Weekly digest
Week 19, 2026 (4–10 May)
A busier-than-usual week with 282 new CVEs (recent average about 204). Of those, 26 critical and 110 high. 21 arrived with exploitation evidence or public exploit code already attached. CISA added one CVE to the Known Exploited Vulnerabilities catalog. Linux was the most-affected vendor with 22.
Added to CISA KEV
Confirmed exploitation in the wild — federal remediation deadlines attach to these.
New this week, ranked by depth score
The 12 that matter most of the 282 published.
CVE-2026-42208Critical· 9.8CISA KEV0dayPoCLiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format
LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. From version 1.81.16 to before version 1.83.7, a database query used during proxy API key checks mixed the caller-supplied key value into the query tex…
CVE-2026-42271High· 8.8CISA KEVPoCLiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format
LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. From version 1.74.2 to before version 1.83.7, two endpoints used to preview an MCP server before saving it — POST /mcp-rest/test/connection and POST /m…
CVE-2026-43284High· 8.8PoCIn the Linux kernel, the following vulnerability has been resolved: xfrm: esp: avoid in-place decrypt on shared skb frags MSG_SPLICE_PAGES can attach pages from a pipe directly to an skb
In the Linux kernel, the following vulnerability has been resolved: xfrm: esp: avoid in-place decrypt on shared skb frags MSG_SPLICE_PAGES can attach pages from a pipe directly to an skb. TCP marks such skbs with SKBFL_SHARED_FRAG afte…
CVE-2026-38360Critical· 9.8PoCdash-uploader has a directory traversal vulnerability
dash-uploader has a directory traversal vulnerability
CVE-2026-42880Critical· 9.6PoCArgoCD ServerSideDiff is vulnerable to Kubernetes Secret Extraction
ArgoCD ServerSideDiff is vulnerable to Kubernetes Secret Extraction
CVE-2026-42216Critical· 9.1PoCOpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry
OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From versions 3.0.0 to before 3.2.9, 3.3.0 to before 3.3.11, and 3.4.0 to before 3.4.11, IDM…
CVE-2026-7482Critical· 9.1PoCOllama contains a heap out-of-bounds read vulnerability in the GGUF model loader
Ollama contains a heap out-of-bounds read vulnerability in the GGUF model loader
CVE-2026-35397High· 8.8PoCJupyter Server is the backend for Jupyter web applications
Jupyter Server is the backend for Jupyter web applications. In versions 2.17.0 and earlier, a path traversal vulnerability in the REST API allows an authenticated user to escape the configured root_dir and access sibling directories whos…
CVE-2026-25243High· 8.8PoCRedis is an in-memory data structure store
Redis is an in-memory data structure store. In versions of redis-server up to 8.6.3, the RESTORE command does not properly validate serialized values. An authenticated attacker with permission to execute RESTORE can supply a crafted seri…
CVE-2026-23479High· 8.8PoCRedis is an in-memory data structure store
Redis is an in-memory data structure store. In redis-server from 7.2.0 until 8.6.3, the unblock client flow does not handle an error return from `processCommandAndResetClient` when re-executing a blocked command. If a blocked client is e…
CVE-2026-23631High· 8.1PoCRedis is an in-memory data structure store
Redis is an in-memory data structure store. In all versions of redis-server with Lua scripting, an authenticated attacker can exploit the master-replica synchronization mechanism to trigger a use-after-free on replicas where replica-read…
CVE-2026-8069High· 7.8PoCPredatorSense version 3.00.3136 to 3.00.3196 contain Local Privilege Escalation (LPE) vulnerability.The program exposes a Windows Named Pipe that uses a custom protocol to invoke internal functions
PredatorSense version 3.00.3136 to 3.00.3196 contain Local Privilege Escalation (LPE) vulnerability.The program exposes a Windows Named Pipe that uses a custom protocol to invoke internal functions. However, this Named Pipe is misconfigu…
Most-affected vendors
By CVEs published in the period.