AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L P N N H H H 9.5 — — YES
AFFECTED Product Versions Fixed ADC unspecified — Gateway unspecified —
TIMELINE Sep 10 Reserved by CNA Sep 27 Added to CISA KEV, due Sep 30 Sep 27 Published (CNA: NetScaler)
A daily page of record for published software vulnerabilities — the previous UTC day, closed and final. New here?
CISA adds 2 to KEV; 151 CVEs published, led by AzuraCast (11).
151 CVEs published September 27, 2026: 10 critical, 61 high, 56 medium, 24 low; 2 in the KEV catalog at press time; 3 with a public exploit reference; 0 awaiting enrichment. Elevated volume. 25 rendered as box scores below; the remaining 126 in the results table.
| MTD | YTD | 2025 same span | 2025 full | |
|---|---|---|---|---|
| CVEs published | 13386 | 48365 | — | — |
| KEV catalog size | 1728 | |||
Publication counts reflect the record since May 20, 2026 (archive start); KEV figures are catalog-wide.
Prior-year comparisons begin when the archive covers a full year; archive begins May 20, 2026.
3120 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. C/H/M/L = YTD disclosures by severity band. KEV = catalog entries all-time / YTD. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100. Med CVSS / Med EPSS = medians over the vendor's YTD disclosures. Δ = this month-to-date minus the same day-span of last month.
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| linux | 2114 | 6205 | 530 | 2638 | 713 | 1 | 15 | 6 | 0.1 | 7.8 | .0019 | +606 ▲ |
| microsoft | 1002 | 2901 | 203 | 1990 | 692 | 16 | 290 | 31 | 1.1 | 7.8 | .0047 | +533 ▲ |
| 518 | 2686 | 332 | 1050 | 1183 | 121 | 80 | 9 | 0.3 | 7.5 | .0027 | +116 ▲ | |
| red hat | 239 | 868 | 51 | 360 | 408 | 49 | 2 | 0 | 0.0 | 6.6 | .0037 | +23 ▲ |
| apple | 246 | 563 | 67 | 165 | 317 | 14 | 88 | 8 | 1.4 | 6.5 | .0019 | +202 ▲ |
| freebsd | 0 | 48 | 2 | 36 | 7 | 3 | 0 | 0 | 0.0 | 7.8 | .0016 | -32 ▼ |
| canonical | 0 | 42 | 13 | 11 | 13 | 5 | 0 | 0 | 0.0 | 7.8 | .0019 | -15 ▼ |
| suse | 13 | 41 | 7 | 21 | 12 | 1 | 0 | 0 | 0.0 | 7.5 | .0039 | +6 ▲ |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| cisco | 97 | 181 | 53 | 72 | 55 | 1 | 59 | 16 | 8.8 | 7.7 | .0046 | +51 ▲ |
| ubiquiti | 6 | 65 | 36 | 28 | 1 | 0 | 3 | 3 | 4.6 | 9.1 | .0050 | -17 ▼ |
| palo alto networks | 9 | 46 | 1 | 4 | 26 | 15 | 13 | 2 | 4.3 | 4.7 | .0022 | -3 ▼ |
| fortinet | 11 | 41 | 11 | 10 | 17 | 3 | 29 | 7 | 17.1 | 7.2 | .0040 | +4 ▲ |
| netgear | 2 | 34 | 0 | 0 | 27 | 7 | 0 | 0 | 0.0 | 4.3 | .0027 | -7 ▼ |
| f5 | 9 | 26 | 7 | 14 | 4 | 1 | 5 | 2 | 7.7 | 8.7 | .0050 | +9 ▲ |
| ivanti | 10 | 24 | 6 | 16 | 2 | 0 | 25 | 5 | 20.8 | 8.8 | .0152 | +7 ▲ |
| sonicwall | 5 | 19 | 7 | 8 | 4 | 0 | 19 | 4 | 21.1 | 8.3 | .0050 | -7 ▼ |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| apache | 137 | 649 | 148 | 275 | 208 | 16 | 33 | 2 | 0.3 | 7.5 | .0064 | -21 ▼ |
