Weekly digest
Week 38, 2026 (14–20 Sep)
A heavy week: 4,908 new CVEs, well above the recent average of about 1,398. Severity skewed high: 508 critical and 2,064 high, 52% of the total. 625 arrived with exploitation evidence or public exploit code already attached. CISA added 7 CVEs to the Known Exploited Vulnerabilities catalog. 2 CVEs saw exploit probability (EPSS) jump by ten points or more. Linux was the most-affected vendor with 878.
Added to CISA KEV
Confirmed exploitation in the wild — federal remediation deadlines attach to these.
CVE-2026-76460Critical· 10.0CISA KEV0dayPoCA vulnerability in an API of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to bypass authentication. This vulnerability is due to insufficient authentication control on an API endpoint
A vulnerability in an API of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to bypass authentication. This vulnerability is due to insufficient authentication control on an API endpoint. An attack…
CVE-2026-76461Critical· 9.8CISA KEV0dayPoCA vulnerability in the email parsing of Cisco AsyncOS Software for Cisco Secure Email Gateway could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on the underlying operating system. This …
A vulnerability in the email parsing of Cisco AsyncOS Software for Cisco Secure Email Gateway could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on the underlying operating system. This …
CVE-2025-39682Critical· 9.8CISA KEVPoC⚖ disputedIn the Linux kernel, the following vulnerability has been resolved: tls: fix handling of zero-length records on the rx_list Each recvmsg() call must process either - only contiguous DATA records (any number of them) - one non-DATA re…
In the Linux kernel, the following vulnerability has been resolved: tls: fix handling of zero-length records on the rx_list Each recvmsg() call must process either - only contiguous DATA records (any number of them) - one non-DATA re…
CVE-2026-58704High· 8.8CISA KEV0dayPoCIn Cellular Modem, there is a possible permission bypass due to a logic error in the code
In Cellular Modem, there is a possible permission bypass due to a logic error in the code. This could lead to remote (proximal/adjacent) escalation of privilege with no additional execution privileges needed. User interaction is not need…
CVE-2026-53266High· 8.8CISA KEVPoCIn the Linux kernel, the following vulnerability has been resolved: netfilter: bridge: make ebt_snat ARP rewrite writable The ebtables SNAT target keeps the Ethernet source address rewrite behind skb_ensure_writable(skb, 0)
In the Linux kernel, the following vulnerability has been resolved: netfilter: bridge: make ebt_snat ARP rewrite writable The ebtables SNAT target keeps the Ethernet source address rewrite behind skb_ensure_writable(skb, 0). This is i…
CVE-2026-87886High· 7.8CISA KEV0dayPoCLocal privilege escalation due to insecure file permissions
Local privilege escalation due to insecure file permissions. The following products are affected: Acronis Backup plugin for cPanel & WHM (Linux) before build 1.9.3.1021, Acronis Backup extension for Plesk (Linux) before build 1.8.11.638,…
CVE-2025-39964High· 7.8CISA KEVPoCIn the Linux kernel, the following vulnerability has been resolved: crypto: af_alg - Disallow concurrent writes in af_alg_sendmsg Issuing two writes to the same af_alg socket is bogus as the data will be interleaved in an unpredictable…
In the Linux kernel, the following vulnerability has been resolved: crypto: af_alg - Disallow concurrent writes in af_alg_sendmsg Issuing two writes to the same af_alg socket is bogus as the data will be interleaved in an unpredictable…
Rising exploit probability
Largest EPSS increases inside the period (≥ 10 points).
- CVE-2026-85706Critical· 10.0GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.7 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that, under certain conditions, an unauthenticated user could have read arbitrary files from the Gi…1.2% → 15%
- CVE-2026-42018High· 7.5Anonymous user token generation exposure in JFrog Artifactory0.92% → 11%
New this week, ranked by depth score
The 12 that matter most of the 4908 published.
CVE-2026-76460Critical· 10.0CISA KEV0dayPoCA vulnerability in an API of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to bypass authentication. This vulnerability is due to insufficient authentication control on an API endpoint
A vulnerability in an API of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to bypass authentication. This vulnerability is due to insufficient authentication control on an API endpoint. An attack…
CVE-2026-19773Critical· 9.80daylibwebsockets HTTP/2 HPACK Path Header Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
libwebsockets HTTP/2 HPACK Path Header Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of libwebsockets. Authentication is no…
CVE-2026-76461Critical· 9.8CISA KEV0dayPoCA vulnerability in the email parsing of Cisco AsyncOS Software for Cisco Secure Email Gateway could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on the underlying operating system. This …
A vulnerability in the email parsing of Cisco AsyncOS Software for Cisco Secure Email Gateway could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on the underlying operating system. This …
CVE-2026-19780High· 8.80dayKoha Eval Code Injection Remote Code Execution Vulnerability
Koha Eval Code Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Koha. Authentication is required to exploit this vulnerability. The specific…
CVE-2026-58704High· 8.8CISA KEV0dayPoCIn Cellular Modem, there is a possible permission bypass due to a logic error in the code
In Cellular Modem, there is a possible permission bypass due to a logic error in the code. This could lead to remote (proximal/adjacent) escalation of privilege with no additional execution privileges needed. User interaction is not need…
MAL-2026-16298Critical⚠ ExploitedMalicious code in urc (PyPI)
Malicious code in urc (PyPI)
MAL-2026-16296Critical⚠ ExploitedMalicious code in py-venv-doctor (PyPI)
Malicious code in py-venv-doctor (PyPI)
MAL-2026-16275Critical⚠ ExploitedMalicious code in requests-triwes (PyPI)
Malicious code in requests-triwes (PyPI)
MAL-2026-16274Critical⚠ ExploitedMalicious code in requests-auroras (PyPI)
Malicious code in requests-auroras (PyPI)
MAL-2026-16269Critical⚠ ExploitedMalicious code in requests-asetwe (PyPI)
Malicious code in requests-asetwe (PyPI)
MAL-2026-16268Critical⚠ ExploitedMalicious code in index-forum (PyPI)
Malicious code in index-forum (PyPI)
MAL-2026-16267Critical⚠ ExploitedMalicious code in pyjstat-smooth (PyPI)
Malicious code in pyjstat-smooth (PyPI)
Most-changed records
Existing CVEs whose severity, score, KEV or exploitation status moved.
- CVE-2019-9901EnvoyProxy Envoy Missing HTTP URL path normalizationseverity, cvss56
- CVE-2025-71348picklescan before 0.0.28 fails to detect malicious pickle files that invoke torch.utils._config_module.load_config function within reduce methodsexploit_available57
- CVE-2014-6407Arbitrary Code Execution in Dockercvss41
- CVE-2026-87491Out of bounds write in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML pageseverity, cvss, kev, exploited, exploit_available, zero_day74
- CVE-2026-86060RouterOS contains an argument-handling flaw in the SSH login path involving usernames that begin with a prohibited character, allowing for the trusted RouterOS policy mask to be changed, leading to privilege escalationcvss, kev, exploited, exploit_available79
- CVE-2026-67277RouterOS accepts a "related" btest connection before the corresponding primary session has completed authenticationcvss, kev, exploited, exploit_available70
- CVE-2026-84869A condition in the ScreenConnect client may allow files to be transferred and executed through an active remote session without authorization or Host confirmation in certain circumstanceskev, exploited, exploit_available80
- CVE-2026-86840The `vtoken-minting` and `slpx` pallets in Bifrost contain an improper authorization vulnerability in channel commission attributionseverity, cvss, exploit_available62
Most-affected vendors
By CVEs published in the period.