VulnSea

Daily digest

Monday 17 August 2026

183 new CVEs this day, in line with the recent average. Of those, 24 critical and 56 high. 15 arrived with exploitation evidence or public exploit code already attached. CISA added one CVE to the Known Exploited Vulnerabilities catalog. apple was the most-affected vendor with 30.

183
New CVEs
24
Critical
1
KEV additions
0
Records changed

Added to CISA KEV

Confirmed exploitation in the wild — federal remediation deadlines attach to these.

New this day, ranked by depth score

The 12 that matter most of the 183 published.

CVE-2026-64849High· 8.5CISA KEVPoC
1mo ago

mlflow: MLflow: Unauthenticated full-read SSRF in webhook delivery: _validate_webhook_url bypassed via unvalidated HTTP redirects (and DNS …

A flaw was found in MLflow. An unauthenticated remote attacker can exploit a Server-Side Request Forgery (SSRF) vulnerability by sending a specially crafted request to the webhook test endpoint. This occurs because the system validates onl…

AbyssalRed Hat · Red Hat OpenShift AI 3.4EPSS 16%via CSAF
CVE-2026-68004Critical· 9.8PoC
1mo ago

An issue in OSSRS SRS (Simple Realtime Server) <v5.0.213 allows a remote attacker to execute arbitrary code via RTMP publish authorization, vhost-level security configuration (security.enabled), SrsSecurity::check(), trunk/src/app/srs_ap…

An issue in OSSRS SRS (Simple Realtime Server) <v5.0.213 allows a remote attacker to execute arbitrary code via RTMP publish authorization, vhost-level security configuration (security.enabled), SrsSecurity::check(), trunk/src/app/srs_ap…

AbyssalEPSS 0.72%via NVD
CVE-2026-67919Critical· 9.8PoC
1mo ago

An issue in Halo 2.25.4 allows a remote attacker to execute arbitrary code via the PluginEndpoint.java, installFromUri method, and DefaultPluginApplicationContextFactory components

An issue in Halo 2.25.4 allows a remote attacker to execute arbitrary code via the PluginEndpoint.java, installFromUri method, and DefaultPluginApplicationContextFactory components

AbyssalEPSS 0.83%via NVD
CVE-2026-38165Critical· 9.8PoC
1mo ago

A Server-Side Template Injection (SSTI) vulnerability in the Velocity template engine configuration of xdocreport v0.9.2 to v2.2.0 allows attackers to execute arbitrary code via a crafted expression.

A Server-Side Template Injection (SSTI) vulnerability in the Velocity template engine configuration of xdocreport v0.9.2 to v2.2.0 allows attackers to execute arbitrary code via a crafted expression.

AbyssalEPSS 0.60%via NVD
GHSA-m5w8-4gq2-6f8xCritical· 10.0
1mo ago

vm2: NodeVM `builtin: ['*']` exposes `os` and `dns` — process-wide observability reads AND writes that hijack the host (sibling class of GHSA-9g8x-92q2-p28f)

vm2: NodeVM `builtin: ['*']` exposes `os` and `dns` — process-wide observability reads AND writes that hijack the host (sibling class of GHSA-9g8x-92q2-p28f)

Midnightvm2 · vm2via GHSA
CVE-2026-66795Critical· 9.9
1mo ago

A flaw was found in the managedcluster-import-controller

A flaw was found in the managedcluster-import-controller. The Certificate Signing Request (CSR) auto-approval logic improperly validates incoming CSRs, specifically by not inspecting the signer name or decoding the PEM-encoded x509 CSR. …

MidnightRed Hat · multicluster-engine/managedcluster-import-controller-rhel9EPSS 0.32%via NVD
CVE-2026-66792Critical· 9.9
1mo ago

A flaw was found in the multicloud-operators-subscription component

A flaw was found in the multicloud-operators-subscription component. This vulnerability allows a user on a managed cluster to escalate their privileges by creating a Subscription with specific, crafted annotations. Successful exploitatio…

MidnightRed Hat · multicluster-globalhub/multicluster-globalhub-agent-rhel9EPSS 0.43%via NVD
CVE-2026-65974Critical· 9.9
1mo ago

ERPNext is a free and open source Enterprise Resource Planning tool

ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.111.0 and 16.22.0, limited authenticated users can cross a permission boundary in Frappe safe execution because frappe.render_template is exposed without fo…

Midnightfrappe · erpnextEPSS 0.56%via NVD
CVE-2026-47686Critical· 9.9
1mo ago

vm2 is an open source vm/sandbox for Node.js

vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.6, handleException() in lib/setup-sandbox.js sanitizes SuppressedError.error, SuppressedError.suppressed, and AggregateError.errors but does not sanitize Error.cause, allowing s…

Midnightvm2 · vm2EPSS 0.38%via NVD
CVE-2026-67967Critical· 9.8
1mo ago

Buffer Overflow vulnerability in Tenda W20E V16.01.0.6(2782) allows an attacker to execute arbitrary code

Buffer Overflow vulnerability in Tenda W20E V16.01.0.6(2782) allows an attacker to execute arbitrary code. This is an incomplete fix for CVE-2025-44867 and CVE-2026-36819

MidnightEPSS 0.55%via NVD
CVE-2026-67917Critical· 9.8
1mo ago

zuraCast versions up to and including 0.23.7 contain a SQL injection vulnerability in the backup restore functionality

zuraCast versions up to and including 0.23.7 contain a SQL injection vulnerability in the backup restore functionality. The `azuracast:restore` command executes the `db.sql` file extracted from a backup archive without any content valida…

MidnightEPSS 0.50%via NVD
CVE-2026-67868Critical· 9.8
1mo ago

A heap-based out-of-bounds write vulnerability exists in S2OPC 1.7.3 in server-side EventFilter handling during CreateMonitoredItems processing

A heap-based out-of-bounds write vulnerability exists in S2OPC 1.7.3 in server-side EventFilter handling during CreateMonitoredItems processing. This allows a remote attacker to execute arbitrary code.

MidnightEPSS 0.76%via NVD

Most-affected vendors

By CVEs published in the period.