Weekly digest
Week 6, 2026 (2–8 Feb)
75 new CVEs this week, in line with the recent average. Of those, 5 critical and 27 high. 7 arrived with exploitation evidence or public exploit code already attached. CISA added one CVE to the Known Exploited Vulnerabilities catalog. Linux was the most-affected vendor with 11.
Added to CISA KEV
Confirmed exploitation in the wild — federal remediation deadlines attach to these.
New this week, ranked by depth score
The 12 that matter most of the 75 published.
CVE-2026-22778Critical· 9.8PoCvLLM is an inference and serving engine for large language models (LLMs)
vLLM is an inference and serving engine for large language models (LLMs). From 0.8.3 to before 0.14.1, when an invalid image is sent to vLLM's multimodal endpoint, PIL throws an error. vLLM returns this error to the client, leaking a hea…
CVE-2025-64712Critical· 9.8Unstructured has Path Traversal via Malicious MSG Attachment that Allows Arbitrary File Write
Unstructured has Path Traversal via Malicious MSG Attachment that Allows Arbitrary File Write
CVE-2026-1709Critical· 9.4A flaw was found in Keylime
A flaw was found in Keylime. The Keylime registrar, since version 7.12.0, does not enforce client-side Transport Layer Security (TLS) authentication. This authentication bypass vulnerability allows unauthenticated clients with network ac…
GHSA-4f84-67cv-qrv3CriticalA single post-release of dydx-v4-client contained obfuscated multi-stage loader
A single post-release of dydx-v4-client contained obfuscated multi-stage loader
CVE-2026-25481CriticalLangroid has WAF Bypass Leading to RCE in TableChatAgent
Langroid has WAF Bypass Leading to RCE in TableChatAgent
CVE-2026-25521High· 8.8Locutus brings stdlibs of other programming languages to JavaScript for educational purposes
Locutus brings stdlibs of other programming languages to JavaScript for educational purposes. In versions from 2.0.12 to before 2.0.39, a prototype pollution vulnerability exists in locutus. Despite a previous fix that attempted to mitig…
CVE-2026-24514Medium· 6.5PoCingress-nginx vulnerable to Allocation of Resources Without Limits or Throttling
ingress-nginx vulnerable to Allocation of Resources Without Limits or Throttling
CVE-2026-1761High· 8.6A flaw was found in libsoup
A flaw was found in libsoup. This stack-based buffer overflow vulnerability occurs during the parsing of multipart HTTP responses due to an incorrect length calculation. A remote attacker can exploit this by sending a specially crafted m…
CVE-2026-25580High· 8.6Pydantic AI is a Python agent framework for building applications and workflows with Generative AI
Pydantic AI is a Python agent framework for building applications and workflows with Generative AI. From 0.0.26 to before 1.56.0, aServer-Side Request Forgery (SSRF) vulnerability exists in Pydantic AI's URL download functionality. When …
CVE-2026-2015Medium· 6.3PoCA weakness has been identified in Portabilis i-Educar up to 2.10
A weakness has been identified in Portabilis i-Educar up to 2.10. Affected is an unknown function of the file FinalStatusImportService.php of the component Final Status Import. Executing a manipulation of the argument school_id can lead …
CVE-2025-61732High· 8.6A discrepancy between how Go and C/C++ comments were parsed allowed for code smuggling into the resulting cgo binary.
A discrepancy between how Go and C/C++ comments were parsed allowed for code smuggling into the resulting cgo binary.
CVE-2026-0599High· 7.5Hugging Face Text Generation Inference vulnerable to Uncontrolled Resource Consumption
Hugging Face Text Generation Inference vulnerable to Uncontrolled Resource Consumption
Most-affected vendors
By CVEs published in the period.