VulnSea

Daily digest · in progress

Sunday 27 September 2026

A quiet day: only 67 new CVEs against a recent average of about 376 so far. Of those, 3 critical and 27 high. One arrived with exploitation evidence or public exploit code already attached. AzuraCast was the most-affected vendor with 11.

67
New CVEs
3
Critical
0
KEV additions
3
Records changed

New this day, ranked by depth score

The 12 that matter most of the 67 published.

MAL-2026-17192Critical⚠ Exploited
today

Malicious code in donutautosellsrc (PyPI)

Malicious code in donutautosellsrc (PyPI)

▾ Abyssaldonutautosellsrc · donutautosellsrcvia OSV
CVE-2026-100740Critical· 9.9
today

A vulnerability was detected in D-Link DIR-895L A1_102b07

A vulnerability was detected in D-Link DIR-895L A1_102b07. Impacted is the function tunnel_set_params of the file tunnel.c of the component L2TP Control Channel Parser. Performing a manipulation results in out-of-bounds write. The attack…

▾ MidnightD-Link · DIR-895Lvia NVD
CVE-2026-100721Critical· 9.0
today

vm2 before 3.12.2 contains an authorization bypass in the NodeVM external-module resolver

vm2 before 3.12.2 contains an authorization bypass in the NodeVM external-module resolver. When an embedder configures `require.external` with a custom resolver (and `context: 'host'`), `LegacyResolver.customResolve` in lib/resolver-comp…

▾ Midnightpatriksimek · vm2via NVD
CVE-2026-100865High· 8.8
today

Heym before 0.0.53 contains multiple independent vulnerabilities

Heym before 0.0.53 contains multiple independent vulnerabilities. (1) The workflow condition evaluator uses Python eval() without an effective sandbox, allowing any user who can edit a workflow branch/condition node — or who can import a…

▾ Twilightheymrun · heymvia NVD
CVE-2026-100864High· 8.8
today

heym before 0.0.91 contains a sandbox escape vulnerability in the expression engine's DotList map/filter and fallback resolver that allows authenticated users to execute arbitrary Python code

heym before 0.0.91 contains a sandbox escape vulnerability in the expression engine's DotList map/filter and fallback resolver that allows authenticated users to execute arbitrary Python code. Attackers can craft workflow expressions usi…

▾ Twilightheymrun · heymvia NVD
CVE-2026-100856High· 8.8
today

AzuraCast before 0.23.6 contains a code injection vulnerability in the remote relay password field due to incomplete migration from the vulnerable cleanUpString method to toRawString

AzuraCast before 0.23.6 contains a code injection vulnerability in the remote relay password field due to incomplete migration from the vulnerable cleanUpString method to toRawString. Attackers with RemoteRelays station permission can in…

▾ TwilightAzuraCast · AzuraCastvia NVD
CVE-2026-100852High· 8.8
today

AzuraCast through 0.23.x contains a command injection vulnerability in the Liquidsoap config generation for live recording that fails to quote the streamer username in process.run calls

AzuraCast through 0.23.x contains a command injection vulnerability in the Liquidsoap config generation for live recording that fails to quote the streamer username in process.run calls. Authenticated station users with Streamers and Pro…

▾ TwilightAzuraCast · AzuraCastvia NVD
CVE-2026-100844High· 8.4
today

MONAI before 1.6.0 is vulnerable to OS command injection in the nnUNetV2Runner component (monai.apps.nnunet.nnunetv2_runner)

MONAI before 1.6.0 is vulnerable to OS command injection in the nnUNetV2Runner component (monai.apps.nnunet.nnunetv2_runner). User-controlled values taken from the YAML configuration file (notably dataset_name_or_id) and from CLI/kwargs …

▾ TwilightProject-MONAI · MONAIvia NVD
CVE-2026-100839High· 8.4
today

Contrast is a confidential-computing runtime for Kubernetes

Contrast is a confidential-computing runtime for Kubernetes. In versions before 1.18.0, the guest kernel's ACPI/AML handling is vulnerable to an AML injection attack ("BadAML"). ACPI tables containing AML bytecode are passed from the unt…

▾ Twilightedgelesssys · contrastvia NVD
CVE-2026-100838High· 8.1
today

Contrast is a confidential-computing runtime for Kubernetes

Contrast is a confidential-computing runtime for Kubernetes. In versions before 1.19.1, the Kata agent policies generated by the Contrast CLI contained a flaw in the CopyFile verification that allowed arbitrary writes to the guest root f…

▾ Twilightedgelesssys · contrastvia NVD
CVE-2026-100833High· 8.2
today

Contrast (edgelesssys/contrast) versions 1.14.0 before 1.23.1 generate runtime policies that fail to detect all container image substitutions

Contrast (edgelesssys/contrast) versions 1.14.0 before 1.23.1 generate runtime policies that fail to detect all container image substitutions. A bad rebase during a Kata Containers update accidentally introduced an `allow_storage` rule t…

▾ Twilightedgelesssys · contrastvia NVD
CVE-2026-100857High· 8.0
today

AzuraCast before 0.23.4 contains a code injection vulnerability in the ConfigWriter::cleanUpString() method that fails to sanitize Liquidsoap string interpolation sequences, allowing authenticated users with Media or Profile permissions …

AzuraCast before 0.23.4 contains a code injection vulnerability in the ConfigWriter::cleanUpString() method that fails to sanitize Liquidsoap string interpolation sequences, allowing authenticated users with Media or Profile permissions …

▾ TwilightAzuraCast · AzuraCastvia NVD

Most-changed records

Existing CVEs whose severity, score, KEV or exploitation status moved.

  • CVE-2019-9901EnvoyProxy Envoy Missing HTTP URL path normalization56
  • CVE-2025-71348picklescan before 0.0.28 fails to detect malicious pickle files that invoke torch.utils._config_module.load_config function within reduce methods57
  • CVE-2014-6407Arbitrary Code Execution in Docker41

Most-affected vendors

By CVEs published in the period.