VulnSea

Daily digest

Friday 11 September 2026

A busier-than-usual day with 725 new CVEs (recent average about 479). Of those, 56 critical and 273 high. 58 arrived with exploitation evidence or public exploit code already attached. CISA added 4 CVEs to the Known Exploited Vulnerabilities catalog. Red Hat was the most-affected vendor with 374.

725
New CVEs
56
Critical
4
KEV additions
690
Records changed

Added to CISA KEV

Confirmed exploitation in the wild — federal remediation deadlines attach to these.

CVE-2026-85706Critical· 10.0CISA KEV0dayPoC
1w ago

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.7 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that, under certain conditions, an unauthenticated user could have read arbitrary files from the Gi…

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.7 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that, under certain conditions, an unauthenticated user could have read arbitrary files from the Gi…

Hadalgitlab · gitlabEPSS 15%via NVD
CVE-2026-84869Critical· 9.9CISA KEVPoC
1w ago

A condition in the ScreenConnect client may allow files to be transferred and executed through an active remote session without authorization or Host confirmation in certain circumstances

A condition in the ScreenConnect client may allow files to be transferred and executed through an active remote session without authorization or Host confirmation in certain circumstances. ScreenConnect servers are not impacted.

Hadalconnectwise · screenconnectEPSS 0.69%via NVD
CVE-2026-42016High· 8.1CISA KEVPoC
1mo ago

Incorrect authorization validation of user token in JFrog Artifactory allows Privilege Escalation

JFrog Artifactory (Self Hosted) versions before 7.133.11 are vulnerable to a privilege escalation attack due to a validation check of the token signature/issuer and not the token’s scope.

Abyssaljfrog · artifactoryEPSS 9.1%via CVEORG
CVE-2026-42018High· 7.5CISA KEVPoC
1mo ago

Anonymous user token generation exposure in JFrog Artifactory

JFrog Artifactory could return an internal anonymous-user token to an unauthenticated caller when anonymous access is disabled, potentially exposing sensitive resources.

Abyssaljfrog · artifactoryEPSS 11%via CVEORG

New this day, ranked by depth score

The 12 that matter most of the 725 published.

MAL-2026-16164Critical⚠ Exploited
1w ago

Malicious code in logs_update (crates.io)

Malicious code in logs_update (crates.io)

Abyssallogs-update · logs-updatevia OSV
MAL-2026-16141Critical⚠ Exploited
1w ago

Malicious code in platform-telemetry-client (PyPI)

Malicious code in platform-telemetry-client (PyPI)

Abyssalplatform-telemetry-client · platform-telemetry-clientvia OSV
MAL-2026-16136Critical⚠ Exploited
1w ago

Malicious code in transfomers (PyPI)

Malicious code in transfomers (PyPI)

Abyssaltransfomers · transfomersvia OSV
MAL-2026-16135Critical⚠ Exploited
1w ago

Malicious code in openaii (PyPI)

Malicious code in openaii (PyPI)

Abyssalopenaii · openaiivia OSV
MAL-2026-16134Critical⚠ Exploited
1w ago

Malicious code in ollamaa (PyPI)

Malicious code in ollamaa (PyPI)

Abyssalollamaa · ollamaavia OSV
MAL-2026-16133Critical⚠ Exploited
1w ago

Malicious code in langgrap (PyPI)

Malicious code in langgrap (PyPI)

Abyssallanggrap · langgrapvia OSV
MAL-2026-16131Critical⚠ Exploited
1w ago

Malicious code in aitextutils-py (PyPI)

Malicious code in aitextutils-py (PyPI)

Abyssalaitextutils-py · aitextutils-pyvia OSV
MAL-2026-16130Critical⚠ Exploited
1w ago

Malicious code in aitextkit-py (PyPI)

Malicious code in aitextkit-py (PyPI)

Abyssalaitextkit-py · aitextkit-pyvia OSV
MAL-2026-16129Critical⚠ Exploited
1w ago

Malicious code in web3-eth-account (PyPI)

Malicious code in web3-eth-account (PyPI)

Abyssalweb3-eth-account · web3-eth-accountvia OSV
MAL-2026-16128Critical⚠ Exploited
1w ago

Malicious code in pymem-win (PyPI)

Malicious code in pymem-win (PyPI)

Abyssalpymem-win · pymem-winvia OSV
MAL-2026-16127Critical⚠ Exploited
1w ago

Malicious code in eth-account-web3 (PyPI)

Malicious code in eth-account-web3 (PyPI)

Abyssaleth-account-web3 · eth-account-web3via OSV
CVE-2026-89010Critical· 9.8PoC
1w ago

WAVLINK WN535M1 and WN535M3 routers running firmware prior to M35M1_V250922 contain an unauthenticated OS command injection vulnerability that allows remote attackers to execute arbitrary commands as root by sending crafted filenames to …

WAVLINK WN535M1 and WN535M3 routers running firmware prior to M35M1_V250922 contain an unauthenticated OS command injection vulnerability that allows remote attackers to execute arbitrary commands as root by sending crafted filenames to …

AbyssalWAVLINK Technology · WN535M1EPSS 2.9%via NVD

Most-changed records

Existing CVEs whose severity, score, KEV or exploitation status moved.

  • CVE-2026-87491Out of bounds write in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page74
  • CVE-2026-86060RouterOS contains an argument-handling flaw in the SSH login path involving usernames that begin with a prohibited character, allowing for the trusted RouterOS policy mask to be changed, leading to privilege escalation79
  • CVE-2026-67277RouterOS accepts a "related" btest connection before the corresponding primary session has completed authentication70
  • CVE-2026-79570mfish-nocode-pro v1.0.0 was discovered to contain a SQL injection vulnerability in the tableName parameter at /sys/dbConnect/data66
  • CVE-2026-79574An issue in the gateway server of mpush v0.8.1 allows attackers to execute arbitrary code via sending a crafted broadcast message.66
  • CVE-2026-78997UC Browser for Android (package com.UCMobile.intl, version 13.7.8.1314) contains a Universal Cross-Site Scripting vulnerability that allows an attacker to execute arbitrary JavaScript in the context of any origin63
  • CVE-2026-79571Incorrect access control in the SellerAuthorizeAspect component of springboot-project v1.0.0 allows unauthenticated attackers to access all seller management interfaces and list all products/orders, put products on/off sale, finish/cance…62
  • CVE-2026-86840The `vtoken-minting` and `slpx` pallets in Bifrost contain an improper authorization vulnerability in channel commission attribution62

Most-affected vendors

By CVEs published in the period.