Daily digest
Thursday 10 September 2026
390 new CVEs this day, in line with the recent average. Severity skewed high: 59 critical and 188 high, 63% of the total. 66 arrived with exploitation evidence or public exploit code already attached. CISA added 2 CVEs to the Known Exploited Vulnerabilities catalog. IBM was the most-affected vendor with 31.
Added to CISA KEV
Confirmed exploitation in the wild — federal remediation deadlines attach to these.
CVE-2026-86060Critical· 9.8CISA KEVPoCRouterOS contains an argument-handling flaw in the SSH login path involving usernames that begin with a prohibited character, allowing for the trusted RouterOS policy mask to be changed, leading to privilege escalation
RouterOS contains an argument-handling flaw in the SSH login path involving usernames that begin with a prohibited character, allowing for the trusted RouterOS policy mask to be changed, leading to privilege escalation. Exploitation requ…
CVE-2026-67277High· 8.2CISA KEVPoCRouterOS accepts a "related" btest connection before the corresponding primary session has completed authentication
RouterOS accepts a "related" btest connection before the corresponding primary session has completed authentication. An unauthenticated client can use this state to start an IPv4 UDP test. With "random-data=false", the sender transmits a…
New this day, ranked by depth score
The 12 that matter most of the 390 published.
MAL-2026-16125Critical⚠ ExploitedMalicious code in lucy-python-script-2030 (PyPI)
Malicious code in lucy-python-script-2030 (PyPI)
MAL-2026-16122Critical⚠ ExploitedMalicious code in pylever (PyPI)
Malicious code in pylever (PyPI)
CVE-2026-77770Critical· 10.0PoCThe miniOrange 2FA WordPress plugin before 6.3.1, miniOrange 2FA WordPress plugin before 19.3 does not require a validated transaction before deleting site options whose names come from unauthenticated request input, allowing any visit…
The miniOrange 2FA WordPress plugin before 6.3.1, miniOrange 2FA WordPress plugin before 19.3 does not require a validated transaction before deleting site options whose names come from unauthenticated request input, allowing any visit…
CVE-2026-88899Critical· 9.8PoCknowns before 0.31.0 External Control of Agent Working Directory via x-opencode-directory Header
knowns versions before 0.31.0 fail to properly validate the x-opencode-directory request header in the /api/opencode proxy endpoint. Remote attackers can supply arbitrary directory paths to execute file operations outside the project roo…
CVE-2026-88018Critical· 9.8PoCrclone is a command-line program to sync files and directories to and from different cloud storage providers
rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1.75.1, rclone serve s3 configured with --auth-proxy but without --auth-key allows authPairMiddleware to register any …
CVE-2026-18351Critical· 9.8PoCThe Drag and Drop File Upload for Elementor Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.6.0 via the elementor_file_upload function
The Drag and Drop File Upload for Elementor Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.6.0 via the elementor_file_upload function. This is due to insufficient file type valid…
CVE-2026-88062Critical· 9.5PoCOmniRoute ACP Custom-Agent Remote Code Execution (RCE)
OmniRoute is an open-source AI gateway providing a single endpoint for multiple model providers. In 3.8.49 and earlier, the OmniRoute POST /api/acp/agents custom ACP agent endpoint accepted attacker-controlled binary and versionCommand v…
CVE-2026-88869Critical· 9.3PoCAVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scripting vulnerability in the AD_Server plugin's log.php endpoint that fails to escape the label parameter before storage
AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scripting vulnerability in the AD_Server plugin's log.php endpoint that fails to escape the label parameter before storage. An unauthenticated at…
CVE-2026-89086Critical· 9.1PoCIn the jose package before 0.11.0 for OCaml, library calls to validate an RSA signature only confirm that PKCS #1 decoding succeeds, and proceed to declare the signature valid without the required steps that involve the public key.
In the jose package before 0.11.0 for OCaml, library calls to validate an RSA signature only confirm that PKCS #1 decoding succeeds, and proceed to declare the signature valid without the required steps that involve the public key.
CVE-2026-88864Critical· 9.1PoCCapgo (capgo.app) fails to restrict direct write access to the public.sso_providers table exposed through Supabase PostgREST
Capgo (capgo.app) fails to restrict direct write access to the public.sso_providers table exposed through Supabase PostgREST. A holder of an ordinary Capgo full API key can insert a row with status='active' and enforce_sso=true, bypassin…
CVE-2026-88044Critical· 9.1PoCrclone is a command-line program to sync files and directories to and from different cloud storage providers
rclone is a command-line program to sync files and directories to and from different cloud storage providers. From 1.70.0 until 1.75.1, the serve/start RC interface accepts per-server proxyOpt.AuthProxy settings, and the FTP and S3 const…
CVE-2026-71640Critical· 9.1PoCAn issue in ZJU-FAST-Lab EGO-Planner-v2 All versions up to commit 5c99a95880401e2599638d567abc0e240396cb42 allows unsafe vehicle motion via improper handling of expired trajectory data in the replanning pipeline
An issue in ZJU-FAST-Lab EGO-Planner-v2 All versions up to commit 5c99a95880401e2599638d567abc0e240396cb42 allows unsafe vehicle motion via improper handling of expired trajectory data in the replanning pipeline
Most-changed records
Existing CVEs whose severity, score, KEV or exploitation status moved.
- CVE-2026-87491Out of bounds write in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML pageseverity, cvss, exploited, exploit_available, kev, zero_day74
- CVE-2026-53758Emlog is an open source website building systemseverity, cvss, exploit_available60
- CVE-2026-52486An issue in OpenDDS 3.33.x allows a local attacker to cause a denial of service via the verify function in the SIgnedDocument moduleseverity, cvss, exploit_available48
- CVE-2026-79570mfish-nocode-pro v1.0.0 was discovered to contain a SQL injection vulnerability in the tableName parameter at /sys/dbConnect/dataseverity, cvss, exploit_available66
- CVE-2026-79574An issue in the gateway server of mpush v0.8.1 allows attackers to execute arbitrary code via sending a crafted broadcast message.severity, cvss, exploit_available66
- CVE-2026-78997UC Browser for Android (package com.UCMobile.intl, version 13.7.8.1314) contains a Universal Cross-Site Scripting vulnerability that allows an attacker to execute arbitrary JavaScript in the context of any originseverity, cvss, exploit_available63
- CVE-2026-79571Incorrect access control in the SellerAuthorizeAspect component of springboot-project v1.0.0 allows unauthenticated attackers to access all seller management interfaces and list all products/orders, put products on/off sale, finish/cance…severity, cvss, exploit_available62
- CVE-2026-79419A reflected cross-site scripting (XSS) vulnerability exists in EMX Tecnologia Gestao X Business Suite 8.4 and earlierseverity, cvss, exploit_available60
Most-affected vendors
By CVEs published in the period.