Daily digest
Friday 11 September 2026
A busier-than-usual day with 725 new CVEs (recent average about 479). Of those, 56 critical and 273 high. 58 arrived with exploitation evidence or public exploit code already attached. CISA added 4 CVEs to the Known Exploited Vulnerabilities catalog. Red Hat was the most-affected vendor with 374.
Added to CISA KEV
Confirmed exploitation in the wild — federal remediation deadlines attach to these.
CVE-2026-85706Critical· 10.0CISA KEV0dayPoCGitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.7 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that, under certain conditions, an unauthenticated user could have read arbitrary files from the Gi…
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.7 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that, under certain conditions, an unauthenticated user could have read arbitrary files from the Gi…
CVE-2026-84869Critical· 9.9CISA KEVPoCA condition in the ScreenConnect client may allow files to be transferred and executed through an active remote session without authorization or Host confirmation in certain circumstances
A condition in the ScreenConnect client may allow files to be transferred and executed through an active remote session without authorization or Host confirmation in certain circumstances. ScreenConnect servers are not impacted.
CVE-2026-42016High· 8.1CISA KEVPoCIncorrect authorization validation of user token in JFrog Artifactory allows Privilege Escalation
JFrog Artifactory (Self Hosted) versions before 7.133.11 are vulnerable to a privilege escalation attack due to a validation check of the token signature/issuer and not the token’s scope.
CVE-2026-42018High· 7.5CISA KEVPoCAnonymous user token generation exposure in JFrog Artifactory
JFrog Artifactory could return an internal anonymous-user token to an unauthenticated caller when anonymous access is disabled, potentially exposing sensitive resources.
New this day, ranked by depth score
The 12 that matter most of the 725 published.
MAL-2026-16164Critical⚠ ExploitedMalicious code in logs_update (crates.io)
Malicious code in logs_update (crates.io)
MAL-2026-16141Critical⚠ ExploitedMalicious code in platform-telemetry-client (PyPI)
Malicious code in platform-telemetry-client (PyPI)
MAL-2026-16136Critical⚠ ExploitedMalicious code in transfomers (PyPI)
Malicious code in transfomers (PyPI)
MAL-2026-16135Critical⚠ ExploitedMalicious code in openaii (PyPI)
Malicious code in openaii (PyPI)
MAL-2026-16134Critical⚠ ExploitedMalicious code in ollamaa (PyPI)
Malicious code in ollamaa (PyPI)
MAL-2026-16133Critical⚠ ExploitedMalicious code in langgrap (PyPI)
Malicious code in langgrap (PyPI)
MAL-2026-16131Critical⚠ ExploitedMalicious code in aitextutils-py (PyPI)
Malicious code in aitextutils-py (PyPI)
MAL-2026-16130Critical⚠ ExploitedMalicious code in aitextkit-py (PyPI)
Malicious code in aitextkit-py (PyPI)
MAL-2026-16129Critical⚠ ExploitedMalicious code in web3-eth-account (PyPI)
Malicious code in web3-eth-account (PyPI)
MAL-2026-16128Critical⚠ ExploitedMalicious code in pymem-win (PyPI)
Malicious code in pymem-win (PyPI)
MAL-2026-16127Critical⚠ ExploitedMalicious code in eth-account-web3 (PyPI)
Malicious code in eth-account-web3 (PyPI)
CVE-2026-89010Critical· 9.8PoCWAVLINK WN535M1 and WN535M3 routers running firmware prior to M35M1_V250922 contain an unauthenticated OS command injection vulnerability that allows remote attackers to execute arbitrary commands as root by sending crafted filenames to …
WAVLINK WN535M1 and WN535M3 routers running firmware prior to M35M1_V250922 contain an unauthenticated OS command injection vulnerability that allows remote attackers to execute arbitrary commands as root by sending crafted filenames to …
Most-changed records
Existing CVEs whose severity, score, KEV or exploitation status moved.
- CVE-2026-87491Out of bounds write in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML pageseverity, cvss, kev, exploited, exploit_available, zero_day74
- CVE-2026-86060RouterOS contains an argument-handling flaw in the SSH login path involving usernames that begin with a prohibited character, allowing for the trusted RouterOS policy mask to be changed, leading to privilege escalationexploited, exploit_available, kev, cvss79
- CVE-2026-67277RouterOS accepts a "related" btest connection before the corresponding primary session has completed authenticationexploited, exploit_available, kev, cvss70
- CVE-2026-79570mfish-nocode-pro v1.0.0 was discovered to contain a SQL injection vulnerability in the tableName parameter at /sys/dbConnect/dataseverity, cvss, exploit_available66
- CVE-2026-79574An issue in the gateway server of mpush v0.8.1 allows attackers to execute arbitrary code via sending a crafted broadcast message.severity, cvss, exploit_available66
- CVE-2026-78997UC Browser for Android (package com.UCMobile.intl, version 13.7.8.1314) contains a Universal Cross-Site Scripting vulnerability that allows an attacker to execute arbitrary JavaScript in the context of any originseverity, cvss, exploit_available63
- CVE-2026-79571Incorrect access control in the SellerAuthorizeAspect component of springboot-project v1.0.0 allows unauthenticated attackers to access all seller management interfaces and list all products/orders, put products on/off sale, finish/cance…severity, cvss, exploit_available62
- CVE-2026-86840The `vtoken-minting` and `slpx` pallets in Bifrost contain an improper authorization vulnerability in channel commission attributionseverity, cvss, exploit_available62
Most-affected vendors
By CVEs published in the period.