VulnSea

Daily digest

Monday 27 July 2026

A quiet day: only 41 new CVEs against a recent average of about 126. Severity skewed high: 2 critical and 19 high, 51% of the total. 5 arrived with exploitation evidence or public exploit code already attached. CISA added one CVE to the Known Exploited Vulnerabilities catalog. apple was the most-affected vendor with 7.

41
New CVEs
2
Critical
1
KEV additions
0
Records changed

Added to CISA KEV

Confirmed exploitation in the wild — federal remediation deadlines attach to these.

New this day, ranked by depth score

The 12 that matter most of the 41 published.

CVE-2026-42016High· 8.1CISA KEVPoC
1mo ago

Incorrect authorization validation of user token in JFrog Artifactory allows Privilege Escalation

JFrog Artifactory (Self Hosted) versions before 7.133.11 are vulnerable to a privilege escalation attack due to a validation check of the token signature/issuer and not the token’s scope.

Abyssaljfrog · artifactoryEPSS 9.1%via CVEORG
CVE-2026-66395Critical· 9.6PoC
1mo ago

SiYuan desktop before v3.7.2 contains a reflected cross-site scripting vulnerability in the bazaar plugin readme handler that allows attackers to execute arbitrary code by crafting a malicious siyuan:// deep link

SiYuan desktop before v3.7.2 contains a reflected cross-site scripting vulnerability in the bazaar plugin readme handler that allows attackers to execute arbitrary code by crafting a malicious siyuan:// deep link. Attackers can inject HT…

Abyssalsiyuan-note · siyuanEPSS 0.40%via NVD
CVE-2026-43760High· 8.6PoC
1mo ago

An access issue was addressed with improved access restrictions

An access issue was addressed with improved access restrictions. This issue is fixed in macOS Sonoma 14.8.8, macOS Tahoe 26.6, macOS Tahoe 26.7. An app may be able to access user-sensitive data.

Midnightapple · macosEPSS 1.1%via NVD
CVE-2026-66396High· 8.4PoC
1mo ago

SiYuan before v3.7.2 fails to escape the title-img Individual Attribute List value when rendering Gallery and Kanban cover images, allowing stored cross-site scripting via unescaped style attribute interpolation

SiYuan before v3.7.2 fails to escape the title-img Individual Attribute List value when rendering Gallery and Kanban cover images, allowing stored cross-site scripting via unescaped style attribute interpolation. Attackers with editor pe…

Midnightsiyuan-note · siyuanEPSS 0.37%via NVD
CVE-2026-64531High· 7.8PoC
1mo ago

In the Linux kernel, the following vulnerability has been resolved: net: openvswitch: reject oversized nested action attrs Open vSwitch stores generated flow actions as nlattrs, whose nla_len field is u16

In the Linux kernel, the following vulnerability has been resolved: net: openvswitch: reject oversized nested action attrs Open vSwitch stores generated flow actions as nlattrs, whose nla_len field is u16. Commit a1e64addf3ff ("net: op…

MidnightEPSS 0.38%via NVD
CVE-2026-43748Critical· 9.8
1mo ago

An out-of-bounds write issue was addressed with improved bounds checking

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Tahoe 26.6. An app may be able to cause unexpected system termination.

Midnightapple · macosEPSS 0.60%via NVD
CVE-2026-66014High· 8.8
1mo ago

JFrog Artifactory contains an authentication handling weakness in internal request processing that, under specific conditions, may allow an attacker to escalate privileges beyond the intended access level.

JFrog Artifactory contains an authentication handling weakness in internal request processing that, under specific conditions, may allow an attacker to escalate privileges beyond the intended access level.

Twilightjfrog · artifactoryEPSS 0.64%via NVD
CVE-2026-64552High· 8.4
1mo ago

In the Linux kernel, the following vulnerability has been resolved: virtio-net: fix len check in receive_big() receive_big() bounds the device-announced length by (big_packets_num_skbfrags + 1) * PAGE_SIZE

In the Linux kernel, the following vulnerability has been resolved: virtio-net: fix len check in receive_big() receive_big() bounds the device-announced length by (big_packets_num_skbfrags + 1) * PAGE_SIZE. That is still too loose: ad…

TwilightLinux · LinuxEPSS 0.14%via NVD
CVE-2026-59250High· 8.3
1mo ago

Classic buffer overflow in the Erlang/OTP megaco flex scanner C driver allows a remote unauthenticated attacker to corrupt the driver's memory (and potentially achieve remote code execution or a denial-of-service crash) by sending a sing…

Classic buffer overflow in the Erlang/OTP megaco flex scanner C driver allows a remote unauthenticated attacker to corrupt the driver's memory (and potentially achieve remote code execution or a denial-of-service crash) by sending a sing…

TwilightErlang · otpEPSS 0.78%via NVD
CVE-2026-43698High· 7.8
1mo ago

An injection issue was addressed with improved validation

An injection issue was addressed with improved validation. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.7. An app may be able to gain root privileges.

Twilightapple · macosEPSS 0.21%via NVD
CVE-2026-24252High· 7.8
1mo ago

NVIDIA NeMo for Linux contains a vulnerability where an attacker may cause OS command injection

NVIDIA NeMo for Linux contains a vulnerability where an attacker may cause OS command injection. A successful exploit of this vulnerability may lead to code execution, data tampering, escalation of privileges and information disclosure.

Twilightnvidia · nemoEPSS 0.88%via NVD
CVE-2026-17523High· 7.8
1mo ago

In the Linux kernel, the following vulnerability has been resolved: can: bcm: switch timer to HRTIMER_MODE_SOFT and remove hrtimer_tasklet This patch switches the timer to HRTIMER_MODE_SOFT, which executed the timer callback in softirq…

In the Linux kernel, the following vulnerability has been resolved: can: bcm: switch timer to HRTIMER_MODE_SOFT and remove hrtimer_tasklet This patch switches the timer to HRTIMER_MODE_SOFT, which executed the timer callback in softirq…

TwilightLinux · LinuxEPSS 0.15%via NVD

Most-affected vendors

By CVEs published in the period.