Daily digest
Wednesday 23 September 2026
487 new CVEs this day, in line with the recent average. Severity skewed high: 43 critical and 205 high, 51% of the total. 65 arrived with exploitation evidence or public exploit code already attached. Red Hat was the most-affected vendor with 50.
New this day, ranked by depth score
The 12 that matter most of the 487 published.
MAL-2026-16475Critical⚠ ExploitedMalicious code in memoryos (PyPI)
Malicious code in memoryos (PyPI)
CVE-2026-96257Critical· 10.0PoCA flaw has been found in Fast FAC1203R Gigabit Edition 2.0.4
A flaw has been found in Fast FAC1203R Gigabit Edition 2.0.4. Affected by this issue is the function copy_msg_element of the component Device Discovery Service. Executing a manipulation can lead to stack-based buffer overflow. The attack…
CVE-2026-59167Critical· 10.0PoCSunEditor is a lightweight and powerful WYSIWYG editor in vanilla JavaScript with no dependencies
SunEditor is a lightweight and powerful WYSIWYG editor in vanilla JavaScript with no dependencies. Prior to 2.47.11, the sanitizer in src/lib/core.js does not consistently reject namespaced or custom HTML elements, allowing event-handler…
CVE-2026-96758Critical· 9.8PoCorval @orval/core before 8.28.0 contains a code injection vulnerability in the form-data serializer that fails to escape multipart property names in generated template literals
orval @orval/core before 8.28.0 contains a code injection vulnerability in the form-data serializer that fails to escape multipart property names in generated template literals. Attackers can inject ${...} expressions into OpenAPI schema…
CVE-2026-96757Critical· 9.8PoCorval before 8.29.0 fails to escape OpenAPI media-type keys when emitting them into single-quoted Content-Type string literals in generated code
orval before 8.29.0 fails to escape OpenAPI media-type keys when emitting them into single-quoted Content-Type string literals in generated code. Attackers can inject JavaScript through crafted media-type keys in OpenAPI specifications t…
CVE-2026-85724Critical· 9.6PoCMoquette is a lightweight Java MQTT broker
Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, when pattern-based ACL rules are configured, AuthorizationsCollector.canDoOperation substitutes client ID and username values directly into rules containing %c or %u and then t…
CVE-2026-95848Critical· 9.3PoCMoquette is a lightweight Java MQTT broker
Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, when a configured authenticator or authorizator class cannot be loaded, Server.initializeAuthenticator and Server.initializeAuthorizatorPolicy treat the failure as though no cu…
CVE-2026-93349High· 8.8PoCFrictionless through 5.20.0rc1 contains an OS command injection vulnerability in the explore console command that allows an attacker who supplies a crafted Data Package descriptor to execute arbitrary operating system commands as the use…
Frictionless through 5.20.0rc1 contains an OS command injection vulnerability in the explore console command that allows an attacker who supplies a crafted Data Package descriptor to execute arbitrary operating system commands as the use…
CVE-2026-77601High· 8.8PoCOpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. From 5.12.0 until 7.3.0, an authenticated actor can write the pypi_url setting through set_setting at POST /openc3-ap…
CVE-2026-95847High· 8.8PoCMoquette is a lightweight Java MQTT broker
Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, H2PersistentQueue derives a session's message-map name as queue_ plus the client ID and its metadata-map name as queue_ plus the client ID plus _meta. A durable session whose c…
CVE-2026-95846High· 8.7PoCMoquette is a lightweight Java MQTT broker
Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, PostOffice.publishWill publishes a client's Last-Will message without applying the canWrite authorization and reserved-topic checks used for a normal PUBLISH. A client can conf…
CVE-2026-95843High· 8.7PoCMoquette is a lightweight Java MQTT broker
Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, PostOffice.subscribe parses a shared-subscription filter through SharedSubscriptionUtils.extractShareName before validating the complete $share/{shareName}/{topicFilter} struct…
Most-changed records
Existing CVEs whose severity, score, KEV or exploitation status moved.
- CVE-2019-9901Envoy 1.9.0 and before does not normalize HTTP URL pathsseverity, cvss37
- CVE-2014-6407Docker before 1.3.2 allows remote attackers to write to arbitrary files and execute arbitrary code via a (1) symlink or (2) hard link attack in an image archive in a (a) pull or (b) load operation.cvss42
- CVE-2025-71348Picklescan is missing detection when calling pytorch function torch.utils._config_module.load_configexploit_available45
- CVE-2026-59650In Bouncy Castle for Java before 1.85, MTI/A0 DH agreement exponentiates unvalidated peer valueseverity, cvss41
- CVE-2026-88415MCMS 6.1.1 through 6.2.1 is vulnerable to stored Cross-Site Scripting (XSS)severity, cvss, exploit_available60
- CVE-2026-88345An out-of-bounds read vulnerability exists in the schema lexer of flatcc 4c3b999eseverity, cvss, exploit_available53
- CVE-2026-37603Improper Restriction of Excessive Authentication Attempts in the administration login of pH7Software pH7Builder (pH7 Social Dating CMS) through 19.2.0severity, cvss, exploit_available48
- CVE-2026-88339A NULL pointer dereference vulnerability exists in the gf_sg_vrml_field_clone() function of GPAC 2d7da22e (26.08-DEV)severity, cvss, exploit_available42
Most-affected vendors
By CVEs published in the period.