Daily digest
Tuesday 1 September 2026
148 new CVEs this day, in line with the recent average. Severity skewed high: 11 critical and 77 high, 59% of the total. 9 arrived with exploitation evidence or public exploit code already attached. Erlang was the most-affected vendor with 16.
New this day, ranked by depth score
The 12 that matter most of the 148 published.
MAL-2026-15810Critical⚠ ExploitedMalicious code in gcphelpit (PyPI)
Malicious code in gcphelpit (PyPI)
CVE-2026-83549High· 7.8CISA KEV0dayPoCPost-authentication Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific conditions could potenti…
Post-authentication Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific conditions could potenti…
CVE-2023-54391Critical· 9.8PoCProxmox Virtual Environment (VE) 7.0 through 8.0 contains an authentication bypass vulnerability in libpve-access-control before 8.0.4 that allows unauthenticated attackers to authenticate as any existing enabled user without a configure…
Proxmox Virtual Environment (VE) 7.0 through 8.0 contains an authentication bypass vulnerability in libpve-access-control before 8.0.4 that allows unauthenticated attackers to authenticate as any existing enabled user without a configure…
CVE-2026-75604Critical· 9.0PoCNext.js is a React framework for building full-stack web applications
Next.js is a React framework for building full-stack web applications. From 13.4.0 until 15.5.24 and 16.3.3, Next.js applications using Pages Router or App Router without Cache Components on Windows-hosted servers do not consistently esc…
CVE-2026-71981High· 8.8PoCCypht before 2.12.2 contains a PHP object injection vulnerability that allows authenticated attackers to execute arbitrary operating system commands by supplying a crafted PHP object graph in the back_query GET parameter of the logout ha…
Cypht before 2.12.2 contains a PHP object injection vulnerability that allows authenticated attackers to execute arbitrary operating system commands by supplying a crafted PHP object graph in the back_query GET parameter of the logout ha…
CVE-2026-65643High· 8.8PoCEval injection in cPanel 11.138.0.0 and earlier allows remote authenticated users to execute arbitrary code as root.
Eval injection in cPanel 11.138.0.0 and earlier allows remote authenticated users to execute arbitrary code as root.
CVE-2026-69664High· 8.7PoCMissing Release of Resource after Effective Lifetime vulnerability in Erlang/OTP inets httpd allows an unauthenticated remote attacker to cause denial of service by sending a request with a chunked body whose chunk-size line is not a hex…
Missing Release of Resource after Effective Lifetime vulnerability in Erlang/OTP inets httpd allows an unauthenticated remote attacker to cause denial of service by sending a request with a chunked body whose chunk-size line is not a hex…
CVE-2026-84480Critical· 9.8WWBN AVideo fails to validate password recovery token expiration in userRecoverPassSave.json.php, allowing attackers to use expired tokens to reset account passwords indefinitely
WWBN AVideo fails to validate password recovery token expiration in userRecoverPassSave.json.php, allowing attackers to use expired tokens to reset account passwords indefinitely. Attackers who obtain a recovery token can use it at any t…
CVE-2026-84372Critical· 9.8Predis is a flexible and feature-complete Redis and Valkey client for PHP
Predis is a flexible and feature-complete Redis and Valkey client for PHP. From version 3.0.0-RC1 until version 3.3.0, pipeline handling on aggregate cluster and replication connections reparses an already serialized RESP buffer in Abstr…
CVE-2026-84325Critical· 9.8Improper input validation in DataTransfer in Google Chrome prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a co-installed app
Improper input validation in DataTransfer in Google Chrome prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a co-installed app. (Chromium security severity: High)
CVE-2026-78012Critical· 9.8An issue in the NetStaX EtherNet/IP Stack prior to v5.6.1 could allow a large Class 3 explicit-message request to exceed the application-side receive buffer without generating an error or warning
An issue in the NetStaX EtherNet/IP Stack prior to v5.6.1 could allow a large Class 3 explicit-message request to exceed the application-side receive buffer without generating an error or warning. The result could be memory corruption, a…
CVE-2026-73749Critical· 9.8Multiple vulnerabilities exist in a daemon of AOS-CX that may allow for improper processing of malformed input
Multiple vulnerabilities exist in a daemon of AOS-CX that may allow for improper processing of malformed input. An unauthenticated remote attacker could exploit these vulnerabilities by sending specially crafted packets to the affected s…
Most-changed records
Existing CVEs whose severity, score, KEV or exploitation status moved.
- CVE-2025-60689An unauthenticated command injection vulnerability exists in the Start_EPI function of the httpd binary on Linksys E1200 v2 routers (Firmware E1200_v2.0.11.001_us.tar.gz)epss, exploit_available45
- CVE-2026-5027The 'POST /api/v2/files' endpoint does not sanitize the 'filename' parameter from the multipart form data, allowing an attacker to write files to arbitrary locations on the filesystem using path traversal sequences ('../').exploit_available68
- CVE-2026-0599Hugging Face Text Generation Inference vulnerable to Uncontrolled Resource Consumptionepss47
Most-affected vendors
By CVEs published in the period.