VulnSea

Daily digest

Friday 18 September 2026

534 new CVEs this day, in line with the recent average. Of those, 54 critical and 208 high. 70 arrived with exploitation evidence or public exploit code already attached. CISA added 3 CVEs to the Known Exploited Vulnerabilities catalog. IBM was the most-affected vendor with 90.

534
New CVEs
54
Critical
3
KEV additions
436
Records changed

Added to CISA KEV

Confirmed exploitation in the wild — federal remediation deadlines attach to these.

CVE-2025-39682Critical· 9.8CISA KEVPoC⚖ disputed
1y ago

In the Linux kernel, the following vulnerability has been resolved: tls: fix handling of zero-length records on the rx_list Each recvmsg() call must process either - only contiguous DATA records (any number of them) - one non-DATA re…

In the Linux kernel, the following vulnerability has been resolved: tls: fix handling of zero-length records on the rx_list Each recvmsg() call must process either - only contiguous DATA records (any number of them) - one non-DATA re…

Hadallinux · linux_kernelEPSS 1.2%via NVD
CVE-2026-53266High· 8.8CISA KEVPoC
2mo ago

In the Linux kernel, the following vulnerability has been resolved: netfilter: bridge: make ebt_snat ARP rewrite writable The ebtables SNAT target keeps the Ethernet source address rewrite behind skb_ensure_writable(skb, 0)

In the Linux kernel, the following vulnerability has been resolved: netfilter: bridge: make ebt_snat ARP rewrite writable The ebtables SNAT target keeps the Ethernet source address rewrite behind skb_ensure_writable(skb, 0). This is i…

Abyssallinux · linux_kernelEPSS 0.28%via NVD
CVE-2025-39964High· 7.8CISA KEVPoC
11mo ago

In the Linux kernel, the following vulnerability has been resolved: crypto: af_alg - Disallow concurrent writes in af_alg_sendmsg Issuing two writes to the same af_alg socket is bogus as the data will be interleaved in an unpredictable…

In the Linux kernel, the following vulnerability has been resolved: crypto: af_alg - Disallow concurrent writes in af_alg_sendmsg Issuing two writes to the same af_alg socket is bogus as the data will be interleaved in an unpredictable…

Abyssallinux · linux_kernelEPSS 0.79%via NVD

New this day, ranked by depth score

The 12 that matter most of the 534 published.

MAL-2026-16296Critical⚠ Exploited
3d ago

Malicious code in py-venv-doctor (PyPI)

Malicious code in py-venv-doctor (PyPI)

Abyssalpy-venv-doctor · py-venv-doctorvia OSV
CVE-2026-93740Critical· 10.0PoC
3d ago

A vulnerability was identified in Totolink A3002MU Hh-B20211125.1046

A vulnerability was identified in Totolink A3002MU Hh-B20211125.1046. Affected is the function formWlEncrypt of the file /boafrm/formWlEncrypt. The manipulation of the argument submit-url leads to buffer overflow. It is possible to initi…

AbyssalTotolink · A3002MUEPSS 0.61%via NVD
CVE-2026-93606Critical· 10.0PoC
3d ago

vm2 (npm) versions 3.12.0 and earlier contain a sandbox escape in `VM` and `NodeVM`

vm2 (npm) versions 3.12.0 and earlier contain a sandbox escape in `VM` and `NodeVM`. When an embedder exposes a host API that returns a host-realm Promise, the bridge's rejection sanitizer (hostPromiseSanitizeReject / makeSanitizedPromis…

Abyssalpatriksimek · vm2EPSS 0.52%via NVD
CVE-2026-84383Critical· 9.8PoC
3d ago

libheif is a HEIF and AVIF file format decoder and encoder

libheif is a HEIF and AVIF file format decoder and encoder. From 1.22.0 until 1.23.2, a crafted HEIF, HEIC, or AVIF item graph using nested iden and auxl references can make HeifPixelImage::transfer_channel_from_image_as() append duplica…

Abyssalstrukturag · libheifEPSS 0.64%via NVD
CVE-2026-63647Critical· 9.3PoC
3d ago

CordysCRM is an open source AI-powered customer relationship management system that supports private deployment

CordysCRM is an open source AI-powered customer relationship management system that supports private deployment. Prior to 1.7.2, SseController exposes the anonymous /sse/subscribe, /sse/broadcast, and /sse/close endpoints because ShiroFi…

Abyssal1Panel-dev · CordysCRMEPSS 0.47%via NVD
CVE-2026-93019Critical· 9.1PoC
3d ago