| mozilla | 113 | 301 | 102 | 126 | 73 | 0 | 9 | 0 | 0.0 | 8.8 | .0032 | +54 ▲ |
| gitlab | 24 | 100 | 7 | 24 | 58 | 11 | 5 | 3 | 3.0 | 5.3 | .0034 | -1 ▼ |
| drupal | 26 | 94 | 11 | 9 | 66 | 8 | 4 | 1 | 1.1 | 5.7 | .0027 | +9 ▲ |
| github | 6 | 23 | 2 | 11 | 10 | 0 | 0 | 0 | 0.0 | 7.4 | .0054 | +1 ▲ |
| docker | 3 | 12 | 1 | 8 | 3 | 0 | 0 | 0 | 0.0 | 8.4 | .0017 | +1 ▲ |
| wordpress | 1 | 6 | 1 | 4 | 1 | 0 | 3 | 3 | 50.0 | 8.7 | .0340 | -1 ▼ |
| go | 4 | 4 | 0 | 2 | 1 | 1 | 0 | 0 | 0.0 | 5.9 | .0034 | +4 ▲ |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| oracle | 634 | 2905 | 581 | 1660 | 563 | 101 | 28 | 4 | 0.1 | 7.8 | .0036 | -256 ▼ |
| ibm | 398 | 1017 | 196 | 467 | 336 | 18 | 6 | 1 | 0.1 | 7.5 | .0037 | +24 ▲ |
| adobe | 224 | 830 | 82 | 364 | 375 | 9 | 21 | 5 | 0.6 | 7.5 | .0036 | +123 ▲ |
| progress | 3 | 64 | 15 | 39 | 10 | 0 | 6 | 1 | 1.6 | 8.1 | .0046 | -16 ▼ |
| zohocorp | 27 | 37 | 6 | 24 | 7 | 0 | 0 | 0 | 0.0 | 8.1 | .0109 | +23 ▲ |
| solarwinds | 3 | 26 | 18 | 5 | 3 | 0 | 10 | 4 | 15.4 | 9.1 | .0067 | +3 ▲ |
| veeam | 0 | 19 | 6 | 10 | 3 | 0 | 1 | 0 | 0.0 | 8.6 | .0042 | -13 ▼ |
| servicenow | 5 | 10 | 7 | 3 | 0 | 0 | 2 | 0 | 0.0 | 9.4 | .0036 | +1 ▲ |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| d-link | 28 | 73 | 22 | 27 | 12 | 12 | 3 | 0 | 0.0 | 8.5 | .0170 | +12 ▲ |
| siemens | 15 | 52 | 6 | 33 | 10 | 3 | 0 | 0 | 0.0 | 7.3 | .0026 | -6 ▼ |
| synology | 19 | 46 | 5 | 10 | 25 | 6 | 0 | 0 | 0.0 | 5.6 | .0032 | +18 ▲ |
| rockwell automation | 18 | 43 | 5 | 32 | 6 | 0 | 0 | 0 | 0.0 | 8.6 | .0029 | +17 ▲ |
| advantech | 17 | 20 | 2 | 17 | 1 | 0 | 0 | 0 | 0.0 | 8.6 | .0071 | +17 ▲ |
| schneider electric | 9 | 18 | 2 | 11 | 5 | 0 | 0 | 0 | 0.0 | 8.5 | .0044 | +9 ▲ |
| hikvision | 3 | 9 | 0 | 5 | 4 | 0 | 0 | 0 | 0.0 | 7.1 | .0038 | +3 ▲ |
| abb | 2 | 9 | 1 | 5 | 3 | 0 | 0 | 0 | 0.0 | 7.2 | .0018 | +2 ▲ |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| dell | 195 | 366 | 31 | 170 | 143 | 22 | 2 | 1 | 0.3 | 7.2 | .0029 | +124 ▲ |
| sourcecodester | 63 | 232 | 0 | 0 | 138 | 94 | 0 | 0 | 0.0 | 5.5 | .0043 | +15 ▲ |
| openclaw | 82 | 215 | 4 | 109 | 81 | 21 | 0 | 0 | 0.0 | 7.1 | .0031 | +82 ▲ |
| nvidia | 51 | 185 | 21 | 127 | 37 | 0 | 0 | 0 | 0.0 | 7.8 | .0040 | -1 ▼ |
| spring | 0 | 170 | 13 | 60 | 83 | 14 | 0 | 0 | 0.0 | 6.5 | .0033 | -91 ▼ |
| mongodb | 71 | 169 | 6 | 99 | 60 | 4 | 1 | 0 | 0.0 | 7.1 | .0038 | +27 ▲ |
| itsourcecode | 37 | 153 | 0 | 0 | 37 | 116 | 0 | 0 | 0.0 | 2.1 | .0033 | +7 ▲ |
| hewlett packard enterprise (hpe) | 139 | 148 | 17 | 77 | 48 | 6 | 1 | 1 | 0.7 | 7.2 | .0044 | +136 ▲ |
| CVE | EPSS | %ile | CVSS |
|---|---|---|---|
| CVE-2026-85706 | .9143 | 99.8 | 10.0 |
