Daily digest
Tuesday 19 May 2026
A busier-than-usual day with 49 new CVEs (recent average about 42). Severity skewed high: 5 critical and 22 high, 55% of the total. 2 arrived with exploitation evidence or public exploit code already attached. mozilla was the most-affected vendor with 17.
New this day, ranked by depth score
The 12 that matter most of the 49 published.
CVE-2026-2587Critical· 9.6PoCA critical Remote Code Execution (RCE) vulnerability was identified in the server-side template rendering mechanism used by the Glassfish gadget handler
A critical Remote Code Execution (RCE) vulnerability was identified in the server-side template rendering mechanism used by the Glassfish gadget handler. The application processes .xml files and evaluates user-supplied values within a co…
CVE-2026-2586Critical· 9.1PoCAn authenticated Remote Code Execution (RCE) vulnerability was identified in GlassFish's Administration Console
An authenticated Remote Code Execution (RCE) vulnerability was identified in GlassFish's Administration Console. A user with access to the panel can send crafted requests that allow the execution of arbitrary operating system commands wi…
CVE-2026-8603Critical· 9.8In ScadaBR version 1.2.0, an OS Command Injection vulnerability could allow an attacker to execute commands as root on the SCADA system.
In ScadaBR version 1.2.0, an OS Command Injection vulnerability could allow an attacker to execute commands as root on the SCADA system.
GHSA-g53w-w6mj-hrppCriticalMCP Gateway: Authority-injection and JWT/session bypass via the unauthenticated router hair-pin "router-key" / "mcp-init-host" path
MCP Gateway: Authority-injection and JWT/session bypass via the unauthenticated router hair-pin "router-key" / "mcp-init-host" path
CVE-2026-8602Critical· 9.1In ScadaBR version 1.2.0, a Missing Authentication for Critical Function vulnerability could allow an unauthenticated attacker to send a HTTP GET requests to the SCADA system and inject arbitrary sensor readings.
In ScadaBR version 1.2.0, a Missing Authentication for Critical Function vulnerability could allow an unauthenticated attacker to send a HTTP GET requests to the SCADA system and inject arbitrary sensor readings.
CVE-2026-8975High· 8.8Memory safety bugs present in Firefox ESR 115.35, Firefox ESR 140.10 and Firefox 150
Memory safety bugs present in Firefox ESR 115.35, Firefox ESR 140.10 and Firefox 150. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary…
CVE-2026-8974High· 8.8Memory safety bugs present in Firefox ESR 140.10 and Firefox 150
Memory safety bugs present in Firefox ESR 140.10 and Firefox 150. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerab…
CVE-2026-8973High· 8.8Memory safety bugs present in Firefox 150
Memory safety bugs present in Firefox 150. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Fire…
CVE-2026-8972High· 8.8Privilege escalation in the WebRTC: Audio/Video component
Privilege escalation in the WebRTC: Audio/Video component. This vulnerability was fixed in Firefox 151 and Thunderbird 151.
CVE-2026-8970High· 8.8Privilege escalation in the Security component
Privilege escalation in the Security component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11.
CVE-2026-8604High· 8.8In ScadaBR version 1.2.0, a CSRF vulnerability could allow an attacker to trigger any authenticated action through a victim's session by luring any logged-in user to a malicious webpage.
In ScadaBR version 1.2.0, a CSRF vulnerability could allow an attacker to trigger any authenticated action through a victim's session by luring any logged-in user to a malicious webpage.
CVE-2026-27173High· 8.7JWT tokens that were used by workers in Kubernetes Executors have been exposed to users who had read only access to Kuberentes Pods
JWT tokens that were used by workers in Kubernetes Executors have been exposed to users who had read only access to Kuberentes Pods. This could allow users with just read-only access to perform actions that were only available to running…
Most-affected vendors
By CVEs published in the period.