Daily digest
Sunday 23 August 2026
A quiet day: only 5 new CVEs against a recent average of about 184. Of those, 1 critical and 1 high.
5
New CVEs
1
Critical
0
KEV additions
2
Records changed
New this day, ranked by depth score
The 5 that matter most of the 5 published.
CVE-2026-78155Critical· 9.9privilege escalation in StackGres operator allows a low-privilege tenant who owns a database to gain administrator privileges
privilege escalation in StackGres operator allows a low-privilege tenant who owns a database to gain administrator privileges
▾ Midnightongres · stackgresEPSS 0.29%via NVD
CVE-2026-78136High· 7.8chirpmyradio CHIRP before 39178db allows eval injection via crafted CSV data
chirpmyradio CHIRP before 39178db allows eval injection via crafted CSV data. This occurs in _clean_tmode in drivers/kenwood_itm.py.
▾ TwilightEPSS 0.19%via NVD
MAL-2026-14389NoneMalicious code in envprovision (PyPI)
Malicious code in envprovision (PyPI)
▾ Sunlitenvprovision · envprovisionvia OSV
MAL-2026-14388NoneMalicious code in cryptgraphy (PyPI)
Malicious code in cryptgraphy (PyPI)
▾ Sunlitcryptgraphy · cryptgraphyvia OSV
MAL-2026-14384NoneMalicious code in mlflow-otel-instrumentor (PyPI)
Malicious code in mlflow-otel-instrumentor (PyPI)
▾ Sunlitmlflow-otel-instrumentor · mlflow-otel-instrumentorvia OSV
Most-changed records
Existing CVEs whose severity, score, KEV or exploitation status moved.
- CVE-2017-8046Malicious PATCH requests submitted to servers using Spring Data REST versions prior to 2.6.9 (Ingalls SR9), versions prior to 3.0.1 (Kay SR1) and Spring Boot versions prior to 1.5.9, 2.0 M6 can use specially crafted JSON data to run arbi…epss87
- CVE-2018-0101A vulnerability in the Secure Sockets Layer (SSL) VPN functionality of the Cisco Adaptive Security Appliance (ASA) Software could allow an unauthenticated, remote attacker to cause a reload of the affected system or to remotely execute c…epss84
Most-affected vendors
By CVEs published in the period.