| CVE-2026-85046 | .4888 | 98.8 | 8.8 |
| CVE-2026-76461 | .2827 | 98.1 | 9.8 |
| CVE-2026-93616 | .1965 | 97.3 | 9.8 |
| CVE-2026-87902 | .1817 | 97.1 | 8.1 |
| CVE-2026-76460 | .1403 | 96.4 | 10.0 |
| CVE-2026-86218 | .1293 | 96.2 | 10.0 |
| CVE-2026-83549 | .1076 | 95.7 | 7.8 |
| CVE-2026-83548 | .0876 | 95.0 | 10.0 |
| CVE-2026-79756 | .0752 | 94.3 | 8.7 |
| CVE | CVSS | EPSS | Note |
|---|---|---|---|
| CVE-2026-85706 | 10.0 | .9143 | KEV |
| CVE-2026-76460 | 10.0 | .1403 | KEV |
| CVE-2026-86218 | 10.0 | .1293 | KEV |
| CVE-2026-83548 | 10.0 | .0876 | KEV |
| CVE-2026-75650 | 10.0 | .0395 | KEV |
| CVE-2026-82004 | 10.0 | .0325 | |
| CVE-2026-86152 | 10.0 | .0288 | |
| CVE-2026-82456 | 10.0 | .0173 | |
| CVE-2026-85978 | 10.0 | .0144 | |
| CVE-2026-73369 | 10.0 | .0125 |
| Vendor | CVEs |
|---|---|
| linux | 2115 |
| microsoft | 1002 |
| oracle | 634 |
| 518 | |
| ibm | 398 |
| apple | 246 |
| red hat | 245 |
| adobe | 224 |
| dell | 196 |
| apache | 147 |
| Vendor | KEV |
|---|---|
| microsoft | 31 |
| cisco | 16 |
| 9 | |
| apple | 8 |
| fortinet | 7 |
| linux | 6 |
| adobe | 5 |
| ivanti | 5 |
| berriai | 4 |
| checkpoint | 4 |
| Ecosystem | Advisories |
|---|---|
| Maven | 93 |
| Packagist | 18 |
| npm | 16 |
| PyPI | 14 |
| crates.io | 9 |
| Go | 2 |
| RubyGems | 2 |
| NuGet | 1 |
| CVE | Vendor | Days |
|---|---|---|
| CVE-2026-58704 | 0 | |
| CVE-2026-75650 | Adobe | 0 |
| CVE-2026-83548 | SonicWall | 0 |
| CVE-2026-83549 | SonicWall | 0 |
| CVE-2026-85046 | 0 | |
| CVE-2026-87491 | 0 | |
| CVE-2026-93952 | Arista Networks | 0 |
| CVE-2026-84869 | ConnectWise | 2 |
| CVE-2026-86218 | N-able | 2 |
| CVE-2026-87902 | WordPress | 2 |
| CVE | Vendor | Due | Days over |
|---|---|---|---|
| CVE-2021-27104 | n/a | 2021-11-17 | 1775 |
| CVE-2021-27102 | n/a | 2021-11-17 | 1775 |
| CVE-2021-27101 | n/a | 2021-11-17 | 1775 |
| CVE-2021-27103 | n/a | 2021-11-17 | 1775 |
| CVE-2021-21017 | Adobe | 2021-11-17 | 1775 |
| CVE-2021-28550 | Adobe | 2021-11-17 | 1775 |
| CVE-2021-42013 | Apache Software Foundation | 2021-11-17 | 1775 |
| CVE-2021-41773 | Apache Software Foundation | 2021-11-17 | 1775 |
| CVE-2021-30858 | Apple | 2021-11-17 | 1775 |
| CVE-2021-30860 | Apple | 2021-11-17 | 1775 |
ADDED TO KEV — CVE-2026-88771 (Citrix NetScaler ADC). Remediation due September 30, 2026.
ADDED TO KEV — CVE-2026-88772 (Citrix NetScaler ADC). Remediation due September 30, 2026.
EXPLOIT PUBLISHED — SourceCodester Drug Recommendation System: 7 CVEs (CVE-2026-92927, CVE-2026-93997, CVE-2026-94015, CVE-2026-94016, CVE-2026-94033, CVE-2026-94034, CVE-2026-94035). Public exploit references added.
EXPLOIT PUBLISHED — CVE-2026-93988 (webkul qloapps). Public exploit reference added.
RESCORED — CVE-2026-96276 (Red Hat Enterprise Linux 10). CVSS 9.8 → 6.5 (NVD).
