VulnSea

Weekly digest

Week 36, 2026 (31 Aug – 6 Sep)

A busier-than-usual week with 1,248 new CVEs (recent average about 985). Of those, 145 critical and 470 high. 205 arrived with exploitation evidence or public exploit code already attached. CISA added 8 CVEs to the Known Exploited Vulnerabilities catalog. 3 CVEs saw exploit probability (EPSS) jump by ten points or more. ibm was the most-affected vendor with 48.

1248
New CVEs
145
Critical
8
KEV additions
11
Records changed

Added to CISA KEV

Confirmed exploitation in the wild — federal remediation deadlines attach to these.

CVE-2026-9586Critical· 9.8CISA KEVPoC
2mo ago

An unauthenticated SQL injection vulnerability exists in Sangoma Switchvox SMB Edition 8.3 (104997). The /pa endpoint processes XML content beginning with <PolycomIPPhone> and directly concatenates the user-controlled PhoneIP value into …

An unauthenticated SQL injection vulnerability exists in Sangoma Switchvox SMB Edition 8.3 (104997). The /pa endpoint processes XML content beginning with <PolycomIPPhone> and directly concatenates the user-controlled PhoneIP value into …

Hadalsangoma · switchvoxEPSS 12%via NVD
CVE-2026-81578Critical· 9.8CISA KEVPoC
3w ago

An improper access control vulnerability exists in the web management interface of PaperCut MF and PaperCut NG

An improper access control vulnerability exists in the web management interface of PaperCut MF and PaperCut NG. Under specific conditions, unauthenticated remote requests targeting administrative functions can trigger backend actions pri…

Hadalpapercut · papercut_mfEPSS 3.3%via NVD
CVE-2026-49869Critical· 10.0CISA KEVPoC
2mo ago

Kestra is an open-source, event-driven orchestration platform

Kestra is an open-source, event-driven orchestration platform. Prior to 1.0.45 and 1.3.21, AuthenticationFilter in Kestra OSS uses request.getPath().endsWith("/configs") to whitelist the public configuration endpoint from Basic Auth. Bec…

Hadalkestra · kestraEPSS 1.9%via NVD
CVE-2026-82078Critical· 9.4CISA KEVPoC
3w ago

PaperCut MF/NG: Unsafe Dynamic Class Loading in Database Connector

An unsafe dynamic class loading vulnerability exists in the database connection utilities of PaperCut MF and PaperCut NG. The application instantiates database driver classes based on configurable driver names without validating against …

HadalPaperCut · PaperCut MF/NGEPSS 3.6%via CVEORG
CVE-2026-85046High· 8.8CISA KEV0dayPoC
2w ago

Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page

Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

Abyssalgoogle · chromeEPSS 1.5%via NVD
CVE-2026-83549High· 7.8CISA KEV0dayPoC
2w ago

Post-authentication Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific conditions could potenti…

Post-authentication Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific conditions could potenti…

Abyssalsonicwall · sma8200vEPSS 8.5%via NVD
CVE-2026-59822High· 8.2CISA KEVPoC
2mo ago

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.84.0, LiteLLM's MCP Streamable HTTP endpoint allowed an unauthenticated attacker to use a fabricated Authorization header to trigger an OAut…

Abyssallitellm · litellmEPSS 0.87%via NVD
CVE-2026-48710Medium· 6.5CISA KEVPoC
3mo ago

Starlette is a lightweight ASGI framework/toolkit

Starlette is a lightweight ASGI framework/toolkit. Prior to version 1.0.1, the HTTP `Host` request header was not validated before being used to reconstruct `request.url`. Because the routing algorithm relies on the raw HTTP path while `…

Midnightstarlette · starletteEPSS 36%via NVD

Rising exploit probability

Largest EPSS increases inside the period (≥ 10 points).

  • CVE-2026-48710Medium· 6.5Starlette is a lightweight ASGI framework/toolkit2.1%36%
  • CVE-2026-73570High· 8.9A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp package is installed and SNMP notifications are enabled21%32%
  • CVE-2026-9198Critical· 9.8IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to chain /api/v1/auto_login (mints SUPERUSER tokens to any network caller) with /api/v1/validate/code (executes user code via exec()) to achieve full RCE on default L…45%57%

New this week, ranked by depth score

The 12 that matter most of the 1248 published.

CVE-2026-86218Critical· 9.8CISA KEVPoC
2w ago

N-central is vulnerable to a pre-auth remote code execution This issue affects N-central: before 2026.3.1.14.

