VulnSea

Daily digest

Wednesday 16 September 2026

A busier-than-usual day with 890 new CVEs (recent average about 730). Severity skewed high: 109 critical and 375 high, 54% of the total. 129 arrived with exploitation evidence or public exploit code already attached. CISA added 3 CVEs to the Known Exploited Vulnerabilities catalog. Linux was the most-affected vendor with 276.

890
New CVEs
109
Critical
3
KEV additions
537
Records changed

Added to CISA KEV

Confirmed exploitation in the wild — federal remediation deadlines attach to these.

New this day, ranked by depth score

The 12 that matter most of the 890 published.

CVE-2026-76460Critical· 10.0CISA KEV0dayPoC
5d ago

A vulnerability in an API of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to bypass authentication. This vulnerability is due to insufficient authentication control on an API endpoint

A vulnerability in an API of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to bypass authentication. This vulnerability is due to insufficient authentication control on an API endpoint. An attack…

Hadalcisco · identity_services_engineEPSS 0.78%via NVD
MAL-2026-16242Critical⚠ Exploited
5d ago

Malicious code in trongappy (PyPI)

Malicious code in trongappy (PyPI)

Abyssaltrongappy · trongappyvia OSV
MAL-2026-16241Critical⚠ Exploited
5d ago

Malicious code in rak-lab-yoav-orca-zrktd2cp5hjmo4x7 (PyPI)

Malicious code in rak-lab-yoav-orca-zrktd2cp5hjmo4x7 (PyPI)

Abyssalrak-lab-yoav-orca-zrktd2cp5hjmo4x7 · rak-lab-yoav-orca-zrktd2cp5hjmo4x7via OSV
MAL-2026-16240Critical⚠ Exploited
5d ago

Malicious code in praetorian-mind-rce-test-2026 (PyPI)

Malicious code in praetorian-mind-rce-test-2026 (PyPI)

Abyssalpraetorian-mind-rce-test-2026 · praetorian-mind-rce-test-2026via OSV
MAL-2026-16219Critical⚠ Exploited
5d ago

Malicious code in licloud (PyPI)

Malicious code in licloud (PyPI)

Abyssallicloud · licloudvia OSV
MAL-2026-16212Critical⚠ Exploited
5d ago

Malicious code in cli-anything-ai-market (PyPI)

Malicious code in cli-anything-ai-market (PyPI)

Abyssalcli-anything-ai-market · cli-anything-ai-marketvia OSV
CVE-2026-20284Critical· 9.1⚠ ExploitedPoC
5d ago

A vulnerability in the SXP REST API of Cisco ISE could allow an authenticated, remote attacker to conduct SQL injection attacks. This vulnerability is due to insufficient validation of user-supplied input in REST API calls

A vulnerability in the SXP REST API of Cisco ISE could allow an authenticated, remote attacker to conduct SQL injection attacks. This vulnerability is due to insufficient validation of user-supplied input in REST API calls. An attacke…

AbyssalCisco · Cisco Identity Services Engine SoftwareEPSS 0.39%via NVD
CVE-2026-92805Critical· 9.8PoC
5d ago

UVdesk Community Skeleton through 1.1.8 fails to authenticate or validate installation state on wizard endpoints in ConfigureHelpdesk controller actions

UVdesk Community Skeleton through 1.1.8 fails to authenticate or validate installation state on wizard endpoints in ConfigureHelpdesk controller actions. Unauthenticated attackers can repoint the database and create super administrator a…

Abyssaluvdesk · community-skeletonEPSS 0.35%via NVD
CVE-2026-92787Critical· 9.8PoC
5d ago

Feast through 0.66.0 fails to verify JWT token signatures before establishing user identity, allowing attackers to bypass all role-based access control by presenting an unverified token with a hardcoded claim value

Feast through 0.66.0 fails to verify JWT token signatures before establishing user identity, allowing attackers to bypass all role-based access control by presenting an unverified token with a hardcoded claim value. Attackers can obtain …

Abyssalfeast-dev · feastEPSS 0.38%via NVD
CVE-2026-91843Critical· 9.8PoC
5d ago

A stack overflow during the unauthenticated login process may allow an attacker to run arbitrary code remotely with root privileges.

A stack overflow during the unauthenticated login process may allow an attacker to run arbitrary code remotely with root privileges.

Abyssalcheckpoint · Quantum Security ManagementEPSS 0.50%via NVD
CVE-2026-51990Critical· 9.8PoC
5d ago

An issue in Sogou Sogou Input Method < 16.3.0.3498 (fixed in 16.3.0.3498) allows a remote attacker to execute arbitrary code via the biz_helper.exe component

An issue in Sogou Sogou Input Method < 16.3.0.3498 (fixed in 16.3.0.3498) allows a remote attacker to execute arbitrary code via the biz_helper.exe component

AbyssalEPSS 1.00%via NVD
CVE-2026-12793Critical· 9.8PoC
5d ago

The JetFormBuilder — Dynamic Blocks Form Builder plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.6.2

The JetFormBuilder — Dynamic Blocks Form Builder plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.6.2. This is due to the plugin not validating that a submitted form ID belongs to a JetFo…

Abyssaljetmonsters · JetFormBuilder — Dynamic Blocks Form BuilderEPSS 0.39%via NVD

Most-changed records

Existing CVEs whose severity, score, KEV or exploitation status moved.

  • CVE-2019-9901EnvoyProxy Envoy Missing HTTP URL path normalization56
  • CVE-2025-71348picklescan before 0.0.28 fails to detect malicious pickle files that invoke torch.utils._config_module.load_config function within reduce methods57
  • CVE-2014-6407Arbitrary Code Execution in Docker41
  • CVE-2026-58704In Cellular Modem, there is a possible permission bypass due to a logic error in the code73
  • CVE-2026-56960In multiple locations, there is a possible use-after-free due to a logic error in the code54
  • CVE-2026-57042In multiple functions of DreamPickerReceiver.kt, there is a possible permission bypass due to a confused deputy37
  • CVE-2026-37152TOTOLINK X5000R V9.1.0cu.2415_B20250515 was discovered to contain a hardcoded password for root access.66
  • CVE-2026-79411Incorrect privilege assignment in the admin user-management component of Webkul Bagisto 2.4.9 allows an authenticated backend user holding only the settings.users.edit permission to escalate to full administrator60

Most-affected vendors

By CVEs published in the period.