How to read these box scores · glossary
151 CVEs published. 25 box scores, 126 table rows — nothing truncated.
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L P N N H H H 9.5 — — YES
AFFECTED Product Versions Fixed ADC unspecified — Gateway unspecified —
TIMELINE Sep 10 Reserved by CNA Sep 27 Added to CISA KEV, due Sep 30 Sep 27 Published (CNA: NetScaler)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N H N N N H H H 9.5 — — YES
AFFECTED Product Versions Fixed ADC unspecified — Gateway unspecified —
TIMELINE Sep 10 Reserved by CNA Sep 27 Added to CISA KEV, due Sep 30 Sep 27 Published (CNA: NetScaler)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L N H H H 8.7 .0372 89.4 —
AFFECTED Product Versions Fixed AzuraCast unspecified —
TIMELINE Sep 27 Reserved by CNA Sep 27 Published (CNA: VulnCheck)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0173 76.7 —
AFFECTED Product Versions Fixed hMailServer 6.0.0 – —
TIMELINE Sep 26 Reserved by CNA Sep 27 Published (CNA: GitLab)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L N H H H 8.7 .0069 50.7 —
AFFECTED Product Versions Fixed heym unspecified 0.0.91
TIMELINE Sep 27 Reserved by CNA Sep 27 Published (CNA: VulnCheck)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV L L N N N H H H 8.6 .0064 48.6 —
AFFECTED Product Versions Fixed MONAI unspecified 1.6.0
TIMELINE Sep 27 Reserved by CNA Sep 27 Published (CNA: VulnCheck)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L P N N L H N 8.3 .0055 43.9 —
AFFECTED Product Versions Fixed wolfSSL 5.6.0 – —
TIMELINE Sep 10 Reserved by CNA Sep 27 Published (CNA: wolfSSL)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N L L L 5.5 .0050 40.2 —
AFFECTED Product Versions Fixed Coolify 4.0 – 4.1.1
TIMELINE Sep 26 Reserved by CNA Sep 27 Published (CNA: VulDB)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N L L L 5.5 .0045 36.9 —
AFFECTED Product Versions Fixed Coolify 4.1.0 – 4.2.0
TIMELINE Sep 26 Reserved by CNA Sep 27 Published (CNA: VulDB)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L N H H H 8.6 .0045 36.9 —
AFFECTED Product Versions Fixed DIR-895L A1_102b07 – —
TIMELINE Sep 26 Reserved by CNA Sep 27 Published (CNA: VulDB)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L N H H H 8.7 .0045 36.3 —
AFFECTED Product Versions Fixed heym unspecified 0.0.53
TIMELINE Sep 27 Reserved by CNA Sep 27 Published (CNA: VulnCheck)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L P N N H H H 9.5 .0040 31.6 —
AFFECTED Product Versions Fixed vm2 unspecified 3.12.2
TIMELINE Sep 26 Reserved by CNA Sep 27 Published (CNA: VulnCheck)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L N H H H 8.7 .0037 28.4 —
AFFECTED Product Versions Fixed AzuraCast unspecified 0.23.6
TIMELINE Sep 27 Reserved by CNA Sep 27 Published (CNA: VulnCheck)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L P N N L H N 8.3 .0036 27.6 —
AFFECTED Product Versions Fixed wolfSSL 5.3.0 – —
TIMELINE Sep 17 Reserved by CNA Sep 27 Published (CNA: wolfSSL)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L P N N N N N 6.3 .0034 25.3 —
AFFECTED Product Versions Fixed http4k unspecified 6.49.0.0 http4k unspecified 5.42.0.0 http4k unspecified 4.51.0.0
TIMELINE Sep 26 Reserved by CNA Sep 27 Published (CNA: VulnCheck)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L P H H H 8.6 .0034 24.4 —
AFFECTED Product Versions Fixed AzuraCast unspecified 0.23.4
TIMELINE Sep 27 Reserved by CNA Sep 27 Published (CNA: VulnCheck)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L P N N H N N 8.2 .0032 22.5 —
AFFECTED Product Versions Fixed http4k unspecified 6.48.0.0 http4k unspecified 5.42.0.0 http4k unspecified 4.51.0.0
TIMELINE Sep 26 Reserved by CNA Sep 27 Published (CNA: VulnCheck)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L P N N N N N 6.9 .0032 22.0 —
