VulnSea

Weekly digest

Week 37, 2026 (7–13 Sep)

A heavy week: 3,879 new CVEs, well above the recent average of about 1,058. Severity skewed high: 308 critical and 1,751 high, 53% of the total. 464 arrived with exploitation evidence or public exploit code already attached. CISA added 14 CVEs to the Known Exploited Vulnerabilities catalog. Microsoft was the most-affected vendor with 972.

3879
New CVEs
308
Critical
14
KEV additions
2490
Records changed

Added to CISA KEV

Confirmed exploitation in the wild — federal remediation deadlines attach to these.

CVE-2026-20079Critical· 10.0CISA KEVPoC
6mo ago

A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to bypass authentication and execute script files on an affected device to obtain root access …

A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to bypass authentication and execute script files on an affected device to obtain root access …

Hadalcisco · secure_firewall_management_centerEPSS 76%via NVD
CVE-2026-85706Critical· 10.0CISA KEV0dayPoC
1w ago

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.7 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that, under certain conditions, an unauthenticated user could have read arbitrary files from the Gi…

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.7 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that, under certain conditions, an unauthenticated user could have read arbitrary files from the Gi…

Hadalgitlab · gitlabEPSS 15%via NVD
CVE-2026-86218Critical· 9.8CISA KEVPoC
2w ago

N-central is vulnerable to a pre-auth remote code execution This issue affects N-central: before 2026.3.1.14.

N-central is vulnerable to a pre-auth remote code execution This issue affects N-central: before 2026.3.1.14.

Hadaln-able · n-centralEPSS 7.5%via NVD
CVE-2026-84869Critical· 9.9CISA KEVPoC
1w ago

A condition in the ScreenConnect client may allow files to be transferred and executed through an active remote session without authorization or Host confirmation in certain circumstances

A condition in the ScreenConnect client may allow files to be transferred and executed through an active remote session without authorization or Host confirmation in certain circumstances. ScreenConnect servers are not impacted.

Hadalconnectwise · screenconnectEPSS 0.69%via NVD
CVE-2026-75650Critical· 10.0CISA KEV0dayPoC
2w ago

Adobe Commerce is affected by an Improper Neutralization of Special Elements Used in a Template Engine vulnerability that could result in arbitrary code execution in the context of the current user

Adobe Commerce is affected by an Improper Neutralization of Special Elements Used in a Template Engine vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnera…

Hadaladobe · commerceEPSS 2.1%via NVD
CVE-2026-19490Critical· 9.8CISA KEVPoC
1mo ago

Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: from 14.1 through 73.32 and from 13.1 through 63.21; Gateway: from 14.1 through 73.32 and from 13.1 through 63.21.

Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: from 14.1 through 73.32 and from 13.1 through 63.21; Gateway: from 14.1 through 73.32 and from 13.1 through 63.21.

Hadalcitrix · netscaler_application_delivery_controllerEPSS 5.6%via NVD
CVE-2026-86060Critical· 9.8CISA KEVPoC
2w ago

RouterOS contains an argument-handling flaw in the SSH login path involving usernames that begin with a prohibited character, allowing for the trusted RouterOS policy mask to be changed, leading to privilege escalation

RouterOS contains an argument-handling flaw in the SSH login path involving usernames that begin with a prohibited character, allowing for the trusted RouterOS policy mask to be changed, leading to privilege escalation. Exploitation requ…

Hadalmikrotik · routerosEPSS 1.1%via NVD
CVE-2026-87491High· 8.8CISA KEV0dayPoC
1w ago

Out of bounds write in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page

Out of bounds write in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

Abyssalgoogle · chromeEPSS 1.00%via NVD
CVE-2026-42016High· 8.1CISA KEVPoC
1mo ago

Incorrect authorization validation of user token in JFrog Artifactory allows Privilege Escalation

JFrog Artifactory (Self Hosted) versions before 7.133.11 are vulnerable to a privilege escalation attack due to a validation check of the token signature/issuer and not the token’s scope.

Abyssaljfrog · artifactoryEPSS 9.1%via CVEORG
CVE-2026-67277High· 8.2CISA KEVPoC
2w ago

RouterOS accepts a "related" btest connection before the corresponding primary session has completed authentication

RouterOS accepts a "related" btest connection before the corresponding primary session has completed authentication. An unauthenticated client can use this state to start an IPv4 UDP test. With "random-data=false", the sender transmits a…

Abyssalmikrotik · routerosEPSS 0.87%via NVD
CVE-2025-25249High· 8.1CISA KEVPoC
8mo ago

A heap-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11, FortiOS 7.0.0 through 7.0.17, FortiOS 6.4 all versions, FortiSwitchManager 7.2.0 through 7.2.6…

A heap-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11, FortiOS 7.0.0 through 7.0.17, FortiOS 6.4 all versions, FortiSwitchManager 7.2.0 through 7.2.6…

Abyssalfortinet · fortiswitchmanagerEPSS 2.4%via NVD
CVE-2026-85880High· 7.8CISA KEV0dayPoC
1w ago

Heap-based buffer overflow in Windows ALPC allows an authorized attacker to elevate privileges locally.

Heap-based buffer overflow in Windows ALPC allows an authorized attacker to elevate privileges locally.

