VulnSea

Daily digest

Tuesday 22 September 2026

462 new CVEs this day, in line with the recent average. Severity skewed high: 89 critical and 181 high, 58% of the total. 83 arrived with exploitation evidence or public exploit code already attached. CISA added 4 CVEs to the Known Exploited Vulnerabilities catalog. Adobe was the most-affected vendor with 53.

462
New CVEs
89
Critical
4
KEV additions
264
Records changed

Added to CISA KEV

Confirmed exploitation in the wild — federal remediation deadlines attach to these.

CVE-2026-93952Critical· 10.0CISA KEV0dayPoC
2d ago

VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privileged internal functionality and impact the VCO host

VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the confidentiality, integ…

▾ Hadalarista · velocloud_orchestratorEPSS 0.74%via NVD
CVE-2026-94127Critical· 9.8CISA KEV0dayPoC
2d ago

When a BIG-IP APM access policy and an OAuth profile are configured on a virtual server, specific malicious traffic can lead to remote code execution (RCE)

When a BIG-IP APM access policy and an OAuth profile are configured on a virtual server, specific malicious traffic can lead to remote code execution (RCE). This vulnerability is only present when BIG-IP APM is configured as an OAuth Aut…

▾ Hadalf5 · big-ip_access_policy_managerEPSS 1.4%via NVD
CVE-2026-93616Critical· 9.8CISA KEV0dayPoC
2d ago

A directory traversal and file upload vulnerability allows an unauthenticated attacker to upload and execute arbitrary scripts on Check Point Management Server.

A directory traversal and file upload vulnerability allows an unauthenticated attacker to upload and execute arbitrary scripts on Check Point Management Server.

▾ Hadalcheckpoint · multi-domain_security_managementEPSS 2.4%via NVD
CVE-2026-85102Critical· 9.8CISA KEVPoC
2w ago

Improper certificate trust validation during VPN negotiation in Check Point Quantum Security Gateway may allow an unauthenticated remote attacker to execute arbitrary code on the Gateway.

Improper certificate trust validation during VPN negotiation in Check Point Quantum Security Gateway may allow an unauthenticated remote attacker to execute arbitrary code on the Gateway.

▾ Hadalcheckpoint · gaia_embeddedEPSS 0.66%via NVD

New this day, ranked by depth score

The 12 that matter most of the 462 published.

CVE-2026-93952Critical· 10.0CISA KEV0dayPoC
2d ago

VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privileged internal functionality and impact the VCO host

VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the confidentiality, integ…

▾ Hadalarista · velocloud_orchestratorEPSS 0.74%via NVD
CVE-2026-94127Critical· 9.8CISA KEV0dayPoC
2d ago

When a BIG-IP APM access policy and an OAuth profile are configured on a virtual server, specific malicious traffic can lead to remote code execution (RCE)

When a BIG-IP APM access policy and an OAuth profile are configured on a virtual server, specific malicious traffic can lead to remote code execution (RCE). This vulnerability is only present when BIG-IP APM is configured as an OAuth Aut…

▾ Hadalf5 · big-ip_access_policy_managerEPSS 1.4%via NVD
CVE-2026-93616Critical· 9.8CISA KEV0dayPoC
2d ago

A directory traversal and file upload vulnerability allows an unauthenticated attacker to upload and execute arbitrary scripts on Check Point Management Server.

A directory traversal and file upload vulnerability allows an unauthenticated attacker to upload and execute arbitrary scripts on Check Point Management Server.

▾ Hadalcheckpoint · multi-domain_security_managementEPSS 2.4%via NVD
MAL-2026-16421Critical⚠ Exploited
2d ago

Malicious code in kerokwis (PyPI)

Malicious code in kerokwis (PyPI)

▾ Abyssalkerokwis · kerokwisvia OSV
MAL-2026-16410Critical⚠ Exploited
2d ago

Malicious code in auclean (PyPI)

Malicious code in auclean (PyPI)

▾ Abyssalauclean · aucleanvia OSV
MAL-2026-16408Critical⚠ Exploited
2d ago

Malicious code in snap-queue (PyPI)

Malicious code in snap-queue (PyPI)

