VulnSea

Daily digest

Tuesday 8 September 2026

A heavy day: 1,599 new CVEs, well above the recent average of about 188. Severity skewed high: 95 critical and 936 high, 64% of the total. 78 arrived with exploitation evidence or public exploit code already attached. CISA added 4 CVEs to the Known Exploited Vulnerabilities catalog. Microsoft was the most-affected vendor with 970.

1599
New CVEs
95
Critical
4
KEV additions
1194
Records changed

Added to CISA KEV

Confirmed exploitation in the wild — federal remediation deadlines attach to these.

CVE-2026-86218Critical· 9.8CISA KEVPoC
2w ago

N-central is vulnerable to a pre-auth remote code execution This issue affects N-central: before 2026.3.1.14.

N-central is vulnerable to a pre-auth remote code execution This issue affects N-central: before 2026.3.1.14.

Hadaln-able · n-centralEPSS 7.5%via NVD
CVE-2026-75650Critical· 10.0CISA KEV0dayPoC
2w ago

Adobe Commerce is affected by an Improper Neutralization of Special Elements Used in a Template Engine vulnerability that could result in arbitrary code execution in the context of the current user

Adobe Commerce is affected by an Improper Neutralization of Special Elements Used in a Template Engine vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnera…

Hadaladobe · commerceEPSS 2.1%via NVD
CVE-2026-85880High· 7.8CISA KEV0dayPoC
1w ago

Heap-based buffer overflow in Windows ALPC allows an authorized attacker to elevate privileges locally.

Heap-based buffer overflow in Windows ALPC allows an authorized attacker to elevate privileges locally.

Abyssalmicrosoft · windows_10_1607EPSS 0.57%via NVD
CVE-2026-81963High· 7.8CISA KEV0dayPoC
1w ago

Improper link resolution before file access ('link following') in Windows Update Stack allows an authorized attacker to elevate privileges locally.

Improper link resolution before file access ('link following') in Windows Update Stack allows an authorized attacker to elevate privileges locally.

Abyssalmicrosoft · windows_11_23h2EPSS 0.63%via NVD

New this day, ranked by depth score

The 12 that matter most of the 1599 published.

CVE-2026-84869Critical· 9.9CISA KEVPoC
1w ago

A condition in the ScreenConnect client may allow files to be transferred and executed through an active remote session without authorization or Host confirmation in certain circumstances

A condition in the ScreenConnect client may allow files to be transferred and executed through an active remote session without authorization or Host confirmation in certain circumstances. ScreenConnect servers are not impacted.

Hadalconnectwise · screenconnectEPSS 0.69%via NVD
CVE-2026-85880High· 7.8CISA KEV0dayPoC
1w ago

Heap-based buffer overflow in Windows ALPC allows an authorized attacker to elevate privileges locally.

Heap-based buffer overflow in Windows ALPC allows an authorized attacker to elevate privileges locally.

Abyssalmicrosoft · windows_10_1607EPSS 0.57%via NVD
CVE-2026-81963High· 7.8CISA KEV0dayPoC
1w ago

Improper link resolution before file access ('link following') in Windows Update Stack allows an authorized attacker to elevate privileges locally.

Improper link resolution before file access ('link following') in Windows Update Stack allows an authorized attacker to elevate privileges locally.

Abyssalmicrosoft · windows_11_23h2EPSS 0.63%via NVD
CVE-2026-86510Critical· 9.9PoC
1w ago

A vulnerability has been found in D-Link DIR-822A A_101

A vulnerability has been found in D-Link DIR-822A A_101. Affected is the function tunnel_set_params of the component L2TP Control Message Parser. Such manipulation leads to out-of-bounds write. The attack can be launched remotely. The ex…

AbyssalD-Link · DIR-822AEPSS 0.46%via NVD
CVE-2026-79577Critical· 9.8PoC
1w ago

An issue in the /cas/login component of sso-master v1.0.0 allows attackers to authenticate into the application without a password via sending a crafted POST request.

An issue in the /cas/login component of sso-master v1.0.0 allows attackers to authenticate into the application without a password via sending a crafted POST request.

AbyssalEPSS 0.27%via NVD
CVE-2026-79576Critical· 9.8PoC
1w ago

An issue in the Single-Sign On (SSO) component of Digital-Infrastructure v9.6.7 allows attackers to authenticate as any user, including the Admin, without a password.

An issue in the Single-Sign On (SSO) component of Digital-Infrastructure v9.6.7 allows attackers to authenticate as any user, including the Admin, without a password.

