VulnSea

Daily digest

Thursday 27 August 2026

127 new CVEs this day, in line with the recent average. Of those, 10 critical and 32 high. 6 arrived with exploitation evidence or public exploit code already attached. CISA added 2 CVEs to the Known Exploited Vulnerabilities catalog. openssl-encrypt was the most-affected vendor with 25.

127
New CVEs
10
Critical
2
KEV additions
7
Records changed

Added to CISA KEV

Confirmed exploitation in the wild — federal remediation deadlines attach to these.

New this day, ranked by depth score

The 12 that matter most of the 127 published.

CVE-2026-47884Critical· 9.8PoC
3w ago

Use of XsltView in a Spring MVC application can result in SSRF and RCE attack if the application has an "/**" mapping that results in view rendering, and where the view name is not explicitly specified. Spring Framework 7.0.0 - 7.0.8 Spr…

Use of XsltView in a Spring MVC application can result in SSRF and RCE attack if the application has an "/**" mapping that results in view rendering, and where the view name is not explicitly specified. Spring Framework 7.0.0 - 7.0.8 Spr…

Abyssalvmware · spring_frameworkEPSS 0.42%via NVD
CVE-2026-76639High· 8.8PoC
3w ago

Unitree G1 EDU firmware through 1.5.2 contains an unauthenticated remote code execution vulnerability that allows network-adjacent attackers to execute arbitrary commands as root by chaining three weaknesses: an unauthenticated WebRTC-to…

Unitree G1 EDU firmware through 1.5.2 contains an unauthenticated remote code execution vulnerability that allows network-adjacent attackers to execute arbitrary commands as root by chaining three weaknesses: an unauthenticated WebRTC-to…

MidnightEPSS 0.71%via NVD
CVE-2026-59313Critical· 9.8
3w ago

Spring MVC applications using the functional web framework are vulnerable to stream corruption when using Server-Sent Events (SSE). Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 Spring Framework 6.1.0 - 6.1.28 Spring Fra…

Spring MVC applications using the functional web framework are vulnerable to stream corruption when using Server-Sent Events (SSE). Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 Spring Framework 6.1.0 - 6.1.28 Spring Fra…

MidnightEPSS 0.39%via NVD
CVE-2026-54687Critical· 9.8
3w ago

n8n-nodes-sqlite3 is a node for operating a local SQLite database from n8n

n8n-nodes-sqlite3 is a node for operating a local SQLite database from n8n. Prior to 1.0.0, nodes/SqliteNode/v1/SqliteV1.node.ts exposes the db_path database file path as a node parameter that permits data expressions from upstream workf…

Midnightdangerblack · n8n-node-sqlite3EPSS 0.46%via NVD
CVE-2026-37006Critical· 9.8
3w ago

A vulnerability in the WebSocket endpoint of gpt-researcher v0.14.7 and before allows an unauthenticated remote attacker to achieve code execution via malicious Model Context Protocol configurations.

A vulnerability in the WebSocket endpoint of gpt-researcher v0.14.7 and before allows an unauthenticated remote attacker to achieve code execution via malicious Model Context Protocol configurations.

MidnightEPSS 0.61%via NVD
CVE-2026-37004Critical· 9.8
3w ago

LiteLLM vulnerable to server-side template injection in the /prompts/test endpoint

LiteLLM vulnerable to server-side template injection in the /prompts/test endpoint

Midnightlitellm · litellmEPSS 0.55%via OSV
CVE-2026-37003Critical· 9.8
3w ago

Agno up to and including 2.5.8 is vulnerable to Remote Code Execution (RCE) via prompt injection

Agno up to and including 2.5.8 is vulnerable to Remote Code Execution (RCE) via prompt injection. The PythonTools and ShellTools components pass unsanitized, LLM-generated arguments directly to execution sinks including exec(), runpy.run…

MidnightEPSS 1.6%via NVD
CVE-2026-35869Critical· 9.8
3w ago

A Command Injection vulnerability exists in the bs_SetLimitCli_info function within the libshare.so library of LB-link Router AC450M V4.0.0

A Command Injection vulnerability exists in the bs_SetLimitCli_info function within the libshare.so library of LB-link Router AC450M V4.0.0. This flaw occurs due to insufficient validation and sanitization of user-supplied input before i…

MidnightEPSS 1.3%via NVD
CVE-2026-35868Critical· 9.8
3w ago

A Command Injection vulnerability exists in the bs_SetLimitCli_info function within the libshare.so library of LB-link Router AC2100_AZ3 V1.0.4

A Command Injection vulnerability exists in the bs_SetLimitCli_info function within the libshare.so library of LB-link Router AC2100_AZ3 V1.0.4. This flaw occurs due to insufficient validation and sanitization of user-supplied input befo…

MidnightEPSS 1.4%via NVD
CVE-2026-16279Critical· 9.3
3w ago

An Improper Authorization vulnerability affecting 3DPassport in 3DSwymer from Release 3DEXPERIENCE R2023x through Release 3DEXPERIENCE R2026x could allow an attacker to gain access to some user accounts.

An Improper Authorization vulnerability affecting 3DPassport in 3DSwymer from Release 3DEXPERIENCE R2023x through Release 3DEXPERIENCE R2026x could allow an attacker to gain access to some user accounts.

MidnightDassault Systèmes · 3DSwymerEPSS 0.25%via NVD
CVE-2026-57499Critical· 9.1
3w ago

Liman is open source server management software

Liman is open source server management software. Prior to 2.2.2 - 1103, an OS command injection vulnerability in the log rotation configuration endpoint allows an authenticated administrator to execute arbitrary operating system commands…

MidnightEPSS 0.96%via NVD
CVE-2026-81726High· 8.7
3w ago

nltk: NLTK: Unauthorized file access via path traversal in model-artifact APIs (CVE-2026-81726)

A flaw was found in NLTK. This vulnerability, known as path traversal, allows an attacker to bypass security restrictions in the model-artifact APIs. By exploiting this, an attacker can perform unauthorized read or write operations on file…

TwilightRed Hat · Red Hat OpenShift AI (RHOAI)EPSS 0.26%via CSAF

Most-changed records

Existing CVEs whose severity, score, KEV or exploitation status moved.

  • CVE-2026-53362In the Linux kernel, the following vulnerability has been resolved: ipv6: account for fraggap on the paged allocation path In __ip6_append_data(), when the paged-allocation branch is taken (MSG_MORE / NETIF_F_SG / large fraglen), alloc…28
  • CVE-2021-23758All versions of package ajaxpro.2 are vulnerable to Deserialization of Untrusted Data due to the possibility of deserialization of arbitrary .NET classes, which can be abused to gain remote code execution.86
  • CVE-2019-1068A remote code execution vulnerability exists in Microsoft SQL Server when it incorrectly handles processing of internal functions, aka 'Microsoft SQL Server Remote Code Execution Vulnerability'.84
  • CVE-2026-73570A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp package is installed and SNMP notifications are enabled80
  • CVE-2026-3576The Planyo Online Reservation System plugin for WordPress is vulnerable to Server-Side Request Forgery leading to Local File Inclusion in all versions up to, and including, 3.054
  • CVE-2026-18577An incomplete patch for CVE-2026-18556 allows for authentication bypass and account takeover in N-central Versions through 2026.3.139
  • CVE-2026-18556Authentication bypass using an alternate path or channel vulnerability in N-able N-central allows Authentication Bypass. This issue affects N-central: through 2026.1.36

Most-affected vendors

By CVEs published in the period.