Daily digest
Monday 7 September 2026
A busier-than-usual day with 259 new CVEs (recent average about 172). Of those, 20 critical and 83 high. 74 arrived with exploitation evidence or public exploit code already attached. dell was the most-affected vendor with 36.
New this day, ranked by depth score
The 12 that matter most of the 259 published.
CVE-2026-75650Critical· 10.0CISA KEV0dayPoCAdobe Commerce is affected by an Improper Neutralization of Special Elements Used in a Template Engine vulnerability that could result in arbitrary code execution in the context of the current user
Adobe Commerce is affected by an Improper Neutralization of Special Elements Used in a Template Engine vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnera…
MAL-2026-16017Critical⚠ ExploitedMalicious code in telegram-helper (PyPI)
Malicious code in telegram-helper (PyPI)
MAL-2026-16016Critical⚠ ExploitedMalicious code in cv-train (PyPI)
Malicious code in cv-train (PyPI)
CVE-2026-86299Critical· 9.9PoCA vulnerability was detected in Linksys RE7000 2.0.15
A vulnerability was detected in Linksys RE7000 2.0.15. This affects the function platform_event_pingTest of the file /cgi-bin/json.cgi?PingTest of the component PingTest Handler. The manipulation of the argument pingTestIp/pingTestPktSiz…
CVE-2026-86296Critical· 10.0PoCA vulnerability was determined in D-Link DIR-822A A_101
A vulnerability was determined in D-Link DIR-822A A_101. This vulnerability affects the function strcpy of the file udhcpcd/serverpacket.c of the component udhcpcd. This manipulation causes stack-based buffer overflow. The attack is poss…
CVE-2026-79698Critical· 9.9PoCA vulnerability was identified in Advantech WISE-6610-NB, WISE-6610-EB, WISE-6610-TB, WISE-6610-JB, WISE-6610-CB, WISE-6610-EL-NB, WISE-6610-EL-EB, WISE-6610-EL-TB, WISE-6610-EL-JB, WISE-6610-EL-CB, WISE-6610P-DEA, WISE-6610P-DNA and WIS…
A vulnerability was identified in Advantech WISE-6610-NB, WISE-6610-EB, WISE-6610-TB, WISE-6610-JB, WISE-6610-CB, WISE-6610-EL-NB, WISE-6610-EL-EB, WISE-6610-EL-TB, WISE-6610-EL-JB, WISE-6610-EL-CB, WISE-6610P-DEA, WISE-6610P-DNA and WIS…
CVE-2026-79697Critical· 9.9PoCA vulnerability was determined in Advantech WISE-6610-NB, WISE-6610-EB, WISE-6610-TB, WISE-6610-JB, WISE-6610-CB, WISE-6610-EL-NB, WISE-6610-EL-EB, WISE-6610-EL-TB, WISE-6610-EL-JB, WISE-6610-EL-CB, WISE-6610P-DEA, WISE-6610P-DNA and WIS…
A vulnerability was determined in Advantech WISE-6610-NB, WISE-6610-EB, WISE-6610-TB, WISE-6610-JB, WISE-6610-CB, WISE-6610-EL-NB, WISE-6610-EL-EB, WISE-6610-EL-TB, WISE-6610-EL-JB, WISE-6610-EL-CB, WISE-6610P-DEA, WISE-6610P-DNA and WIS…
CVE-2026-86426Critical· 9.8PoCLibreNMS before 26.8.0 contains an authentication bypass vulnerability in the REST API that allows unauthenticated attackers to access protected endpoints by sending numeric values instead of string tokens
LibreNMS before 26.8.0 contains an authentication bypass vulnerability in the REST API that allows unauthenticated attackers to access protected endpoints by sending numeric values instead of string tokens. Attackers can exploit MySQL ty…
CVE-2026-76578Critical· 9.8PoCA flaw was found in FreeIPA
A flaw was found in FreeIPA. The self-managed OTP token ACI does not require authentication and does not restrict which attributes may be added alongside the token entry. An unauthenticated LDAP client can exploit this, combined with a r…
CVE-2026-86295High· 8.3PoCA vulnerability was found in D-Link DIR-895L A1_102b07
A vulnerability was found in D-Link DIR-895L A1_102b07. This affects the function sendACK of the file udhcpcd/serverpacket.c of the component udhcpcd. The manipulation of the argument Hostname results in command injection. The attack can…
CVE-2026-84173High· 8.3PoCIn Eclipse Ankaios versions v0.5.1 through v1.0.1, the agent-side Control Interface authorizer incorrectly evaluates multi-segment allow rules whose first path segment is a wildcard
In Eclipse Ankaios versions v0.5.1 through v1.0.1, the agent-side Control Interface authorizer incorrectly evaluates multi-segment allow rules whose first path segment is a wildcard. An authenticated workload with access restricted by su…
CVE-2026-19843High· 8.4PoCA flaw was found in 389-ds-base
A flaw was found in 389-ds-base. The Cockpit 389 Console's LDAP editor constructs an ldapsearch command by embedding an LDAP entry's distinguished name (DN) into a shell command string without proper escaping. An LDAP user with delegated…
Most-changed records
Existing CVEs whose severity, score, KEV or exploitation status moved.
- CVE-2022-26258D-Link DIR-820L 1.05B03 was discovered to contain remote command execution (RCE) vulnerability via HTTP POST to get set ccp.epss97
- CVE-2023-37941Apache Superset Deserialization of Untrusted Data vulnerabilityepss55
Most-affected vendors
By CVEs published in the period.