AbyssalEPSS 0.33%via NVD
CVE-2026-79574Critical· 9.8PoC
1w ago

An issue in the gateway server of mpush v0.8.1 allows attackers to execute arbitrary code via sending a crafted broadcast message.

An issue in the gateway server of mpush v0.8.1 allows attackers to execute arbitrary code via sending a crafted broadcast message.

AbyssalEPSS 0.48%via NVD
CVE-2026-79570Critical· 9.8PoC
1w ago

mfish-nocode-pro v1.0.0 was discovered to contain a SQL injection vulnerability in the tableName parameter at /sys/dbConnect/data

mfish-nocode-pro v1.0.0 was discovered to contain a SQL injection vulnerability in the tableName parameter at /sys/dbConnect/data. This vulnerability allows attackers to access sensitive database information via a crafted SQL statement.

AbyssalEPSS 0.32%via NVD
CVE-2026-79569Critical· 9.8PoC
1w ago

Movie_Recommend v1.0.0 was discovered to contain a SQL injection vulnerability in the sort parameter at /loadingmore

Movie_Recommend v1.0.0 was discovered to contain a SQL injection vulnerability in the sort parameter at /loadingmore. This vulnerability allows attackers to access sensitive database information via a crafted SQL statement.

AbyssalEPSS 0.39%via NVD
CVE-2026-86509Critical· 9.6PoC
1w ago

A flaw has been found in D-Link DIR-895L A1_102b07

A flaw has been found in D-Link DIR-895L A1_102b07. This impacts the function sendOffer/sendACK of the file udhcpcd/serverpacket.c of the component udhcpcd. This manipulation causes stack-based buffer overflow. The attack can only be don…

AbyssalD-Link · DIR-895LEPSS 0.43%via NVD
CVE-2026-78997Critical· 9.3PoC
1w ago

UC Browser for Android (package com.UCMobile.intl, version 13.7.8.1314) contains a Universal Cross-Site Scripting vulnerability that allows an attacker to execute arbitrary JavaScript in the context of any origin

UC Browser for Android (package com.UCMobile.intl, version 13.7.8.1314) contains a Universal Cross-Site Scripting vulnerability that allows an attacker to execute arbitrary JavaScript in the context of any origin. An attacker hosts a spe…

AbyssalEPSS 0.28%via NVD
CVE-2026-86840Critical· 9.1PoC
1w ago

The `vtoken-minting` and `slpx` pallets in Bifrost contain an improper authorization vulnerability in channel commission attribution

The `vtoken-minting` and `slpx` pallets in Bifrost contain an improper authorization vulnerability in channel commission attribution. A signed account can supply an arbitrary registered `channel_id` when minting tokens without verifying …

AbyssalBitfrost.io · BifrostEPSS 0.24%via NVD

Most-changed records

Existing CVEs whose severity, score, KEV or exploitation status moved.

  • CVE-2026-86196Grav API plugin versions before 1.0.20 build password reset links from the untrusted Host header in the forgot-password endpoint, allowing unauthenticated attackers to redirect reset tokens to attacker-controlled domains60
  • CVE-2026-86218N-central is vulnerable to a pre-auth remote code execution This issue affects N-central: before 2026.3.1.14.80
  • CVE-2026-79569Movie_Recommend v1.0.0 was discovered to contain a SQL injection vulnerability in the sort parameter at /loadingmore66
  • CVE-2026-86195grav-plugin-api versions before 1.0.20 contain a privilege escalation vulnerability in the InvitationsController where the stripSuperFlags() method only removes nested super flags but fails to strip dot-keyed equivalents like api.super60
  • CVE-2026-82209When libpsl support is enabled, libcurl fails to enforce the Public Suffix List boundary check when processing a `Set-Cookie` header where the `Domain` attribute explicitly matches an origin host that is itself a public suffix (e.g., `Do…57
  • CVE-2026-80230When `CURLOPT_PINNEDPUBLICKEY` is configured alongside options that disable standard peer verification (`CURLOPT_SSL_VERIFYPEER = 0` and `CURLOPT_SSL_VERIFYHOST = 0`), libcurl fails to enforce public key pinning on connections establishe…53
  • CVE-2026-80231A flaw in libcurl makes it wrongly reuse an existing HTTPS connection setup for a given hostname even when using a different Native CA Store setting (`CURLSSLOPT_NATIVE_CA`) than when the connection was created.53
  • CVE-2026-80255A `Set-Cookie:` header using tab (horizontal tab, ASCII code 9) instead of space (ascii code 32) immediately before the `Secure` attribute causes curl to store the cookie without its Secure flag53

Most-affected vendors

By CVEs published in the period.