VulnSea

Daily digest

Thursday 17 September 2026

A heavy day: 1,056 new CVEs, well above the recent average of about 641. Of those, 82 critical and 350 high. 88 arrived with exploitation evidence or public exploit code already attached. Linux was the most-affected vendor with 602.

1056
New CVEs
82
Critical
0
KEV additions
353
Records changed

New this day, ranked by depth score

The 12 that matter most of the 1056 published.

MAL-2026-16275Critical⚠ Exploited
4d ago

Malicious code in requests-triwes (PyPI)

Malicious code in requests-triwes (PyPI)

Abyssalrequests-triwes · requests-triwesvia OSV
MAL-2026-16274Critical⚠ Exploited
4d ago

Malicious code in requests-auroras (PyPI)

Malicious code in requests-auroras (PyPI)

Abyssalrequests-auroras · requests-aurorasvia OSV
MAL-2026-16269Critical⚠ Exploited
4d ago

Malicious code in requests-asetwe (PyPI)

Malicious code in requests-asetwe (PyPI)

Abyssalrequests-asetwe · requests-asetwevia OSV
MAL-2026-16268Critical⚠ Exploited
4d ago

Malicious code in index-forum (PyPI)

Malicious code in index-forum (PyPI)

Abyssalindex-forum · index-forumvia OSV
MAL-2026-16267Critical⚠ Exploited
4d ago

Malicious code in pyjstat-smooth (PyPI)

Malicious code in pyjstat-smooth (PyPI)

Abyssalpyjstat-smooth · pyjstat-smoothvia OSV
MAL-2026-16264Critical⚠ Exploited
4d ago

Malicious code in aiosendletter (PyPI)

Malicious code in aiosendletter (PyPI)

Abyssalaiosendletter · aiosendlettervia OSV
MAL-2026-16250Critical⚠ Exploited
4d ago

Malicious code in marketing-mcp (PyPI)

Malicious code in marketing-mcp (PyPI)

Abyssalmarketing-mcp · marketing-mcpvia OSV
CVE-2026-87886High· 7.8CISA KEV0dayPoC
4d ago

Local privilege escalation due to insecure file permissions

Local privilege escalation due to insecure file permissions. The following products are affected: Acronis Backup plugin for cPanel & WHM (Linux) before build 1.9.3.1021, Acronis Backup extension for Plesk (Linux) before build 1.8.11.638,…

Abyssalacronis · acronis_backupEPSS 0.25%via NVD
CVE-2026-92960Critical· 10.0PoC
4d ago

vm2 before 3.11.6 fails to restrict access to os and dns builtins under the builtin: ['*'] configuration, allowing sandbox code to read host process identity and network topology

vm2 before 3.11.6 fails to restrict access to os and dns builtins under the builtin: ['*'] configuration, allowing sandbox code to read host process identity and network topology. Attackers can invoke dns.setServers() to hijack the host …

Abyssalpatriksimek · vm2EPSS 0.43%via NVD
CVE-2026-92957Critical· 9.9PoC
4d ago

vm2 through 3.11.6 does not normalize `node:`-prefixed builtin specifiers when evaluating user-supplied negative (deny) entries in a NodeVM wildcard require policy

vm2 through 3.11.6 does not normalize `node:`-prefixed builtin specifiers when evaluating user-supplied negative (deny) entries in a NodeVM wildcard require policy. Although NodeVM strips the `node:` prefix during require() resolution, n…

Abyssalpatriksimek · vm2EPSS 0.49%via NVD
CVE-2026-92955Critical· 10.0PoC
4d ago

vm2 before 3.11.8 contains a sandbox escape vulnerability in NodeVM that allows attackers to access the host __proto__ getter/setter through console._stdout and console._stderr

vm2 before 3.11.8 contains a sandbox escape vulnerability in NodeVM that allows attackers to access the host __proto__ getter/setter through console._stdout and console._stderr. Attackers can overwrite EventEmitter.prototype.emit and tri…

Abyssalpatriksimek · vm2EPSS 0.62%via NVD
CVE-2026-92953Critical· 10.0PoC
4d ago

vm2 versions from 3.11.0 before 3.11.8 fail to protect host TypedArray and ArrayBuffer prototypes from sandbox mutation

vm2 versions from 3.11.0 before 3.11.8 fail to protect host TypedArray and ArrayBuffer prototypes from sandbox mutation. Attackers can use prototype-walking primitives to reach and modify host Uint8Array.prototype, %TypedArray%.prototype…

Abyssalpatriksimek · vm2EPSS 0.34%via NVD

Most-changed records

Existing CVEs whose severity, score, KEV or exploitation status moved.

  • CVE-2019-9901EnvoyProxy Envoy Missing HTTP URL path normalization56
  • CVE-2025-71348picklescan before 0.0.28 fails to detect malicious pickle files that invoke torch.utils._config_module.load_config function within reduce methods57
  • CVE-2014-6407Arbitrary Code Execution in Docker41
  • CVE-2026-92005Use-after-free in the Audio/Video: Web Codecs component29
  • CVE-2025-56563A Server-Side Request Forgery vulnerability exists in sat_proxy.php in Zenith Satellite Tracker 1.066
  • CVE-2026-88592kkFileView >= 4.2.0 is vulnerable to Server-Side Request Forgery (SSRF)62
  • CVE-2026-79419A reflected cross-site scripting (XSS) vulnerability exists in EMX Tecnologia Gestao X Business Suite 8.4 and earlier60
  • CVE-2026-88743Bacularis 4.7.0 - 6.5.0 is vulnerable to Stored cross-site scripting (XSS) in director tags.46

Most-affected vendors

By CVEs published in the period.