VulnSea

Weekly digest

Week 35, 2026 (24–30 Aug)

958 new CVEs this week, in line with the recent average. Of those, 102 critical and 345 high. 41 arrived with exploitation evidence or public exploit code already attached. CISA added 9 CVEs to the Known Exploited Vulnerabilities catalog. 5 CVEs saw exploit probability (EPSS) jump by ten points or more. google was the most-affected vendor with 63.

958
New CVEs
102
Critical
9
KEV additions
39
Records changed

Added to CISA KEV

Confirmed exploitation in the wild — federal remediation deadlines attach to these.

CVE-2026-60004Critical· 9.8CISA KEV0dayPoC
3w ago

Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation.

Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation.

HadalGitea · GiteaEPSS 87%via CVEORG
CVE-2026-21962Critical· 10.0CISA KEVPoC
8mo ago

Vulnerability in the Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in product of Oracle Fusion Middleware (component: Weblogic Server Proxy Plug-in for Apache HTTP Server, Weblogic Server Proxy Plug-in for IIS)

Vulnerability in the Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in product of Oracle Fusion Middleware (component: Weblogic Server Proxy Plug-in for Apache HTTP Server, Weblogic Server Proxy Plug-in for IIS). Supported versio…

Hadaloracle · http_serverEPSS 42%via NVD
CVE-2023-49105Critical· 9.8CISA KEVPoC
2y ago

An issue was discovered in ownCloud owncloud/core before 10.13.1

An issue was discovered in ownCloud owncloud/core before 10.13.1. An attacker can access, modify, or delete any file without authentication if the username of a victim is known, and the victim has no signing-key configured. This occurs b…

Hadalowncloud · owncloud_serverEPSS 43%via NVD
CVE-2021-23758High· 8.1CISA KEVPoC
4y ago

All versions of package ajaxpro.2 are vulnerable to Deserialization of Untrusted Data due to the possibility of deserialization of arbitrary .NET classes, which can be abused to gain remote code execution.

All versions of package ajaxpro.2 are vulnerable to Deserialization of Untrusted Data due to the possibility of deserialization of arbitrary .NET classes, which can be abused to gain remote code execution.

Abyssalajaxpro.2_project · ajaxpro.2EPSS 84%via NVD
CVE-2019-1068High· 8.8CISA KEVPoC
7y ago

A remote code execution vulnerability exists in Microsoft SQL Server when it incorrectly handles processing of internal functions, aka 'Microsoft SQL Server Remote Code Execution Vulnerability'.

A remote code execution vulnerability exists in Microsoft SQL Server when it incorrectly handles processing of internal functions, aka 'Microsoft SQL Server Remote Code Execution Vulnerability'.

Abyssalmicrosoft · sql_serverEPSS 53%via NVD
CVE-2022-0995High· 7.8CISA KEVPoC
4y ago

An out-of-bounds (OOB) memory write flaw was found in the Linux kernel’s watch_queue event notification subsystem

An out-of-bounds (OOB) memory write flaw was found in the Linux kernel’s watch_queue event notification subsystem. This flaw can overwrite parts of the kernel state, potentially allowing a local user to gain privileged access or cause a …

Abyssallinux · linux_kernelEPSS 9.4%via NVD
CVE-2015-5287High· 7.8CISA KEVPoC
10y ago

The abrt-hook-ccpp help program in Automatic Bug Reporting Tool (ABRT) before 2.7.1 allows local users with certain permissions to gain privileges via a symlink attack on a file with a predictable name, as demonstrated by /var/tmp/abrt/a…

The abrt-hook-ccpp help program in Automatic Bug Reporting Tool (ABRT) before 2.7.1 allows local users with certain permissions to gain privileges via a symlink attack on a file with a predictable name, as demonstrated by /var/tmp/abrt/a…

Abyssalredhat · automatic_bug_reporting_toolEPSS 5.0%via NVD
CVE-2015-3246Medium· 5.1CISA KEVPoC
11y ago

libuser before 0.56.13-8 and 0.60 before 0.60-7, as used in the userhelper program in the usermode package, directly modifies /etc/passwd, which allows local users to cause a denial of service (inconsistent file state) by causing an erro…

libuser before 0.56.13-8 and 0.60 before 0.60-7, as used in the userhelper program in the usermode package, directly modifies /etc/passwd, which allows local users to cause a denial of service (inconsistent file state) by causing an erro…

