VulnSea

Daily digest

Tuesday 25 August 2026

A busier-than-usual day with 269 new CVEs (recent average about 176). Of those, 20 critical and 92 high. 13 arrived with exploitation evidence or public exploit code already attached. CISA added one CVE to the Known Exploited Vulnerabilities catalog. Google was the most-affected vendor with 61.

269
New CVEs
20
Critical
1
KEV additions
1
Records changed

Added to CISA KEV

Confirmed exploitation in the wild — federal remediation deadlines attach to these.

New this day, ranked by depth score

The 12 that matter most of the 269 published.

CVE-2026-56705Critical· 9.8PoC
1mo ago

Adminer before 5.4.3 fails to sanitize the server field before constructing a PDO DSN string, allowing unauthenticated attackers to inject ODBC parameters via semicolons

Adminer before 5.4.3 fails to sanitize the server field before constructing a PDO DSN string, allowing unauthenticated attackers to inject ODBC parameters via semicolons. Attackers can inject TraceFile and TraceOn parameters to write PHP…

AbyssalEPSS 0.50%via NVD
CVE-2026-49757CriticalPoC
1mo ago

AshAuthentication vulnerable to OAuth2/OIDC account takeover via email-based user matching

AshAuthentication vulnerable to OAuth2/OIDC account takeover via email-based user matching

Abyssalash_authentication · ash_authenticationEPSS 0.61%via GHSA
CVE-2026-62862Critical· 9.1PoC
1mo ago

Typebot is an open-source chatbot builder

Typebot is an open-source chatbot builder. In self-hosted versions up to and including 3.17.1, the default passwordless email magic-link authentication is vulnerable to login-code brute forcing that leads to account takeover. The email p…

AbyssalbaptisteArno · typebot.ioEPSS 0.51%via NVD
CVE-2026-77998Critical· 10.0
1mo ago

Joomla Extension - miniorange.com - Unauthenticated Authentication Bypass via SAMLResponse Parameter in miniOrange SAML SSO < 11.0.2, SAML SP Single Sign On – Login with ADFS < 6.4, SAML SP Single Sign On – SAML SSO login with Google Ap…

Joomla Extension - miniorange.com - Unauthenticated Authentication Bypass via SAMLResponse Parameter in miniOrange SAML SSO < 11.0.2, SAML SP Single Sign On – Login with ADFS < 6.4, SAML SP Single Sign On – SAML SSO login with Google Ap…

Midnightminiorange.com · SAML SSO Free for Joomla extension for JoomlaEPSS 0.34%via NVD
CVE-2026-76197Critical· 10.0
1mo ago

Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could result in arbitrary code execution in the context of the current user

Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An …

MidnightEPSS 1.6%via NVD
CVE-2026-76195Critical· 10.0
1mo ago

Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could result in arbitrary code execution in the context of the current user

Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An …

MidnightEPSS 1.6%via NVD
CVE-2026-76193Critical· 10.0
1mo ago

Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in arbitrary code execution in the context of the current user

Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbi…

MidnightEPSS 0.68%via NVD
GHSA-9557-234j-7rv9Critical· 9.8
1mo ago

Duplicate Advisory: Dormant multi-line git-config values are corrupted into live injected directives (e.g. core.hooksPath) on any unrelated GitConfigParser write, enabling RCE

Duplicate Advisory: Dormant multi-line git-config values are corrupted into live injected directives (e.g. core.hooksPath) on any unrelated GitConfigParser write, enabling RCE

MidnightGitPython · GitPythonvia GHSA
CVE-2026-80104Critical· 9.8
1mo ago

DB-GPT builds the destination path for an uploaded skill from the multipart filename without constraining it to the upload directory

DB-GPT builds the destination path for an uploaded skill from the multipart filename without constraining it to the upload directory. skill_upload in packages/dbgpt-app/src/dbgpt_app/openapi/api_v1/agentic_data_api.py takes file.filename…

MidnightEPSS 0.71%via NVD
CVE-2026-78676Critical· 9.8
1mo ago

gitpython: GitPython before 3.1.59 Remote Code Execution via Config Injection (CVE-2026-78676)

GitPython before 3.1.59 fails to safely re-serialize multi-line git-config values during write operations, corrupting dormant quoted values into injected directives like core.hooksPath. Attackers can craft config files with embedded newlin…

MidnightRed Hat · Red Hat OpenShift AI (RHOAI)EPSS 0.43%via CSAF
CVE-2026-63073Critical· 9.8⚖ disputed
1mo ago

Issue summary: OpenSSL CMP response validation passed an unexpected response sender distinguished name directly as the format string to `ERR_raise_data()`. Impact summary: A malicious or intercepted CMP endpoint can crash a CMP client t…

Issue summary: OpenSSL CMP response validation passed an unexpected response sender distinguished name directly as the format string to `ERR_raise_data()`. Impact summary: A malicious or intercepted CMP endpoint can crash a CMP client t…

Midnightopenssl · opensslEPSS 0.93%via NVD
CVE-2026-55546Critical· 9.8
1mo ago

qwed-mcp has Unsafe SymPy `parse_expr()` Remote Code Execution via Unsanitized Math Expression Input

qwed-mcp has Unsafe SymPy `parse_expr()` Remote Code Execution via Unsanitized Math Expression Input

Midnightqwed-mcp · qwed-mcpEPSS 0.41%via OSV

Most-changed records

Existing CVEs whose severity, score, KEV or exploitation status moved.

  • CVE-2026-40217LiteLLM has a sandbox escape in custom-code guardrail63

Most-affected vendors

By CVEs published in the period.