This week in CVEs
In the last seven days 4,901 CVEs were published, 481 of them critical. 7 were added to CISA’s known-exploited list. 8 KEV deadlines fall in the coming week.
RSS feed ↗Only for my products →Refreshed daily · rolling seven days
Added to CISA KEV this week
Vulnerabilities CISA confirmed are being exploited in the wild. If any of these is in your estate it is an emergency change, and the due date is the latest anyone should tolerate.
| CVE | Summary | Affects | Priority | Added |
|---|---|---|---|---|
| CVE-2025-39682 | Linux Kernel Improper Check for Unusual or Exceptional Conditions Vulnerability | linux/linux kernel · debian/debian linux | KEVHIGH 7.1EPSS 1.20% | 18 September 2026 |
| CVE-2025-39964 | Linux Kernel Race Condition Vulnerability | linux/linux kernel · siemens/simatic s7-1500 cpu 1518-4 pn\/dp mfp firmware · siemens/simatic s7-1500 cpu 1518f-4 pn\/dp mfp firmware | KEVMEDIUM 5.5EPSS 0.79% | 18 September 2026 |
| CVE-2026-53266 | Linux Kernel Out-of-Bounds Write Vulnerability | linux/linux kernel | KEVHIGH 8.8EPSS 0.28% | 18 September 2026 |
| CVE-2026-58704 | Google Pixel Improper Authorization Vulnerability | google/android | KEVHIGH 8.8EPSS 0.21% | 16 September 2026 |
| CVE-2026-76460 | Cisco Identity Services Engine Incorrect Use of Privileged APIs Vulnerability | cisco/identity services engine · cisco/identity services engine passive identity connector | KEVCRITICAL 10.0EPSS 0.78% | 16 September 2026 |
| CVE-2026-87886 | Acronis Backup Incorrect Default Permissions Vulnerability | acronis/acronis backup | KEVHIGH 7.8EPSS 0.25% | 16 September 2026 |
| CVE-2026-76461 | Cisco Secure Email Gateway SQL Injection Vulnerability | cisco/asyncos | KEVCRITICAL 9.8EPSS 2.01% | 14 September 2026 |
KEV deadlines in the coming week
Full calendar →| CVE | Summary | Affects | Priority | Due |
|---|---|---|---|---|
| CVE-2025-39682 | Linux Kernel Improper Check for Unusual or Exceptional Conditions Vulnerability | linux/linux kernel · debian/debian linux | KEVHIGH 7.1EPSS 1.20% | 21 September 2026 |
| CVE-2025-39964 | Linux Kernel Race Condition Vulnerability | linux/linux kernel · siemens/simatic s7-1500 cpu 1518-4 pn\/dp mfp firmware · siemens/simatic s7-1500 cpu 1518f-4 pn\/dp mfp firmware | KEVMEDIUM 5.5EPSS 0.79% | 21 September 2026 |
| CVE-2026-53266 | Linux Kernel Out-of-Bounds Write Vulnerability | linux/linux kernel | KEVHIGH 8.8EPSS 0.28% | 21 September 2026 |
| CVE-2026-81963 | Microsoft Windows Link Following Vulnerability | microsoft/windows 11 23h2 · microsoft/windows 11 24h2 · microsoft/windows 11 25h2 +2 | KEVHIGH 7.8EPSS 0.63% | 22 September 2026 |
| CVE-2026-85880 | Microsoft Windows Heap-Based Buffer Overflow Vulnerability | microsoft/windows 10 1607 · microsoft/windows 10 1809 · microsoft/windows 10 21h2 +5 | KEVHIGH 7.8EPSS 0.57% | 22 September 2026 |
| CVE-2026-87491 | Google Chromium V8 Out of Bounds Write Vulnerability | google/chrome | KEVHIGH 8.8EPSS 1.00% | 23 September 2026 |
| CVE-2026-42016 | JFrog Artifactory Incorrect Authorization Vulnerability | jfrog/artifactory | KEVHIGH 8.8EPSS 9.06% | 25 September 2026 |
| CVE-2026-42018 | JFrog Artifactory Improper Authentication Vulnerability | jfrog/artifactory | KEVHIGH 7.5EPSS 11.0% | 25 September 2026 |
New public exploits
CVEs that gained their first public exploit in Exploit-DB this week. A published exploit removes the skill barrier; these tend to appear in scanning traffic within days.
