VulnSea

Daily digest

Monday 7 September 2026

A busier-than-usual day with 259 new CVEs (recent average about 172). Of those, 20 critical and 83 high. 74 arrived with exploitation evidence or public exploit code already attached. dell was the most-affected vendor with 36.

259
New CVEs
20
Critical
0
KEV additions
2
Records changed

New this day, ranked by depth score

The 12 that matter most of the 259 published.

CVE-2026-75650Critical· 10.0CISA KEV0dayPoC
2w ago

Adobe Commerce is affected by an Improper Neutralization of Special Elements Used in a Template Engine vulnerability that could result in arbitrary code execution in the context of the current user

Adobe Commerce is affected by an Improper Neutralization of Special Elements Used in a Template Engine vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnera…

Hadaladobe · commerceEPSS 2.1%via NVD
MAL-2026-16017Critical⚠ Exploited
2w ago

Malicious code in telegram-helper (PyPI)

Malicious code in telegram-helper (PyPI)

Abyssaltelegram-helper · telegram-helpervia OSV
MAL-2026-16016Critical⚠ Exploited
2w ago

Malicious code in cv-train (PyPI)

Malicious code in cv-train (PyPI)

Abyssalcv-train · cv-trainvia OSV
CVE-2026-86299Critical· 9.9PoC
2w ago

A vulnerability was detected in Linksys RE7000 2.0.15

A vulnerability was detected in Linksys RE7000 2.0.15. This affects the function platform_event_pingTest of the file /cgi-bin/json.cgi?PingTest of the component PingTest Handler. The manipulation of the argument pingTestIp/pingTestPktSiz…

AbyssalLinksys · RE7000EPSS 2.0%via NVD
CVE-2026-86296Critical· 10.0PoC
2w ago

A vulnerability was determined in D-Link DIR-822A A_101

A vulnerability was determined in D-Link DIR-822A A_101. This vulnerability affects the function strcpy of the file udhcpcd/serverpacket.c of the component udhcpcd. This manipulation causes stack-based buffer overflow. The attack is poss…

AbyssalD-Link · DIR-822AEPSS 1.3%via NVD
CVE-2026-79698Critical· 9.9PoC
2w ago

A vulnerability was identified in Advantech WISE-6610-NB, WISE-6610-EB, WISE-6610-TB, WISE-6610-JB, WISE-6610-CB, WISE-6610-EL-NB, WISE-6610-EL-EB, WISE-6610-EL-TB, WISE-6610-EL-JB, WISE-6610-EL-CB, WISE-6610P-DEA, WISE-6610P-DNA and WIS…

A vulnerability was identified in Advantech WISE-6610-NB, WISE-6610-EB, WISE-6610-TB, WISE-6610-JB, WISE-6610-CB, WISE-6610-EL-NB, WISE-6610-EL-EB, WISE-6610-EL-TB, WISE-6610-EL-JB, WISE-6610-EL-CB, WISE-6610P-DEA, WISE-6610P-DNA and WIS…

AbyssalAdvantech · WISE-6610-NBEPSS 1.7%via NVD
CVE-2026-79697Critical· 9.9PoC
2w ago

A vulnerability was determined in Advantech WISE-6610-NB, WISE-6610-EB, WISE-6610-TB, WISE-6610-JB, WISE-6610-CB, WISE-6610-EL-NB, WISE-6610-EL-EB, WISE-6610-EL-TB, WISE-6610-EL-JB, WISE-6610-EL-CB, WISE-6610P-DEA, WISE-6610P-DNA and WIS…

A vulnerability was determined in Advantech WISE-6610-NB, WISE-6610-EB, WISE-6610-TB, WISE-6610-JB, WISE-6610-CB, WISE-6610-EL-NB, WISE-6610-EL-EB, WISE-6610-EL-TB, WISE-6610-EL-JB, WISE-6610-EL-CB, WISE-6610P-DEA, WISE-6610P-DNA and WIS…

AbyssalAdvantech · WISE-6610-NBEPSS 3.4%via NVD
CVE-2026-86426Critical· 9.8PoC
2w ago

LibreNMS before 26.8.0 contains an authentication bypass vulnerability in the REST API that allows unauthenticated attackers to access protected endpoints by sending numeric values instead of string tokens

LibreNMS before 26.8.0 contains an authentication bypass vulnerability in the REST API that allows unauthenticated attackers to access protected endpoints by sending numeric values instead of string tokens. Attackers can exploit MySQL ty…

Abyssallibrenms · librenmsEPSS 2.1%via NVD
CVE-2026-76578Critical· 9.8PoC
2w ago

A flaw was found in FreeIPA

A flaw was found in FreeIPA. The self-managed OTP token ACI does not require authentication and does not restrict which attributes may be added alongside the token entry. An unauthenticated LDAP client can exploit this, combined with a r…

AbyssalRed Hat · ipaEPSS 0.45%via NVD
CVE-2026-86295High· 8.3PoC
2w ago

A vulnerability was found in D-Link DIR-895L A1_102b07

A vulnerability was found in D-Link DIR-895L A1_102b07. This affects the function sendACK of the file udhcpcd/serverpacket.c of the component udhcpcd. The manipulation of the argument Hostname results in command injection. The attack can…

MidnightD-Link · DIR-895LEPSS 1.7%via NVD
CVE-2026-84173High· 8.3PoC
2w ago

In Eclipse Ankaios versions v0.5.1 through v1.0.1, the agent-side Control Interface authorizer incorrectly evaluates multi-segment allow rules whose first path segment is a wildcard

In Eclipse Ankaios versions v0.5.1 through v1.0.1, the agent-side Control Interface authorizer incorrectly evaluates multi-segment allow rules whose first path segment is a wildcard. An authenticated workload with access restricted by su…

MidnightEclipse Foundation · Eclipse AnkaiosEPSS 0.11%via NVD
CVE-2026-19843High· 8.4PoC
2w ago

A flaw was found in 389-ds-base

A flaw was found in 389-ds-base. The Cockpit 389 Console's LDAP editor constructs an ldapsearch command by embedding an LDAP entry's distinguished name (DN) into a shell command string without proper escaping. An LDAP user with delegated…

MidnightRed Hat · redhat-ds:11EPSS 0.48%via NVD

Most-changed records

Existing CVEs whose severity, score, KEV or exploitation status moved.

  • CVE-2022-26258D-Link DIR-820L 1.05B03 was discovered to contain remote command execution (RCE) vulnerability via HTTP POST to get set ccp.97
  • CVE-2023-37941Apache Superset Deserialization of Untrusted Data vulnerability55

Most-affected vendors

By CVEs published in the period.