AFFECTED Product Versions Fixed vm2 unspecified 3.12.2
TIMELINE Sep 26 Reserved by CNA Sep 27 Published (CNA: VulnCheck)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U L N N 5.3 .0031 21.3 —
AFFECTED Product Versions Fixed WebFacing™ 5.3 – —
TIMELINE Sep 1 Reserved by CNA Sep 27 Published (CNA: WPScan)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L N L L L 2.1 .0031 21.3 —
AFFECTED Product Versions Fixed BR-6428nC 1.16 – —
TIMELINE Sep 26 Reserved by CNA Sep 27 Published (CNA: VulDB)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N H P L N N N L 2.3 .0028 18.7 —
AFFECTED Product Versions Fixed wolfSSL 4.4.0 – —
TIMELINE Jul 10 Reserved by CNA Sep 27 Published (CNA: wolfSSL)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N H P H P H H H 8.8 .0027 17.3 —
AFFECTED Product Versions Fixed MONAI unspecified 1.5.2
TIMELINE Sep 27 Reserved by CNA Sep 27 Published (CNA: VulnCheck)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N H P L N H H N 7.6 .0027 17.0 —
AFFECTED Product Versions Fixed heym unspecified 0.0.109
TIMELINE Sep 27 Reserved by CNA Sep 27 Published (CNA: VulnCheck)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L P N N N N H 8.9 .0026 15.9 —
AFFECTED Product Versions Fixed vm2 unspecified 3.12.2
TIMELINE Sep 26 Reserved by CNA Sep 27 Published (CNA: VulnCheck)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H N N 8.7 .0026 15.3 —
AFFECTED Product Versions Fixed AzuraCast unspecified 0.23.8
TIMELINE Sep 27 Reserved by CNA Sep 27 Published (CNA: VulnCheck)
| CVE | CVSS | EPSS %ile | Vendor | Product | CWE | Title |
|---|---|---|---|---|---|---|
| CVE-2026-100859 | 7.1 | 15.1 | heymrun | heym | CWE-918 | Heym before 0.0.106 Credential Exfiltration via URL Override |
| CVE-2026-89102 | 8.3 | 14.7 | wolfSSL | wolfSSL | CWE-295 | OCSP stapling v2 multi accepts non-CA chain certificates as issuers |
| CVE-2026-100863 | 5.3 | 14.2 | heymrun | heym | CWE-918 | Heym before 0.0.91 SSRF via image fetching and IPv6 validation |
| CVE-2026-100853 | 8.2 | 13.8 | AzuraCast | AzuraCast | CWE-862 | AzuraCast before 0.23.8 On-Demand Download Endpoint Authorization Bypass |
| CVE-2026-100725 | 8.3 | 13.5 | http4k | http4k | CWE-200 | http4k before 6.48.0.0 Cookie Scoping Bypass via BasicCookieStorage |
| CVE-2026-100849 | 7.1 | 13.5 | AzuraCast | AzuraCast | CWE-918 | AzuraCast before 0.23.8 SSRF Filter Bypass via Hostname and Private IPs |
| CVE-2026-89133 | 6.3 | 12.1 | wolfSSL | wolfSSL | CWE-295 | NameConstraints not enforced across unconstrained intermediate CA |
| CVE-2026-94417 | 2.3 | 12.1 | wolfSSL | wolfSSL | CWE-299 | CRL check skipped when OCSP enabled and certificate has no OCSP URL |
| CVE-2026-100833 | 7.6 | 12.0 | edgelesssys | contrast | CWE-20 | Contrast before 1.23.1 Image Substitution via Policy Generation |
| CVE-2026-100850 | 4.8 | 11.9 | AzuraCast | AzuraCast | CWE-918 | AzuraCast before 0.23.8 SSRF and Local File Read via Remote Playlist |
| CVE-2026-100838 | 8.6 | 11.4 | edgelesssys | contrast | CWE-59 | Contrast before 1.19.1 CopyFile Policy Symlink Subversion |
| CVE-2026-100835 | 9.1 | 10.9 | edgelesssys | contrast | CWE-295 | Contrast before 1.16.0 Remote Attestation Relay Attack |
| CVE-2026-89134 | 6.3 | 10.9 | wolfSSL | wolfSSL | CWE-295 | Subject CN name-constraint check bypassed when non-DNS SAN present |
| CVE-2026-100837 | 6.3 | 10.4 | edgelesssys | contrast | CWE-1289 | Edgeless Systems Contrast through 1.20.0 Credential Leak via Registry Suffix … |
| CVE-2026-100855 | 7.1 | 9.8 | AzuraCast | AzuraCast | CWE-862 | AzuraCast before 0.23.6 Missing Permission Check via /play |
| CVE-2026-100840 | 8.5 | 9.7 | Project-MONAI | MONAI | CWE-95 | MONAI through 1.6.0 Remote Code Execution via bundle configuration |
