Daily digest
Tuesday 22 September 2026
462 new CVEs this day, in line with the recent average. Severity skewed high: 89 critical and 181 high, 58% of the total. 83 arrived with exploitation evidence or public exploit code already attached. CISA added 4 CVEs to the Known Exploited Vulnerabilities catalog. Adobe was the most-affected vendor with 53.
Added to CISA KEV
Confirmed exploitation in the wild — federal remediation deadlines attach to these.
CVE-2026-93952Critical· 10.0CISA KEV0dayPoCVeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privileged internal functionality and impact the VCO host
VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the confidentiality, integ…
CVE-2026-94127Critical· 9.8CISA KEV0dayPoCWhen a BIG-IP APM access policy and an OAuth profile are configured on a virtual server, specific malicious traffic can lead to remote code execution (RCE)
When a BIG-IP APM access policy and an OAuth profile are configured on a virtual server, specific malicious traffic can lead to remote code execution (RCE). This vulnerability is only present when BIG-IP APM is configured as an OAuth Aut…
CVE-2026-93616Critical· 9.8CISA KEV0dayPoCA directory traversal and file upload vulnerability allows an unauthenticated attacker to upload and execute arbitrary scripts on Check Point Management Server.
A directory traversal and file upload vulnerability allows an unauthenticated attacker to upload and execute arbitrary scripts on Check Point Management Server.
CVE-2026-85102Critical· 9.8CISA KEVPoCImproper certificate trust validation during VPN negotiation in Check Point Quantum Security Gateway may allow an unauthenticated remote attacker to execute arbitrary code on the Gateway.
Improper certificate trust validation during VPN negotiation in Check Point Quantum Security Gateway may allow an unauthenticated remote attacker to execute arbitrary code on the Gateway.
New this day, ranked by depth score
The 12 that matter most of the 462 published.
CVE-2026-93952Critical· 10.0CISA KEV0dayPoCVeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privileged internal functionality and impact the VCO host
VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the confidentiality, integ…
CVE-2026-94127Critical· 9.8CISA KEV0dayPoCWhen a BIG-IP APM access policy and an OAuth profile are configured on a virtual server, specific malicious traffic can lead to remote code execution (RCE)
When a BIG-IP APM access policy and an OAuth profile are configured on a virtual server, specific malicious traffic can lead to remote code execution (RCE). This vulnerability is only present when BIG-IP APM is configured as an OAuth Aut…
CVE-2026-93616Critical· 9.8CISA KEV0dayPoCA directory traversal and file upload vulnerability allows an unauthenticated attacker to upload and execute arbitrary scripts on Check Point Management Server.
A directory traversal and file upload vulnerability allows an unauthenticated attacker to upload and execute arbitrary scripts on Check Point Management Server.
MAL-2026-16421Critical⚠ ExploitedMalicious code in kerokwis (PyPI)
Malicious code in kerokwis (PyPI)
MAL-2026-16410Critical⚠ ExploitedMalicious code in auclean (PyPI)
Malicious code in auclean (PyPI)
MAL-2026-16408Critical⚠ ExploitedMalicious code in snap-queue (PyPI)
Malicious code in snap-queue (PyPI)
MAL-2026-16407Critical⚠ ExploitedMalicious code in poly-check-b (PyPI)
Malicious code in poly-check-b (PyPI)
MAL-2026-16406Critical⚠ ExploitedMalicious code in crypto-trader-py (PyPI)
Malicious code in crypto-trader-py (PyPI)
MAL-2026-16377Critical⚠ ExploitedMalicious code in cloushaar-poc-exfil-91827 (PyPI)
Malicious code in cloushaar-poc-exfil-91827 (PyPI)
CVE-2026-95675Critical· 9.8PoCD-Link DAP-1360 firmware version 6.14 and earlier contains an unauthenticated remote code execution vulnerability that allows remote attackers to execute arbitrary commands as root by sending crafted requests to the device's web manageme…
D-Link DAP-1360 firmware version 6.14 and earlier contains an unauthenticated remote code execution vulnerability that allows remote attackers to execute arbitrary commands as root by sending crafted requests to the device's web manageme…
CVE-2026-43641Critical· 9.8PoCSoftaculous Virtualizor before 3.2.9 (Patch 9) and 3.0.0 contains an OS command injection vulnerability in the billing module handler that allows unauthenticated remote attackers to execute arbitrary commands as root by bypassing authent…
Softaculous Virtualizor before 3.2.9 (Patch 9) and 3.0.0 contains an OS command injection vulnerability in the billing module handler that allows unauthenticated remote attackers to execute arbitrary commands as root by bypassing authent…
CVE-2026-93088Critical· 9.8PoCSGLang's multimodal generation runtime is vulnerable to unauthenticated arbitrary code execution because the disaggregated-diffusion orchestrator's DiffusionServer binds an unauthenticated ZeroMQ ROUTER socket to a network interface and …
SGLang's multimodal generation runtime is vulnerable to unauthenticated arbitrary code execution because the disaggregated-diffusion orchestrator's DiffusionServer binds an unauthenticated ZeroMQ ROUTER socket to a network interface and …
Most-changed records
Existing CVEs whose severity, score, KEV or exploitation status moved.
- CVE-2019-9901Envoy 1.9.0 and before does not normalize HTTP URL pathsseverity, cvss37
- CVE-2025-71348Picklescan is missing detection when calling pytorch function torch.utils._config_module.load_configexploit_available45
- CVE-2014-6407Docker before 1.3.2 allows remote attackers to write to arbitrary files and execute arbitrary code via a (1) symlink or (2) hard link attack in an image archive in a (a) pull or (b) load operation.cvss42
- CVE-2026-92072Incorrect boundary conditions in the Safe Browsing componentseverity, cvss44
- CVE-2026-78847An issue in gray-matter All versions (verified on 4.0.3) allows the JavaScript engine in lib/engines.js using eval() to parse front matter when language is js/javascript.This allows arbitrary code execution.severity, cvss, exploit_available66
- CVE-2026-88402A SQL injection vulnerability in the checkSQL function of nocobase v2.1.21 allows attackers to access sesntive database information via injecting crafted SQL statements.severity, cvss, exploit_available66
- CVE-2026-88404A remote code execution (RCE) vulnerability in the UniscriptExecutionService.execute() function (/services/script-execution.service.ts) of Univer v1.0.0-alpha.2 allows attackers to execute arbitrary code via a crafted payload.severity, cvss, exploit_available66
- CVE-2026-93088SGLang's multimodal generation runtime is vulnerable to unauthenticated arbitrary code execution because the disaggregated-diffusion orchestrator's DiffusionServer binds an unauthenticated ZeroMQ ROUTER socket to a network interface and …severity, cvss, exploit_available66
Most-affected vendors
By CVEs published in the period.