VulnSea

Daily digest

Thursday 21 May 2026

31 new CVEs this day, in line with the recent average. Severity skewed high: 5 critical and 12 high, 55% of the total. 7 arrived with exploitation evidence or public exploit code already attached. CISA added one CVE to the Known Exploited Vulnerabilities catalog. concretecms was the most-affected vendor with 3.

31
New CVEs
5
Critical
1
KEV additions
0
Records changed

Added to CISA KEV

Confirmed exploitation in the wild — federal remediation deadlines attach to these.

New this day, ranked by depth score

The 12 that matter most of the 31 published.

CVE-2026-43501Critical· 9.8PoC
4mo ago

In the Linux kernel, the following vulnerability has been resolved: ipv6: rpl: reserve mac_len headroom when recompressed SRH grows ipv6_rpl_srh_rcv() decompresses an RFC 6554 Source Routing Header, swaps the next segment into ipv6_hdr…

In the Linux kernel, the following vulnerability has been resolved: ipv6: rpl: reserve mac_len headroom when recompressed SRH grows ipv6_rpl_srh_rcv() decompresses an RFC 6554 Source Routing Header, swaps the next segment into ipv6_hdr…

▾ Abyssallinux · linux_kernelEPSS 0.99%via NVD
CVE-2026-47102High· 8.8PoC
4mo ago

LiteLLM prior to 1.83.10 allows a user to modify their own user_role via the /user/update endpoint

LiteLLM prior to 1.83.10 allows a user to modify their own user_role via the /user/update endpoint. While the endpoint correctly restricts users to updating only their own account, it does not restrict which fields may be changed. A user…

▾ Midnightlitellm · litellmEPSS 0.82%via NVD
CVE-2026-47101High· 8.8PoC
4mo ago

LiteLLM prior to 1.83.14 allows an authenticated internal_user to create API keys with access to routes that their role does not permit

LiteLLM prior to 1.83.14 allows an authenticated internal_user to create API keys with access to routes that their role does not permit. When generating a key, the allowed_routes field is stored without verifying that the specified route…

▾ Midnightlitellm · litellmEPSS 1.3%via NVD
CVE-2026-46695Critical· 10.0
4mo ago

BoxLite: Permission Bypass Allows Modification of Read-Only Files

BoxLite: Permission Bypass Allows Modification of Read-Only Files

▾ Midnightboxlite · boxliteEPSS 0.48%via OSV
CVE-2026-43502High· 7.8PoC
4mo ago

In the Linux kernel, the following vulnerability has been resolved: net/rds: handle zerocopy send cleanup before the message is queued A zerocopy send can fail after user pages have been pinned but before the message is attached to the…

In the Linux kernel, the following vulnerability has been resolved: net/rds: handle zerocopy send cleanup before the message is queued A zerocopy send can fail after user pages have been pinned but before the message is attached to the…

▾ Midnightlinux · linux_kernelEPSS 0.18%via NVD
CVE-2026-43499High· 7.8PoC
4mo ago

In the Linux kernel, the following vulnerability has been resolved: rtmutex: Use waiter::task instead of current in remove_waiter() remove_waiter() is used by the slowlock paths, but it is also used for proxy-lock rollback in rt_mutex_…

In the Linux kernel, the following vulnerability has been resolved: rtmutex: Use waiter::task instead of current in remove_waiter() remove_waiter() is used by the slowlock paths, but it is also used for proxy-lock rollback in rt_mutex_…

▾ Midnightlinux · linux_kernelEPSS 0.28%via NVD
CVE-2026-48207Critical· 9.8
4mo ago

Apache Fory PyFory Deserialization of Untrusted Data

Apache Fory PyFory Deserialization of Untrusted Data

▾ Midnightpyfory · pyforyEPSS 0.82%via OSV
CVE-2026-46703Critical· 9.6
4mo ago

Boxlite: Path Traversal Vulnerability Leads to Arbitrary File Write on the Host

Boxlite: Path Traversal Vulnerability Leads to Arbitrary File Write on the Host

▾ Midnightboxlite · boxliteEPSS 0.78%via OSV
CVE-2026-5433Critical· 9.1
4mo ago

Honeywell Control Network Module (CNM) contains command injection vulnerability in the web interface

Honeywell Control Network Module (CNM) contains command injection vulnerability in the web interface. An attacker could exploit this vulnerability via command delimiters, potentially resulting in Remote Code Execution (RCE).  Honeywel…

▾ MidnightEPSS 1.6%via NVD
CVE-2026-46612High· 8.8
4mo ago

Fission StorageSvc /v1/archive endpoint exposes unauthenticated CRUD over all function archives

Fission StorageSvc /v1/archive endpoint exposes unauthenticated CRUD over all function archives

▾ Twilightfission · github.com/fission/fissionEPSS 0.66%via OSV
CVE-2026-46517High· 7.8
4mo ago

lmdeploy: Hardcoded trust_remote_code=True is an implicit unsafe remote-code load path with no user opt-out

lmdeploy: Hardcoded trust_remote_code=True is an implicit unsafe remote-code load path with no user opt-out

▾ Twilightlmdeploy · lmdeployEPSS 0.43%via OSV
CVE-2026-46432High· 7.8
4mo ago

LMDeploy: Arbitrary code execution via hardcoded trust_remote_code=True in lmdeploy model initialization

LMDeploy: Arbitrary code execution via hardcoded trust_remote_code=True in lmdeploy model initialization

▾ Twilightlmdeploy · lmdeployEPSS 0.20%via OSV

Most-affected vendors

By CVEs published in the period.