VulnSea

Daily digest

Thursday 3 September 2026

A heavy day: 270 new CVEs, well above the recent average of about 136. Severity skewed high: 37 critical and 116 high, 57% of the total. 18 arrived with exploitation evidence or public exploit code already attached. siyuan-note was the most-affected vendor with 22.

270
New CVEs
37
Critical
0
KEV additions
3
Records changed

New this day, ranked by depth score

The 12 that matter most of the 270 published.

CVE-2026-85046High· 8.8CISA KEV0dayPoC
3w ago

Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page

Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

▾ Abyssalgoogle · chromeEPSS 49%via NVD
MAL-2026-15864Critical⚠ Exploited
3w ago

Malicious code in asti (PyPI)

Malicious code in asti (PyPI)

▾ Abyssalasti · astivia OSV
CVE-2026-69084Critical· 10.0PoC
3w ago

SiYuan: Unauthenticated arbitrary SQL execution via searchEmbedBlock (publish mode) : reader-reachable raw statement on read-write handle, cross-notebook read/write

SiYuan: Unauthenticated arbitrary SQL execution via searchEmbedBlock (publish mode) : reader-reachable raw statement on read-write handle, cross-notebook read/write

▾ Abyssalsiyuan-note · github.com/siyuan-note/siyuan/kernelEPSS 1.6%via GHSA
CVE-2026-69083Critical· 10.0PoC
3w ago

SiYuan: Unauthenticated SQL execution and REGEXP injection via fullTextSearchAssetContent (publish mode): reader-reachable raw SQL (method 2) and unescaped REGEXP (method 3) on read-write asset-content DB

SiYuan: Unauthenticated SQL execution and REGEXP injection via fullTextSearchAssetContent (publish mode): reader-reachable raw SQL (method 2) and unescaped REGEXP (method 3) on read-write asset-content DB

▾ Abyssalsiyuan-note · github.com/siyuan-note/siyuan/kernelEPSS 0.47%via GHSA
CVE-2026-84753Critical· 9.8PoC
3w ago

Unauthenticated PHP Object Injection in Mail Mint <= 1.31.0 versions.

Unauthenticated PHP Object Injection in Mail Mint <= 1.31.0 versions.

▾ AbyssalEPSS 0.56%via NVD
CVE-2026-85183Critical· 9.3PoC
3w ago

Taipy configures its socket.io server with wildcard CORS origin and credential flag enabled, allowing any web page to establish credentialed WebSocket connections to victim applications

Taipy configures its socket.io server with wildcard CORS origin and credential flag enabled, allowing any web page to establish credentialed WebSocket connections to victim applications. Attackers can open socket.io sessions from arbitra…

▾ AbyssalAvaiga · taipyEPSS 0.23%via NVD
CVE-2026-85179High· 8.5PoC
3w ago

Label Studio through 1.23.0 fails to validate webhook URLs, allowing authenticated users to dispatch requests to internal services including RFC 1918 addresses and cloud metadata endpoints

Label Studio through 1.23.0 fails to validate webhook URLs, allowing authenticated users to dispatch requests to internal services including RFC 1918 addresses and cloud metadata endpoints. Attackers can create webhooks targeting private…

▾ MidnightHumanSignal · label-studioEPSS 0.40%via NVD
CVE-2026-85048High· 8.3PoC
3w ago

Use after free in Compositing in Google Chrome prior to 152.0.7977.82 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page

Use after free in Compositing in Google Chrome prior to 152.0.7977.82 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: …

▾ Midnightgoogle · chromeEPSS 0.40%via NVD
CVE-2026-85214High· 8.1PoC
3w ago

vhr fails to validate user authorization in the PUT /hr/info endpoint, allowing authenticated users to modify arbitrary HR profiles by supplying any profile ID in the request body

vhr fails to validate user authorization in the PUT /hr/info endpoint, allowing authenticated users to modify arbitrary HR profiles by supplying any profile ID in the request body. Attackers can overwrite other users' names, addresses, a…

▾ Midnightlenve · vhrEPSS 0.50%via NVD
CVE-2026-85165Critical· 9.9
3w ago

n8n versions before 2.36.2 contain an expression sandbox bypass vulnerability where free identifiers in spread, computed-key, switch-case, or class-extension positions resolve against process globals

n8n versions before 2.36.2 contain an expression sandbox bypass vulnerability where free identifiers in spread, computed-key, switch-case, or class-extension positions resolve against process globals. Authenticated users with workflow-ed…

▾ Midnightn8n · n8nEPSS 0.57%via NVD
CVE-2026-85061Critical· 10.0
3w ago

MapLibre GL JS is an interactive vector tile map library for web browsers

MapLibre GL JS is an interactive vector tile map library for web browsers. Prior to 6.4.1, DOM.sanitize() in src/util/dom.ts iterates elem.attributes as a live NamedNodeMap while removeAttributes() removes attributes from the same collec…

▾ Midnightmaplibre-gl · maplibre-glEPSS 0.52%via NVD
CVE-2026-83711Critical· 10.0
3w ago

Authorization bypass through user-controlled key in Microsoft Azure Active Directory B2C allows an unauthorized attacker to elevate privileges over a network.

Authorization bypass through user-controlled key in Microsoft Azure Active Directory B2C allows an unauthorized attacker to elevate privileges over a network.

▾ MidnightMicrosoft · EntraEPSS 0.81%via NVD

Most-changed records

Existing CVEs whose severity, score, KEV or exploitation status moved.

  • CVE-2026-9198IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to chain /api/v1/auto_login (mints SUPERUSER tokens to any network caller) with /api/v1/validate/code (executes user code via exec()) to achieve full RCE on default L…85
  • CVE-2026-73570A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp package is installed and SNMP notifications are enabled76
  • CVE-2026-48710Starlette is a lightweight ASGI framework/toolkit62

Most-affected vendors

By CVEs published in the period.