| CVE-2026-100851 | 7.2 | 9.7 | AzuraCast | AzuraCast | CWE-200 | AzuraCast before 0.23.8 Broken Access Control via GET /api/station/{id}/vue/p… |
| CVE-2026-89135 | 6.3 | 9.7 | wolfSSL | wolfSSL | CWE-295 | Failed X509_verify_cert leaves unverified CA in shared CertManager |
| CVE-2025-71423 | 8.5 | 9.5 | edgelesssys | contrast | CWE-532 | Edgelesssys Contrast before 1.12.2 Workload Secrets Information Disclosure |
| CVE-2026-100862 | 6.9 | 8.1 | heymrun | heym | CWE-312 | heym before 0.0.91 Multiple Secrets Plaintext Storage |
| CVE-2026-93304 | 6.3 | 8.2 | wolfSSL | wolfSSL | CWE-696 | (D)TLS 1.2 client accepts early ChangeCipherSpec before ClientKeyExchange |
| CVE-2025-71425 | 8.5 | 7.7 | edgelesssys | contrast | CWE-532 | Contrast before 1.8.1 Information Disclosure via Logging |
| CVE-2026-100843 | 8.5 | 7.6 | Project-MONAI | MONAI | CWE-502 | MONAI before 1.6.0 Remote Code Execution via algo_from_pickle |
| CVE-2026-96896 | 7.2 | 7.2 | Unknown | Malcure Malware Shield — Removal, Repair, Monitor | CWE-862 | Malcure Malware Shield < 19.9.7 - Multisite Subsite Admin+ Arbitrary File Wri… |
| CVE-2026-100861 | 5.3 | 7.0 | heymrun | heym | CWE-918 | heym before 0.0.105 SSRF via credential-controlled base URLs |
| CVE-2026-100848 | 7.1 | 6.6 | AzuraCast | AzuraCast | CWE-918 | AzuraCast before 0.23.8 Server-Side Request Forgery via Remote Relay URL |
| CVE-2026-92436 | 5.3 | 6.5 | Unknown | Mailchimp for WooCommerce | CWE-639 | Mailchimp for WooCommerce < 6.3 - Unauthenticated Customer Email and Cart Dis… |
| CVE-2026-86609 | 8.8 | 5.9 | Unknown | Download Manager | CWE-79 | Download Manager Pro < 7.5.6 - Unauthenticated Stored XSS via Email Lock Subs… |
| CVE-2025-71424 | 5.1 | 4.9 | edgelesssys | contrast | CWE-693 | Edgeless Systems Contrast before 1.9.1 Insecure Volume Mount |
| CVE-2026-100854 | 5.3 | 4.4 | AzuraCast | AzuraCast | CWE-862 | AzuraCast before 0.23.6 Metadata Injection via Liquidsoap API |
| CVE-2026-81655 | 7.5 | 3.7 | Unknown | Ad Inserter | CWE-94 | Ad Inserter 2.8.12 - 2.8.18 - Subscriber+ RCE / Stored XSS via Global Custom … |
| CVE-2026-85002 | 6.8 | 3.7 | Unknown | EmbedPress | CWE-79 | EmbedPress < 4.6.7 - Contributor+ Stored XSS via Instagram Carousel Block Att… |
| CVE-2026-89006 | 6.8 | 3.7 | Unknown | WPeMatico RSS Feed Fetcher | CWE-79 | WPeMatico RSS Feed Fetcher < 2.8.27 - Contributor+ Stored XSS via Feed Import |
| CVE-2026-96895 | 6.8 | 3.7 | Unknown | WP YouTube Lyte | CWE-79 | WP YouTube Lyte < 1.7.31 - Contributor+ Stored XSS via Embed Block Attributes |
| CVE-2026-96899 | 6.8 | 3.7 | Unknown | Optima Express IDX | CWE-79 | Optima Express 8.6.0 - 8.7.5 - Author+ Stored XSS via faq_script |
| CVE-2026-97319 | 6.8 | 3.7 | Unknown | PowerPress Podcasting plugin by Blubrry | CWE-79 | PowerPress < 11.17.2 - Contributor+ Stored XSS via Podcast Player Block |
| CVE-2026-86841 | 4.7 | 3.5 | Unknown | Online Scheduling and Appointment Booking System | CWE-502 | Bookly 23.2 - 28.2 - Bookly Administrator+ PHP Object Injection via Diagnosti… |
| CVE-2026-100839 | 8.4 | 3.4 | edgelesssys | contrast | CWE-94 | Contrast before 1.18.0 AML Injection Remote Code Execution |
| CVE-2026-100842 | 7.3 | 3.4 | Project-MONAI | MONAI | CWE-95 | MONAI through 1.6.0 _get_fake_spatial_shape eval() Sandbox Bypass via Attribu… |
| CVE-2026-100836 | 5.3 | 3.3 | edgelesssys | contrast | CWE-129 | Edgeless Systems Contrast through 1.20.0 Denial of Service via ciphertextCont… |
| CVE-2026-92995 | 5.3 | 3.2 | Unknown | Verge3D Publishing and E-Commerce | CWE-200 | Verge3D <= 4.13.0 - Unauthenticated Product Download Disclosure via v3d_downl… |
| CVE-2025-71426 | 7.1 | 2.8 | edgelesssys | contrast | CWE-285 | Contrast before 1.4.1 Coordinator Impersonation via Unauthenticated Recovery |
| CVE-2026-82841 | 5.3 | 2.7 | Unknown | UpdraftPlus: WP Backup & Migration Plugin | CWE-200 | UpdraftPlus 1.23.8 - 1.26.7 - Subscriber+ Remote Storage Credential Disclosur… |
