Weekly digest
Week 37, 2026 (7–13 Sep)
A heavy week: 3,879 new CVEs, well above the recent average of about 1,058. Severity skewed high: 308 critical and 1,751 high, 53% of the total. 464 arrived with exploitation evidence or public exploit code already attached. CISA added 14 CVEs to the Known Exploited Vulnerabilities catalog. Microsoft was the most-affected vendor with 972.
Added to CISA KEV
Confirmed exploitation in the wild — federal remediation deadlines attach to these.
CVE-2026-20079Critical· 10.0CISA KEVPoCA vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to bypass authentication and execute script files on an affected device to obtain root access …
A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to bypass authentication and execute script files on an affected device to obtain root access …
CVE-2026-85706Critical· 10.0CISA KEV0dayPoCGitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.7 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that, under certain conditions, an unauthenticated user could have read arbitrary files from the Gi…
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.7 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that, under certain conditions, an unauthenticated user could have read arbitrary files from the Gi…
CVE-2026-86218Critical· 9.8CISA KEVPoCN-central is vulnerable to a pre-auth remote code execution This issue affects N-central: before 2026.3.1.14.
N-central is vulnerable to a pre-auth remote code execution This issue affects N-central: before 2026.3.1.14.
CVE-2026-84869Critical· 9.9CISA KEVPoCA condition in the ScreenConnect client may allow files to be transferred and executed through an active remote session without authorization or Host confirmation in certain circumstances
A condition in the ScreenConnect client may allow files to be transferred and executed through an active remote session without authorization or Host confirmation in certain circumstances. ScreenConnect servers are not impacted.
CVE-2026-75650Critical· 10.0CISA KEV0dayPoCAdobe Commerce is affected by an Improper Neutralization of Special Elements Used in a Template Engine vulnerability that could result in arbitrary code execution in the context of the current user
Adobe Commerce is affected by an Improper Neutralization of Special Elements Used in a Template Engine vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnera…
CVE-2026-19490Critical· 9.8CISA KEVPoCVulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: from 14.1 through 73.32 and from 13.1 through 63.21; Gateway: from 14.1 through 73.32 and from 13.1 through 63.21.
Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: from 14.1 through 73.32 and from 13.1 through 63.21; Gateway: from 14.1 through 73.32 and from 13.1 through 63.21.
CVE-2026-86060Critical· 9.8CISA KEVPoCRouterOS contains an argument-handling flaw in the SSH login path involving usernames that begin with a prohibited character, allowing for the trusted RouterOS policy mask to be changed, leading to privilege escalation
RouterOS contains an argument-handling flaw in the SSH login path involving usernames that begin with a prohibited character, allowing for the trusted RouterOS policy mask to be changed, leading to privilege escalation. Exploitation requ…
CVE-2026-87491High· 8.8CISA KEV0dayPoCOut of bounds write in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page
Out of bounds write in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-42016High· 8.1CISA KEVPoCIncorrect authorization validation of user token in JFrog Artifactory allows Privilege Escalation
JFrog Artifactory (Self Hosted) versions before 7.133.11 are vulnerable to a privilege escalation attack due to a validation check of the token signature/issuer and not the token’s scope.
CVE-2026-67277High· 8.2CISA KEVPoCRouterOS accepts a "related" btest connection before the corresponding primary session has completed authentication
RouterOS accepts a "related" btest connection before the corresponding primary session has completed authentication. An unauthenticated client can use this state to start an IPv4 UDP test. With "random-data=false", the sender transmits a…
CVE-2025-25249High· 8.1CISA KEVPoCA heap-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11, FortiOS 7.0.0 through 7.0.17, FortiOS 6.4 all versions, FortiSwitchManager 7.2.0 through 7.2.6…
A heap-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11, FortiOS 7.0.0 through 7.0.17, FortiOS 6.4 all versions, FortiSwitchManager 7.2.0 through 7.2.6…
CVE-2026-85880High· 7.8CISA KEV0dayPoCHeap-based buffer overflow in Windows ALPC allows an authorized attacker to elevate privileges locally.
Heap-based buffer overflow in Windows ALPC allows an authorized attacker to elevate privileges locally.
CVE-2026-81963High· 7.8CISA KEV0dayPoCImproper link resolution before file access ('link following') in Windows Update Stack allows an authorized attacker to elevate privileges locally.
