VulnSea

Daily digest

Friday 22 May 2026

A busier-than-usual day with 46 new CVEs (recent average about 30). Severity skewed high: 10 critical and 18 high, 61% of the total. 6 arrived with exploitation evidence or public exploit code already attached. microsoft was the most-affected vendor with 11.

46
New CVEs
10
Critical
0
KEV additions
0
Records changed

New this day, ranked by depth score

The 12 that matter most of the 46 published.

CVE-2026-45659High· 8.8CISA KEVPoC
4mo ago

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

▾ Abyssalmicrosoft · sharepoint_serverEPSS 2.7%via NVD
CVE-2026-9018High· 8.8PoC
4mo ago

The Easy Elements for Elementor – Addons & Website Templates plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.4.5 via the `easyel_handle_register()` function

The Easy Elements for Elementor – Addons & Website Templates plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.4.5 via the `easyel_handle_register()` function. This is due to the `wp_ajax_…

▾ MidnightEPSS 0.59%via NVD
CVE-2026-9277High· 8.1PoC
4mo ago

shell-quote's `quote()` function did not validate object-token inputs against the operator model used by `parse()`

shell-quote's `quote()` function did not validate object-token inputs against the operator model used by `parse()`. The `.op` field was backslash-escaped character by character using `/(.)/g`, which in JavaScript does not match line term…

▾ MidnightEPSS 0.95%via NVD
CVE-2026-5843High· 8.2PoC
4mo ago

The MLX inference backend in Docker Model Runner on macOS uses the MLX-LM library, which unconditionally imports and executes arbitrary Python files from model directories via the model_file configuration field in config.json

The MLX inference backend in Docker Model Runner on macOS uses the MLX-LM library, which unconditionally imports and executes arbitrary Python files from model directories via the model_file configuration field in config.json. When a mod…

▾ Midnightdocker · docker_desktopEPSS 0.18%via NVD
CVE-2026-5817High· 8.2PoC
4mo ago

The vllm-metal inference backend in Docker Model Runner on macOS unconditionally sets trust_remote_code=True when loading model tokenizers, and runs without sandboxing

The vllm-metal inference backend in Docker Model Runner on macOS unconditionally sets trust_remote_code=True when loading model tokenizers, and runs without sandboxing. This causes transformers.AutoTokenizer.from_pretrained() to import a…

▾ Midnightdocker · docker_desktopEPSS 0.18%via NVD
CVE-2026-41104Critical· 10.0
4mo ago

Deserialization of untrusted data in Microsoft Planetary Computer Pro allows an unauthorized attacker to disclose information over a network.

Deserialization of untrusted data in Microsoft Planetary Computer Pro allows an unauthorized attacker to disclose information over a network.

▾ Midnightmicrosoft · planetary_computerEPSS 1.7%via NVD
CVE-2026-40412Critical· 10.0
4mo ago

Unrestricted upload of file with dangerous type in Azure Orbital Spatio allows an unauthorized attacker to execute code over a network.

Unrestricted upload of file with dangerous type in Azure Orbital Spatio allows an unauthorized attacker to execute code over a network.

▾ Midnightmicrosoft · azure_orbital_spatioEPSS 0.97%via NVD
CVE-2026-40411Critical· 9.9
4mo ago

Improper input validation in Azure Virtual Network Gateway allows an authorized attacker to execute code over a network.

Improper input validation in Azure Virtual Network Gateway allows an authorized attacker to execute code over a network.

▾ Midnightmicrosoft · azure_virtual_network_gatewayEPSS 0.96%via NVD
CVE-2026-23652Critical· 10.0
4mo ago

Improper neutralization of special elements used in a command ('command injection') in Microsoft Power Pages allows an unauthorized attacker to execute code over a network.

Improper neutralization of special elements used in a command ('command injection') in Microsoft Power Pages allows an unauthorized attacker to execute code over a network.

▾ Midnightmicrosoft · power_pagesEPSS 0.58%via NVD
CVE-2026-39821Critical· 9.6
4mo ago

The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label

The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode("xn--example-.com") incorrectly returns the name "example.com" rather than an error. This behavior …

▾ Midnightgolang · netEPSS 0.69%via NVD
CVE-2026-46595High· 7.1PoC⚖ disputed
4mo ago

golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Authorization bypass due to skipped source-address validation (CVE-2026-46595)

A flaw was found in golang.org/x/crypto/ssh. Source-address validation can be skipped when an SSH server configuration uses an authentication callback type other than public key, allowing authorization bypass in misconfigured servers. This…

▾ MidnightRed Hat · Red Hat Openshift Data Foundation 4.22EPSS 0.60%via CSAF
CVE-2026-41090Critical· 9.3
4mo ago

Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to perform tampering over a network.

Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to perform tampering over a network.

▾ Midnightmicrosoft · 365_copilotEPSS 0.76%via NVD

Most-affected vendors

By CVEs published in the period.