VulnSea

Daily digest

Thursday 28 May 2026

A busier-than-usual day with 44 new CVEs (recent average about 29). Severity skewed high: 5 critical and 20 high, 57% of the total. 4 arrived with exploitation evidence or public exploit code already attached. linux was the most-affected vendor with 19.

44
New CVEs
5
Critical
0
KEV additions
0
Records changed

New this day, ranked by depth score

The 12 that matter most of the 44 published.

CVE-2026-46817Critical· 9.8CISA KEVPoC
4mo ago

Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission)

Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with netwo…

▾ Hadaloracle · e-business_suiteEPSS 0.81%via NVD
CVE-2026-4408Critical· 9.0PoC
4mo ago

A flaw was found in Samba

A flaw was found in Samba. A remote attacker can exploit a misconfiguration in Samba file servers and classic domain controllers that use the "check password script" feature. If this script is configured with the %u substitution characte…

▾ Abyssalredhat · openshift_container_platformEPSS 1.8%via NVD
CVE-2026-9094Critical· 9.8
4mo ago

Casdoor: GetTokenExchangeToken bypass through lack of cross-organization JWT signature check

Casdoor: GetTokenExchangeToken bypass through lack of cross-organization JWT signature check

▾ Midnightcasdoor · github.com/casdoor/casdoorEPSS 0.48%via OSV
CVE-2026-46195Critical· 9.8
4mo ago

smb: client: validate dacloffset before building DACL pointers

In the Linux kernel, the following vulnerability has been resolved: smb: client: validate dacloffset before building DACL pointers parse_sec_desc(), build_sec_desc(), and the chown path in id_mode_to_cifs_acl() all add the server-suppl…

▾ MidnightLinux · LinuxEPSS 0.68%via CVEORG
CVE-2026-46135Critical· 9.8
4mo ago

In the Linux kernel, the following vulnerability has been resolved: nvmet-tcp: fix race between ICReq handling and queue teardown nvmet_tcp_handle_icreq() updates queue->state after sending an Initialization Connection Response (ICResp…

In the Linux kernel, the following vulnerability has been resolved: nvmet-tcp: fix race between ICReq handling and queue teardown nvmet_tcp_handle_icreq() updates queue->state after sending an Initialization Connection Response (ICResp…

▾ Midnightlinux · linux_kernelEPSS 0.40%via NVD
CVE-2026-48526High· 7.4PoC
4mo ago

PyJWT is a JSON Web Token implementation in Python

PyJWT is a JSON Web Token implementation in Python. Prior to 2.13.0, when the verifier is decoding JSON Web Tokens, while supporting both asymmetric and HMAC algorithms, the library does not validate use of JSON Web Keys in HMAC algorith…

▾ Midnightpyjwt_project · pyjwtEPSS 0.43%via NVD
CVE-2026-32996High· 7.3PoC
4mo ago

This vulnerability in Veeam Agent for Microsoft Windows allows for Local Privilege Escalation.

This vulnerability in Veeam Agent for Microsoft Windows allows for Local Privilege Escalation.

▾ MidnightVeeam · Backup and ReplicationEPSS 0.17%via NVD
CVE-2026-46174High· 8.8
4mo ago

x86/CPU/AMD: Prevent improper isolation of shared resources in Zen2's op cache

In the Linux kernel, the following vulnerability has been resolved: x86/CPU/AMD: Prevent improper isolation of shared resources in Zen2's op cache Make sure resources are not improperly shared in the op cache and cause instruction corr…

▾ TwilightLinux · LinuxEPSS 0.18%via CVEORG
CVE-2026-46152High· 8.8
4mo ago

In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: drop stray 'static' from fast-RX rx_result ieee80211_invoke_fast_rx() is documented as safe for parallel RX, but its per-invocation rx_result is declar…

In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: drop stray 'static' from fast-RX rx_result ieee80211_invoke_fast_rx() is documented as safe for parallel RX, but its per-invocation rx_result is declar…

▾ Twilightlinux · linux_kernelEPSS 0.24%via NVD
CVE-2026-42999High· 8.3⚖ disputed
4mo ago

openstack-keystone: OpenStack Keystone: Unauthorized access and privilege escalation via arbitrary policy attribute injection (CVE-2026-429…

A flaw was found in OpenStack Keystone. This vulnerability allows an authenticated user to bypass Role-Based Access Control (RBAC) checks by injecting arbitrary policy target attributes into the request body. This enables the user to perfo…

▾ TwilightRed Hat · Red Hat OpenStack Platform 16.2EPSS 0.42%via CSAF
CVE-2026-44973High· 8.1
4mo ago

github.com/go-git/go-billy: Go-billy: Arbitrary file access due to path traversal vulnerability (CVE-2026-44973)

A flaw was found in go-billy, an interface filesystem abstraction for Go. Multiple path traversal vulnerabilities exist due to insufficient path sanitization and boundary enforcement. A remote attacker could exploit this by crafting malici…

▾ TwilightRed Hat · Multicluster Engine for KubernetesEPSS 0.47%via CSAF
CVE-2026-46227High· 7.8
4mo ago

In the Linux kernel, the following vulnerability has been resolved: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL The SCTP_SENDALL path in sctp_sendmsg() iterates ep->asocs with list_for_each_entry_safe(), w…

In the Linux kernel, the following vulnerability has been resolved: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL The SCTP_SENDALL path in sctp_sendmsg() iterates ep->asocs with list_for_each_entry_safe(), w…

▾ Twilightlinux · linux_kernelEPSS 0.14%via NVD

Most-affected vendors

By CVEs published in the period.