VulnSea

Weekly digest

Week 38, 2026 (14–20 Sep)

A heavy week: 4,908 new CVEs, well above the recent average of about 1,398. Severity skewed high: 508 critical and 2,064 high, 52% of the total. 625 arrived with exploitation evidence or public exploit code already attached. CISA added 7 CVEs to the Known Exploited Vulnerabilities catalog. 2 CVEs saw exploit probability (EPSS) jump by ten points or more. Linux was the most-affected vendor with 878.

4908
New CVEs
508
Critical
7
KEV additions
3190
Records changed

Added to CISA KEV

Confirmed exploitation in the wild — federal remediation deadlines attach to these.

CVE-2026-76460Critical· 10.0CISA KEV0dayPoC
5d ago

A vulnerability in an API of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to bypass authentication. This vulnerability is due to insufficient authentication control on an API endpoint

A vulnerability in an API of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to bypass authentication. This vulnerability is due to insufficient authentication control on an API endpoint. An attack…

Hadalcisco · identity_services_engineEPSS 0.78%via NVD
CVE-2026-76461Critical· 9.8CISA KEV0dayPoC
1w ago

A vulnerability in the email parsing of Cisco AsyncOS Software for Cisco Secure Email Gateway could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on the underlying operating system. This …

A vulnerability in the email parsing of Cisco AsyncOS Software for Cisco Secure Email Gateway could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on the underlying operating system. This …

Hadalcisco · asyncosEPSS 2.0%via NVD
CVE-2025-39682Critical· 9.8CISA KEVPoC⚖ disputed
1y ago

In the Linux kernel, the following vulnerability has been resolved: tls: fix handling of zero-length records on the rx_list Each recvmsg() call must process either - only contiguous DATA records (any number of them) - one non-DATA re…

In the Linux kernel, the following vulnerability has been resolved: tls: fix handling of zero-length records on the rx_list Each recvmsg() call must process either - only contiguous DATA records (any number of them) - one non-DATA re…

Hadallinux · linux_kernelEPSS 1.2%via NVD
CVE-2026-58704High· 8.8CISA KEV0dayPoC
6d ago

In Cellular Modem, there is a possible permission bypass due to a logic error in the code

In Cellular Modem, there is a possible permission bypass due to a logic error in the code. This could lead to remote (proximal/adjacent) escalation of privilege with no additional execution privileges needed. User interaction is not need…

Abyssalgoogle · androidEPSS 0.21%via NVD
CVE-2026-53266High· 8.8CISA KEVPoC
2mo ago

In the Linux kernel, the following vulnerability has been resolved: netfilter: bridge: make ebt_snat ARP rewrite writable The ebtables SNAT target keeps the Ethernet source address rewrite behind skb_ensure_writable(skb, 0)

In the Linux kernel, the following vulnerability has been resolved: netfilter: bridge: make ebt_snat ARP rewrite writable The ebtables SNAT target keeps the Ethernet source address rewrite behind skb_ensure_writable(skb, 0). This is i…

Abyssallinux · linux_kernelEPSS 0.28%via NVD
CVE-2026-87886High· 7.8CISA KEV0dayPoC
4d ago

Local privilege escalation due to insecure file permissions

Local privilege escalation due to insecure file permissions. The following products are affected: Acronis Backup plugin for cPanel & WHM (Linux) before build 1.9.3.1021, Acronis Backup extension for Plesk (Linux) before build 1.8.11.638,…

Abyssalacronis · acronis_backupEPSS 0.25%via NVD
CVE-2025-39964High· 7.8CISA KEVPoC
11mo ago

In the Linux kernel, the following vulnerability has been resolved: crypto: af_alg - Disallow concurrent writes in af_alg_sendmsg Issuing two writes to the same af_alg socket is bogus as the data will be interleaved in an unpredictable…

In the Linux kernel, the following vulnerability has been resolved: crypto: af_alg - Disallow concurrent writes in af_alg_sendmsg Issuing two writes to the same af_alg socket is bogus as the data will be interleaved in an unpredictable…

Abyssallinux · linux_kernelEPSS 0.79%via NVD

Rising exploit probability

Largest EPSS increases inside the period (≥ 10 points).

  • CVE-2026-85706Critical· 10.0GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.7 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that, under certain conditions, an unauthenticated user could have read arbitrary files from the Gi…1.2%15%
  • CVE-2026-42018High· 7.5Anonymous user token generation exposure in JFrog Artifactory0.92%11%

New this week, ranked by depth score

The 12 that matter most of the 4908 published.