No CVE gained its first public exploit this week.
EPSS jumps
CVEs whose EPSS score rose by five points or more, or crossed the ten per cent line, in the last seven days. A jump usually means a public exploit or a scanning campaign appeared.
No material EPSS moves were recorded this week. Scores are compared daily; the first comparison happens the day after this feature went live.
New critical CVEs, most likely exploited first
The 481 critical-severity CVEs published this week, ordered by EPSS. The top of this list is where a patch cycle should start when nothing above applies.
| CVE | Summary | Affects | Priority | Published |
|---|---|---|---|---|
| CVE-2026-89308 | An unauthenticated OS command injection vulnerability exists in the ping.php endpoint, allowing remote attackers to execute arbitrary commands on the underlying operating system and achieve remote code execution. | — | CRITICAL 9.3EPSS 2.97% | 15 September 2026 |
| CVE-2026-58146 | WNC T-Mobile 5G Box IDU router is vulnerable to OS command injection vulnerability. | — | CRITICAL 9.4EPSS 2.12% | 16 September 2026 |
| CVE-2026-52824 | An unauthenticated attacker who reaches a deployment that did not override APP_SECRET, knows a username, correctly guesses the account ID associated with that username, and targets an account without active two-factor authentication can forge… | — | CRITICAL 9.1EPSS 2.06% | 15 September 2026 |
| CVE-2026-76461 | Cisco Secure Email Gateway SQL Injection Vulnerability | cisco/asyncos | KEVCRITICAL 9.8EPSS 2.01% | 14 September 2026 |
| CVE-2026-73172 | Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the edgserver management service of Advantech EKI-1242EIMS in firmware version V1.06.01 that allows a… | — | CRITICAL 9.3EPSS 1.73% | 16 September 2026 |
| CVE-2026-90822 | FatPipe MPVPN, WARP, and IPVPN appliances running the end-of-life firmware version 10.1.2r60p100 contain an OS command injection vulnerability in the xtremed daemon. | — | CRITICAL 9.8EPSS 1.41% | 17 September 2026 |
| CVE-2026-20306 | A vulnerability in the REST API of Cisco ISE and ISE-PIC could allow an authenticated, remote attacker to perform command injection attacks on the underlying operating system and elevate privileges to root. | — | CRITICAL 9.1EPSS 1.37% | 16 September 2026 |
| CVE-2026-20305 | A vulnerability in the diagnostic tools of Cisco ISE and ISE-PIC could allow an authenticated, remote attacker to perform command injection attacks on the underlying operating system and elevate privileges to root. | — | CRITICAL 9.1EPSS 1.37% | 16 September 2026 |
| CVE-2026-76675 | A command injection vulnerability exists in the command line interface of EdgeConnect SD-WAN Gateways. | — | CRITICAL 9.1EPSS 1.34% | 15 September 2026 |
| CVE-2026-54501 | From 1.15.0 until 1.22.8, Browsertrix improperly sanitizes Git URLs specified as Custom Behaviors, allowing command injection through /api/orgs/*/crawlconfigs/validate/custom-behavior. | — | CRITICAL 9.4EPSS 1.22% | 17 September 2026 |
| CVE-2026-58147 | WNC T-Mobile 5G Box IDU router contains an OS command injection vulnerability in the portal.cgi component's password change functionality. | — | CRITICAL 9.3EPSS 1.20% | 16 September 2026 |
| CVE-2026-40855 | WNC T-Mobile 5G Box IDU router is vulnerable to a command injection. | — | CRITICAL 9.3EPSS 1.13% | 16 September 2026 |
| CVE-2026-76674 | Buffer overflow vulnerabilities exist in the underlying operating system of HPE Networking EdgeConnect SD-WAN Gateways that could allow an unauthenticated remote attacker to execute arbitrary code. | — | CRITICAL 9.8EPSS 1.06% | 15 September 2026 |
| CVE-2026-90919 | LightLLM through 1.2.0 contains a remote code execution vulnerability in the Config Server's unauthenticated /visual_register WebSocket endpoint that passes the first client frame directly to pickle.loads(). | — | CRITICAL 9.3EPSS 1.01% | 14 September 2026 |
| CVE-2026-51990 | An issue in Sogou Sogou Input Method < 16.3.0.3498 (fixed in 16.3.0.3498) allows a remote attacker to execute arbitrary code via the biz_helper.exe component | — | CRITICAL 9.8EPSS 1.00% | 16 September 2026 |
