VulnSea

Weekly digest

Week 16, 2026 (13–19 Apr)

178 new CVEs this week, in line with the recent average. Severity skewed high: 18 critical and 76 high, 53% of the total. 12 arrived with exploitation evidence or public exploit code already attached. CISA added one CVE to the Known Exploited Vulnerabilities catalog. adobe was the most-affected vendor with 25.

178
New CVEs
18
Critical
1
KEV additions
0
Records changed

Added to CISA KEV

Confirmed exploitation in the wild — federal remediation deadlines attach to these.

New this week, ranked by depth score

The 12 that matter most of the 178 published.

CVE-2026-39808Critical· 9.8CISA KEVPoC
5mo ago

A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.8 may allow attacker to execute unauthorized code or commands via <insert attack vector…

A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.8 may allow attacker to execute unauthorized code or commands via <insert attack vector…

Hadalfortinet · fortisandboxEPSS 93%via NVD
CVE-2026-33824Critical· 9.8CISA KEVPoC
5mo ago

Double free in Windows IKE Extension allows an unauthorized attacker to execute code over a network.

Double free in Windows IKE Extension allows an unauthorized attacker to execute code over a network.

Hadalmicrosoft · windows_10_1607EPSS 73%via NVD
CVE-2026-20180Critical· 9.9PoC
5mo ago

A vulnerability in Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device

A vulnerability in Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device. To exploit this vulnerability, the attacker mus…

Abyssalcisco · identity_services_engineEPSS 6.0%via NVD
CVE-2026-41242Critical· 9.8PoC
5mo ago

protobufjs compiles protobuf definitions into JavaScript (JS) functions

protobufjs compiles protobuf definitions into JavaScript (JS) functions. In versions prior to 8.0.1 and 7.5.5, attackers can inject arbitrary code in the "type" fields of protobuf definitions, which will then execute during object decodi…

Abyssalprotobufjs_project · protobufjsEPSS 0.77%via NVD
CVE-2026-40477Critical· 9.0PoC
5mo ago

Thymeleaf is a server-side Java template engine for web and standalone environments

Thymeleaf is a server-side Java template engine for web and standalone environments. Versions 3.1.3.RELEASE and prior contain a security bypass vulnerability in the expression execution mechanisms. Although the library provides mechanism…

Abyssalthymeleaf · thymeleafEPSS 0.85%via NVD
CVE-2026-32202Medium· 4.3CISA KEVPoC
5mo ago

Protection mechanism failure in Windows Shell allows an unauthorized attacker to perform spoofing over a network.

Protection mechanism failure in Windows Shell allows an unauthorized attacker to perform spoofing over a network.

Midnightmicrosoft · windows_10_1607EPSS 64%via NVD
CVE-2026-41490High· 8.3PoC
5mo ago

Dagster Vulnerable to SQL Injection via Dynamic Partition Keys in Database I/O Manager Integrations

Dagster Vulnerable to SQL Injection via Dynamic Partition Keys in Database I/O Manager Integrations

Midnightdagster-duckdb · dagster-duckdbEPSS 0.27%via OSV
CVE-2026-20147Critical· 9.9
5mo ago

A vulnerability in Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device

A vulnerability in Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device. To exploit this vulnerability, the attacker must have va…

Midnightcisco · identity_services_engine_passive_identity_connectorEPSS 10%via NVD
CVE-2026-20186Critical· 9.9
5mo ago

A vulnerability in Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device

A vulnerability in Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device. To exploit this vulnerability, the attacker mus…

Midnightcisco · identity_services_engineEPSS 5.6%via NVD
CVE-2026-31843Critical· 9.8
5mo ago

The goodoneuz/pay-uz Laravel package (<= 2.2.24) contains a critical vulnerability in the /payment/api/editable/update endpoint that allows unauthenticated attackers to overwrite existing PHP payment hook files

The goodoneuz/pay-uz Laravel package (<= 2.2.24) contains a critical vulnerability in the /payment/api/editable/update endpoint that allows unauthenticated attackers to overwrite existing PHP payment hook files. The endpoint is exposed v…

MidnightEPSS 1.4%via NVD
CVE-2026-5189Critical· 9.8
5mo ago

CWE-798: Use of Hard-coded Credentials in Sonatype Nexus Repository Manager versions 3.0.0 through 3.70.5 allows an unauthenticated attacker with network access to gain unauthorized read/write access to the internal database and execute …

CWE-798: Use of Hard-coded Credentials in Sonatype Nexus Repository Manager versions 3.0.0 through 3.70.5 allows an unauthenticated attacker with network access to gain unauthorized read/write access to the internal database and execute …

Midnightsonatype · nexus_repository_managerEPSS 0.53%via NVD
CVE-2026-31414Critical· 9.8
5mo ago

netfilter: nf_conntrack_expect: use expect->helper

In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conntrack_expect: use expect->helper Use expect->helper in ctnetlink and /proc to dump the helper name. Using nfct_help() without holding a reference to …

MidnightLinux · LinuxEPSS 0.40%via CVEORG

Most-affected vendors

By CVEs published in the period.