VulnSea

Daily digest · in progress

Wednesday 7 October 2026

A quiet day: only 27 new CVEs against a recent average of about 475 so far. Severity skewed high: 3 critical and 18 high, 78% of the total. One arrived with exploitation evidence or public exploit code already attached. IBM was the most-affected vendor with 24.

27
New CVEs
3
Critical
0
KEV additions
3
Records changed

New this day, ranked by depth score

The 12 that matter most of the 27 published.

CVE-2026-93674Critical· 9.8PoC
today

IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote attacker to execute arbitrary code due to improper neutralization of special elements used in an OS command.

IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote attacker to execute arbitrary code due to improper neutralization of special elements used in an OS command.

▾ AbyssalIBM · Langflow OSSvia NVD
CVE-2026-104334Critical· 9.8
today

IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote attacker to execute arbitrary code due to improper control of code generation.

IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote attacker to execute arbitrary code due to improper control of code generation.

▾ MidnightIBM · Langflow OSSvia NVD
CVE-2026-105324Critical· 9.2
today

An HTTP header injection vulnerability was found in the ADM

An HTTP header injection vulnerability in start-page-loader.cgi of ADM allows an unauthenticated remote attacker to read arbitrary files on the host system. By sending a crafted HTTP request with injected headers via the state parameter,…

▾ MidnightASUSTOR Inc. · ADMvia CVEORG
CVE-2026-97679High· 8.8
today

IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of special elements used in an OS command ('Code Injection') related to improper input validation.

IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of special elements used in an OS command ('Code Injection') related to improper input validation.

▾ TwilightIBM · Langflow OSSvia NVD
CVE-2026-97678High· 8.8
today

IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper input validation.

IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper input validation.

▾ TwilightIBM · Langflow OSSvia NVD
CVE-2026-97676High· 8.8
today

IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of special elements used in code, resulting in a sandbox escape.

IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of special elements used in code, resulting in a sandbox escape.

▾ TwilightIBM · Langflow OSSvia NVD
CVE-2026-97673High· 8.8
today

IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper input validation.

IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper input validation.

▾ TwilightIBM · Langflow OSSvia NVD
CVE-2026-97655High· 8.8
today

IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote attacker to execute arbitrary code due to an incomplete blocklist in the code security scanner.

IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote attacker to execute arbitrary code due to an incomplete blocklist in the code security scanner.

▾ TwilightIBM · Langflow OSSvia NVD
CVE-2026-93675High· 8.8
today

IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote attacker to execute arbitrary code due to an expected dependency confusion.

IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote attacker to execute arbitrary code due to an expected dependency confusion.

▾ TwilightIBM · Langflow OSSvia NVD
CVE-2026-88962High· 8.8
today

IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper control of code generation.

IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper control of code generation.

▾ TwilightIBM · Langflow OSSvia NVD
CVE-2026-104335High· 8.8
today

IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper access control.

IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper access control.

▾ TwilightIBM · Langflow OSSvia NVD
CVE-2026-93449High· 8.5
today

IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper control of code generation.

IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper control of code generation.

▾ TwilightIBM · Langflow OSSvia NVD

Most-changed records

Existing CVEs whose severity, score, KEV or exploitation status moved.

  • CVE-2019-9901Envoy 1.9.0 and before does not normalize HTTP URL paths37
  • CVE-2025-71348picklescan before 0.0.28 fails to detect malicious pickle files that invoke torch.utils._config_module.load_config function within reduce methods45
  • CVE-2014-6407Docker before 1.3.2 allows remote attackers to write to arbitrary files and execute arbitrary code via a (1) symlink or (2) hard link attack in an image archive in a (a) pull or (b) load operation.42

Most-affected vendors

By CVEs published in the period.