| CVE-2026-96897 | 5.3 | 2.5 | Unknown | Optima Express IDX | CWE-862 | Optima Express 8.5.0 - 8.7.5 - Unauthenticated Author Account Creation & Appl… |
| CVE-2026-100845 | 8.5 | 2.5 | Project-MONAI | MONAI | CWE-502 | MONAI before 1.6.0 Remote Code Execution via NumpyReader |
| CVE-2026-97227 | 5.9 | 2.3 | Unknown | NextScripts: Social Networks Auto-Poster | CWE-862 | NextScripts: Social Networks Auto-Poster < 4.4.8 - Authenticated Social Accou… |
| CVE-2026-89001 | 4.9 | 2.3 | Unknown | WPeMatico RSS Feed Fetcher | CWE-269 | WPeMatico RSS Feed Fetcher < 2.8.27 - Contributor+ Post Publication and Autho… |
| CVE-2026-89000 | 4.1 | 2.3 | Unknown | WPeMatico RSS Feed Fetcher | CWE-918 | WPeMatico RSS Feed Fetcher < 2.8.27 - Contributor+ SSRF via Campaign Run |
| CVE-2026-89003 | 4.1 | 2.3 | Unknown | WPeMatico RSS Feed Fetcher | CWE-918 | WPeMatico RSS Feed Fetcher < 2.8.27 - Contributor+ SSRF via Campaign Preview |
| CVE-2026-86839 | 3.8 | 2.3 | Unknown | Online Scheduling and Appointment Booking System | CWE-639 | Bookly < 28.3 - Staff+ Appointment and Payment Disclosure, Modification and D… |
| CVE-2026-100841 | 8.5 | 1.9 | Project-MONAI | MONAI | CWE-502 | MONAI through 1.6.0 PersistentDataset Remote Code Execution via Pickle Cache |
| CVE-2026-100860 | 6.8 | 1.4 | heymrun | heym | CWE-636 | heym before 0.0.105 Authentication Bypass via Redis Node |
| CVE-2026-94419 | 2.3 | 0.1 | wolfSSL | wolfSSL | CWE-287 | Client session cache reference poisoning allows resumption with wrong server |
| CVE-2025-71422 | 6.9 | 0.1 | edgelesssys | contrast | CWE-347 | Contrast before 1.12.1 Insecure LUKS2 Persistent Storage |
| CVE-2026-94418 | 2.3 | 0.0 | wolfSSL | wolfSSL | CWE-347 | Signature failure masked by date error under WOLFSSL_SMALL_CERT_VERIFY |
| CVE-2026-88773 | 9.3 | — | Citrix NetScaler | ADC | CWE-444 | HTTP Request Smuggling |
| CVE-2026-100886 | 9.3 | — | Seetong | T8108 | CWE-287 | Seetong T8108/T8108P/T8116/T8232 Debug Service improper authentication |
| CVE-2026-101065 | 9.3 | — | obot-platform | obot | CWE-306 | Obot Quickstart Docker Deployment Unauthenticated Admin Access |
| CVE-2026-101084 | 9.3 | — | obot-platform | obot | CWE-639 | obot before v0.21.1 Authorization Bypass via /mcp-connect |
| CVE-2026-101090 | 9.3 | — | nezhahq | nezha | CWE-601 | Nezha through 2.2.3 Host Header Injection via OAuth2 redirect_uri |
| CVE-2026-101045 | 8.9 | — | fleetdm | fleet | CWE-78 | Fleet Homebrew Cask OS Command Injection via Metadata |
| CVE-2026-88775 | 8.8 | — | Citrix NetScaler | ADC | — | Memory overflow vulnerability leading to unpredictable or erroneous behavior … |
| CVE-2026-88776 | 8.8 | — | Citrix NetScaler | ADC | — | Memory overflow vulnerability leading to unpredictable or erroneous behavior … |
| CVE-2026-88777 | 8.8 | — | Citrix NetScaler | ADC | — | Memory overflow vulnerability leading to unpredictable or erroneous behavior … |
| CVE-2026-88778 | 8.8 | — | Citrix NetScaler | ADC | CWE-342 | TCP Initial Sequence Number (ISN) prediction |
| CVE-2026-100870 | 8.7 | — | Sylius | Sylius | CWE-640 | Sylius before 1.12.25, 1.13.17, 1.14.20, 2.1.16, and 2.2.9 Admin Password Res… |
| CVE-2026-100871 | 8.7 | — | Sylius | Sylius | CWE-287 | Sylius before 1.12.25, 1.13.17, 1.14.20, 2.1.16, and 2.2.9 JWT Audience Confu… |
| CVE-2026-100872 | 8.7 | — | Sylius | Sylius | CWE-345 | Sylius 2.x before 2.1.16 and 2.2.9 Payment Amount Overwrite |
| CVE-2026-101062 | 8.7 | — | obot-platform | obot | CWE-863 | Obot before v0.23.0 Authentication Bypass via OAuth Dynamic Client Registration |
| CVE-2026-101060 | 8.4 | — | universal-tool-calling-protocol | python-utcp | CWE-918 | python-utcp before 1.1.4 SSRF via unvalidated HTTP redirects |