Improper link resolution before file access ('link following') in Windows Update Stack allows an authorized attacker to elevate privileges locally.
CVE-2026-42018High· 7.5CISA KEVPoCAnonymous user token generation exposure in JFrog Artifactory
JFrog Artifactory could return an internal anonymous-user token to an unauthenticated caller when anonymous access is disabled, potentially exposing sensitive resources.
New this week, ranked by depth score
The 12 that matter most of the 3879 published.
CVE-2026-85706Critical· 10.0CISA KEV0dayPoCGitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.7 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that, under certain conditions, an unauthenticated user could have read arbitrary files from the Gi…
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.7 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that, under certain conditions, an unauthenticated user could have read arbitrary files from the Gi…
CVE-2026-84869Critical· 9.9CISA KEVPoCA condition in the ScreenConnect client may allow files to be transferred and executed through an active remote session without authorization or Host confirmation in certain circumstances
A condition in the ScreenConnect client may allow files to be transferred and executed through an active remote session without authorization or Host confirmation in certain circumstances. ScreenConnect servers are not impacted.
CVE-2026-75650Critical· 10.0CISA KEV0dayPoCAdobe Commerce is affected by an Improper Neutralization of Special Elements Used in a Template Engine vulnerability that could result in arbitrary code execution in the context of the current user
Adobe Commerce is affected by an Improper Neutralization of Special Elements Used in a Template Engine vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnera…
CVE-2026-87491High· 8.8CISA KEV0dayPoCOut of bounds write in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page
Out of bounds write in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
MAL-2026-16143Critical⚠ ExploitedMalicious code in chroma-client (PyPI)
Malicious code in chroma-client (PyPI)
MAL-2026-16142Critical⚠ ExploitedMalicious code in python-fork (PyPI)
Malicious code in python-fork (PyPI)
MAL-2026-16164Critical⚠ ExploitedMalicious code in logs_update (crates.io)
Malicious code in logs_update (crates.io)
MAL-2026-16141Critical⚠ ExploitedMalicious code in platform-telemetry-client (PyPI)
Malicious code in platform-telemetry-client (PyPI)
MAL-2026-16136Critical⚠ ExploitedMalicious code in transfomers (PyPI)
Malicious code in transfomers (PyPI)
MAL-2026-16135Critical⚠ ExploitedMalicious code in openaii (PyPI)
Malicious code in openaii (PyPI)
MAL-2026-16134Critical⚠ ExploitedMalicious code in ollamaa (PyPI)
Malicious code in ollamaa (PyPI)
MAL-2026-16133Critical⚠ ExploitedMalicious code in langgrap (PyPI)
Malicious code in langgrap (PyPI)
Most-changed records
Existing CVEs whose severity, score, KEV or exploitation status moved.
- CVE-2026-87491Out of bounds write in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML pageseverity, cvss, exploited, exploit_available, kev, zero_day74
- CVE-2026-78741Silverpeas Core <=6.4.6 is vulnerable to Cross Site Scripting (XSS) in the wysiwyg-CKEditor image upload feature.severity, cvss, exploit_available46
- CVE-2026-52486An issue in OpenDDS 3.33.x allows a local attacker to cause a denial of service via the verify function in the SIgnedDocument moduleseverity, cvss, exploit_available48
- CVE-2026-79570mfish-nocode-pro v1.0.0 was discovered to contain a SQL injection vulnerability in the tableName parameter at /sys/dbConnect/dataseverity, cvss, exploit_available66
- CVE-2026-78742Silverpeas Core <=6.4.6 is vulnerable to Cross Site Scripting (XSS) via the Multimedia library application introduction.severity, cvss, exploit_available46
- CVE-2026-53758Emlog is an open source website building systemseverity, cvss, exploit_available60
- CVE-2026-79574An issue in the gateway server of mpush v0.8.1 allows attackers to execute arbitrary code via sending a crafted broadcast message.severity, cvss, exploit_available66
- CVE-2026-78997UC Browser for Android (package com.UCMobile.intl, version 13.7.8.1314) contains a Universal Cross-Site Scripting vulnerability that allows an attacker to execute arbitrary JavaScript in the context of any originseverity, cvss, exploit_available63
Most-affected vendors
By CVEs published in the period.