Daily digest
Thursday 17 September 2026
A heavy day: 1,056 new CVEs, well above the recent average of about 641. Of those, 82 critical and 350 high. 88 arrived with exploitation evidence or public exploit code already attached. Linux was the most-affected vendor with 602.
New this day, ranked by depth score
The 12 that matter most of the 1056 published.
MAL-2026-16275Critical⚠ ExploitedMalicious code in requests-triwes (PyPI)
Malicious code in requests-triwes (PyPI)
MAL-2026-16274Critical⚠ ExploitedMalicious code in requests-auroras (PyPI)
Malicious code in requests-auroras (PyPI)
MAL-2026-16269Critical⚠ ExploitedMalicious code in requests-asetwe (PyPI)
Malicious code in requests-asetwe (PyPI)
MAL-2026-16268Critical⚠ ExploitedMalicious code in index-forum (PyPI)
Malicious code in index-forum (PyPI)
MAL-2026-16267Critical⚠ ExploitedMalicious code in pyjstat-smooth (PyPI)
Malicious code in pyjstat-smooth (PyPI)
MAL-2026-16264Critical⚠ ExploitedMalicious code in aiosendletter (PyPI)
Malicious code in aiosendletter (PyPI)
MAL-2026-16250Critical⚠ ExploitedMalicious code in marketing-mcp (PyPI)
Malicious code in marketing-mcp (PyPI)
CVE-2026-87886High· 7.8CISA KEV0dayPoCLocal privilege escalation due to insecure file permissions
Local privilege escalation due to insecure file permissions. The following products are affected: Acronis Backup plugin for cPanel & WHM (Linux) before build 1.9.3.1021, Acronis Backup extension for Plesk (Linux) before build 1.8.11.638,…
CVE-2026-92960Critical· 10.0PoCvm2 before 3.11.6 fails to restrict access to os and dns builtins under the builtin: ['*'] configuration, allowing sandbox code to read host process identity and network topology
vm2 before 3.11.6 fails to restrict access to os and dns builtins under the builtin: ['*'] configuration, allowing sandbox code to read host process identity and network topology. Attackers can invoke dns.setServers() to hijack the host …
CVE-2026-92957Critical· 9.9PoCvm2 through 3.11.6 does not normalize `node:`-prefixed builtin specifiers when evaluating user-supplied negative (deny) entries in a NodeVM wildcard require policy
vm2 through 3.11.6 does not normalize `node:`-prefixed builtin specifiers when evaluating user-supplied negative (deny) entries in a NodeVM wildcard require policy. Although NodeVM strips the `node:` prefix during require() resolution, n…
CVE-2026-92955Critical· 10.0PoCvm2 before 3.11.8 contains a sandbox escape vulnerability in NodeVM that allows attackers to access the host __proto__ getter/setter through console._stdout and console._stderr
vm2 before 3.11.8 contains a sandbox escape vulnerability in NodeVM that allows attackers to access the host __proto__ getter/setter through console._stdout and console._stderr. Attackers can overwrite EventEmitter.prototype.emit and tri…
CVE-2026-92953Critical· 10.0PoCvm2 versions from 3.11.0 before 3.11.8 fail to protect host TypedArray and ArrayBuffer prototypes from sandbox mutation
vm2 versions from 3.11.0 before 3.11.8 fail to protect host TypedArray and ArrayBuffer prototypes from sandbox mutation. Attackers can use prototype-walking primitives to reach and modify host Uint8Array.prototype, %TypedArray%.prototype…
Most-changed records
Existing CVEs whose severity, score, KEV or exploitation status moved.
- CVE-2019-9901EnvoyProxy Envoy Missing HTTP URL path normalizationseverity, cvss56
- CVE-2025-71348picklescan before 0.0.28 fails to detect malicious pickle files that invoke torch.utils._config_module.load_config function within reduce methodsexploit_available57
- CVE-2014-6407Arbitrary Code Execution in Dockercvss41
- CVE-2026-92005Use-after-free in the Audio/Video: Web Codecs componentseverity, cvss29
- CVE-2025-56563A Server-Side Request Forgery vulnerability exists in sat_proxy.php in Zenith Satellite Tracker 1.0severity, cvss, exploit_available66
- CVE-2026-88592kkFileView >= 4.2.0 is vulnerable to Server-Side Request Forgery (SSRF)severity, cvss, exploit_available62
- CVE-2026-79419A reflected cross-site scripting (XSS) vulnerability exists in EMX Tecnologia Gestao X Business Suite 8.4 and earliercvss, severity60
- CVE-2026-88743Bacularis 4.7.0 - 6.5.0 is vulnerable to Stored cross-site scripting (XSS) in director tags.severity, cvss, exploit_available46
Most-affected vendors
By CVEs published in the period.