Daily digest
Thursday 24 September 2026
A busier-than-usual day with 576 new CVEs (recent average about 492). Of those, 30 critical and 184 high. 50 arrived with exploitation evidence or public exploit code already attached. CISA added 2 CVEs to the Known Exploited Vulnerabilities catalog. Linux was the most-affected vendor with 234.
Added to CISA KEV
Confirmed exploitation in the wild — federal remediation deadlines attach to these.
CVE-2026-5430Critical· 10.0CISA KEVPoCThe JWT authentication mechanism accepts tokens signed with algorithms other than those explicitly configured or supported
The JWT authentication mechanism accepts tokens signed with algorithms other than those explicitly configured or supported. This allows an attacker to craft a JWT with an unsupported algorithm, which is then incorrectly validated, leadin…
CVE-2026-71362Critical· 9.1CISA KEVPoCAdobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation
Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain elevated access to sensitive resources. Exploitation of this issue do…
New this day, ranked by depth score
The 12 that matter most of the 576 published.
MAL-2026-17168Critical⚠ ExploitedMalicious code in vercel-runtime-python (PyPI)
Malicious code in vercel-runtime-python (PyPI)
MAL-2026-17167Critical⚠ ExploitedMalicious code in prosocks (PyPI)
Malicious code in prosocks (PyPI)
CVE-2026-97360Critical· 10.0PoCHFS2 version 2.4.0 and earlier contains an unauthenticated arbitrary file access vulnerability that allows unauthenticated attackers to read, write, append, and delete files anywhere the HFS service account has filesystem access outside …
HFS2 version 2.4.0 and earlier contains an unauthenticated arbitrary file access vulnerability that allows unauthenticated attackers to read, write, append, and delete files anywhere the HFS service account has filesystem access outside …
CVE-2026-61732Critical· 10.0PoCDecepticon is an autonomous hacking agent for red teams
Decepticon is an autonomous hacking agent for red teams. Versions prior to 1.1.17 wrap web crawl results — the output of agent reconnaissance against target services — into LLM messages without neutralizing ChatML special-token literals.…
CVE-2026-93425Critical· 9.9PoCDokploy is a free, self-hostable Platform as a Service (PaaS)
Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the patch.readRepoDirectories tRPC procedure passes the user-controlled repoPath value from apps/dokploy/server/api/routers/patch.ts into a shell command in…
CVE-2026-12227Critical· 9.8PoCThe Visual Composer Website Builder plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 45.16.0 via the `vcv-template` parameter
The Visual Composer Website Builder plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 45.16.0 via the `vcv-template` parameter. This makes it possible for unauthenticated attackers to includ…
CVE-2026-61742Critical· 9.3PoCDBHub is a database MCP server for Postgres, MySQL, SQL Server, Oracle, MariaDB, SQLite
DBHub is a database MCP server for Postgres, MySQL, SQL Server, Oracle, MariaDB, SQLite. Versions prior to 0.22.5 expose an unauthenticated HTTP MCP endpoint when started with the documented HTTP transport mode, for example `--transport …
CVE-2026-94609High· 8.8PoCauthentik is an open-source identity provider
authentik is an open-source identity provider. Prior to 2026.2.7, 2026.5.7, and 2026.8.2, an account with delegated permission to manage a group, group membership, or a user can grant superuser status to an account or assign an existing …
CVE-2026-96515High· 8.6PoCThis vulnerability exists in the Netlink ICT HG323RW router due to insufficient authorization and input validation controls in the diagnostic script import functionality
This vulnerability exists in the Netlink ICT HG323RW router due to insufficient authorization and input validation controls in the diagnostic script import functionality. An authenticated attacker could exploit this vulnerability by uplo…
CVE-2026-77581High· 8.6PoCBentoPDF is a client-side PDF toolkit that is self hostable
BentoPDF is a client-side PDF toolkit that is self hostable. In 2.8.6 and earlier, the certificate and timestamp CORS proxy in cloudflare/cors-proxy-worker.js uses isPrivateOrReservedHost() to validate a supplied hostname separately from…
CVE-2026-97055High· 8.1PoCSigNoz from v0.8.0 before v0.143.0 defaults the JWT tokenizer signing secret (tokenizer::jwt::secret, set via SIGNOZ_TOKENIZER_JWT_SECRET or the deprecated SIGNOZ_JWT_SECRET) to an empty string, and Config.Validate() does not reject the …
SigNoz from v0.8.0 before v0.143.0 defaults the JWT tokenizer signing secret (tokenizer::jwt::secret, set via SIGNOZ_TOKENIZER_JWT_SECRET or the deprecated SIGNOZ_JWT_SECRET) to an empty string, and Config.Validate() does not reject the …
CVE-2026-77294High· 8.1PoCTREK is a collaborative travel planner
TREK is a collaborative travel planner. Prior to 3.3.0, TREK allows an authenticated user to store an attacker-controlled llm_base_url through the settings API when the LLM_PARSING feature is enabled. Write permission to the target trip …
Most-changed records
Existing CVEs whose severity, score, KEV or exploitation status moved.
- CVE-2019-9901Envoy 1.9.0 and before does not normalize HTTP URL pathsseverity, cvss37
- CVE-2014-6407Docker before 1.3.2 allows remote attackers to write to arbitrary files and execute arbitrary code via a (1) symlink or (2) hard link attack in an image archive in a (a) pull or (b) load operation.cvss42
- CVE-2025-71348Picklescan is missing detection when calling pytorch function torch.utils._config_module.load_configexploit_available45
- CVE-2026-56812Improper Check for Unusual or Exceptional Conditions vulnerability in phoenixframework phoenix (Presence JavaScript client) allows an attacker with ordinary channel access to cause a persistent client-side denial of service against every…cvss, exploit_available, severity53
- CVE-2026-71362Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalationepss, kev, exploited76
- CVE-2026-67827Incorrect Access Control in the HTTP API module in ZLMediaKit commit 9fd5152 allows remote attackers to achieve Remote Code Execution (RCE) via unauthenticated access to the setServerConfig API endpoint, which permits overwriting the ffm…severity, cvss, exploit_available66
- CVE-2026-88405A remote code execution (RCE) vulnerability in the RemoteRegisterFunctionService function (/remote/remote-register-function.service.ts) of Univer v1.0.0-alpha.2 allows attackers to execute arbitrary code via a crafted payload.severity, cvss, exploit_available66
- CVE-2026-88390An out-of-bounds write vulnerability in jslGetTokenValueAsString() in Espruino 2v29 (commit bffc6d0) allows crafted JavaScript input containing an overlong token to trigger a one-byte write beyond the JsLex.token buffer in RELEASE/NO_ASS…severity, cvss, exploit_available54
Most-affected vendors
By CVEs published in the period.