Weekly digest
Week 10, 2026 (2–8 Mar)
97 new CVEs this week, in line with the recent average. Severity skewed high: 14 critical and 37 high, 53% of the total. 9 arrived with exploitation evidence or public exploit code already attached. CISA added one CVE to the Known Exploited Vulnerabilities catalog. cisco was the most-affected vendor with 16.
Added to CISA KEV
Confirmed exploitation in the wild — federal remediation deadlines attach to these.
New this week, ranked by depth score
The 12 that matter most of the 97 published.
CVE-2026-20079Critical· 10.0CISA KEVPoCA vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to bypass authentication and execute script files on an affected device to obtain root access …
A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to bypass authentication and execute script files on an affected device to obtain root access …
CVE-2025-66024Critical· 9.0PoCThe XWiki blog application allows users of the XWiki platform to create and manage blog posts
The XWiki blog application allows users of the XWiki platform to create and manage blog posts. Versions starting with 9.15 and prior to 9.15.7 are vulnerable to Stored Cross-Site Scripting (XSS) via the Blog Post Title. The vulnerability…
CVE-2026-0847High· 8.6PoCPath Traversal in nltk/nltk
A vulnerability in NLTK versions up to and including 3.9.2 allows arbitrary file read via path traversal in multiple CorpusReader classes, including WordListCorpusReader, TaggedCorpusReader, and BracketParseCorpusReader. These classes fa…
CVE-2026-0013High· 8.4PoCIn setupLayout of PickActivity.java, there is a possible way to start any activity as a DocumentsUI app due to a confused deputy
In setupLayout of PickActivity.java, there is a possible way to start any activity as a DocumentsUI app due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User inter…
CVE-2026-0010High· 8.4PoCIn onTransact of IDrmManagerService.cpp, there is a possible out of bounds write due to a missing bounds check
In onTransact of IDrmManagerService.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not need…
CVE-2026-27446Critical· 9.8Missing Authentication for Critical Function (CWE-306) vulnerability in Apache Artemis, Apache ActiveMQ Artemis
Missing Authentication for Critical Function (CWE-306) vulnerability in Apache Artemis, Apache ActiveMQ Artemis. An unauthenticated remote attacker can use the Core protocol to force a target broker to establish an outbound Core federati…
CVE-2026-23231High· 7.8PoCnetfilter: nf_tables: fix use-after-free in nf_tables_addchain()
In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: fix use-after-free in nf_tables_addchain() nf_tables_addchain() publishes the chain to table->chains via list_add_tail_rcu() (in nft_chain_add())…
CVE-2021-36783Critical· 9.9Rancher doesn't properly sanitize credentials in cluster template answers
Rancher doesn't properly sanitize credentials in cluster template answers
CVE-2021-25320Critical· 9.9Rancher cloud credentials can be used through proxy API by users without access
Rancher cloud credentials can be used through proxy API by users without access
CVE-2026-29063Critical· 9.8Immutable.js provides many Persistent Immutable data structures
Immutable.js provides many Persistent Immutable data structures. Prior to versions 3.8.3, 4.3.7, and 5.1.5, Prototype Pollution is possible in immutable via the mergeDeep(), mergeDeepWith(), merge(), Map.toJS(), and Map.toObject() APIs. …
CVE-2026-28802Critical· 9.8⚖ disputedAuthlib is a Python library which builds OAuth and OpenID Connect servers
Authlib is a Python library which builds OAuth and OpenID Connect servers. From version 1.6.5 to before version 1.6.7, previous tests involving passing a malicious JWT containing alg: none and an empty signature was passing the signature…
CVE-2026-30789Critical· 9.8Use of Password Hash With Insufficient Computational Effort, Improper Restriction of Excessive Authentication Attempts vulnerability in rustdesk-client RustDesk Client rustdesk-client on Windows, MacOS, Linux, iOS, Android (Client login,…
Use of Password Hash With Insufficient Computational Effort, Improper Restriction of Excessive Authentication Attempts vulnerability in rustdesk-client RustDesk Client rustdesk-client on Windows, MacOS, Linux, iOS, Android (Client login,…
Most-affected vendors
By CVEs published in the period.