VulnSea

Weekly digest

Week 18, 2026 (27 Apr – 3 May)

108 new CVEs this week, in line with the recent average. Severity skewed high: 8 critical and 48 high, 52% of the total. 11 arrived with exploitation evidence or public exploit code already attached. CISA added 2 CVEs to the Known Exploited Vulnerabilities catalog. Linux was the most-affected vendor with 23.

108
New CVEs
8
Critical
2
KEV additions
0
Records changed

Added to CISA KEV

Confirmed exploitation in the wild — federal remediation deadlines attach to these.

New this week, ranked by depth score

The 12 that matter most of the 108 published.

CVE-2026-40453Critical· 9.9PoC
4mo ago

The fix for CVE-2025-27636 added setLowerCase(true) to HttpHeaderFilterStrategy so that case-variant header names such as 'CAmelExecCommandExecutable' are filtered out alongside 'CamelExecCommandExecutable'

The fix for CVE-2025-27636 added setLowerCase(true) to HttpHeaderFilterStrategy so that case-variant header names such as 'CAmelExecCommandExecutable' are filtered out alongside 'CamelExecCommandExecutable'. The same setLowerCase(true) c…

AbyssalEPSS 1.6%via NVD
CVE-2026-40860Critical· 9.8PoC⚖ disputed
4mo ago

JmsBinding.extractBodyFromJms() in camel-jms, and the equivalent JmsBinding class in camel-sjms, deserialized the payload of incoming JMS ObjectMessage values via javax.jms.ObjectMessage.getObject() without applying any ObjectInputFilter…

JmsBinding.extractBodyFromJms() in camel-jms, and the equivalent JmsBinding class in camel-sjms, deserialized the payload of incoming JMS ObjectMessage values via javax.jms.ObjectMessage.getObject() without applying any ObjectInputFilter…

Abyssalapache · camelEPSS 1.2%via NVD
CVE-2026-40280Critical· 9.3PoC
4mo ago

Gotenberg has case-insensitive URL scheme that bypasses webhook and downloadFrom deny-list SSRF protection

Gotenberg has case-insensitive URL scheme that bypasses webhook and downloadFrom deny-list SSRF protection

Abyssalgotenberg · github.com/gotenberg/gotenberg/v8EPSS 1.9%via OSV
CVE-2026-33454Critical· 9.4PoC
4mo ago

The Camel-Mail component is vulnerable to Camel message header injection

The Camel-Mail component is vulnerable to Camel message header injection. The custom header filter strategy used by the component (MailHeaderFilterStrategy) only filters the 'out' direction via setOutFilterStartsWith, while it does not c…

AbyssalEPSS 0.62%via NVD
CVE-2026-40858High· 8.8PoC
4mo ago

The camel-infinispan component's ProtoStream-based remote aggregation repository deserializes data read from a remote Infinispan cache using java.io.ObjectInputStream without applying any ObjectInputFilter

The camel-infinispan component's ProtoStream-based remote aggregation repository deserializes data read from a remote Infinispan cache using java.io.ObjectInputStream without applying any ObjectInputFilter. An attacker who can write to t…

Midnightapache · camelEPSS 0.93%via NVD
CVE-2026-42167High· 8.1PoC
4mo ago

mod_sql in ProFTPD before 1.3.9a allows remote attackers to execute arbitrary code via a username, in scenarios where there is logging of USER requests with an expansion such as %U, and the SQL backend allows commands (e.g., COPY TO PROG…

mod_sql in ProFTPD before 1.3.9a allows remote attackers to execute arbitrary code via a username, in scenarios where there is logging of USER requests with an expansion such as %U, and the SQL backend allows commands (e.g., COPY TO PROG…

Midnightproftpd · proftpdEPSS 7.4%via NVD
CVE-2026-31694High· 7.8PoC
4mo ago

In the Linux kernel, the following vulnerability has been resolved: fuse: reject oversized dirents in page cache fuse_add_dirent_to_cache() computes a serialized dirent size from the server-controlled namelen field and copies the diren…

In the Linux kernel, the following vulnerability has been resolved: fuse: reject oversized dirents in page cache fuse_add_dirent_to_cache() computes a serialized dirent size from the server-controlled namelen field and copies the diren…

Midnightlinux · linux_kernelEPSS 0.28%via NVD
CVE-2026-43038Critical· 9.8
4mo ago

In the Linux kernel, the following vulnerability has been resolved: ipv6: icmp: clear skb2->cb[] in ip6_err_gen_icmpv6_unreach() Sashiko AI-review observed: In ip6_err_gen_icmpv6_unreach(), the skb is an outer IPv4 ICMP error packet…

In the Linux kernel, the following vulnerability has been resolved: ipv6: icmp: clear skb2->cb[] in ip6_err_gen_icmpv6_unreach() Sashiko AI-review observed: In ip6_err_gen_icmpv6_unreach(), the skb is an outer IPv4 ICMP error packet…

Midnightlinux · linux_kernelEPSS 0.26%via NVD
CVE-2026-43037Critical· 9.8
4mo ago

In the Linux kernel, the following vulnerability has been resolved: ip6_tunnel: clear skb2->cb[] in ip4ip6_err() Oskar Kjos reported the following problem. ip4ip6_err() calls icmp_send() on a cloned skb whose cb[] was written by the I…

In the Linux kernel, the following vulnerability has been resolved: ip6_tunnel: clear skb2->cb[] in ip4ip6_err() Oskar Kjos reported the following problem. ip4ip6_err() calls icmp_send() on a cloned skb whose cb[] was written by the I…

MidnightEPSS 0.56%via NVD
CVE-2026-43011Critical· 9.8
4mo ago

net/x25: Fix potential double free of skb

In the Linux kernel, the following vulnerability has been resolved: net/x25: Fix potential double free of skb When alloc_skb fails in x25_queue_rx_frame it calls kfree_skb(skb) at line 48 and returns 1 (error). This error propagates ba…

MidnightLinux · LinuxEPSS 0.59%via CVEORG
CVE-2026-42031HighPoC
4mo ago

CKAN has Unauthenticated SQL Injection and Authorization Bypass in `datastore_search_sql`

CKAN has Unauthenticated SQL Injection and Authorization Bypass in `datastore_search_sql`

Midnightckan · ckanEPSS 1.8%via OSV
CVE-2026-32644Critical· 9.8
4mo ago

Specific firmware versions of Milesight AIOT cameras use SSL certificates with default private keys.

Specific firmware versions of Milesight AIOT cameras use SSL certificates with default private keys.

MidnightEPSS 0.22%via NVD

Most-affected vendors

By CVEs published in the period.