VulnSea

Daily digest

Wednesday 9 September 2026

A heavy day: 681 new CVEs, well above the recent average of about 378. Of those, 63 critical and 200 high. 92 arrived with exploitation evidence or public exploit code already attached. CISA added 4 CVEs to the Known Exploited Vulnerabilities catalog. google was the most-affected vendor with 232.

681
New CVEs
63
Critical
4
KEV additions
595
Records changed

Added to CISA KEV

Confirmed exploitation in the wild — federal remediation deadlines attach to these.

CVE-2026-20079Critical· 10.0CISA KEVPoC
6mo ago

A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to bypass authentication and execute script files on an affected device to obtain root access …

A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to bypass authentication and execute script files on an affected device to obtain root access …

Hadalcisco · secure_firewall_management_centerEPSS 76%via NVD
CVE-2026-19490Critical· 9.8CISA KEVPoC
1mo ago

Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: from 14.1 through 73.32 and from 13.1 through 63.21; Gateway: from 14.1 through 73.32 and from 13.1 through 63.21.

Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: from 14.1 through 73.32 and from 13.1 through 63.21; Gateway: from 14.1 through 73.32 and from 13.1 through 63.21.

Hadalcitrix · netscaler_application_delivery_controllerEPSS 5.6%via NVD
CVE-2026-87491High· 8.8CISA KEV0dayPoC
1w ago

Out of bounds write in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page

Out of bounds write in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

Abyssalgoogle · chromeEPSS 1.00%via NVD
CVE-2025-25249High· 8.1CISA KEVPoC
8mo ago

A heap-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11, FortiOS 7.0.0 through 7.0.17, FortiOS 6.4 all versions, FortiSwitchManager 7.2.0 through 7.2.6…

A heap-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11, FortiOS 7.0.0 through 7.0.17, FortiOS 6.4 all versions, FortiSwitchManager 7.2.0 through 7.2.6…

Abyssalfortinet · fortiswitchmanagerEPSS 2.4%via NVD

New this day, ranked by depth score

The 12 that matter most of the 681 published.

CVE-2026-87491High· 8.8CISA KEV0dayPoC
1w ago

Out of bounds write in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page

Out of bounds write in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

Abyssalgoogle · chromeEPSS 1.00%via NVD
MAL-2026-16121Critical⚠ Exploited
1w ago

Malicious code in websetup (PyPI)

Malicious code in websetup (PyPI)

Abyssalwebsetup · websetupvia OSV
MAL-2026-16099Critical⚠ Exploited
1w ago

Malicious code in bq-sdist-probe-vrp (PyPI)

Malicious code in bq-sdist-probe-vrp (PyPI)

Abyssalbq-sdist-probe-vrp · bq-sdist-probe-vrpvia OSV
MAL-2026-16098Critical⚠ Exploited
1w ago

Malicious code in bq-build-probe-vrp-2026 (PyPI)

Malicious code in bq-build-probe-vrp-2026 (PyPI)

Abyssalbq-build-probe-vrp-2026 · bq-build-probe-vrp-2026via OSV
MAL-2026-16080Critical⚠ Exploited
1w ago

Malicious code in databricks-webapp-navigation-homepage (PyPI)

Malicious code in databricks-webapp-navigation-homepage (PyPI)

Abyssaldatabricks-webapp-navigation-homepage · databricks-webapp-navigation-homepagevia OSV
CVE-2026-67401Critical· 9.9PoC
1w ago

A vulnerability in cPanel allows a mail-enabled account to achieve remote code execution as root through SQLi in EmailTrack component

A vulnerability in cPanel allows a mail-enabled account to achieve remote code execution as root through SQLi in EmailTrack component

AbyssalWebPros · cPanelEPSS 1.0%via NVD
CVE-2026-87929Critical· 9.8PoC
1w ago

MaxSite CMS through 109.6 ships with a hardcoded session encryption key in application/config/config.php that is never changed during installation, allowing unauthenticated attackers to forge administrator session cookies

MaxSite CMS through 109.6 ships with a hardcoded session encryption key in application/config/config.php that is never changed during installation, allowing unauthenticated attackers to forge administrator session cookies. Attackers can …

AbyssalMaxSite · MaxSite CMSEPSS 0.29%via NVD
CVE-2026-71805Critical· 9.8PoC
1w ago

An arbitrary file upload and path traversal vulnerability exists in LZ-litchi 1.0.0

An arbitrary file upload and path traversal vulnerability exists in LZ-litchi 1.0.0. Unauthenticated remote attackers can upload arbitrary files and write them outside the intended storage directory via the directory parameter in POST /a…

AbyssalEPSS 0.36%via NVD
CVE-2026-71801Critical· 9.8PoC
1w ago

An issue was discovered in s-pms SPMS-Server through v1.0

An issue was discovered in s-pms SPMS-Server through v1.0. The application contains a hardcoded default access token secret within its core configuration file, which is not overridden or removed in the production environment profile. A r…

AbyssalEPSS 0.53%via NVD
CVE-2026-36433Critical· 9.8PoC
1w ago

An issue in Actions Semiconductor Co

An issue in Actions Semiconductor Co. Ltd Tool- Media Player Utilities v.4.46 allows a physically proximate attacker execute arbitrary code via the Production.dll and RdiskUpgrade.exe components

AbyssalEPSS 0.48%via CVEORG
CVE-2026-87492Critical· 9.6PoC
1w ago

Incorrect authorization in DevTools in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page

Incorrect authorization in DevTools in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

Abyssalgoogle · chromeEPSS 0.33%via NVD
CVE-2026-54694Critical· 9.6PoC
1w ago

SkillTree is a micro-learning gamification platform

SkillTree is a micro-learning gamification platform. Prior to version 4.4.2, two independent code flaws combine into a single exploitable attack chain, with three distinct exploitation paths of escalating impact. `StringHighlighter.js` b…

AbyssalNationalSecurityAgency · skills-serviceEPSS 0.28%via NVD

Most-changed records

Existing CVEs whose severity, score, KEV or exploitation status moved.

  • CVE-2026-87491Out of bounds write in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page74
  • CVE-2026-75650Adobe Commerce is affected by an Improper Neutralization of Special Elements Used in a Template Engine vulnerability that could result in arbitrary code execution in the context of the current user80
  • MAL-2026-15931Malicious code in metricboxlite (PyPI)70
  • CVE-2026-81963Improper link resolution before file access ('link following') in Windows Update Stack allows an authorized attacker to elevate privileges locally.68
  • CVE-2026-85880Heap-based buffer overflow in Windows ALPC allows an authorized attacker to elevate privileges locally.68
  • CVE-2026-87523Race condition in DataTransfer in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page29
  • CVE-2026-87529Numeric truncation error in Media in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page53
  • CVE-2026-87547Incorrect reference resolution in FileSystem in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page53

Most-affected vendors

By CVEs published in the period.