Daily digest
Sunday 13 September 2026
A quiet day: only 133 new CVEs against a recent average of about 498. Of those, 2 critical and 46 high. 74 arrived with exploitation evidence or public exploit code already attached. jaychouchannel was the most-affected vendor with 5.
New this day, ranked by depth score
The 12 that matter most of the 133 published.
MAL-2026-16143Critical⚠ ExploitedMalicious code in chroma-client (PyPI)
Malicious code in chroma-client (PyPI)
CVE-2026-81648Critical· 10.0PoCThe CryptoPayment Gateway WordPress plugin from 1.2.1 to 1.2.2 does not apply an authorization check on one of its AJAX endpoints, allowing unauthenticated users to invoke administrative operations, including deleting arbitrary files on …
The CryptoPayment Gateway WordPress plugin from 1.2.1 to 1.2.2 does not apply an authorization check on one of its AJAX endpoints, allowing unauthenticated users to invoke administrative operations, including deleting arbitrary files on …
CVE-2026-90777High· 8.8PoCESPnet before 202609 deserializes pretrained model checkpoints using torch.load with weights_only=False, allowing arbitrary code execution from attacker-supplied files
ESPnet before 202609 deserializes pretrained model checkpoints using torch.load with weights_only=False, allowing arbitrary code execution from attacker-supplied files. Attackers can craft malicious checkpoint files that execute code dur…
CVE-2026-90493High· 8.8PoCA vulnerability was detected in Tonec Internet Download Manager up to 6.42 Build 63 on Windows
A vulnerability was detected in Tonec Internet Download Manager up to 6.42 Build 63 on Windows. The impacted element is an unknown function of the file idmwfp.sys of the component Kernel Driver. The manipulation results in improper acces…
CVE-2026-90510High· 8.3PoCA security vulnerability has been detected in dromara orion-visor up to 2.5.7
A security vulnerability has been detected in dromara orion-visor up to 2.5.7. This affects the function HostKeyServiceImpl.encryptKey of the file orion-visor-modules/orion-visor-module-asset/orion-visor-module-asset-service/src/main/jav…
CVE-2026-90562High· 8.1PoCLangBot before 4.10.11 generates password recovery keys with only 24 bits of entropy and applies no rate limiting to the unauthenticated reset-password endpoint
LangBot before 4.10.11 generates password recovery keys with only 24 bits of entropy and applies no rate limiting to the unauthenticated reset-password endpoint. Remote attackers knowing the administrator email can exhaust the keyspace t…
CVE-2026-37008High· 8.1PoCCrewAI before fb2323b offers a Python blocklist approach that operates at the wrong level of abstraction, a different vulnerability than CVE-2026-2275
CrewAI before fb2323b offers a Python blocklist approach that operates at the wrong level of abstraction, a different vulnerability than CVE-2026-2275. Import-time blocking of module names does not address the availability of Python's co…
CVE-2026-90772High· 7.6PoCAmundsen frontend through 4.3.0 renders table, dashboard, and feature descriptions with dangerouslySetInnerHTML without HTML sanitization in ResourceListItem components
Amundsen frontend through 4.3.0 renders table, dashboard, and feature descriptions with dangerouslySetInnerHTML without HTML sanitization in ResourceListItem components. Attackers can inject malicious markup like img elements with onerro…
CVE-2026-90769High· 7.7PoCOpen Notebook before 1.11.0 fails to validate the URL parameter in POST /api/sources endpoint, allowing authenticated users to perform server-side requests to internal services
Open Notebook before 1.11.0 fails to validate the URL parameter in POST /api/sources endpoint, allowing authenticated users to perform server-side requests to internal services. Attackers can supply arbitrary URLs to read cloud metadata,…
CVE-2026-90776High· 7.5PoCNodemailer versions 9.1.0 through 10.0.4 contain a quadratic time complexity vulnerability in the addressparser component when parsing email addresses with RFC 5322 comments
Nodemailer versions 9.1.0 through 10.0.4 contain a quadratic time complexity vulnerability in the addressparser component when parsing email addresses with RFC 5322 comments. Attackers can craft malicious email headers with comment-separ…
CVE-2026-90774High· 7.5PoCrustypaste before 0.18.1 validates the destination path before applying the optional custom filename HTTP header, allowing attackers to bypass directory-escape checks
rustypaste before 0.18.1 validates the destination path before applying the optional custom filename HTTP header, allowing attackers to bypass directory-escape checks. Attackers can supply path traversal sequences in the filename header …
CVE-2026-90601High· 7.3PoCA vulnerability was found in getzep graphiti up to 0.30.2
A vulnerability was found in getzep graphiti up to 0.30.2. Affected is an unknown function of the file server/graph_service/main.py of the component REST API. The manipulation results in improper authentication. The attack can be launche…
Most-changed records
Existing CVEs whose severity, score, KEV or exploitation status moved.
- CVE-2026-87491Out of bounds write in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML pageseverity, cvss, kev, exploited, exploit_available, zero_day74
- CVE-2026-67277RouterOS accepts a "related" btest connection before the corresponding primary session has completed authenticationcvss, kev, exploited, exploit_available70
- CVE-2026-86060RouterOS contains an argument-handling flaw in the SSH login path involving usernames that begin with a prohibited character, allowing for the trusted RouterOS policy mask to be changed, leading to privilege escalationcvss, kev, exploited, exploit_available79
- CVE-2026-20079A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to bypass authentication and execute script files on an affected device to obtain root access …epss, kev, exploited95
- CVE-2026-53758Emlog is an open source website building systemseverity, cvss, exploit_available60
- CVE-2026-49881In serviceClassExists of InCallController.java, there is a possible arbitrary code execution due to a logic error in the codeseverity, cvss, exploit_available55
- CVE-2026-79570mfish-nocode-pro v1.0.0 was discovered to contain a SQL injection vulnerability in the tableName parameter at /sys/dbConnect/dataseverity, cvss, exploit_available66
- CVE-2026-79574An issue in the gateway server of mpush v0.8.1 allows attackers to execute arbitrary code via sending a crafted broadcast message.severity, cvss, exploit_available66
Most-affected vendors
By CVEs published in the period.