Daily digest
Wednesday 9 September 2026
A heavy day: 681 new CVEs, well above the recent average of about 378. Of those, 63 critical and 200 high. 92 arrived with exploitation evidence or public exploit code already attached. CISA added 4 CVEs to the Known Exploited Vulnerabilities catalog. google was the most-affected vendor with 232.
Added to CISA KEV
Confirmed exploitation in the wild — federal remediation deadlines attach to these.
CVE-2026-20079Critical· 10.0CISA KEVPoCA vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to bypass authentication and execute script files on an affected device to obtain root access …
A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to bypass authentication and execute script files on an affected device to obtain root access …
CVE-2026-19490Critical· 9.8CISA KEVPoCVulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: from 14.1 through 73.32 and from 13.1 through 63.21; Gateway: from 14.1 through 73.32 and from 13.1 through 63.21.
Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: from 14.1 through 73.32 and from 13.1 through 63.21; Gateway: from 14.1 through 73.32 and from 13.1 through 63.21.
CVE-2026-87491High· 8.8CISA KEV0dayPoCOut of bounds write in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page
Out of bounds write in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
CVE-2025-25249High· 8.1CISA KEVPoCA heap-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11, FortiOS 7.0.0 through 7.0.17, FortiOS 6.4 all versions, FortiSwitchManager 7.2.0 through 7.2.6…
A heap-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11, FortiOS 7.0.0 through 7.0.17, FortiOS 6.4 all versions, FortiSwitchManager 7.2.0 through 7.2.6…
New this day, ranked by depth score
The 12 that matter most of the 681 published.
CVE-2026-87491High· 8.8CISA KEV0dayPoCOut of bounds write in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page
Out of bounds write in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
MAL-2026-16121Critical⚠ ExploitedMalicious code in websetup (PyPI)
Malicious code in websetup (PyPI)
MAL-2026-16099Critical⚠ ExploitedMalicious code in bq-sdist-probe-vrp (PyPI)
Malicious code in bq-sdist-probe-vrp (PyPI)
MAL-2026-16098Critical⚠ ExploitedMalicious code in bq-build-probe-vrp-2026 (PyPI)
Malicious code in bq-build-probe-vrp-2026 (PyPI)
MAL-2026-16080Critical⚠ ExploitedMalicious code in databricks-webapp-navigation-homepage (PyPI)
Malicious code in databricks-webapp-navigation-homepage (PyPI)
CVE-2026-67401Critical· 9.9PoCA vulnerability in cPanel allows a mail-enabled account to achieve remote code execution as root through SQLi in EmailTrack component
A vulnerability in cPanel allows a mail-enabled account to achieve remote code execution as root through SQLi in EmailTrack component
CVE-2026-87929Critical· 9.8PoCMaxSite CMS through 109.6 ships with a hardcoded session encryption key in application/config/config.php that is never changed during installation, allowing unauthenticated attackers to forge administrator session cookies
MaxSite CMS through 109.6 ships with a hardcoded session encryption key in application/config/config.php that is never changed during installation, allowing unauthenticated attackers to forge administrator session cookies. Attackers can …
CVE-2026-71805Critical· 9.8PoCAn arbitrary file upload and path traversal vulnerability exists in LZ-litchi 1.0.0
An arbitrary file upload and path traversal vulnerability exists in LZ-litchi 1.0.0. Unauthenticated remote attackers can upload arbitrary files and write them outside the intended storage directory via the directory parameter in POST /a…
CVE-2026-71801Critical· 9.8PoCAn issue was discovered in s-pms SPMS-Server through v1.0
An issue was discovered in s-pms SPMS-Server through v1.0. The application contains a hardcoded default access token secret within its core configuration file, which is not overridden or removed in the production environment profile. A r…
CVE-2026-36433Critical· 9.8PoCAn issue in Actions Semiconductor Co
An issue in Actions Semiconductor Co. Ltd Tool- Media Player Utilities v.4.46 allows a physically proximate attacker execute arbitrary code via the Production.dll and RdiskUpgrade.exe components
CVE-2026-87492Critical· 9.6PoCIncorrect authorization in DevTools in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page
Incorrect authorization in DevTools in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
CVE-2026-54694Critical· 9.6PoCSkillTree is a micro-learning gamification platform
SkillTree is a micro-learning gamification platform. Prior to version 4.4.2, two independent code flaws combine into a single exploitable attack chain, with three distinct exploitation paths of escalating impact. `StringHighlighter.js` b…
Most-changed records
Existing CVEs whose severity, score, KEV or exploitation status moved.
- CVE-2026-87491Out of bounds write in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML pageseverity, cvss, exploited, exploit_available74
- CVE-2026-75650Adobe Commerce is affected by an Improper Neutralization of Special Elements Used in a Template Engine vulnerability that could result in arbitrary code execution in the context of the current userexploited, kev, zero_day80
- MAL-2026-15931Malicious code in metricboxlite (PyPI)severity, exploited70
- CVE-2026-81963Improper link resolution before file access ('link following') in Windows Update Stack allows an authorized attacker to elevate privileges locally.kev, zero_day68
- CVE-2026-85880Heap-based buffer overflow in Windows ALPC allows an authorized attacker to elevate privileges locally.kev, zero_day68
- CVE-2026-87523Race condition in DataTransfer in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML pageseverity, cvss29
- CVE-2026-87529Numeric truncation error in Media in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML pageseverity, cvss53
- CVE-2026-87547Incorrect reference resolution in FileSystem in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML pageseverity, cvss53
Most-affected vendors
By CVEs published in the period.