VulnSea

Weekly digest

Week 7, 2026 (9–15 Feb)

A heavy week: 129 new CVEs, well above the recent average of about 74. Severity skewed high: 5 critical and 72 high, 60% of the total. 10 arrived with exploitation evidence or public exploit code already attached. No new KEV entries. adobe was the most-affected vendor with 44.

129
New CVEs
5
Critical
0
KEV additions
0
Records changed

New this week, ranked by depth score

The 12 that matter most of the 129 published.

CVE-2026-2441High· 8.8CISA KEVPoC
7mo ago

Use after free in CSS in Google Chrome prior to 145.0.7632.75 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page

Use after free in CSS in Google Chrome prior to 145.0.7632.75 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

AbyssalGoogle · ChromeEPSS 22%via CVEORG
CVE-2026-26190Critical· 9.8PoC
7mo ago

Milvus: Unauthenticated Access to Restful API on Metrics Port (9091) Leads to Critical System Compromise

Milvus: Unauthenticated Access to Restful API on Metrics Port (9091) Leads to Critical System Compromise

Abyssalmilvus-io · github.com/milvus-io/milvusEPSS 37%via OSV
CVE-2025-68686Medium· 5.9CISA KEV
7mo ago

An Exposure of Sensitive Information to an Unauthorized Actor vulnerability [CWE-200] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.1, FortiOS 7.4.0 through 7.4.6, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all…

An Exposure of Sensitive Information to an Unauthorized Actor vulnerability [CWE-200] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.1, FortiOS 7.4.0 through 7.4.6, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all…

Midnightfortinet · fortiosEPSS 30%via NVD
CVE-2026-2005High· 8.8PoC
7mo ago

Heap buffer overflow in PostgreSQL pgcrypto allows a ciphertext provider to execute arbitrary code as the operating system user running the database

Heap buffer overflow in PostgreSQL pgcrypto allows a ciphertext provider to execute arbitrary code as the operating system user running the database. Versions before PostgreSQL 18.2, 17.8, 16.12, 15.16, and 14.21 are affected.

Midnightpostgresql · postgresqlEPSS 1.3%via NVD
CVE-2026-25890High· 8.1PoC
7mo ago

File Browser has a Path-Based Access Control Bypass via Multiple Leading Slashes in URL

File Browser has a Path-Based Access Control Bypass via Multiple Leading Slashes in URL

Midnightfilebrowser · github.com/filebrowser/filebrowser/v2EPSS 0.47%via OSV
CVE-2026-1529High· 8.1PoC
7mo ago

A flaw was found in Keycloak

A flaw was found in Keycloak. An attacker can exploit this vulnerability by modifying the organization ID and target email within a legitimate invitation token's JSON Web Token (JWT) payload. This lack of cryptographic signature verifica…

MidnightEPSS 0.46%via NVD
CVE-2026-23111High· 7.8PoC
7mo ago

In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: fix inverted genmask check in nft_map_catchall_activate() nft_map_catchall_activate() has an inverted element activity check compared to its non-…

In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: fix inverted genmask check in nft_map_catchall_activate() nft_map_catchall_activate() has an inverted element activity check compared to its non-…

Midnightlinux · linux_kernelEPSS 0.49%via NVD
CVE-2026-0651High· 7.8PoC
7mo ago

A path traversal vulnerability was identified TP-Link Tapo C260 v1, D235 v1, C211 v2 and C520WS v2.6 within the HTTP server’s handling of GET requests

A path traversal vulnerability was identified TP-Link Tapo C260 v1, D235 v1, C211 v2 and C520WS v2.6 within the HTTP server’s handling of GET requests. The server performs path normalization before fully decoding URL encoded input and fa…

Midnighttp-link · tapo_c260_firmwareEPSS 0.32%via NVD
CVE-2025-69872Critical· 9.8
7mo ago

DiskCache (python-diskcache) through 5.6.3 uses Python pickle for serialization by default

DiskCache (python-diskcache) through 5.6.3 uses Python pickle for serialization by default. An attacker with write access to the cache directory can achieve arbitrary code execution when a victim application reads from the cache.

Midnightdiskcache · diskcacheEPSS 0.53%via NVD
CVE-2026-1615Critical· 9.8
7mo ago

Versions of the package jsonpath before 1.3.0 are vulnerable to Arbitrary Code Injection via unsafe evaluation of user-supplied JSON Path expressions

Versions of the package jsonpath before 1.3.0 are vulnerable to Arbitrary Code Injection via unsafe evaluation of user-supplied JSON Path expressions. The library relies on the static-eval module to process JSON Path input, which is not …

MidnightEPSS 1.1%via NVD
CVE-2025-66630Critical
7mo ago

Fiber has an insecure fallback in utils.UUIDv4() / utils.UUID() — predictable / zero‑UUID on crypto/rand failure

Fiber has an insecure fallback in utils.UUIDv4() / utils.UUID() — predictable / zero‑UUID on crypto/rand failure

Midnightgofiber · github.com/gofiber/fiber/v2EPSS 0.49%via OSV
CVE-2026-26157High· 7.0PoC
7mo ago

A flaw was found in BusyBox

A flaw was found in BusyBox. Incomplete path sanitization in its archive extraction utilities allows an attacker to craft malicious archives that when extracted, and under specific conditions, may write to files outside the intended dire…

MidnightEPSS 0.71%via NVD

Most-affected vendors

By CVEs published in the period.