Daily digest
Saturday 18 July 2026
83 new CVEs this day, in line with the recent average. Of those, 3 critical and 28 high. 2 arrived with exploitation evidence or public exploit code already attached.
New this day, ranked by depth score
The 12 that matter most of the 83 published.
MAL-2026-10779Critical⚠ ExploitedMalicious code in mlflow-ui (PyPI)
Malicious code in mlflow-ui (PyPI)
CVE-2026-9147High· 7.8PoCuproot dynamically generates Python class source code from ROOT TStreamerInfo records in a file and compiles it at runtime
uproot dynamically generates Python class source code from ROOT TStreamerInfo records in a file and compiles it at runtime. Some file-controlled streamer metadata fields (for example, streamer element names) are interpolated into the gen…
CVE-2026-16117Critical· 10.0Impact: @fastify/http-proxy versions up to and including 11.5.0 fail to rewrite the request prefix when the prefix segment is URL-encoded
Impact: @fastify/http-proxy versions up to and including 11.5.0 fail to rewrite the request prefix when the prefix segment is URL-encoded. Fastify's router URL-decodes paths for route matching, but request.url retains the original encode…
CVE-2026-47865Critical· 9.8VMware Avi Load Balancer contains an authentication bypass vulnerability
VMware Avi Load Balancer contains an authentication bypass vulnerability. A malicious user with network access may be able to access the Avi Control plane by bypassing the authentication mechanism. Affected versions: 31.1.1 through 31.2…
CVE-2026-47871High· 8.8VMware Avi Load Balancer contains a directory traversal vulnerability
VMware Avi Load Balancer contains a directory traversal vulnerability. Flaws in file path validation allow malicious, authenticated network users to perform directory traversal attacks. Affected versions: 32.1.1 (fixed in 32.1.2) 31.1.1…
CVE-2026-16097High· 8.8A vulnerability was found in Shibby Tomato 1.28
A vulnerability was found in Shibby Tomato 1.28. This vulnerability affects the function sub_42537C of the component Scheduler Name Handler. The manipulation of the argument a1 results in stack-based buffer overflow. It is possible to la…
CVE-2026-16096High· 8.8A vulnerability has been found in Shibby Tomato 1.28 RT-N5x MIPSR2 Build 124
A vulnerability has been found in Shibby Tomato 1.28 RT-N5x MIPSR2 Build 124. This affects the function sub_40BB50 of the file /proc/webmon_recent_domains. The manipulation leads to stack-based buffer overflow. It is possible to initiate…
CVE-2026-16095High· 8.8A flaw has been found in Shibby Tomato 1.28 RT-N5x MIPSR2 Build 124
A flaw has been found in Shibby Tomato 1.28 RT-N5x MIPSR2 Build 124. Affected by this issue is the function setup_conntrack of the file /sbin/rc. Executing a manipulation of the argument ct_tcp_timeout can lead to out-of-bounds write. Th…
CVE-2026-11826High· 8.8OpenPLC_v3 contains a heap-based buffer overflow in the getData() function in webserver/core/modbus_master.cpp
OpenPLC_v3 contains a heap-based buffer overflow in the getData() function in webserver/core/modbus_master.cpp. getData() reads characters between two delimiters into a caller-supplied buffer with no size parameter and no bounds check. I…
CVE-2024-58362High· 8.8SurrealDB before 1.5.5 (and 2.0.0-beta before 2.0.0-beta.3) accepts an arbitrary object in the signin and signup operations of the RPC API without recursively validating it for non-computed values
SurrealDB before 1.5.5 (and 2.0.0-beta before 2.0.0-beta.3) accepts an arbitrary object in the signin and signup operations of the RPC API without recursively validating it for non-computed values. When a record access method defines a S…
CVE-2026-47869High· 8.7VMware Avi Load Balancer contains a remote code execution vulnerability
VMware Avi Load Balancer contains a remote code execution vulnerability. A malicious authenticated user with network access may be able to inject and execute code. Affected versions: 32.1.1 (fixed in 32.1.2) 31.1.1 through 31.2.2 (fixed…
CVE-2026-47867High· 8.7VMware Avi Load Balancer contains a remote code execution vulnerability
VMware Avi Load Balancer contains a remote code execution vulnerability. A malicious user with network access may be able to access the Avi Control plane and execute code remotely. Affected versions: 32.1.1 (fixed in 32.1.2) 31.1.1 thro…
Most-affected vendors
By CVEs published in the period.