VulnSea

Daily digest

Saturday 5 September 2026

148 new CVEs this day, in line with the recent average. Of those, 17 critical and 41 high. 37 arrived with exploitation evidence or public exploit code already attached. YesWiki was the most-affected vendor with 12.

148
New CVEs
17
Critical
0
KEV additions
3
Records changed

New this day, ranked by depth score

The 12 that matter most of the 148 published.

CVE-2026-86060Critical· 9.8CISA KEVPoC
2w ago

RouterOS contains an argument-handling flaw in the SSH login path involving usernames that begin with a prohibited character, allowing for the trusted RouterOS policy mask to be changed, leading to privilege escalation

RouterOS contains an argument-handling flaw in the SSH login path involving usernames that begin with a prohibited character, allowing for the trusted RouterOS policy mask to be changed, leading to privilege escalation. Exploitation requ…

▾ Hadalmikrotik · routerosEPSS 1.8%via NVD
MAL-2026-15935Critical⚠ Exploited
2w ago

Malicious code in proxycer (PyPI)

Malicious code in proxycer (PyPI)

▾ Abyssalproxycer · proxycervia OSV
CVE-2026-67277High· 8.2CISA KEVPoC
2w ago

RouterOS accepts a "related" btest connection before the corresponding primary session has completed authentication

RouterOS accepts a "related" btest connection before the corresponding primary session has completed authentication. An unauthenticated client can use this state to start an IPv4 UDP test. With "random-data=false", the sender transmits a…

▾ Abyssalmikrotik · routerosEPSS 1.6%via NVD
CVE-2026-86121Critical· 9.8PoC
2w ago

Cua computer-server versions before 0.3.42 skip authentication when the CONTAINER_NAME environment variable is unset and bind to all interfaces by default, allowing unauthenticated attackers to execute arbitrary commands

Cua computer-server versions before 0.3.42 skip authentication when the CONTAINER_NAME environment variable is unset and bind to all interfaces by default, allowing unauthenticated attackers to execute arbitrary commands. Attackers can r…

▾ Abyssaltrycua · cua-computer-serverEPSS 1.1%via NVD
CVE-2026-13447Critical· 9.8PoC
2w ago

The Mstore Api plugin for WordPress is vulnerable to Authentication Bypass via JWT Forgery in versions up to, and including, 4.20.0 This is due to missing cryptographic signature verification in the FirebasePhoneAuthHelper::verify_id_tok…

The Mstore Api plugin for WordPress is vulnerable to Authentication Bypass via JWT Forgery in versions up to, and including, 4.20.0 This is due to missing cryptographic signature verification in the FirebasePhoneAuthHelper::verify_id_tok…

▾ AbyssalEPSS 0.45%via NVD
CVE-2026-67276Critical· 9.2PoC
2w ago

RouterOS does not compare the complete RSA public key when matching an SSH authentication request to an authorized user key, checking the key type and modulus but omitting the exponent

RouterOS does not compare the complete RSA public key when matching an SSH authentication request to an authorized user key, checking the key type and modulus but omitting the exponent. Because signature verification uses the client-supp…

▾ AbyssalMikrotik · RouterOSEPSS 0.37%via NVD
CVE-2026-86190Critical· 9.1PoC
2w ago

WWBN AVideo contains a broken access control vulnerability in videoViewsInfo endpoints that returns complete user records including password hashes, recovery tokens, and live session identifiers to unauthenticated callers when a hash par…

WWBN AVideo contains a broken access control vulnerability in videoViewsInfo endpoints that returns complete user records including password hashes, recovery tokens, and live session identifiers to unauthenticated callers when a hash par…

▾ AbyssalWWBN · AVideoEPSS 0.44%via NVD
CVE-2026-52766Critical· 9.1PoC
2w ago

YesWiki is a wiki system written in PHP

YesWiki is a wiki system written in PHP. Prior to version 4.6.6, the {{erasespamedcomments}} wiki action (actions/EraseSpamedCommentsAction.php) accepts a suppr[] array from POST and deletes every wiki page whose tag appears in that arra…

▾ AbyssalYesWiki · yeswikiEPSS 0.58%via NVD
CVE-2026-86177High· 8.8PoC
2w ago

Pterodactyl Panel before 1.14.1 fails to validate action-specific permissions in scheduled task creation, allowing subusers with only schedule.update permission to execute arbitrary console commands

Pterodactyl Panel before 1.14.1 fails to validate action-specific permissions in scheduled task creation, allowing subusers with only schedule.update permission to execute arbitrary console commands. Attackers can create and immediately …

▾ Midnightpterodactyl · panelEPSS 0.58%via NVD
CVE-2026-86196High· 8.7PoC
2w ago

Grav API plugin versions before 1.0.20 build password reset links from the untrusted Host header in the forgot-password endpoint, allowing unauthenticated attackers to redirect reset tokens to attacker-controlled domains

Grav API plugin versions before 1.0.20 build password reset links from the untrusted Host header in the forgot-password endpoint, allowing unauthenticated attackers to redirect reset tokens to attacker-controlled domains. Attackers can s…

▾ Midnightgetgrav · grav-plugin-apiEPSS 0.43%via NVD
CVE-2026-86195High· 8.7PoC
2w ago

grav-plugin-api versions before 1.0.20 contain a privilege escalation vulnerability in the InvitationsController where the stripSuperFlags() method only removes nested super flags but fails to strip dot-keyed equivalents like api.super

grav-plugin-api versions before 1.0.20 contain a privilege escalation vulnerability in the InvitationsController where the stripSuperFlags() method only removes nested super flags but fails to strip dot-keyed equivalents like api.super. …

▾ Midnightgetgrav · grav-plugin-apiEPSS 0.39%via NVD
CVE-2026-86193High· 8.7PoC
2w ago

grav-plugin-api before 1.0.20 fails to validate group-inherited super permissions in user-management guards, allowing non-super user managers to modify super-admin accounts

grav-plugin-api before 1.0.20 fails to validate group-inherited super permissions in user-management guards, allowing non-super user managers to modify super-admin accounts. Attackers with api.access and api.users.write can patch passwor…

▾ Midnightgetgrav · grav-plugin-apiEPSS 0.36%via NVD

Most-changed records

Existing CVEs whose severity, score, KEV or exploitation status moved.

  • CVE-2017-8046Malicious PATCH requests submitted to servers using Spring Data REST versions prior to 2.6.9 (Ingalls SR9), versions prior to 3.0.1 (Kay SR1) and Spring Boot versions prior to 1.5.9, 2.0 M6 can use specially crafted JSON data to run arbi…87
  • CVE-2018-0101A vulnerability in the Secure Sockets Layer (SSL) VPN functionality of the Cisco Adaptive Security Appliance (ASA) Software could allow an unauthenticated, remote attacker to cause a reload of the affected system or to remotely execute c…84
  • CVE-2025-67038An issue was discovered in Lantronix EDS5000 2.1.0.0R383

Most-affected vendors

By CVEs published in the period.