VulnSea

Weekly digest

Week 33, 2026 (10–16 Aug)

A heavy week: 1,432 new CVEs, well above the recent average of about 759. Severity skewed high: 140 critical and 656 high, 56% of the total. 40 arrived with exploitation evidence or public exploit code already attached. CISA added 2 CVEs to the Known Exploited Vulnerabilities catalog. One CVE saw exploit probability (EPSS) jump by ten points or more. Microsoft was the most-affected vendor with 407.

1432
New CVEs
140
Critical
2
KEV additions
6
Records changed

Added to CISA KEV

Confirmed exploitation in the wild — federal remediation deadlines attach to these.

Rising exploit probability

Largest EPSS increases inside the period (≥ 10 points).

  • CVE-2026-58644Critical· 9.8Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.6.4%45%

New this week, ranked by depth score

The 12 that matter most of the 1432 published.

CVE-2026-73570High· 8.9CISA KEVPoC
1mo ago

A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp package is installed and SNMP notifications are enabled

A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp package is installed and SNMP notifications are enabled. Due to improper sanitization of untrusted input during SNMP …

Abyssalsynacor · zimbra_collaboration_suiteEPSS 32%via NVD
CVE-2026-20349High· 8.6CISA KEV0dayPoC
1mo ago

A vulnerability in the Remote Access SSL VPN service for Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause th…

A vulnerability in the Remote Access SSL VPN service for Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause th…

Abyssalcisco · adaptive_security_appliance_softwareEPSS 2.2%via NVD
CVE-2026-42018High· 7.5CISA KEVPoC
1mo ago

Anonymous user token generation exposure in JFrog Artifactory

JFrog Artifactory could return an internal anonymous-user token to an unauthenticated caller when anonymous access is disabled, potentially exposing sensitive resources.

Abyssaljfrog · artifactoryEPSS 11%via CVEORG
CVE-2026-15826Critical· 9.8PoC
1mo ago

The User Profile Builder plugin for WordPress is vulnerable to Authentication Bypass via Type Confusion in versions up to, and including, 3.16.4

The User Profile Builder plugin for WordPress is vulnerable to Authentication Bypass via Type Confusion in versions up to, and including, 3.16.4. This is due to the wppb_log_in_user() function calling absint() on the return value of wp_i…

AbyssalEPSS 3.9%via NVD
CVE-2026-71362Critical· 9.1PoC
1mo ago

Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation

Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain elevated access to sensitive resources. Exploitation of this issue do…

Abyssaladobe · commerceEPSS 25%via NVD
CVE-2026-19598Critical· 9.8PoC
1mo ago

The Pods – Custom Content Types and Fields plugin for WordPress is vulnerable to Privilege Escalation via Authorization Bypass in all versions up to, and including, 3.3.9

The Pods – Custom Content Types and Fields plugin for WordPress is vulnerable to Privilege Escalation via Authorization Bypass in all versions up to, and including, 3.3.9. The vulnerability exists because the pods_admin AJAX router funne…

AbyssalEPSS 2.8%via NVD
CVE-2026-49819Critical· 9.8PoC
1mo ago

UpSnap is a wake on lan web app

UpSnap is a wake on lan web app. Versions 4.4.1 through 5.3.5 are vulnerable to a missing-authentication / privilege-escalation chain in `pb.HandlerInitSuperuser` (`backend/pb/handlers.go:249`), reachable as `POST /api/upsnap/init-superu…

Abyssalseriousm4x · UpSnapEPSS 0.79%via NVD
CVE-2026-63297Critical· 9.9PoC
1mo ago

An authorization bypass vulnerability in LXD due to a timing flaw during configuration merging allows an authenticated attacker to bypass target project restrictions during cross-project instance copies

An authorization bypass vulnerability in LXD due to a timing flaw during configuration merging allows an authenticated attacker to bypass target project restrictions during cross-project instance copies. When copying an instance to a tar…

Abyssalcanonical · lxdEPSS 0.24%via NVD
CVE-2026-46670Critical· 9.8PoC
1mo ago

YesWiki is a wiki system written in PHP

YesWiki is a wiki system written in PHP. Prior to version 4.6.4, an unauthenticated SQL injection in the Bazar form-import path (`FormManager::create()`) allows any unauthenticated visitor of a default YesWiki install to inject arbitrar…

AbyssalEPSS 1.9%via NVD
CVE-2026-68820High· 7.0CISA KEV0dayPoC
1mo ago

Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability

Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

AbyssalMicrosoft · Windows 10 Version 1607EPSS 6.2%via CVEORG
CVE-2026-73296Critical· 9.4PoC
1mo ago

Microsoft UFO open-source framework for intelligent automation across devices and platforms

Microsoft UFO open-source framework for intelligent automation across devices and platforms. Prior to 3.0.8, create_mobile_data_collection_server and create_mobile_action_server in ufo/client/mcp/http_servers/mobile_mcp_server.py exposed…

AbyssalEPSS 2.9%via NVD
CVE-2026-48046Critical· 9.3PoC
1mo ago

Streambert is a cross-platform Electron Desktop App to stream and download video content

Streambert is a cross-platform Electron Desktop App to stream and download video content. Versions prior to 2.5.0 contain an unvalidated auto-updater URL vulnerability that allows a compromised renderer process to make the main process d…

Abyssaltruelockmc · streambertEPSS 0.35%via NVD

Most-changed records

Existing CVEs whose severity, score, KEV or exploitation status moved.

  • CVE-2026-58644Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.91
  • CVE-2021-31196Microsoft Exchange Server Remote Code Execution Vulnerability75
  • CVE-2026-61447PraisonAI before 1.6.78 contains a remote code execution vulnerability in CodeAgent._execute_python() that executes LLM-generated Python code without AST validation, import restrictions, or sandbox enforcement67
  • CVE-2026-61459MCP Server Kubernetes before 3.9.0 contains an argument injection vulnerability in structured tools (kubectl_get, kubectl_describe, kubectl_delete) that allows attackers to bypass the assertNoDangerousFlags security check by supplying re…66
  • CVE-2026-61876LuCI versions fail to properly encode DHCPv6 lease hostnames before rendering in status tables, allowing adjacent network attackers to inject HTML markup61
  • CVE-2026-3576The Planyo Online Reservation System plugin for WordPress is vulnerable to Server-Side Request Forgery leading to Local File Inclusion in all versions up to, and including, 3.054

Most-affected vendors

By CVEs published in the period.