N-central is vulnerable to a pre-auth remote code execution This issue affects N-central: before 2026.3.1.14.

Hadaln-able · n-centralEPSS 7.5%via NVD
CVE-2026-86060Critical· 9.8CISA KEVPoC
2w ago

RouterOS contains an argument-handling flaw in the SSH login path involving usernames that begin with a prohibited character, allowing for the trusted RouterOS policy mask to be changed, leading to privilege escalation

RouterOS contains an argument-handling flaw in the SSH login path involving usernames that begin with a prohibited character, allowing for the trusted RouterOS policy mask to be changed, leading to privilege escalation. Exploitation requ…

Hadalmikrotik · routerosEPSS 1.1%via NVD
CVE-2026-85046High· 8.8CISA KEV0dayPoC
2w ago

Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page

Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

Abyssalgoogle · chromeEPSS 1.5%via NVD
MAL-2026-15938Critical⚠ Exploited
2w ago

Malicious code in dac-tools (PyPI)

Malicious code in dac-tools (PyPI)

Abyssaldac-tools · dac-toolsvia OSV
MAL-2026-15935Critical⚠ Exploited
2w ago

Malicious code in proxycer (PyPI)

Malicious code in proxycer (PyPI)

Abyssalproxycer · proxycervia OSV
CVE-2026-67277High· 8.2CISA KEVPoC
2w ago

RouterOS accepts a "related" btest connection before the corresponding primary session has completed authentication

RouterOS accepts a "related" btest connection before the corresponding primary session has completed authentication. An unauthenticated client can use this state to start an IPv4 UDP test. With "random-data=false", the sender transmits a…

Abyssalmikrotik · routerosEPSS 0.87%via NVD
MAL-2026-16044Critical⚠ Exploited
2w ago

Malicious code in tsshare (PyPI)

Malicious code in tsshare (PyPI)

Abyssaltsshare · tssharevia OSV
MAL-2026-15931Critical⚠ Exploited
2w ago

Malicious code in metricboxlite (PyPI)

Malicious code in metricboxlite (PyPI)

Abyssalmetricboxlite · metricboxlitevia OSV
MAL-2026-15864Critical⚠ Exploited
2w ago

Malicious code in asti (PyPI)

Malicious code in asti (PyPI)

Abyssalasti · astivia OSV
MAL-2026-15810Critical⚠ Exploited
2w ago

Malicious code in gcphelpit (PyPI)

Malicious code in gcphelpit (PyPI)

Abyssalgcphelpit · gcphelpitvia OSV
CVE-2026-83549High· 7.8CISA KEV0dayPoC
2w ago

Post-authentication Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific conditions could potenti…

Post-authentication Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific conditions could potenti…

Abyssalsonicwall · sma8200vEPSS 8.5%via NVD
MAL-2026-15603Critical⚠ Exploited
3w ago

Malicious code in pyservercheck (PyPI)

Malicious code in pyservercheck (PyPI)

Abyssalpyservercheck · pyservercheckvia OSV

Most-changed records

Existing CVEs whose severity, score, KEV or exploitation status moved.

  • CVE-2026-48710Starlette is a lightweight ASGI framework/toolkit68
  • CVE-2026-9198IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to chain /api/v1/auto_login (mints SUPERUSER tokens to any network caller) with /api/v1/validate/code (executes user code via exec()) to achieve full RCE on default L…91
  • CVE-2017-8046Malicious PATCH requests submitted to servers using Spring Data REST versions prior to 2.6.9 (Ingalls SR9), versions prior to 3.0.1 (Kay SR1) and Spring Boot versions prior to 1.5.9, 2.0 M6 can use specially crafted JSON data to run arbi…83
  • CVE-2018-0101A vulnerability in the Secure Sockets Layer (SSL) VPN functionality of the Cisco Adaptive Security Appliance (ASA) Software could allow an unauthenticated, remote attacker to cause a reload of the affected system or to remotely execute c…82
  • CVE-2026-59822LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format70
  • CVE-2025-60689An unauthenticated command injection vulnerability exists in the Start_EPI function of the httpd binary on Linksys E1200 v2 routers (Firmware E1200_v2.0.11.001_us.tar.gz)45
  • CVE-2025-67038An issue was discovered in Lantronix EDS5000 2.1.0.0R383
  • CVE-2026-73570A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp package is installed and SNMP notifications are enabled80

Most-affected vendors

By CVEs published in the period.