Weekly digest
Week 9, 2026 (23 Feb – 1 Mar)
67 new CVEs this week, in line with the recent average. Of those, 7 critical and 19 high. 11 arrived with exploitation evidence or public exploit code already attached. No new KEV entries. arcinfo was the most-affected vendor with 7.
New this week, ranked by depth score
The 12 that matter most of the 67 published.
CVE-2026-27577Critical· 9.9PoCn8n is an open source workflow automation platform
n8n is an open source workflow automation platform. Prior to versions 2.10.1, 2.9.3, and 1.123.22, additional exploits in the expression evaluation of n8n have been identified and patched following CVE-2025-68613. An authenticated user w…
CVE-2026-27941Critical· 9.9PoCOpenLIT is an open source platform for AI engineering. Prior to version 1.37.1, several GitHub Actions workflows in OpenLIT's GitHub repo…
OpenLIT is an open source platform for AI engineering. Prior to version 1.37.1, several GitHub Actions workflows in OpenLIT's GitHub repository use the `pull_request_target` event while checking out and executing untrusted code from fork…
CVE-2026-27727Critical· 9.8PoCmchange-commons-java, a library that provides Java utilities, includes code that mirrors early implementations of JNDI functionality, including support for remote `factoryClassLocation` values, by which code can be downloaded and invoked…
mchange-commons-java, a library that provides Java utilities, includes code that mirrors early implementations of JNDI functionality, including support for remote `factoryClassLocation` values, by which code can be downloaded and invoked…
CVE-2026-27606Critical· 9.8PoCRollup is a module bundler for JavaScript
Rollup is a module bundler for JavaScript. Versions prior to 2.80.0, 3.30.0, and 4.59.0 of the Rollup module bundler (specifically v4.x and present in current source) is vulnerable to an Arbitrary File Write via Path Traversal. Insecure …
CVE-2026-27483High· 8.8PoCMindsDB: Path Traversal in /api/files Leading to Remote Code Execution
MindsDB: Path Traversal in /api/files Leading to Remote Code Execution
CVE-2026-26331High· 8.8PoCyt-dlp: Arbitrary Command Injection when using the `--netrc-cmd` option
yt-dlp: Arbitrary Command Injection when using the `--netrc-cmd` option
CVE-2026-25747High· 8.8PoCDeserialization of Untrusted Data vulnerability in Apache Camel LevelDB component. The Camel-LevelDB DefaultLevelDBSerializer class deserializes data read from the LevelDB aggregation repository using java.io.ObjectInputStream without a…
Deserialization of Untrusted Data vulnerability in Apache Camel LevelDB component. The Camel-LevelDB DefaultLevelDBSerializer class deserializes data read from the LevelDB aggregation repository using java.io.ObjectInputStream without a…
CVE-2026-21660Critical· 9.8A Hardcoded Email Credentials Saved as Plaintext in Firmware (CWE-256: Plaintext Storage of a Password) vulnerability in Frick Controls Quantum HD version 10.22 and prior lead to unauthorized access, exposure of sensitive information, an…
A Hardcoded Email Credentials Saved as Plaintext in Firmware (CWE-256: Plaintext Storage of a Password) vulnerability in Frick Controls Quantum HD version 10.22 and prior lead to unauthorized access, exposure of sensitive information, an…
CVE-2026-2771Critical· 9.8Undefined behavior in the DOM: Core & HTML component
Undefined behavior in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.
CVE-2026-28231Critical· 9.1pillow_heif is a Python library for working with HEIF images and plugin for Pillow. Prior to version 1.3.0, an integer overflow in the en…
pillow_heif is a Python library for working with HEIF images and plugin for Pillow. Prior to version 1.3.0, an integer overflow in the encode path buffer validation of `_pillow_heif.c` allows an attacker to bypass bounds checks by provid…
CVE-2026-27696High· 8.6changedetection.io is Vulnerable to SSRF via Watch URLs
changedetection.io is Vulnerable to SSRF via Watch URLs
CVE-2026-27645Medium· 6.1PoCchangedetection.io Vulnerable to Reflected XSS in RSS Single Watch Error Response
changedetection.io Vulnerable to Reflected XSS in RSS Single Watch Error Response
Most-affected vendors
By CVEs published in the period.