VulnSea

Daily digest

Tuesday 1 September 2026

148 new CVEs this day, in line with the recent average. Severity skewed high: 11 critical and 77 high, 59% of the total. 9 arrived with exploitation evidence or public exploit code already attached. Erlang was the most-affected vendor with 16.

148
New CVEs
11
Critical
0
KEV additions
3
Records changed

New this day, ranked by depth score

The 12 that matter most of the 148 published.

MAL-2026-15810Critical⚠ Exploited
3w ago

Malicious code in gcphelpit (PyPI)

Malicious code in gcphelpit (PyPI)

▾ Abyssalgcphelpit · gcphelpitvia OSV
CVE-2026-83549High· 7.8CISA KEV0dayPoC
3w ago

Post-authentication Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific conditions could potenti…

Post-authentication Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific conditions could potenti…

▾ Abyssalsonicwall · sma8200vEPSS 8.5%via NVD
CVE-2023-54391Critical· 9.8PoC
3w ago

Proxmox Virtual Environment (VE) 7.0 through 8.0 contains an authentication bypass vulnerability in libpve-access-control before 8.0.4 that allows unauthenticated attackers to authenticate as any existing enabled user without a configure…

Proxmox Virtual Environment (VE) 7.0 through 8.0 contains an authentication bypass vulnerability in libpve-access-control before 8.0.4 that allows unauthenticated attackers to authenticate as any existing enabled user without a configure…

▾ AbyssalEPSS 1.7%via NVD
CVE-2026-75604Critical· 9.0PoC
3w ago

Next.js is a React framework for building full-stack web applications

Next.js is a React framework for building full-stack web applications. From 13.4.0 until 15.5.24 and 16.3.3, Next.js applications using Pages Router or App Router without Cache Components on Windows-hosted servers do not consistently esc…

▾ Abyssalnext · nextEPSS 2.5%via NVD
CVE-2026-71981High· 8.8PoC
3w ago

Cypht before 2.12.2 contains a PHP object injection vulnerability that allows authenticated attackers to execute arbitrary operating system commands by supplying a crafted PHP object graph in the back_query GET parameter of the logout ha…

Cypht before 2.12.2 contains a PHP object injection vulnerability that allows authenticated attackers to execute arbitrary operating system commands by supplying a crafted PHP object graph in the back_query GET parameter of the logout ha…

▾ MidnightEPSS 0.56%via NVD
CVE-2026-65643High· 8.8PoC
3w ago

Eval injection in cPanel 11.138.0.0 and earlier allows remote authenticated users to execute arbitrary code as root.

Eval injection in cPanel 11.138.0.0 and earlier allows remote authenticated users to execute arbitrary code as root.

▾ Midnightcpanel · cpanelEPSS 0.90%via NVD
CVE-2026-69664High· 8.7PoC
3w ago

Missing Release of Resource after Effective Lifetime vulnerability in Erlang/OTP inets httpd allows an unauthenticated remote attacker to cause denial of service by sending a request with a chunked body whose chunk-size line is not a hex…

Missing Release of Resource after Effective Lifetime vulnerability in Erlang/OTP inets httpd allows an unauthenticated remote attacker to cause denial of service by sending a request with a chunked body whose chunk-size line is not a hex…

▾ MidnightErlang · otpEPSS 0.70%via NVD
CVE-2026-84480Critical· 9.8
3w ago

WWBN AVideo fails to validate password recovery token expiration in userRecoverPassSave.json.php, allowing attackers to use expired tokens to reset account passwords indefinitely

WWBN AVideo fails to validate password recovery token expiration in userRecoverPassSave.json.php, allowing attackers to use expired tokens to reset account passwords indefinitely. Attackers who obtain a recovery token can use it at any t…

▾ MidnightEPSS 0.29%via NVD
CVE-2026-84372Critical· 9.8
3w ago

Predis is a flexible and feature-complete Redis and Valkey client for PHP

Predis is a flexible and feature-complete Redis and Valkey client for PHP. From version 3.0.0-RC1 until version 3.3.0, pipeline handling on aggregate cluster and replication connections reparses an already serialized RESP buffer in Abstr…

▾ Midnightpredis · predis/predisEPSS 0.41%via NVD
CVE-2026-84325Critical· 9.8
3w ago

Improper input validation in DataTransfer in Google Chrome prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a co-installed app

Improper input validation in DataTransfer in Google Chrome prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a co-installed app. (Chromium security severity: High)

▾ MidnightGoogle · ChromeEPSS 0.25%via CVEORG
CVE-2026-78012Critical· 9.8
3w ago

An issue in the NetStaX EtherNet/IP Stack prior to v5.6.1 could allow a large Class 3 explicit-message request to exceed the application-side receive buffer without generating an error or warning

An issue in the NetStaX EtherNet/IP Stack prior to v5.6.1 could allow a large Class 3 explicit-message request to exceed the application-side receive buffer without generating an error or warning. The result could be memory corruption, a…

▾ MidnightEPSS 0.47%via NVD
CVE-2026-73749Critical· 9.8
3w ago

Multiple vulnerabilities exist in a daemon of AOS-CX that may allow for improper processing of malformed input

Multiple vulnerabilities exist in a daemon of AOS-CX that may allow for improper processing of malformed input. An unauthenticated remote attacker could exploit these vulnerabilities by sending specially crafted packets to the affected s…

▾ Midnighthpe · arubaos-cxEPSS 0.49%via NVD

Most-changed records

Existing CVEs whose severity, score, KEV or exploitation status moved.

  • CVE-2025-60689An unauthenticated command injection vulnerability exists in the Start_EPI function of the httpd binary on Linksys E1200 v2 routers (Firmware E1200_v2.0.11.001_us.tar.gz)45
  • CVE-2026-5027The 'POST /api/v2/files' endpoint does not sanitize the 'filename' parameter from the multipart form data, allowing an attacker to write files to arbitrary locations on the filesystem using path traversal sequences ('../').68
  • CVE-2026-0599Hugging Face Text Generation Inference vulnerable to Uncontrolled Resource Consumption47

Most-affected vendors

By CVEs published in the period.