Midnightredhat · libuserEPSS 8.8%via NVD
CVE-2026-53362NoneCISA KEVPoC
2mo ago

In the Linux kernel, the following vulnerability has been resolved: ipv6: account for fraggap on the paged allocation path In __ip6_append_data(), when the paged-allocation branch is taken (MSG_MORE / NETIF_F_SG / large fraglen), alloc…

In the Linux kernel, the following vulnerability has been resolved: ipv6: account for fraggap on the paged allocation path In __ip6_append_data(), when the paged-allocation branch is taken (MSG_MORE / NETIF_F_SG / large fraglen), alloc…

TwilightEPSS 0.51%via NVD

Rising exploit probability

Largest EPSS increases inside the period (≥ 10 points).

  • CVE-2026-18577NoneAn incomplete patch for CVE-2026-18556 allows for authentication bypass and account takeover in N-central Versions through 2026.3.16.2%54%
  • CVE-2026-18556NoneAuthentication bypass using an alternate path or channel vulnerability in N-able N-central allows Authentication Bypass. This issue affects N-central: through 2026.1.3.9%40%
  • CVE-2023-49105Critical· 9.8An issue was discovered in ownCloud owncloud/core before 10.13.111%43%
  • CVE-2026-73570High· 8.9A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp package is installed and SNMP notifications are enabled1.5%21%
  • CVE-2025-34027NoneThe Versa Concerto SD-WAN orchestration platform is vulnerable to an authentication bypass in the Traefik reverse proxy configuration, allowing at attacker to access administrative endpoints32%45%

New this week, ranked by depth score

The 12 that matter most of the 958 published.

CVE-2026-60004Critical· 9.8CISA KEV0dayPoC
3w ago

Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation.

Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation.

HadalGitea · GiteaEPSS 87%via CVEORG
CVE-2026-81578Critical· 9.8CISA KEVPoC
3w ago

An improper access control vulnerability exists in the web management interface of PaperCut MF and PaperCut NG

An improper access control vulnerability exists in the web management interface of PaperCut MF and PaperCut NG. Under specific conditions, unauthenticated remote requests targeting administrative functions can trigger backend actions pri…

Hadalpapercut · papercut_mfEPSS 3.3%via NVD
CVE-2026-82078Critical· 9.4CISA KEVPoC
3w ago

PaperCut MF/NG: Unsafe Dynamic Class Loading in Database Connector

An unsafe dynamic class loading vulnerability exists in the database connection utilities of PaperCut MF and PaperCut NG. The application instantiates database driver classes based on configurable driver names without validating against …

HadalPaperCut · PaperCut MF/NGEPSS 3.6%via CVEORG
MAL-2026-14545Critical⚠ Exploited
3w ago

Malicious code in pybitjs (PyPI)

Malicious code in pybitjs (PyPI)

Abyssalpybitjs · pybitjsvia OSV
MAL-2026-15693Critical⚠ Exploited
4w ago

Malicious code in py-devoli-common (PyPI)

Malicious code in py-devoli-common (PyPI)

Abyssalpy-devoli-common · py-devoli-commonvia OSV
CVE-2026-82456Critical· 10.0PoC
3w ago

argocd-mcp 0.8.0 binds its HTTP transport to every network interface and accepts MCP sessions without requiring caller credentials when ARGOCD_API_TOKEN is configured

argocd-mcp 0.8.0 binds its HTTP transport to every network interface and accepts MCP sessions without requiring caller credentials when ARGOCD_API_TOKEN is configured. Attackers who can reach the listener can invoke the full tool surface…

AbyssalEPSS 1.4%via NVD
CVE-2026-47884Critical· 9.8PoC
3w ago

Use of XsltView in a Spring MVC application can result in SSRF and RCE attack if the application has an "/**" mapping that results in view rendering, and where the view name is not explicitly specified. Spring Framework 7.0.0 - 7.0.8 Spr…

