Weekly digest · in progress
Week 39, 2026 (21–27 Sep)
A quiet week: only 157 new CVEs against a recent average of about 1,903 so far. Of those, 14 critical and 61 high. 19 arrived with exploitation evidence or public exploit code already attached. Red Hat was the most-affected vendor with 12.
New this week, ranked by depth score
The 12 that matter most of the 157 published.
MAL-2026-16346Critical⚠ ExploitedMalicious code in rrs (PyPI)
Malicious code in rrs (PyPI)
CVE-2026-94101Critical· 9.9PoCA security vulnerability has been detected in Netcore NBR200V2 1.3.241127.071246
A security vulnerability has been detected in Netcore NBR200V2 1.3.241127.071246. The affected element is the function vlan_load_form_uci of the file /usr/bin/routerd. The manipulation of the argument wan_num leads to buffer overflow. It…
CVE-2026-94096Critical· 9.9PoCA vulnerability was found in Netcore NBR200V2 1.3.241127.071246
A vulnerability was found in Netcore NBR200V2 1.3.241127.071246. Affected by this issue is some unknown functionality of the file /usr/bin/network_tools of the component LAN IP Configuration Handler. The manipulation of the argument ipv4…
CVE-2026-94098Critical· 9.1PoCA vulnerability was identified in Netcore NBR200V2 1.3.241127.071246
A vulnerability was identified in Netcore NBR200V2 1.3.241127.071246. This vulnerability affects unknown code of the file /www/cgi-bin/upgrade of the component Firmware Upgrade CGI Endpoint. Such manipulation of the argument QUERY_STRING…
CVE-2025-12999Critical· 9.1PoCUrlUtil.getBaseUrl builds the absolute URLs in a response — download links, icons, asset and API URLs — from the X-Forwarded-Host, X-Forwarded-Proto and X-Forwarded-Prefix request headers, with no check on whether the sender was a truste…
UrlUtil.getBaseUrl builds the absolute URLs in a response — download links, icons, asset and API URLs — from the X-Forwarded-Host, X-Forwarded-Proto and X-Forwarded-Prefix request headers, with no check on whether the sender was a truste…
CVE-2026-94129High· 8.8PoCA vulnerability was detected in BioStar VALKYRIE AURORA 2.10.2411.0800
A vulnerability was detected in BioStar VALKYRIE AURORA 2.10.2411.0800. This vulnerability affects the function sub_1105C of the file BS_RVSIO64.sys of the component IOCTL Handler. The manipulation of the argument PhysicalAddress results…
CVE-2026-55071High· 8.4PoCMCP-for-Stata is a MCP server for integrating Stata into agent loops with a safety-first design
MCP-for-Stata is a MCP server for integrating Stata into agent loops with a safety-first design. Prior to version 1.19.0, the ado_package_install MCP tool in stata-mcp concatenates user-controlled input directly into a Stata command stri…
CVE-2026-94100Critical· 9.9A weakness has been identified in Netcore NBR200V2 1.3.241127.071246
A weakness has been identified in Netcore NBR200V2 1.3.241127.071246. Impacted is the function wan_config_set_vlan of the file /usr/bin/routerd of the component WAN VLAN Reconfiguration. Executing a manipulation of the argument vlan_wanX…
CVE-2026-94099Critical· 9.9A security flaw has been discovered in Netcore NBR200V2 1.3.241127.071246
A security flaw has been discovered in Netcore NBR200V2 1.3.241127.071246. This issue affects some unknown processing of the file restore.cgi of the component Backup Restore. Performing a manipulation of the argument QUERY_STRING results…
CVE-2026-94097Critical· 10.0A vulnerability was determined in Netcore NBR200V2 1.3.241127.071246
A vulnerability was determined in Netcore NBR200V2 1.3.241127.071246. This affects an unknown part of the file /www/cgi-bin/network_tools of the component CGI Diagnostic Endpoint. This manipulation of the argument param/key/val causes co…
CVE-2026-94095Critical· 9.9A vulnerability has been found in Netcore NBR200V2 1.3.241127.071246
A vulnerability has been found in Netcore NBR200V2 1.3.241127.071246. Affected by this vulnerability is an unknown functionality of the file /usr/bin/network_tools of the component Traceroute Diagnostic Feature. The manipulation of the a…
CVE-2026-55567High· 7.8PoCBleachBit cleans files to free disk space and to maintain privacy
BleachBit cleans files to free disk space and to maintain privacy. Prior to 6.0.1, privileged Windows cleaning does not lock and validate a target's parent directory before deletion. A local unprivileged user can replace that directory w…
Most-changed records
Existing CVEs whose severity, score, KEV or exploitation status moved.
- CVE-2019-9901EnvoyProxy Envoy Missing HTTP URL path normalizationseverity, cvss56
- CVE-2025-71348picklescan before 0.0.28 fails to detect malicious pickle files that invoke torch.utils._config_module.load_config function within reduce methodsexploit_available57
- CVE-2014-6407Arbitrary Code Execution in Dockercvss41
- CVE-2026-64849mlflow: MLflow: Unauthenticated full-read SSRF in webhook delivery: _validate_webhook_url bypassed via unvalidated HTTP redirects (and DNS …severity, cvss75
- CVE-2025-55190github.com/argoproj/argo-cd: Project API Token Exposes Repository Credentials (CVE-2025-55190)severity, cvss61
- CVE-2026-81627A flaw was found in QEMUseverity, cvss57
- CVE-2026-82187The Web to Print Online Designer WordPress plugin before 2.15.0 does not validate the type or extension of uploaded files, and hands the token protecting those uploads to any visitor who asks for it, allowing unauthenticated attackers to…severity, cvss54
- CVE-2026-89492In the Linux kernel, the following vulnerability has been resolved: ocfs2: validate directory-index entry counts when reading metadata ocfs2_validate_dx_leaf() and ocfs2_validate_dx_root() check the ECC and signature of an indexed-dire…severity, cvss54
Most-affected vendors
By CVEs published in the period.