Daily digest
Wednesday 16 September 2026
A busier-than-usual day with 890 new CVEs (recent average about 730). Severity skewed high: 109 critical and 375 high, 54% of the total. 129 arrived with exploitation evidence or public exploit code already attached. CISA added 3 CVEs to the Known Exploited Vulnerabilities catalog. Linux was the most-affected vendor with 276.
Added to CISA KEV
Confirmed exploitation in the wild — federal remediation deadlines attach to these.
CVE-2026-76460Critical· 10.0CISA KEV0dayPoCA vulnerability in an API of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to bypass authentication. This vulnerability is due to insufficient authentication control on an API endpoint
A vulnerability in an API of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to bypass authentication. This vulnerability is due to insufficient authentication control on an API endpoint. An attack…
CVE-2026-58704High· 8.8CISA KEV0dayPoCIn Cellular Modem, there is a possible permission bypass due to a logic error in the code
In Cellular Modem, there is a possible permission bypass due to a logic error in the code. This could lead to remote (proximal/adjacent) escalation of privilege with no additional execution privileges needed. User interaction is not need…
CVE-2026-87886High· 7.8CISA KEV0dayPoCLocal privilege escalation due to insecure file permissions
Local privilege escalation due to insecure file permissions. The following products are affected: Acronis Backup plugin for cPanel & WHM (Linux) before build 1.9.3.1021, Acronis Backup extension for Plesk (Linux) before build 1.8.11.638,…
New this day, ranked by depth score
The 12 that matter most of the 890 published.
CVE-2026-76460Critical· 10.0CISA KEV0dayPoCA vulnerability in an API of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to bypass authentication. This vulnerability is due to insufficient authentication control on an API endpoint
A vulnerability in an API of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to bypass authentication. This vulnerability is due to insufficient authentication control on an API endpoint. An attack…
MAL-2026-16242Critical⚠ ExploitedMalicious code in trongappy (PyPI)
Malicious code in trongappy (PyPI)
MAL-2026-16241Critical⚠ ExploitedMalicious code in rak-lab-yoav-orca-zrktd2cp5hjmo4x7 (PyPI)
Malicious code in rak-lab-yoav-orca-zrktd2cp5hjmo4x7 (PyPI)
MAL-2026-16240Critical⚠ ExploitedMalicious code in praetorian-mind-rce-test-2026 (PyPI)
Malicious code in praetorian-mind-rce-test-2026 (PyPI)
MAL-2026-16219Critical⚠ ExploitedMalicious code in licloud (PyPI)
Malicious code in licloud (PyPI)
MAL-2026-16212Critical⚠ ExploitedMalicious code in cli-anything-ai-market (PyPI)
Malicious code in cli-anything-ai-market (PyPI)
CVE-2026-20284Critical· 9.1⚠ ExploitedPoCA vulnerability in the SXP REST API of Cisco ISE could allow an authenticated, remote attacker to conduct SQL injection attacks. This vulnerability is due to insufficient validation of user-supplied input in REST API calls
A vulnerability in the SXP REST API of Cisco ISE could allow an authenticated, remote attacker to conduct SQL injection attacks. This vulnerability is due to insufficient validation of user-supplied input in REST API calls. An attacke…
CVE-2026-92805Critical· 9.8PoCUVdesk Community Skeleton through 1.1.8 fails to authenticate or validate installation state on wizard endpoints in ConfigureHelpdesk controller actions
UVdesk Community Skeleton through 1.1.8 fails to authenticate or validate installation state on wizard endpoints in ConfigureHelpdesk controller actions. Unauthenticated attackers can repoint the database and create super administrator a…
CVE-2026-92787Critical· 9.8PoCFeast through 0.66.0 fails to verify JWT token signatures before establishing user identity, allowing attackers to bypass all role-based access control by presenting an unverified token with a hardcoded claim value
Feast through 0.66.0 fails to verify JWT token signatures before establishing user identity, allowing attackers to bypass all role-based access control by presenting an unverified token with a hardcoded claim value. Attackers can obtain …
CVE-2026-91843Critical· 9.8PoCA stack overflow during the unauthenticated login process may allow an attacker to run arbitrary code remotely with root privileges.
A stack overflow during the unauthenticated login process may allow an attacker to run arbitrary code remotely with root privileges.
CVE-2026-51990Critical· 9.8PoCAn issue in Sogou Sogou Input Method < 16.3.0.3498 (fixed in 16.3.0.3498) allows a remote attacker to execute arbitrary code via the biz_helper.exe component
An issue in Sogou Sogou Input Method < 16.3.0.3498 (fixed in 16.3.0.3498) allows a remote attacker to execute arbitrary code via the biz_helper.exe component
CVE-2026-12793Critical· 9.8PoCThe JetFormBuilder — Dynamic Blocks Form Builder plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.6.2
The JetFormBuilder — Dynamic Blocks Form Builder plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.6.2. This is due to the plugin not validating that a submitted form ID belongs to a JetFo…
Most-changed records
Existing CVEs whose severity, score, KEV or exploitation status moved.
- CVE-2019-9901EnvoyProxy Envoy Missing HTTP URL path normalizationseverity, cvss56
- CVE-2025-71348picklescan before 0.0.28 fails to detect malicious pickle files that invoke torch.utils._config_module.load_config function within reduce methodsexploit_available57
- CVE-2014-6407Arbitrary Code Execution in Dockercvss41
- CVE-2026-58704In Cellular Modem, there is a possible permission bypass due to a logic error in the codeexploited, exploit_available, kev, zero_day, cvss73
- CVE-2026-56960In multiple locations, there is a possible use-after-free due to a logic error in the codeseverity, cvss54
- CVE-2026-57042In multiple functions of DreamPickerReceiver.kt, there is a possible permission bypass due to a confused deputyseverity, cvss37
- CVE-2026-37152TOTOLINK X5000R V9.1.0cu.2415_B20250515 was discovered to contain a hardcoded password for root access.severity, cvss, exploit_available66
- CVE-2026-79411Incorrect privilege assignment in the admin user-management component of Webkul Bagisto 2.4.9 allows an authenticated backend user holding only the settings.users.edit permission to escalate to full administratorseverity, cvss, exploit_available60
Most-affected vendors
By CVEs published in the period.