Daily digest
Monday 25 May 2026
A quiet day: only 2 new CVEs against a recent average of about 28. Severity skewed high: 2 high, 100% of the total. One arrived with exploitation evidence or public exploit code already attached.
2
New CVEs
0
Critical
0
KEV additions
0
Records changed
New this day, ranked by depth score
The 2 that matter most of the 2 published.
CVE-2026-48842High· 8.1PoCRoundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1 has Pre-authentication SQL injection in the virtuser_query plugin via a preg_replace() backslash escape bypass.
Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1 has Pre-authentication SQL injection in the virtuser_query plugin via a preg_replace() backslash escape bypass.
▾ MidnightRoundcube · WebmailEPSS 0.89%via NVD
CVE-2026-45361High· 8.1Apache Airflow providers-google's `ComputeEngineSSHHook` disables SSH host-key verification by default, exposing SSH traffic between an A…
Apache Airflow providers-google's `ComputeEngineSSHHook` disables SSH host-key verification by default, exposing SSH traffic between an Airflow worker and a Compute Engine VM to in-path network attackers who can intercept or modify the s…
▾ Twilightapache-airflow-providers-google · apache-airflow-providers-googleEPSS 0.80%via OSV
Most-affected vendors
By CVEs published in the period.