Use of XsltView in a Spring MVC application can result in SSRF and RCE attack if the application has an "/**" mapping that results in view rendering, and where the view name is not explicitly specified. Spring Framework 7.0.0 - 7.0.8 Spr…

Abyssalvmware · spring_frameworkEPSS 0.42%via NVD
CVE-2026-80428Critical· 9.8PoC
3w ago

ILIAS before versions 9.22, 10.10, and 11.3 contains an unauthenticated PHP object injection vulnerability that allows unauthenticated attackers to execute arbitrary code by injecting serialized objects through the LTI authentication end…

ILIAS before versions 9.22, 10.10, and 11.3 contains an unauthenticated PHP object injection vulnerability that allows unauthenticated attackers to execute arbitrary code by injecting serialized objects through the LTI authentication end…

AbyssalEPSS 2.3%via NVD
CVE-2026-56705Critical· 9.8PoC
3w ago

Adminer before 5.4.3 fails to sanitize the server field before constructing a PDO DSN string, allowing unauthenticated attackers to inject ODBC parameters via semicolons

Adminer before 5.4.3 fails to sanitize the server field before constructing a PDO DSN string, allowing unauthenticated attackers to inject ODBC parameters via semicolons. Attackers can inject TraceFile and TraceOn parameters to write PHP…

AbyssalEPSS 0.50%via NVD
CVE-2026-49757CriticalPoC
3w ago

AshAuthentication vulnerable to OAuth2/OIDC account takeover via email-based user matching

AshAuthentication vulnerable to OAuth2/OIDC account takeover via email-based user matching

Abyssalash_authentication · ash_authenticationEPSS 0.61%via GHSA
CVE-2026-77635CriticalPoC
4w ago

CakePHP is a rapid development framework for PHP

CakePHP is a rapid development framework for PHP. Prior to versions 5.1.10, 5.2.15, and 5.3.7 on their respective release lines, FunctionsBuilder::jsonValue() with PostgresDriver is vulnerable to SQL injection when user-controlled data i…

Abyssalcakephp · cakephp/cakephpEPSS 0.29%via NVD
CVE-2026-82539Critical· 9.1PoC
3w ago

A vulnerability was determined in TOTOLINK A720R 4.1.5cu.630_B20250509

A vulnerability was determined in TOTOLINK A720R 4.1.5cu.630_B20250509. This impacts the function setMacFilterRules of the file cstecgi.cgi of the component MAC Filtering. Executing a manipulation of the argument desc can lead to memory …

AbyssalEPSS 0.60%via NVD

Most-changed records

Existing CVEs whose severity, score, KEV or exploitation status moved.

  • CVE-2019-1068A remote code execution vulnerability exists in Microsoft SQL Server when it incorrectly handles processing of internal functions, aka 'Microsoft SQL Server Remote Code Execution Vulnerability'.84
  • CVE-2017-8046Malicious PATCH requests submitted to servers using Spring Data REST versions prior to 2.6.9 (Ingalls SR9), versions prior to 3.0.1 (Kay SR1) and Spring Boot versions prior to 1.5.9, 2.0 M6 can use specially crafted JSON data to run arbi…83
  • CVE-2018-0101A vulnerability in the Secure Sockets Layer (SSL) VPN functionality of the Cisco Adaptive Security Appliance (ASA) Software could allow an unauthenticated, remote attacker to cause a reload of the affected system or to remotely execute c…82
  • CVE-2026-16232An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges89
  • CVE-2026-66066Action Pack is a framework for handling and responding to web requests70
  • CVE-2026-53362In the Linux kernel, the following vulnerability has been resolved: ipv6: account for fraggap on the paged allocation path In __ip6_append_data(), when the paged-allocation branch is taken (MSG_MORE / NETIF_F_SG / large fraglen), alloc…28
  • CVE-2026-45659Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.94
  • CVE-2026-33824Double free in Windows IKE Extension allows an unauthorized attacker to execute code over a network.93

Most-affected vendors

By CVEs published in the period.