▾ Abyssalsnap-queue · snap-queuevia OSV
MAL-2026-16407Critical⚠ Exploited
2d ago

Malicious code in poly-check-b (PyPI)

Malicious code in poly-check-b (PyPI)

▾ Abyssalpoly-check-b · poly-check-bvia OSV
MAL-2026-16406Critical⚠ Exploited
2d ago

Malicious code in crypto-trader-py (PyPI)

Malicious code in crypto-trader-py (PyPI)

▾ Abyssalcrypto-trader-py · crypto-trader-pyvia OSV
MAL-2026-16377Critical⚠ Exploited
2d ago

Malicious code in cloushaar-poc-exfil-91827 (PyPI)

Malicious code in cloushaar-poc-exfil-91827 (PyPI)

▾ Abyssalcloushaar-poc-exfil-91827 · cloushaar-poc-exfil-91827via OSV
CVE-2026-95675Critical· 9.8PoC
2d ago

D-Link DAP-1360 firmware version 6.14 and earlier contains an unauthenticated remote code execution vulnerability that allows remote attackers to execute arbitrary commands as root by sending crafted requests to the device's web manageme…

D-Link DAP-1360 firmware version 6.14 and earlier contains an unauthenticated remote code execution vulnerability that allows remote attackers to execute arbitrary commands as root by sending crafted requests to the device's web manageme…

▾ AbyssalD-LINK · DAP-1360EPSS 3.9%via NVD
CVE-2026-43641Critical· 9.8PoC
2d ago

Softaculous Virtualizor before 3.2.9 (Patch 9) and 3.0.0 contains an OS command injection vulnerability in the billing module handler that allows unauthenticated remote attackers to execute arbitrary commands as root by bypassing authent…

Softaculous Virtualizor before 3.2.9 (Patch 9) and 3.0.0 contains an OS command injection vulnerability in the billing module handler that allows unauthenticated remote attackers to execute arbitrary commands as root by bypassing authent…

▾ AbyssalSoftaculous · VirtualizorEPSS 3.0%via NVD
CVE-2026-93088Critical· 9.8PoC
2d ago

SGLang's multimodal generation runtime is vulnerable to unauthenticated arbitrary code execution because the disaggregated-diffusion orchestrator's DiffusionServer binds an unauthenticated ZeroMQ ROUTER socket to a network interface and …

SGLang's multimodal generation runtime is vulnerable to unauthenticated arbitrary code execution because the disaggregated-diffusion orchestrator's DiffusionServer binds an unauthenticated ZeroMQ ROUTER socket to a network interface and …

▾ AbyssalSGLang · SGLangEPSS 0.73%via NVD

Most-changed records

Existing CVEs whose severity, score, KEV or exploitation status moved.

  • CVE-2019-9901Envoy 1.9.0 and before does not normalize HTTP URL paths37
  • CVE-2025-71348Picklescan is missing detection when calling pytorch function torch.utils._config_module.load_config45
  • CVE-2014-6407Docker before 1.3.2 allows remote attackers to write to arbitrary files and execute arbitrary code via a (1) symlink or (2) hard link attack in an image archive in a (a) pull or (b) load operation.42
  • CVE-2026-92072Incorrect boundary conditions in the Safe Browsing component44
  • CVE-2026-78847An issue in gray-matter All versions (verified on 4.0.3) allows the JavaScript engine in lib/engines.js using eval() to parse front matter when language is js/javascript.This allows arbitrary code execution.66
  • CVE-2026-88402A SQL injection vulnerability in the checkSQL function of nocobase v2.1.21 allows attackers to access sesntive database information via injecting crafted SQL statements.66
  • CVE-2026-88404A remote code execution (RCE) vulnerability in the UniscriptExecutionService.execute() function (/services/script-execution.service.ts) of Univer v1.0.0-alpha.2 allows attackers to execute arbitrary code via a crafted payload.66
  • CVE-2026-93088SGLang's multimodal generation runtime is vulnerable to unauthenticated arbitrary code execution because the disaggregated-diffusion orchestrator's DiffusionServer binds an unauthenticated ZeroMQ ROUTER socket to a network interface and …66

Most-affected vendors

By CVEs published in the period.