Weekly digest
Week 5, 2026 (26 Jan – 1 Feb)
53 new CVEs this week, in line with the recent average. Severity skewed high: 3 critical and 26 high, 55% of the total. 8 arrived with exploitation evidence or public exploit code already attached. CISA added 2 CVEs to the Known Exploited Vulnerabilities catalog. Linux was the most-affected vendor with 8.
Added to CISA KEV
Confirmed exploitation in the wild — federal remediation deadlines attach to these.
CVE-2026-23760Critical· 9.8CISA KEVPoCSmarterTools SmarterMail versions prior to build 9511 contain an authentication bypass vulnerability in the password reset API
SmarterTools SmarterMail versions prior to build 9511 contain an authentication bypass vulnerability in the password reset API. The force-reset-password endpoint permits anonymous requests and fails to verify the existing password or a r…
CVE-2026-21509High· 7.8CISA KEV0dayPoCReliance on untrusted inputs in a security decision in Microsoft Office allows an unauthorized attacker to bypass a security feature locally.
Reliance on untrusted inputs in a security decision in Microsoft Office allows an unauthorized attacker to bypass a security feature locally.
New this week, ranked by depth score
The 12 that matter most of the 53 published.
CVE-2026-21509High· 7.8CISA KEV0dayPoCReliance on untrusted inputs in a security decision in Microsoft Office allows an unauthorized attacker to bypass a security feature locally.
Reliance on untrusted inputs in a security decision in Microsoft Office allows an unauthorized attacker to bypass a security feature locally.
CVE-2025-15467High· 8.8PoCIssue summary: Parsing CMS AuthEnvelopedData or EnvelopedData message with maliciously crafted AEAD parameters can trigger a stack buffer overflow. Impact summary: A stack buffer overflow may lead to a crash, causing Denial of Service, …
Issue summary: Parsing CMS AuthEnvelopedData or EnvelopedData message with maliciously crafted AEAD parameters can trigger a stack buffer overflow. Impact summary: A stack buffer overflow may lead to a crash, causing Denial of Service, …
CVE-2026-24486High· 8.6PoCPython-Multipart is a streaming multipart parser for Python
Python-Multipart is a streaming multipart parser for Python. Prior to version 0.0.22, a Path Traversal vulnerability exists when using non-default configuration options `UPLOAD_DIR` and `UPLOAD_KEEP_FILENAME=True`. An attacker can write …
CVE-2025-24293High· 8.1PoC# Active Storage allowed transformation methods potentially unsafe Active Storage attempts to prevent the use of potentially unsafe image transformation methods and parameters by default. The default allowed list contains three me…
# Active Storage allowed transformation methods potentially unsafe Active Storage attempts to prevent the use of potentially unsafe image transformation methods and parameters by default. The default allowed list contains three me…
CVE-2026-21721High· 8.1PoCThe dashboard permissions API does not verify the target dashboard scope and only checks the dashboards.permissions:* action
The dashboard permissions API does not verify the target dashboard scope and only checks the dashboards.permissions:* action. As a result, a user who has permission management rights on one dashboard can read and modify permissions on ot…
CVE-2025-61140Critical· 9.8The value function in jsonpath 1.1.1 lib/index.js is vulnerable to Prototype Pollution.
The value function in jsonpath 1.1.1 lib/index.js is vulnerable to Prototype Pollution.
CVE-2020-36939High· 7.5PoCCassandra Web - Remote File Read
Cassandra Web - Remote File Read
CVE-2026-40035CriticalUnfurl's debug mode cannot be disabled due to string config parsing (Werkzeug debugger exposure)
Unfurl's debug mode cannot be disabled due to string config parsing (Werkzeug debugger exposure)
CVE-2026-24874Critical· 9.1Access of Resource Using Incompatible Type ('Type Confusion') vulnerability in themrdemonized xray-monolith.This issue affects xray-monolith: before 2025.12.30.
Access of Resource Using Incompatible Type ('Type Confusion') vulnerability in themrdemonized xray-monolith.This issue affects xray-monolith: before 2025.12.30.
CVE-2026-24747High· 8.8PyTorch is a Python package that provides tensor computation
PyTorch is a Python package that provides tensor computation. Prior to version 2.10.0, a vulnerability in PyTorch's `weights_only` unpickler allows an attacker to craft a malicious checkpoint file (`.pth`) that, when loaded with `torch.l…
CVE-2026-24869High· 8.8Use-after-free in the Layout: Scrolling and Overflow component
Use-after-free in the Layout: Scrolling and Overflow component. This vulnerability was fixed in Firefox 147.0.2.
CVE-2025-14459High· 8.5A flaw was found in KubeVirt Containerized Data Importer (CDI)
A flaw was found in KubeVirt Containerized Data Importer (CDI). This vulnerability allows a user to clone PersistentVolumeClaims (PVCs) from unauthorized namespaces, resulting in unauthorized access to data via the DataImportCron PVC sou…
Most-affected vendors
By CVEs published in the period.