VulnSea

Daily digest

Wednesday 23 September 2026

487 new CVEs this day, in line with the recent average. Severity skewed high: 43 critical and 205 high, 51% of the total. 65 arrived with exploitation evidence or public exploit code already attached. Red Hat was the most-affected vendor with 50.

487
New CVEs
43
Critical
0
KEV additions
192
Records changed

New this day, ranked by depth score

The 12 that matter most of the 487 published.

MAL-2026-16475Critical⚠ Exploited
2d ago

Malicious code in memoryos (PyPI)

Malicious code in memoryos (PyPI)

▾ Abyssalmemoryos · memoryosvia OSV
CVE-2026-96257Critical· 10.0PoC
2d ago

A flaw has been found in Fast FAC1203R Gigabit Edition 2.0.4

A flaw has been found in Fast FAC1203R Gigabit Edition 2.0.4. Affected by this issue is the function copy_msg_element of the component Device Discovery Service. Executing a manipulation can lead to stack-based buffer overflow. The attack…

▾ AbyssalFast · FAC1203R Gigabit EditionEPSS 0.58%via NVD
CVE-2026-59167Critical· 10.0PoC
2d ago

SunEditor is a lightweight and powerful WYSIWYG editor in vanilla JavaScript with no dependencies

SunEditor is a lightweight and powerful WYSIWYG editor in vanilla JavaScript with no dependencies. Prior to 2.47.11, the sanitizer in src/lib/core.js does not consistently reject namespaced or custom HTML elements, allowing event-handler…

▾ Abyssalsuneditor · suneditorEPSS 0.39%via NVD
CVE-2026-96758Critical· 9.8PoC
2d ago

orval @orval/core before 8.28.0 contains a code injection vulnerability in the form-data serializer that fails to escape multipart property names in generated template literals

orval @orval/core before 8.28.0 contains a code injection vulnerability in the form-data serializer that fails to escape multipart property names in generated template literals. Attackers can inject ${...} expressions into OpenAPI schema…

▾ Abyssalorval-labs · orvalEPSS 0.54%via NVD
CVE-2026-96757Critical· 9.8PoC
2d ago

orval before 8.29.0 fails to escape OpenAPI media-type keys when emitting them into single-quoted Content-Type string literals in generated code

orval before 8.29.0 fails to escape OpenAPI media-type keys when emitting them into single-quoted Content-Type string literals in generated code. Attackers can inject JavaScript through crafted media-type keys in OpenAPI specifications t…

▾ Abyssalorval-labs · orvalEPSS 0.57%via NVD
CVE-2026-85724Critical· 9.6PoC
2d ago

Moquette is a lightweight Java MQTT broker

Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, when pattern-based ACL rules are configured, AuthorizationsCollector.canDoOperation substitutes client ID and username values directly into rules containing %c or %u and then t…

▾ Abyssalmoquette-io · moquetteEPSS 0.26%via NVD
CVE-2026-95848Critical· 9.3PoC
2d ago

Moquette is a lightweight Java MQTT broker

Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, when a configured authenticator or authorizator class cannot be loaded, Server.initializeAuthenticator and Server.initializeAuthorizatorPolicy treat the failure as though no cu…

▾ Abyssalmoquette-io · moquetteEPSS 0.51%via NVD
CVE-2026-93349High· 8.8PoC
2d ago

Frictionless through 5.20.0rc1 contains an OS command injection vulnerability in the explore console command that allows an attacker who supplies a crafted Data Package descriptor to execute arbitrary operating system commands as the use…

Frictionless through 5.20.0rc1 contains an OS command injection vulnerability in the explore console command that allows an attacker who supplies a crafted Data Package descriptor to execute arbitrary operating system commands as the use…

▾ Midnightfrictionlessdata · frictionless-pyEPSS 2.0%via NVD
CVE-2026-77601High· 8.8PoC
2d ago

OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems

OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. From 5.12.0 until 7.3.0, an authenticated actor can write the pypi_url setting through set_setting at POST /openc3-ap…

▾ MidnightOpenC3 · cosmosEPSS 0.58%via NVD
CVE-2026-95847High· 8.8PoC
2d ago

Moquette is a lightweight Java MQTT broker

Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, H2PersistentQueue derives a session's message-map name as queue_ plus the client ID and its metadata-map name as queue_ plus the client ID plus _meta. A durable session whose c…

▾ Midnightmoquette-io · moquetteEPSS 0.41%via NVD
CVE-2026-95846High· 8.7PoC
2d ago

Moquette is a lightweight Java MQTT broker

Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, PostOffice.publishWill publishes a client's Last-Will message without applying the canWrite authorization and reserved-topic checks used for a normal PUBLISH. A client can conf…

▾ Midnightmoquette-io · moquetteEPSS 0.29%via NVD
CVE-2026-95843High· 8.7PoC
2d ago

Moquette is a lightweight Java MQTT broker

Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, PostOffice.subscribe parses a shared-subscription filter through SharedSubscriptionUtils.extractShareName before validating the complete $share/{shareName}/{topicFilter} struct…

▾ Midnightmoquette-io · moquetteEPSS 0.38%via NVD

Most-changed records

Existing CVEs whose severity, score, KEV or exploitation status moved.

  • CVE-2019-9901Envoy 1.9.0 and before does not normalize HTTP URL paths37
  • CVE-2014-6407Docker before 1.3.2 allows remote attackers to write to arbitrary files and execute arbitrary code via a (1) symlink or (2) hard link attack in an image archive in a (a) pull or (b) load operation.42
  • CVE-2025-71348Picklescan is missing detection when calling pytorch function torch.utils._config_module.load_config45
  • CVE-2026-59650In Bouncy Castle for Java before 1.85, MTI/A0 DH agreement exponentiates unvalidated peer value41
  • CVE-2026-88415MCMS 6.1.1 through 6.2.1 is vulnerable to stored Cross-Site Scripting (XSS)60
  • CVE-2026-88345An out-of-bounds read vulnerability exists in the schema lexer of flatcc 4c3b999e53
  • CVE-2026-37603Improper Restriction of Excessive Authentication Attempts in the administration login of pH7Software pH7Builder (pH7 Social Dating CMS) through 19.2.048
  • CVE-2026-88339A NULL pointer dereference vulnerability exists in the gf_sg_vrml_field_clone() function of GPAC 2d7da22e (26.08-DEV)42

Most-affected vendors

By CVEs published in the period.