| CVE-2026-65414 | An out-of-bounds write issue was addressed with improved bounds checking. | apple/ipados · apple/iphone os · apple/macos +2 | CRITICAL 9.8EPSS 0.99% | 14 September 2026 |
| CVE-2026-45140 | Prior to 2.0.1, Chamilo LMS allows an unauthenticated remote attacker to execute arbitrary code on the server. | — | CRITICAL 9.8EPSS 0.98% | 17 September 2026 |
| CVE-2026-57131 | Network clients can submit attacker-controlled prompts and agent configuration, list and read jobs, stream results, and cancel or delete other jobs, exposing service credentials and connected tool capabilities to unauthorized agent execution. | — | CRITICAL 9.8EPSS 0.97% | 14 September 2026 |
| CVE-2026-20307 | A vulnerability in the web-based management interface of Cisco ISE could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device. | — | CRITICAL 9.9EPSS 0.95% | 16 September 2026 |
| CVE-2026-27546 | An unauthenticated remote attacker can exploit an authentication bypass in the _account_log function to log in as an admin, even when accounts are properly configured. | — | CRITICAL 9.8EPSS 0.95% | 16 September 2026 |
| CVE-2026-82311 | An attacker who already holds a copy of the victim's session cookie keeps access as that user after the password change, so the reset does not evict them. | apache/apache-airflow-providers-fab | CRITICAL 9.8EPSS 0.95% | 16 September 2026 |
| CVE-2026-76187 | No allowlist restricts which client ids may authenticate, so the credentials of an unrelated application that happens to share the realm are valid Airflow login credentials, and Airflow mints a signed session token for that application's service account. | apache/apache-airflow-providers-keycloak | CRITICAL 9.8EPSS 0.95% | 16 September 2026 |
| CVE-2026-27565 | An unauthenticated remote attacker can upload a malicious IODD file that places and executes a shell script with root privileges. | — | CRITICAL 9.8EPSS 0.94% | 16 September 2026 |
| CVE-2026-89040 | Tencent Mass Service Engine in Cluster (MSEC) allows a remote, unauthenticated attacker to send a crafted POST request including ../ and gain root access on the target device. | — | CRITICAL 9.3EPSS 0.93% | 15 September 2026 |
| CVE-2026-70416 | Dell ObjectScale, versions prior to 4.4.0.0, contains a Deserialization of Untrusted Data vulnerability. | — | CRITICAL 10.0EPSS 0.91% | 16 September 2026 |
| CVE-2026-57127 | Unauthenticated clients can then reach recipe execution, input, and output surfaces and may trigger connected tools despite the operator explicitly enabling authentication. | — | CRITICAL 9.8EPSS 0.90% | 14 September 2026 |
| CVE-2026-12351 | IBM MQ 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 LTS, and 10.0.0.0 could allow a remote attacker to execute arbitrary code due to unsafe JNDI lookup processing when the IVT… | — | CRITICAL 9.8EPSS 0.86% | 15 September 2026 |
| CVE-2026-76834 | Unauthenticated attackers can submit crafted serialized PHP objects via POST requests to htsrv/call_plugin.php that bypass validation and reach unserialize(), instantiating arbitrary PHP objects with attacker-chosen properties that may enable code… | — | CRITICAL 9.2EPSS 0.85% | 17 September 2026 |
| CVE-2026-90413 | In the Linux kernel, the following vulnerability has been resolved: IB/isert: reject login PDUs declaring more data than was received isert_login_recv_done() records how many bytes the HCA actually placed in the login buffer, but nothing compares that… | — | CRITICAL 9.1EPSS 0.83% | 17 September 2026 |
| CVE-2026-90011 | In the Linux kernel, the following vulnerability has been resolved: scsi: target: iscsi: Reserve a terminator byte for the login payload iscsi_target_check_login_request() rejects a login PDU whose DataSegmentLength exceeds MAX_KEY_VALUE_PAIRS, but the… | — | CRITICAL 9.1EPSS 0.83% | 16 September 2026 |
