Weekly digest
Week 11, 2026 (9–15 Mar)
A busier-than-usual week with 114 new CVEs (recent average about 95). Severity skewed high: 12 critical and 53 high, 57% of the total. 20 arrived with exploitation evidence or public exploit code already attached. No new KEV entries. adobe was the most-affected vendor with 24.
New this week, ranked by depth score
The 12 that matter most of the 114 published.
CVE-2025-67038Critical· 9.8CISA KEVPoCAn issue was discovered in Lantronix EDS5000 2.1.0.0R3
An issue was discovered in Lantronix EDS5000 2.1.0.0R3. The HTTP RPC module executes a shell command to write logs when user's authentication fails. The username is directly concatenated with the command without any sanitization. This al…
CVE-2026-31900Critical· 9.8PoCBlack is the uncompromising Python code formatter. Black provides a GitHub action for formatting code. This action supports an option, us…
Black is the uncompromising Python code formatter. Black provides a GitHub action for formatting code. This action supports an option, use_pyproject: true, for reading the version of Black to use from the repository pyproject.toml. A mal…
CVE-2026-23813Critical· 9.8PoCA vulnerability has been identified in the web-based management interface of AOS-CX switches that could potentially allow an unauthenticated remote actor to circumvent existing authentication controls
A vulnerability has been identified in the web-based management interface of AOS-CX switches that could potentially allow an unauthenticated remote actor to circumvent existing authentication controls. In some cases this could enable res…
CVE-2026-26118High· 8.8PoCAzure MCP Server has Server-Side Request Forgery issue that allows authorized attacker to elevate privileges over a network
Azure MCP Server has Server-Side Request Forgery issue that allows authorized attacker to elevate privileges over a network
CVE-2025-69219High· 8.8PoCApache Airflow Providers Http has Unsafe Pickle Deserializatio leading to RCE via HttpOperator
Apache Airflow Providers Http has Unsafe Pickle Deserializatio leading to RCE via HttpOperator
CVE-2026-31844High· 8.8PoCAn authenticated SQL Injection vulnerability (CWE-89) exists in the Koha staff interface in the /cgi-bin/koha/suggestion/suggestion.pl endpoint due to improper validation of the displayby parameter used by the GetDistinctValues functiona…
An authenticated SQL Injection vulnerability (CWE-89) exists in the Koha staff interface in the /cgi-bin/koha/suggestion/suggestion.pl endpoint due to improper validation of the displayby parameter used by the GetDistinctValues functiona…
CVE-2026-27826High· 8.2PoCMCP Atlassian has SSRF via unvalidated X-Atlassian-Jira-Url / X-Atlassian-Confluence-Url headers
MCP Atlassian has SSRF via unvalidated X-Atlassian-Jira-Url / X-Atlassian-Confluence-Url headers
CVE-2026-0846High· 8.6PoCArbitrary File Read via Absolute Path Input in nltk.util.filestring()
A vulnerability in the `filestring()` function of the `nltk.util` module in nltk version 3.9.2 allows arbitrary file read due to improper validation of input paths. The function directly opens files specified by user input without saniti…
CVE-2026-32247High· 8.1PoCGraphiti vulnerable to Cypher Injection via unsanitized node_labels in search filters
Graphiti vulnerable to Cypher Injection via unsanitized node_labels in search filters
CVE-2026-24294High· 7.8PoCImproper authentication in Windows SMB Server allows an authorized attacker to elevate privileges locally.
Improper authentication in Windows SMB Server allows an authorized attacker to elevate privileges locally.
CVE-2026-28384Critical· 9.9An improper sanitization of the compression_algorithm parameter in Canonical LXD allows an authenticated, unprivileged user to execute commands as the LXD daemon on the LXD server via API calls to the image and backup endpoints
An improper sanitization of the compression_algorithm parameter in Canonical LXD allows an authenticated, unprivileged user to execute commands as the LXD daemon on the LXD server via API calls to the image and backup endpoints. This iss…
CVE-2026-27280High· 7.8PoCDNG SDK versions 1.7.1 2471 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user
DNG SDK versions 1.7.1 2471 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a…
Most-affected vendors
By CVEs published in the period.