Weekly digest
Week 4, 2026 (19–25 Jan)
A busier-than-usual week with 83 new CVEs (recent average about 67). Severity skewed high: 17 critical and 33 high, 60% of the total. 20 arrived with exploitation evidence or public exploit code already attached. No new KEV entries. Linux was the most-affected vendor with 13.
New this week, ranked by depth score
The 12 that matter most of the 83 published.
CVE-2026-24423Critical· 9.8CISA KEVPoCSmarterTools SmarterMail versions prior to build 9511 contain an unauthenticated remote code execution vulnerability in the ConnectToHub API method
SmarterTools SmarterMail versions prior to build 9511 contain an unauthenticated remote code execution vulnerability in the ConnectToHub API method. The attacker could point the SmarterMail to the malicious HTTP server, which serves the …
CVE-2026-23760Critical· 9.8CISA KEVPoCSmarterTools SmarterMail versions prior to build 9511 contain an authentication bypass vulnerability in the password reset API
SmarterTools SmarterMail versions prior to build 9511 contain an authentication bypass vulnerability in the password reset API. The force-reset-password endpoint permits anonymous requests and fails to verify the existing password or a r…
CVE-2026-21962Critical· 10.0CISA KEVPoCVulnerability in the Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in product of Oracle Fusion Middleware (component: Weblogic Server Proxy Plug-in for Apache HTTP Server, Weblogic Server Proxy Plug-in for IIS)
Vulnerability in the Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in product of Oracle Fusion Middleware (component: Weblogic Server Proxy Plug-in for Apache HTTP Server, Weblogic Server Proxy Plug-in for IIS). Supported versio…
CVE-2026-0770HighCISA KEV0dayPoCLangflow affected by Remote Code Execution via validate_code() exec()
Langflow affected by Remote Code Execution via validate_code() exec()
CVE-2025-56005Critical· 9.8PoC⚖ disputedAn undocumented and unsafe feature in the PLY (Python Lex-Yacc) library 3.11 allows Remote Code Execution (RCE) via the `picklefile` parameter in the `yacc()` function
An undocumented and unsafe feature in the PLY (Python Lex-Yacc) library 3.11 allows Remote Code Execution (RCE) via the `picklefile` parameter in the `yacc()` function. This parameter accepts a `.pkl` file that is deserialized with `pick…
CVE-2025-15059High· 7.80dayGIMP PSP File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability
GIMP PSP File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vu…
CVE-2026-0775High· 7.00daynpm cli Incorrect Permission Assignment Local Privilege Escalation Vulnerability
npm cli Incorrect Permission Assignment Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of npm cli. An attacker must first obtain the ability to execute…
CVE-2025-55130Critical· 9.1PoCA flaw in Node.js’s Permissions model allows attackers to bypass `--allow-fs-read` and `--allow-fs-write` restrictions using crafted relative symlink paths
A flaw in Node.js’s Permissions model allows attackers to bypass `--allow-fs-read` and `--allow-fs-write` restrictions using crafted relative symlink paths. By chaining directories and symlinks, a script granted access only to the curren…
CVE-2026-22807High· 8.8PoCvLLM is an inference and serving engine for large language models (LLMs)
vLLM is an inference and serving engine for large language models (LLMs). Starting in version 0.10.1 and prior to version 0.14.0, vLLM loads Hugging Face `auto_map` dynamic modules during model resolution without gating on `trust_remote_…
CVE-2026-0603High· 8.3PoCA flaw was found in Hibernate
A flaw was found in Hibernate. A remote attacker with low privileges could exploit a second-order SQL injection vulnerability by providing specially crafted, unsanitized non-alphanumeric characters in the ID column when the InlineIdsOrCl…
CVE-2026-24009High· 8.1PoCdocling-core vulnerable to Remote Code Execution via unsafe PyYAML usage
docling-core vulnerable to Remote Code Execution via unsafe PyYAML usage
CVE-2026-23010High· 7.8PoCipv6: Fix use-after-free in inet6_addr_del().
In the Linux kernel, the following vulnerability has been resolved: ipv6: Fix use-after-free in inet6_addr_del(). syzbot reported use-after-free of inet6_ifaddr in inet6_addr_del(). [0] The cited commit accidentally moved ipv6_del_add…
Most-affected vendors
By CVEs published in the period.