| CVE-2026-53710 | Prior to 1.0.2, the python_sandbox_server in mcp-servers/python/python_sandbox_server/src/python_sandbox_server/server_fastmcp.py exposes raw getattr through safe_builtins, omits a required _getattr_ guard, and relies on validate_code checks for literal… | — | CRITICAL 10.0EPSS 0.83% | 15 September 2026 |
| CVE-2026-91932 | Flowise before 3.1.4 contains a validation bypass vulnerability in MCP server configuration allowing authenticated attackers remote code execution through an unvalidated cwd parameter. | — | CRITICAL 9.0EPSS 0.82% | 15 September 2026 |
| CVE-2026-86462 | An attacker who already holds a copy of the victim's session cookie keeps full access as that user after the password change, so the password reset does not evict them. | apache/apache-airflow-providers-fab | CRITICAL 9.1EPSS 0.80% | 16 September 2026 |
| CVE-2026-92937 | vm2 3.11.6 is vulnerable to a sandbox escape leading to remote code execution in the host Node.js process. | — | CRITICAL 10.0EPSS 0.79% | 17 September 2026 |
| CVE-2026-76186 | A user who holds any valid Airflow login of their own, together with another subject's Keycloak access or refresh token obtained out of band, can pair the two: Airflow then authorizes requests with the foreign token's privileges while the session… | apache/apache-airflow-providers-keycloak | CRITICAL 9.1EPSS 0.79% | 16 September 2026 |
| CVE-2026-76460 | Cisco Identity Services Engine Incorrect Use of Privileged APIs Vulnerability | cisco/identity services engine · cisco/identity services engine passive identity connector | KEVCRITICAL 10.0EPSS 0.78% | 16 September 2026 |
| CVE-2026-61534 | Prior to 4.3.0, Store and LegacyStore use attacker-controlled JSON:API type, id, and relationship names as keys in plain-object lookup tables in src/yayson/store.ts and src/yayson/legacy-store.ts. | — | CRITICAL 9.1EPSS 0.78% | 14 September 2026 |
| CVE-2026-89970 | In the Linux kernel, the following vulnerability has been resolved: nvmet-auth: Synchronize timeout work during SQ teardown nvmet_auth_sq_free() cancels auth_expired_work with cancel_delayed_work(). | — | CRITICAL 9.8EPSS 0.78% | 16 September 2026 |
| CVE-2026-20176 | A vulnerability in Cisco ISE could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device. | — | CRITICAL 9.1EPSS 0.78% | 16 September 2026 |
| CVE-2026-57147 | A remote unauthenticated attacker can mint an HS256 token with an arbitrary sub and email, and the platform's AuthService._verify_token() and get_current_user dependency accept the forged identity for protected API routes. | — | CRITICAL 9.8EPSS 0.77% | 15 September 2026 |
New this week with the highest EPSS, any severity
| CVE | Summary | Affects | Priority | Published |
|---|---|---|---|---|
| CVE-2026-76698 | A command injection vulnerability exists in the web-based management interface of HPE Networking EdgeConnect SD-WAN Gateways. | — | MEDIUM 6.5EPSS 4.11% | 15 September 2026 |
| CVE-2026-89308 | An unauthenticated OS command injection vulnerability exists in the ping.php endpoint, allowing remote attackers to execute arbitrary commands on the underlying operating system and achieve remote code execution. | — | CRITICAL 9.3EPSS 2.97% | 15 September 2026 |
| CVE-2026-90703 | A vulnerability has been found in D-Link DWR-M921 1.1.52. | — | HIGH 8.5EPSS 2.80% | 14 September 2026 |
| CVE-2026-90702 | This manipulation of the argument partition causes os command injection. | — | HIGH 8.5EPSS 2.80% | 14 September 2026 |
| CVE-2026-92398 | A vulnerability was found in Ruijie RG-EW3000GX EW_3.0(1)B11P380. | — | HIGH 8.5EPSS 2.47% | 16 September 2026 |
| CVE-2026-92397 | A vulnerability has been found in Ruijie RG-EW3000GX EW_3.0(1)B11P380. | — | HIGH 8.5EPSS 2.30% | 16 September 2026 |
| CVE-2026-27562 | A high-privileged remote attacker can exploit a command injection vulnerability in the /api/iodd/config endpoint by sending a crafted PUT request with admin credentials allowing execution of commands with root privileges on the device. | — | HIGH 7.2EPSS 2.23% | 16 September 2026 |
| CVE-2026-27561 | A high-privileged remote attacker can exploit a command injection vulnerability in the /api/iodd/config endpoint by sending a crafted GET request with admin credentials allowing execution of commands with root privileges on the device. | — | HIGH 7.2EPSS 2.23% | 16 September 2026 |
