VulnSea

Daily digest

Thursday 10 September 2026

390 new CVEs this day, in line with the recent average. Severity skewed high: 59 critical and 188 high, 63% of the total. 66 arrived with exploitation evidence or public exploit code already attached. CISA added 2 CVEs to the Known Exploited Vulnerabilities catalog. IBM was the most-affected vendor with 31.

390
New CVEs
59
Critical
2
KEV additions
659
Records changed

Added to CISA KEV

Confirmed exploitation in the wild — federal remediation deadlines attach to these.

New this day, ranked by depth score

The 12 that matter most of the 390 published.

MAL-2026-16125Critical⚠ Exploited
1w ago

Malicious code in lucy-python-script-2030 (PyPI)

Malicious code in lucy-python-script-2030 (PyPI)

Abyssallucy-python-script-2030 · lucy-python-script-2030via OSV
MAL-2026-16122Critical⚠ Exploited
1w ago

Malicious code in pylever (PyPI)

Malicious code in pylever (PyPI)

Abyssalpylever · pylevervia OSV
CVE-2026-77770Critical· 10.0PoC
1w ago

The miniOrange 2FA WordPress plugin before 6.3.1, miniOrange 2FA WordPress plugin before 19.3 does not require a validated transaction before deleting site options whose names come from unauthenticated request input, allowing any visit…

The miniOrange 2FA WordPress plugin before 6.3.1, miniOrange 2FA WordPress plugin before 19.3 does not require a validated transaction before deleting site options whose names come from unauthenticated request input, allowing any visit…

AbyssalEPSS 0.24%via NVD
CVE-2026-88899Critical· 9.8PoC
1w ago

knowns before 0.31.0 External Control of Agent Working Directory via x-opencode-directory Header

knowns versions before 0.31.0 fail to properly validate the x-opencode-directory request header in the /api/opencode proxy endpoint. Remote attackers can supply arbitrary directory paths to execute file operations outside the project roo…

Abyssalknowns-dev · knownsEPSS 0.44%via CVEORG
CVE-2026-88018Critical· 9.8PoC
1w ago

rclone is a command-line program to sync files and directories to and from different cloud storage providers

rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1.75.1, rclone serve s3 configured with --auth-proxy but without --auth-key allows authPairMiddleware to register any …

Abyssalrclone · rcloneEPSS 0.50%via NVD
CVE-2026-18351Critical· 9.8PoC
1w ago

The Drag and Drop File Upload for Elementor Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.6.0 via the elementor_file_upload function

The Drag and Drop File Upload for Elementor Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.6.0 via the elementor_file_upload function. This is due to insufficient file type valid…

Abyssaladdonsorg · Drag and Drop File Upload for Elementor FormsEPSS 0.77%via NVD
CVE-2026-88062Critical· 9.5PoC
1w ago

OmniRoute ACP Custom-Agent Remote Code Execution (RCE)

OmniRoute is an open-source AI gateway providing a single endpoint for multiple model providers. In 3.8.49 and earlier, the OmniRoute POST /api/acp/agents custom ACP agent endpoint accepted attacker-controlled binary and versionCommand v…

Abyssaldiegosouzapw · OmniRouteEPSS 0.94%via CVEORG
CVE-2026-88869Critical· 9.3PoC
1w ago

AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scripting vulnerability in the AD_Server plugin's log.php endpoint that fails to escape the label parameter before storage

AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scripting vulnerability in the AD_Server plugin's log.php endpoint that fails to escape the label parameter before storage. An unauthenticated at…

AbyssalWWBN · AVideoEPSS 0.48%via NVD
CVE-2026-89086Critical· 9.1PoC
1w ago

In the jose package before 0.11.0 for OCaml, library calls to validate an RSA signature only confirm that PKCS #1 decoding succeeds, and proceed to declare the signature valid without the required steps that involve the public key.

In the jose package before 0.11.0 for OCaml, library calls to validate an RSA signature only confirm that PKCS #1 decoding succeeds, and proceed to declare the signature valid without the required steps that involve the public key.

AbyssalOCaml · joseEPSS 0.20%via NVD
CVE-2026-88864Critical· 9.1PoC
1w ago

Capgo (capgo.app) fails to restrict direct write access to the public.sso_providers table exposed through Supabase PostgREST

Capgo (capgo.app) fails to restrict direct write access to the public.sso_providers table exposed through Supabase PostgREST. A holder of an ordinary Capgo full API key can insert a row with status='active' and enforce_sso=true, bypassin…

AbyssalCap-go · capgo.appEPSS 0.26%via NVD
CVE-2026-88044Critical· 9.1PoC
1w ago

rclone is a command-line program to sync files and directories to and from different cloud storage providers

rclone is a command-line program to sync files and directories to and from different cloud storage providers. From 1.70.0 until 1.75.1, the serve/start RC interface accepts per-server proxyOpt.AuthProxy settings, and the FTP and S3 const…

Abyssalrclone · rcloneEPSS 0.49%via NVD
CVE-2026-71640Critical· 9.1PoC
1w ago

An issue in ZJU-FAST-Lab EGO-Planner-v2 All versions up to commit 5c99a95880401e2599638d567abc0e240396cb42 allows unsafe vehicle motion via improper handling of expired trajectory data in the replanning pipeline

An issue in ZJU-FAST-Lab EGO-Planner-v2 All versions up to commit 5c99a95880401e2599638d567abc0e240396cb42 allows unsafe vehicle motion via improper handling of expired trajectory data in the replanning pipeline

AbyssalEPSS 0.45%via NVD

Most-changed records

Existing CVEs whose severity, score, KEV or exploitation status moved.

  • CVE-2026-87491Out of bounds write in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page74
  • CVE-2026-53758Emlog is an open source website building system60
  • CVE-2026-52486An issue in OpenDDS 3.33.x allows a local attacker to cause a denial of service via the verify function in the SIgnedDocument module48
  • CVE-2026-79570mfish-nocode-pro v1.0.0 was discovered to contain a SQL injection vulnerability in the tableName parameter at /sys/dbConnect/data66
  • CVE-2026-79574An issue in the gateway server of mpush v0.8.1 allows attackers to execute arbitrary code via sending a crafted broadcast message.66
  • CVE-2026-78997UC Browser for Android (package com.UCMobile.intl, version 13.7.8.1314) contains a Universal Cross-Site Scripting vulnerability that allows an attacker to execute arbitrary JavaScript in the context of any origin63
  • CVE-2026-79571Incorrect access control in the SellerAuthorizeAspect component of springboot-project v1.0.0 allows unauthenticated attackers to access all seller management interfaces and list all products/orders, put products on/off sale, finish/cance…62
  • CVE-2026-79419A reflected cross-site scripting (XSS) vulnerability exists in EMX Tecnologia Gestao X Business Suite 8.4 and earlier60

Most-affected vendors

By CVEs published in the period.