Daily digest
Monday 14 September 2026
A busier-than-usual day with 787 new CVEs (recent average about 496). Of those, 69 critical and 248 high. 156 arrived with exploitation evidence or public exploit code already attached. CISA added one CVE to the Known Exploited Vulnerabilities catalog. apple was the most-affected vendor with 245.
Added to CISA KEV
Confirmed exploitation in the wild — federal remediation deadlines attach to these.
New this day, ranked by depth score
The 12 that matter most of the 787 published.
CVE-2026-76461Critical· 9.8CISA KEV0dayPoCA vulnerability in the email parsing of Cisco AsyncOS Software for Cisco Secure Email Gateway could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on the underlying operating system. This …
A vulnerability in the email parsing of Cisco AsyncOS Software for Cisco Secure Email Gateway could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on the underlying operating system. This …
MAL-2026-16203Critical⚠ ExploitedMalicious code in faiss-cpu-avx512 (PyPI)
Malicious code in faiss-cpu-avx512 (PyPI)
CVE-2026-90699Critical· 9.9PoCA weakness has been identified in D-Link DWR-M920 1.1.7
A weakness has been identified in D-Link DWR-M920 1.1.7. This issue affects the function sub_41E60C of the file /boafrm/formPinManageSetup. This manipulation of the argument newPin causes os command injection. The attack can be initiated…
CVE-2026-90693Critical· 9.9PoCA flaw has been found in D-Link DIR-878 120B05
A flaw has been found in D-Link DIR-878 120B05. This impacts the function SetWan3Settings of the component WAN Settings. This manipulation of the argument Primary/Secondary causes stack-based buffer overflow. Remote exploitation of the a…
CVE-2026-90608Critical· 9.9PoCA flaw has been found in Totolink A3002MU Hh-B20211125.1046
A flaw has been found in Totolink A3002MU Hh-B20211125.1046. The affected element is the function formPortFw of the file /boafrm/formPortFw of the component boa. This manipulation of the argument service_type causes buffer overflow. It i…
CVE-2026-90607Critical· 9.9PoCA vulnerability was detected in Totolink A3002MU Hh-B20211125.1046
A vulnerability was detected in Totolink A3002MU Hh-B20211125.1046. Impacted is the function formNewSchedule of the file /boafrm/formNewSchedule of the component boa. The manipulation of the argument submit-url results in buffer overflow…
CVE-2026-90606Critical· 9.9PoCA security vulnerability has been detected in Totolink A3002MU Hh-B20211125.1046
A security vulnerability has been detected in Totolink A3002MU Hh-B20211125.1046. This issue affects the function formIpv6Setup of the file /boafrm/formIpv6Setup of the component boa. The manipulation of the argument static_ipv6 leads to…
CVE-2026-90605Critical· 9.9PoCA weakness has been identified in Totolink A3002MU Hh-B20211125.1046
A weakness has been identified in Totolink A3002MU Hh-B20211125.1046. This vulnerability affects the function formFilter of the file /boafrm/formFilter of the component boa. Executing a manipulation of the argument ip6addr can lead to bu…
CVE-2026-90945Critical· 9.8PoCCrawlab through 0.6.3 uses a hard-coded HMAC-SHA256 secret for JWT token signing that cannot be overridden via configuration or environment variables
Crawlab through 0.6.3 uses a hard-coded HMAC-SHA256 secret for JWT token signing that cannot be overridden via configuration or environment variables. Unauthenticated attackers can forge valid administrator tokens to access administrativ…
CVE-2026-90919Critical· 9.8PoCLightLLM through 1.2.0 contains a remote code execution vulnerability in the Config Server's unauthenticated /visual_register WebSocket endpoint that passes the first client frame directly to pickle.loads()
LightLLM through 1.2.0 contains a remote code execution vulnerability in the Config Server's unauthenticated /visual_register WebSocket endpoint that passes the first client frame directly to pickle.loads(). Attackers can reach the Confi…
CVE-2026-57131Critical· 9.8PoCPraisonAI is a multi-agent teams system
PraisonAI is a multi-agent teams system. Prior to 4.6.58, praisonai.jobs.server.create_app mounts praisonai.jobs.router.create_router under /api/v1/runs without authentication or per-job authorization. Network clients can submit attacker…
CVE-2026-57127Critical· 9.8PoCPraisonAI is a multi-agent teams system
PraisonAI is a multi-agent teams system. Prior to 4.6.58, recipe serve installs APIKeyAuthMiddleware or JWTAuthMiddleware when an operator selects api-key or JWT authentication, but each middleware forwards requests when PRAISONAI_API_KE…
Most-changed records
Existing CVEs whose severity, score, KEV or exploitation status moved.
- CVE-2026-87491Out of bounds write in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML pageseverity, cvss, kev, exploited, exploit_available, zero_day74
- CVE-2026-86060RouterOS contains an argument-handling flaw in the SSH login path involving usernames that begin with a prohibited character, allowing for the trusted RouterOS policy mask to be changed, leading to privilege escalationcvss, kev, exploited, exploit_available79
- CVE-2026-67277RouterOS accepts a "related" btest connection before the corresponding primary session has completed authenticationcvss, kev, exploited, exploit_available70
- CVE-2019-9901EnvoyProxy Envoy Missing HTTP URL path normalizationseverity, cvss56
- CVE-2026-84869A condition in the ScreenConnect client may allow files to be transferred and executed through an active remote session without authorization or Host confirmation in certain circumstanceskev, exploited, exploit_available80
- CVE-2026-86840The `vtoken-minting` and `slpx` pallets in Bifrost contain an improper authorization vulnerability in channel commission attributionseverity, cvss, exploit_available62
- CVE-2026-87575Incorrect authorization in Loader in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML pageseverity, cvss, exploit_available42
- CVE-2026-87492Incorrect authorization in DevTools in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML pageseverity, cvss, exploit_available65
Most-affected vendors
By CVEs published in the period.