| CVE-2026-27560 | A high-privileged remote attacker can exploit a command injection vulnerability in the /api/status/data endpoint by sending a crafted DELETE request with admin credentials allowing execution of commands with root privileges on the device. | — | HIGH 7.2EPSS 2.23% | 16 September 2026 |
| CVE-2026-90847 | A vulnerability was determined in EFM ipTIME C200E 1.094. | — | HIGH 8.5EPSS 2.18% | 15 September 2026 |
| CVE-2026-58146 | WNC T-Mobile 5G Box IDU router is vulnerable to OS command injection vulnerability. | — | CRITICAL 9.4EPSS 2.12% | 16 September 2026 |
| CVE-2026-27559 | A low-privileged remote attacker can exploit a command injection vulnerability in the /api/status/data endpoint by sending a crafted GET request with user credentials allowing execution of commands with root privileges on the device. | — | HIGH 8.8EPSS 2.12% | 16 September 2026 |
| CVE-2026-27558 | A low-privileged remote attacker can exploit a command injection vulnerability in the /index.php/attached_devices_tab/ajax_remove_uploaded_iodd_files endpoint using operator credentials allowing execution of commands with root privileges on the device. | — | HIGH 8.8EPSS 2.12% | 16 September 2026 |
| CVE-2026-27554 | A low-privileged remote attacker can exploit a command injection vulnerability in the /index.php/ajax/save_iodd_parameters endpoint using operator credentials allowing execution of commands with root privileges on the device. | — | HIGH 8.8EPSS 2.12% | 16 September 2026 |
| CVE-2026-27551 | A low-privileged remote attacker can exploit a command injection vulnerability in the /index.php/ajax/parameterManage endpoint using user credentials allowing execution of commands with root privileges on the device. | — | HIGH 8.8EPSS 2.12% | 16 September 2026 |
| CVE-2026-27550 | A low-privileged remote attacker can exploit a command injection vulnerability in the Field_Shadow_Password class using operator credentials allowing execution of commands with root privileges on the device. | — | HIGH 8.8EPSS 2.12% | 16 September 2026 |
| CVE-2026-27549 | A low-privileged remote attacker can exploit a command injection vulnerability in the /index.php/attached_devices_tab/do_upload endpoint using operator credentials allowing execution of commands with root privileges on the device. | — | HIGH 8.8EPSS 2.12% | 16 September 2026 |
| CVE-2026-27548 | A low-privileged remote attacker can exploit a command injection vulnerability in the /index.php/ajax/get_iodd_port_info endpoint using user or operator credentials allowing execution of commands with root privileges on the device. | — | HIGH 8.8EPSS 2.12% | 16 September 2026 |
| CVE-2026-27547 | A low-privileged remote attacker can exploit a command injection vulnerability in the /index.php/ajax/get_iodd_menu_info endpoint using valid user or operator credentials allowing execution of commands with root privileges on the device. | — | HIGH 8.8EPSS 2.12% | 16 September 2026 |
| CVE-2026-52824 | An unauthenticated attacker who reaches a deployment that did not override APP_SECRET, knows a username, correctly guesses the account ID associated with that username, and targets an account without active two-factor authentication can forge… | — | CRITICAL 9.1EPSS 2.06% | 15 September 2026 |
How to read this page
Volume is not the story; the story is the handful that matter. Start with the KEV additions, which are confirmed exploitation, then the new public exploits and the EPSS jumps, which are exploitation becoming easy and likely, then the new criticals in EPSS order. Everything else goes in the normal cycle. The watchlist applies exactly this ordering to just your products and will email it to you; the KEV calendar shows the deadlines further out.
Data from NVD, FIRST EPSS, CISA KEV and Exploit-DB, refreshed daily. The window is a rolling seven days ending now, so the page is different every day and the feed carries each item once.