CVE-2026-76460Critical· 10.0CISA KEV0dayPoC
5d ago

A vulnerability in an API of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to bypass authentication. This vulnerability is due to insufficient authentication control on an API endpoint

A vulnerability in an API of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to bypass authentication. This vulnerability is due to insufficient authentication control on an API endpoint. An attack…

Hadalcisco · identity_services_engineEPSS 0.78%via NVD
CVE-2026-19773Critical· 9.80day
6d ago

libwebsockets HTTP/2 HPACK Path Header Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability

libwebsockets HTTP/2 HPACK Path Header Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of libwebsockets. Authentication is no…

Hadallibwebsockets · libwebsocketsEPSS 0.65%via NVD
CVE-2026-76461Critical· 9.8CISA KEV0dayPoC
1w ago

A vulnerability in the email parsing of Cisco AsyncOS Software for Cisco Secure Email Gateway could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on the underlying operating system. This …

A vulnerability in the email parsing of Cisco AsyncOS Software for Cisco Secure Email Gateway could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on the underlying operating system. This …

Hadalcisco · asyncosEPSS 2.0%via NVD
CVE-2026-19780High· 8.80day
6d ago

Koha Eval Code Injection Remote Code Execution Vulnerability

Koha Eval Code Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Koha. Authentication is required to exploit this vulnerability. The specific…

AbyssalKoha · KohaEPSS 0.96%via NVD
CVE-2026-58704High· 8.8CISA KEV0dayPoC
6d ago

In Cellular Modem, there is a possible permission bypass due to a logic error in the code

In Cellular Modem, there is a possible permission bypass due to a logic error in the code. This could lead to remote (proximal/adjacent) escalation of privilege with no additional execution privileges needed. User interaction is not need…

Abyssalgoogle · androidEPSS 0.21%via NVD
MAL-2026-16298Critical⚠ Exploited
2d ago

Malicious code in urc (PyPI)

Malicious code in urc (PyPI)

Abyssalurc · urcvia OSV
MAL-2026-16296Critical⚠ Exploited
3d ago

Malicious code in py-venv-doctor (PyPI)

Malicious code in py-venv-doctor (PyPI)

Abyssalpy-venv-doctor · py-venv-doctorvia OSV
MAL-2026-16275Critical⚠ Exploited
4d ago

Malicious code in requests-triwes (PyPI)

Malicious code in requests-triwes (PyPI)

Abyssalrequests-triwes · requests-triwesvia OSV
MAL-2026-16274Critical⚠ Exploited
4d ago

Malicious code in requests-auroras (PyPI)

Malicious code in requests-auroras (PyPI)

Abyssalrequests-auroras · requests-aurorasvia OSV
MAL-2026-16269Critical⚠ Exploited
4d ago

Malicious code in requests-asetwe (PyPI)

Malicious code in requests-asetwe (PyPI)

Abyssalrequests-asetwe · requests-asetwevia OSV
MAL-2026-16268Critical⚠ Exploited
4d ago

Malicious code in index-forum (PyPI)

Malicious code in index-forum (PyPI)

Abyssalindex-forum · index-forumvia OSV
MAL-2026-16267Critical⚠ Exploited
4d ago

Malicious code in pyjstat-smooth (PyPI)

Malicious code in pyjstat-smooth (PyPI)

Abyssalpyjstat-smooth · pyjstat-smoothvia OSV

Most-changed records

Existing CVEs whose severity, score, KEV or exploitation status moved.

  • CVE-2019-9901EnvoyProxy Envoy Missing HTTP URL path normalization56
  • CVE-2025-71348picklescan before 0.0.28 fails to detect malicious pickle files that invoke torch.utils._config_module.load_config function within reduce methods57
  • CVE-2014-6407Arbitrary Code Execution in Docker41
  • CVE-2026-87491Out of bounds write in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page74
  • CVE-2026-86060RouterOS contains an argument-handling flaw in the SSH login path involving usernames that begin with a prohibited character, allowing for the trusted RouterOS policy mask to be changed, leading to privilege escalation79
  • CVE-2026-67277RouterOS accepts a "related" btest connection before the corresponding primary session has completed authentication70
  • CVE-2026-84869A condition in the ScreenConnect client may allow files to be transferred and executed through an active remote session without authorization or Host confirmation in certain circumstances80
  • CVE-2026-86840The `vtoken-minting` and `slpx` pallets in Bifrost contain an improper authorization vulnerability in channel commission attribution62

Most-affected vendors

By CVEs published in the period.