VulnSea

Daily digest

Friday 21 August 2026

136 new CVEs this day, in line with the recent average. Severity skewed high: 28 critical and 54 high, 60% of the total. 6 arrived with exploitation evidence or public exploit code already attached. CISA added one CVE to the Known Exploited Vulnerabilities catalog. esri was the most-affected vendor with 13.

136
New CVEs
28
Critical
1
KEV additions
0
Records changed

Added to CISA KEV

Confirmed exploitation in the wild — federal remediation deadlines attach to these.

New this day, ranked by depth score

The 12 that matter most of the 136 published.

CVE-2026-77806Critical· 9.8⚠ ExploitedPoC
1mo ago

SPIP before 4.4.21 allows unauthenticated remote attackers to execute arbitrary code, as exploited in the wild in August 2026

SPIP before 4.4.21 allows unauthenticated remote attackers to execute arbitrary code, as exploited in the wild in August 2026. This is related to code injection via an X-Spip-Filtre HTTP request header that is mishandled by analyse_resul…

▾ AbyssalEPSS 4.2%via NVD
CVE-2026-76904Critical· 9.8PoC
1mo ago

GeoTools is an open source Java library that provides tools for geospatial data

GeoTools is an open source Java library that provides tools for geospatial data. Starting in version 30.5 and prior to versions 33.6, 34.5, and 33.6, an SQL Injection Vulnerability is present when executing OGC Filters with PostGIS DataS…

▾ Abyssalgeotools · org.geotools.jdbc:gt-jdbc-postgisEPSS 1.8%via NVD
CVE-2026-62316High· 8.8PoC
1mo ago

Microsoft UFO open-source framework for intelligent automation across devices and platforms

Microsoft UFO open-source framework for intelligent automation across devices and platforms. Prior to 3.0.8, ufo/client/mcp/http_servers/linux_mcp_server.py binds a FastMCP streamable HTTP server to localhost:8010 but does not validate t…

▾ Midnightmicrosoft · UFOEPSS 0.36%via NVD
CVE-2026-69502Critical· 10.0
1mo ago

Server-side request forgery (ssrf) in Azure SQL Database allows an unauthorized attacker to elevate privileges over a network.

Server-side request forgery (ssrf) in Azure SQL Database allows an unauthorized attacker to elevate privileges over a network.

▾ Midnightmicrosoft · azure_sql_databaseEPSS 0.57%via NVD
CVE-2026-63343Critical· 9.9
1mo ago

Incus is a system container and virtual machine manager

Incus is a system container and virtual machine manager. Prior to version 7.3.0, a malicious image containing a `metadata.yaml` symlink pointing to an arbitrary host path allows an authenticated Incus user to read or overwrite any file o…

▾ MidnightEPSS 0.27%via NVD
CVE-2026-63125Critical· 9.9
1mo ago

Incus is a system container and virtual machine manager

Incus is a system container and virtual machine manager. Prior to version 7.3.0, an unprivileged, project-confined Incus user (a non-admin TLS/RBAC identity with `can_create_images` and `can_create_instances`) can execute arbitrary code …

▾ MidnightEPSS 0.50%via NVD
CVE-2026-62941Critical· 9.9
1mo ago

Incus is a system container and virtual machine manager

Incus is a system container and virtual machine manager. Prior to version 7.3.0, when copying an instance across projects, the project restriction check (`AllowInstanceCreation`) runs BEFORE the source instance's configuration is merged …

▾ MidnightEPSS 0.31%via NVD
CVE-2026-62867Critical· 9.9
1mo ago

Incus is a system container and virtual machine manager

Incus is a system container and virtual machine manager. Prior to version 7.3.0, improper validation of user-provided `block.create_options` in storage volume configuration leads to argument injection in the constructed filesystem creati…

▾ MidnightEPSS 0.29%via NVD
CVE-2026-62283Critical· 9.9
1mo ago

Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool

Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. Nezha versions 1.14.13 through 1.14.14 and 2.0.0 through 2.0.9 do not bind stream identifiers created by CreateStream in service/rpc/io_strea…

▾ Midnightnezhahq · github.com/nezhahq/nezhaEPSS 0.37%via NVD
CVE-2026-61539Critical· 10.0
1mo ago

Xinference vulnerable to remote code execution via unsafe `eval()` in Llama3 tool-call parsing

Xinference vulnerable to remote code execution via unsafe `eval()` in Llama3 tool-call parsing

▾ Midnightxinference · xinferenceEPSS 0.66%via OSV
CVE-2026-48769Critical· 9.9
1mo ago

Incus is a system container and virtual machine manager

Incus is a system container and virtual machine manager. Prior to version 7.2.0, an arbitrary file write exists in the Incus client when a malicious image server returns a crafted `Incus-Image-Hash` header. This can lead to arbitrary com…

▾ Midnightlxc · github.com/lxc/incus/v7/cmd/incusdEPSS 0.54%via NVD
CVE-2026-48755Critical· 9.9
1mo ago

Incus is a system container and virtual machine manager

Incus is a system container and virtual machine manager. Prior to version 7.1.0, improper validation of user-provided backup compression algorithm leads to argument injection in the constructed command line. This leads to an arbitrary fi…

▾ Midnightlxc · github.com/lxc/incus/v7/cmd/incusdEPSS 0.44%via NVD

Most-affected vendors

By CVEs published in the period.