Abyssalmicrosoft · windows_10_1607EPSS 0.57%via NVD
CVE-2026-81963High· 7.8CISA KEV0dayPoC
1w ago

Improper link resolution before file access ('link following') in Windows Update Stack allows an authorized attacker to elevate privileges locally.

Improper link resolution before file access ('link following') in Windows Update Stack allows an authorized attacker to elevate privileges locally.

Abyssalmicrosoft · windows_11_23h2EPSS 0.63%via NVD
CVE-2026-42018High· 7.5CISA KEVPoC
1mo ago

Anonymous user token generation exposure in JFrog Artifactory

JFrog Artifactory could return an internal anonymous-user token to an unauthenticated caller when anonymous access is disabled, potentially exposing sensitive resources.

Abyssaljfrog · artifactoryEPSS 11%via CVEORG

New this week, ranked by depth score

The 12 that matter most of the 3879 published.

CVE-2026-85706Critical· 10.0CISA KEV0dayPoC
1w ago

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.7 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that, under certain conditions, an unauthenticated user could have read arbitrary files from the Gi…

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.7 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that, under certain conditions, an unauthenticated user could have read arbitrary files from the Gi…

Hadalgitlab · gitlabEPSS 15%via NVD
CVE-2026-84869Critical· 9.9CISA KEVPoC
1w ago

A condition in the ScreenConnect client may allow files to be transferred and executed through an active remote session without authorization or Host confirmation in certain circumstances

A condition in the ScreenConnect client may allow files to be transferred and executed through an active remote session without authorization or Host confirmation in certain circumstances. ScreenConnect servers are not impacted.

Hadalconnectwise · screenconnectEPSS 0.69%via NVD
CVE-2026-75650Critical· 10.0CISA KEV0dayPoC
2w ago

Adobe Commerce is affected by an Improper Neutralization of Special Elements Used in a Template Engine vulnerability that could result in arbitrary code execution in the context of the current user

Adobe Commerce is affected by an Improper Neutralization of Special Elements Used in a Template Engine vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnera…

Hadaladobe · commerceEPSS 2.1%via NVD
CVE-2026-87491High· 8.8CISA KEV0dayPoC
1w ago

Out of bounds write in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page

Out of bounds write in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

Abyssalgoogle · chromeEPSS 1.00%via NVD
MAL-2026-16143Critical⚠ Exploited
1w ago

Malicious code in chroma-client (PyPI)

Malicious code in chroma-client (PyPI)

Abyssalchroma-client · chroma-clientvia OSV
MAL-2026-16142Critical⚠ Exploited
1w ago

Malicious code in python-fork (PyPI)

Malicious code in python-fork (PyPI)

Abyssalpython-fork · python-forkvia OSV
MAL-2026-16164Critical⚠ Exploited
1w ago

Malicious code in logs_update (crates.io)

Malicious code in logs_update (crates.io)

Abyssallogs-update · logs-updatevia OSV
MAL-2026-16141Critical⚠ Exploited
1w ago

Malicious code in platform-telemetry-client (PyPI)

Malicious code in platform-telemetry-client (PyPI)

Abyssalplatform-telemetry-client · platform-telemetry-clientvia OSV
MAL-2026-16136Critical⚠ Exploited
1w ago

Malicious code in transfomers (PyPI)

Malicious code in transfomers (PyPI)

Abyssaltransfomers · transfomersvia OSV
MAL-2026-16135Critical⚠ Exploited
1w ago

Malicious code in openaii (PyPI)

Malicious code in openaii (PyPI)

Abyssalopenaii · openaiivia OSV
MAL-2026-16134Critical⚠ Exploited
1w ago

Malicious code in ollamaa (PyPI)

Malicious code in ollamaa (PyPI)

Abyssalollamaa · ollamaavia OSV
MAL-2026-16133Critical⚠ Exploited
1w ago

Malicious code in langgrap (PyPI)

Malicious code in langgrap (PyPI)

Abyssallanggrap · langgrapvia OSV

Most-changed records

Existing CVEs whose severity, score, KEV or exploitation status moved.

  • CVE-2026-87491Out of bounds write in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page74
  • CVE-2026-78741Silverpeas Core <=6.4.6 is vulnerable to Cross Site Scripting (XSS) in the wysiwyg-CKEditor image upload feature.46
  • CVE-2026-52486An issue in OpenDDS 3.33.x allows a local attacker to cause a denial of service via the verify function in the SIgnedDocument module48
  • CVE-2026-79570mfish-nocode-pro v1.0.0 was discovered to contain a SQL injection vulnerability in the tableName parameter at /sys/dbConnect/data66
  • CVE-2026-78742Silverpeas Core <=6.4.6 is vulnerable to Cross Site Scripting (XSS) via the Multimedia library application introduction.46
  • CVE-2026-53758Emlog is an open source website building system60
  • CVE-2026-79574An issue in the gateway server of mpush v0.8.1 allows attackers to execute arbitrary code via sending a crafted broadcast message.66
  • CVE-2026-78997UC Browser for Android (package com.UCMobile.intl, version 13.7.8.1314) contains a Universal Cross-Site Scripting vulnerability that allows an attacker to execute arbitrary JavaScript in the context of any origin63

Most-affected vendors

By CVEs published in the period.