to trigger any authenticated action through a victim's session by luring any logged-in user to a malicious webpage.

▾ Twilightscadabr · scadabrEPSS 0.21%via NVD
CVE-2026-27173High· 8.7
4mo ago

JWT tokens that were used by workers in Kubernetes Executors have been exposed to users who had read only access to Kuberentes Pods

JWT tokens that were used by workers in Kubernetes Executors have been exposed to users who had read only access to Kuberentes Pods. This could allow users with just read-only access to perform actions that were only available to running…

▾ Twilightapache · airflow_cncf_kubernetesEPSS 0.21%via NVD

Most-affected vendors

By CVEs published in the period.