VulnSea

Daily digest

Friday 28 August 2026

A heavy day: 227 new CVEs, well above the recent average of about 126. Severity skewed high: 33 critical and 105 high, 61% of the total. 11 arrived with exploitation evidence or public exploit code already attached. yamcs was the most-affected vendor with 9.

227
New CVEs
33
Critical
0
KEV additions
3
Records changed

New this day, ranked by depth score

The 12 that matter most of the 227 published.

CVE-2026-81578Critical· 9.8CISA KEVPoC
3w ago

An improper access control vulnerability exists in the web management interface of PaperCut MF and PaperCut NG

An improper access control vulnerability exists in the web management interface of PaperCut MF and PaperCut NG. Under specific conditions, unauthenticated remote requests targeting administrative functions can trigger backend actions pri…

Hadalpapercut · papercut_mfEPSS 3.3%via NVD
CVE-2026-82078Critical· 9.4CISA KEVPoC
3w ago

PaperCut MF/NG: Unsafe Dynamic Class Loading in Database Connector

An unsafe dynamic class loading vulnerability exists in the database connection utilities of PaperCut MF and PaperCut NG. The application instantiates database driver classes based on configurable driver names without validating against …

HadalPaperCut · PaperCut MF/NGEPSS 3.6%via CVEORG
CVE-2026-55511Critical· 9.1PoC
3w ago

Yamcs is a mission control framework

Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, Yamcs allows a user with SystemPrivilege.ControlArchiving to create a double-quoted StreamSQL column name that is interpolated into generated Java source by Expression.fil…

Abyssalyamcs · org.yamcs:yamcs-coreEPSS 0.68%via NVD
CVE-2026-80724High· 8.8PoC
3w ago

In the Linux kernel, the following vulnerability has been resolved: ptp: vmclock: prevent read-only mappings from becoming writable vmclock_miscdev_mmap() rejects writable mappings of the shared vmclock ABI page with -EROFS, but leaves…

In the Linux kernel, the following vulnerability has been resolved: ptp: vmclock: prevent read-only mappings from becoming writable vmclock_miscdev_mmap() rejects writable mappings of the shared vmclock ABI page with -EROFS, but leaves…

MidnightLinux · LinuxEPSS 0.12%via NVD
CVE-2026-50979High· 8.1PoC
3w ago

A command injection vulnerability in the 'advanced/curl' component of Osbil Technology oPanel v1.19.50 and earlier allows authenticated attackers to execute arbitrary shell commands via the 'url' parameter

A command injection vulnerability in the 'advanced/curl' component of Osbil Technology oPanel v1.19.50 and earlier allows authenticated attackers to execute arbitrary shell commands via the 'url' parameter

MidnightEPSS 1.4%via NVD
CVE-2026-55634Critical· 9.9
3w ago

Pimcore is an Open Source Data & Experience Management Platform

Pimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.19, 12.3.10, and 2026.1.6, the class-definition import endpoint /pimcore-studio/api/class/definition/configuration-view/detail/{id}/import accepts a DataObjec…

Midnightpimcore · pimcore/pimcoreEPSS 0.45%via NVD
CVE-2026-55565Critical· 9.9
3w ago

Yamcs is a mission control framework

Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, Yamcs LikeExpression.fillCode_getValueReturn in yamcs-core/src/main/java/org/yamcs/yarch/streamsql/LikeExpression.java inserts an unescaped LIKE pattern into Java source c…

Midnightyamcs · org.yamcs:yamcs-coreEPSS 0.46%via NVD
CVE-2026-54745Critical· 10.0
3w ago

Kubeflow Pipelines enables users to build and deploy portable, scalable machine learning workflows

Kubeflow Pipelines enables users to build and deploy portable, scalable machine learning workflows. Prior to 2.17.0, the Kubeflow Pipelines frontend exposes an unauthenticated server-side request forgery vulnerability through the /_proxy…

MidnightEPSS 0.43%via NVD
CVE-2026-80681Critical· 9.8
3w ago

In the Linux kernel, the following vulnerability has been resolved: vxlan: re-fetch eth header after route_shortcircuit() Before route_shortcircuit(), the eth header pointer is cached from eth_hdr(skb). Inside route_shortcircuit(), ps…

In the Linux kernel, the following vulnerability has been resolved: vxlan: re-fetch eth header after route_shortcircuit() Before route_shortcircuit(), the eth header pointer is cached from eth_hdr(skb). Inside route_shortcircuit(), ps…

MidnightEPSS 0.51%via NVD
CVE-2026-80674Critical· 9.8
3w ago

In the Linux kernel, the following vulnerability has been resolved: ntfs: validate resident attribute lists and harden the validator A base inode's $ATTRIBUTE_LIST is sanity-checked by load_attribute_list() only on the non-resident pat…

In the Linux kernel, the following vulnerability has been resolved: ntfs: validate resident attribute lists and harden the validator A base inode's $ATTRIBUTE_LIST is sanity-checked by load_attribute_list() only on the non-resident pat…

MidnightEPSS 0.38%via NVD
CVE-2026-80673Critical· 9.8
3w ago

In the Linux kernel, the following vulnerability has been resolved: ntfs: bound the look-ahead attribute-list entry in ntfs_external_attr_find() When resolving an attribute lookup with a non-zero @lowest_vcn, ntfs_external_attr_find() …

In the Linux kernel, the following vulnerability has been resolved: ntfs: bound the look-ahead attribute-list entry in ntfs_external_attr_find() When resolving an attribute lookup with a non-zero @lowest_vcn, ntfs_external_attr_find() …

MidnightEPSS 0.38%via NVD
CVE-2026-80668Critical· 9.8
3w ago

In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conntrack_expect: use conntrack GC to reap expectations This patch replaces the timer API by GC worker approach for expectations, as it already happened …

In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conntrack_expect: use conntrack GC to reap expectations This patch replaces the timer API by GC worker approach for expectations, as it already happened …

MidnightEPSS 0.38%via NVD

Most-changed records

Existing CVEs whose severity, score, KEV or exploitation status moved.

  • CVE-2023-49105An issue was discovered in ownCloud owncloud/core before 10.13.188
  • CVE-2017-8046Malicious PATCH requests submitted to servers using Spring Data REST versions prior to 2.6.9 (Ingalls SR9), versions prior to 3.0.1 (Kay SR1) and Spring Boot versions prior to 1.5.9, 2.0 M6 can use specially crafted JSON data to run arbi…83
  • CVE-2018-0101A vulnerability in the Secure Sockets Layer (SSL) VPN functionality of the Cisco Adaptive Security Appliance (ASA) Software could allow an unauthenticated, remote attacker to cause a reload of the affected system or to remotely execute c…82

Most-affected vendors

By CVEs published in the period.