Imager versions before 1.036 for Perl exit the process reading a TGA with a colour map length of 32768 or more in tga_palette_read. The reader unpacks the two-byte colour map length into a signed short, so a length of 32768 or more beco…

Imager versions before 1.036 for Perl exit the process reading a TGA with a colour map length of 32768 or more in tga_palette_read. The reader unpacks the two-byte colour map length into a signed short, so a length of 32768 or more beco…

AbyssalEPSS 0.61%via NVD
CVE-2026-92701Critical· 9.1PoC
3d ago

Cocos AI is a confidential computing system for running AI workloads inside trusted execution environments

Cocos AI is a confidential computing system for running AI workloads inside trusted execution environments. In versions up to and including 0.8.2, the intra-handshake attested TLS (aTLS) Intel TDX verification path does not copy the expe…

Abyssalultravioletrs · cocosEPSS 0.22%via NVD
CVE-2026-59163Critical· 9.1PoC
3d ago

Mnemosyne is a memory layer for artificial intelligence agents

Mnemosyne is a memory layer for artificial intelligence agents. Prior to v3.10.1, the auth check in mnemosyne/core/sync_server.py parsed the JWT's header and payload using base64 decoding, then passed the token to a jwt library call with…

Abyssalmnemosyne-memory · mnemosyne-memoryEPSS 0.25%via NVD
CVE-2026-88622High· 8.8PoC
3d ago

NUUO Network Video Recorder 2.0.0 is vulnerable to Command Injection in handle_import_privilege.php.

NUUO Network Video Recorder 2.0.0 is vulnerable to Command Injection in handle_import_privilege.php.

MidnightEPSS 1.1%via NVD
CVE-2026-93659High· 8.7PoC
3d ago

Concrete CMS Community Store before 2.7.8 renders customer-supplied order fields without HTML escaping in checkout and admin views

Concrete CMS Community Store before 2.7.8 renders customer-supplied order fields without HTML escaping in checkout and admin views. Unauthenticated attackers can store script payloads in billing name, email, or phone fields that execute …

Midnightconcretecms-community-store · concretecms-community-store/community_storeEPSS 0.26%via NVD
CVE-2026-58197High· 8.8PoC
3d ago

ToolHive is a utility designed to simplify the deployment and management of Model Context Protocol servers

ToolHive is a utility designed to simplify the deployment and management of Model Context Protocol servers. Prior to ToolHive CLI 0.30.1 and ToolHive Studio 0.38.0, locally run MCP server containers use the default network permission pro…

Midnightstacklok · github.com/stacklok/toolhiveEPSS 0.36%via NVD
CVE-2025-61682High· 8.6PoC
3d ago

Semantic MediaWiki is a free, open-source extension to MediaWiki that lets users store and query data within the wiki's pages

Semantic MediaWiki is a free, open-source extension to MediaWiki that lets users store and query data within the wiki's pages. Versions starting in 3.1.0 and prior to 7.0.0 insert the unsanitized value of a data attribute into the DOM as…

Midnightmediawiki · mediawiki/semantic-media-wikiEPSS 0.29%via NVD

Most-changed records

Existing CVEs whose severity, score, KEV or exploitation status moved.

  • CVE-2019-9901EnvoyProxy Envoy Missing HTTP URL path normalization56
  • CVE-2025-71348picklescan before 0.0.28 fails to detect malicious pickle files that invoke torch.utils._config_module.load_config function within reduce methods57
  • CVE-2014-6407Arbitrary Code Execution in Docker41
  • CVE-2026-53266In the Linux kernel, the following vulnerability has been resolved: netfilter: bridge: make ebt_snat ARP rewrite writable The ebtables SNAT target keeps the Ethernet source address rewrite behind skb_ensure_writable(skb, 0)73
  • CVE-2026-93019Imager versions before 1.036 for Perl exit the process reading a TGA with a colour map length of 32768 or more in tga_palette_read. The reader unpacks the two-byte colour map length into a signed short, so a length of 32768 or more beco…62
  • CVE-2026-93578A flaw was found in Netty's Online Certificate Status Protocol (OCSP) Client44
  • CVE-2025-39964In the Linux kernel, the following vulnerability has been resolved: crypto: af_alg - Disallow concurrent writes in af_alg_sendmsg Issuing two writes to the same af_alg socket is bogus as the data will be interleaved in an unpredictable…68
  • CVE-2018-13410Info-ZIP Zip 3.0, when the -T and -TT command-line options are used, allows attackers to cause a denial of service (invalid free and application crash) or possibly have unspecified other impact because of an off-by-one error67

Most-affected vendors

By CVEs published in the period.