| CVE-2026-101043 | 8.3 | — | pnpm | pnpm | CWE-201 | pnpm 11.0.0 before 11.11.0 Environment Variable Exfiltration via Proxy Settings |
| CVE-2026-101049 | 8.3 | — | heymrun | heym | CWE-287 | Heym before 0.0.53 Slack Webhook Signature Verification Bypass |
| CVE-2026-101050 | 8.3 | — | heymrun | heym | CWE-287 | Heym before 0.0.53 Authentication Bypass via Telegram Webhook |
| CVE-2026-101064 | 8.3 | — | obot-platform | obot | CWE-918 | Obot before v0.23.0 Server-Side Request Forgery via MCP |
| CVE-2026-100869 | 8.2 | — | Sylius | Sylius | CWE-863 | Sylius 2.x before 2.1.16 and 2.2.9 Arbitrary Payment Action via Shop API |
| CVE-2026-96280 | 7.5 | — | Red Hat | Red Hat Enterprise Linux 10 | CWE-197 | Flatpak: flatpak: buffer overflow in oci delta stream path names on 32-bit sy… |
| CVE-2026-101042 | 7.4 | — | parse-community | parse-server | CWE-287 | Parse Server 9.0.0 Authentication Bypass via Unverified Provider Identity |
| CVE-2026-101032 | 7.3 | — | denisidoro | navi | CWE-78 | navi through 2.24.0 OS Command Injection via Cheatsheet Variables |
| CVE-2026-101044 | 7.1 | — | pnpm | pnpm | CWE-22 | pacquet before 12.0.0-alpha.5 Path Traversal via lockfile alias |
| CVE-2026-101058 | 7.1 | — | universal-tool-calling-protocol | python-utcp | CWE-918 | python-utcp before 1.1.12 SSRF via Remote HTTP Manual |
| CVE-2026-101059 | 7.1 | — | universal-tool-calling-protocol | python-utcp | CWE-918 | utcp-http before 1.1.4 OAuth2 tokenUrl Trust Boundary Bypass |
| CVE-2026-101085 | 7.1 | — | nezhahq | nezha | CWE-197 | Nezha before 2.3.8 Denial of Service via Alert Rule |
| CVE-2026-101086 | 7.1 | — | nezhahq | nezha | CWE-269 | Nezha Dashboard before 2.3.5 Task Type Validation Bypass |
| CVE-2026-88774 | 7.0 | — | Citrix NetScaler | ADC | — | Feature policy bypass due to improper HTTP URL based expression usage |
| CVE-2026-97164 | 7.0 | — | svenbluege.de | Event Gallery for Joomla | CWE-22 | Joomla Extension - svenbluege.de - Path Traversal in Clear Cache task in Even… |
| CVE-2026-100748 | 6.9 | — | svenbluege.de | Event Gallery for Joomla | CWE-352 | Joomla Extension - svenbluege.de - CSRF in various cart actions in Event Gall… |
| CVE-2026-100888 | 6.9 | — | Trusted Domain Project | OpenDKIM | CWE-787 | Trusted Domain Project OpenDKIM DKIM Signature Header Selection dkim-canon.c … |
| CVE-2026-100889 | 6.9 | — | Trusted Domain Project | OpenDKIM | CWE-193 | Trusted Domain Project OpenDKIM Decoder util.c dkim_qp_decode off-by-one |
| CVE-2026-101047 | 6.9 | — | fleetdm | fleet | CWE-862 | Fleet before 4.87.0 Unauthenticated iOS App Download via Predictable URLs |
| CVE-2026-101056 | 6.9 | — | cloudreve | cloudreve | CWE-863 | Cloudreve before 4.16.1 Authentication Bypass via Cached Context Hint |
| CVE-2026-101063 | 6.9 | — | obot-platform | obot | CWE-862 | Obot before v0.23.0 Authentication Bypass via Registry API |
| CVE-2026-96279 | 6.5 | — | Red Hat | Red Hat Enterprise Linux 10 | CWE-59 | Flatpak: flatpak: path traversal issue in oci archive extraction via hardlinks |
| CVE-2026-101041 | 6.3 | — | vulnerability-lookup | vulnerability-lookup | CWE-20 | Vulnerability-Lookup - Race Condition in Account Recovery Token Consumption A… |
| CVE-2026-96281 | 6.2 | — | Red Hat | Red Hat Enterprise Linux 10 | CWE-284 | Flatpak: flatpak: unprivileged active user can bypass anti-downgrade checks f… |
| CVE-2026-101088 | 6.0 | — | nezhahq | nezha | CWE-367 | Nezha before 2.3.1 Denial of Service via Concurrent Server Delete |
| CVE-2026-100874 | 5.5 | — | mathurvishal | CloudClassroom-PHP-Project | CWE-74 | mathurvishal CloudClassroom-PHP-Project addnewstudent.php sql injection |
| CVE-2026-100875 | 5.5 | — | mathurvishal | CloudClassroom-PHP-Project | CWE-74 | mathurvishal CloudClassroom-PHP-Project updatedetailsfromfaculty.php sql inje… |
| CVE-2026-100885 | 5.5 | — | Krayin | laravel-crm | CWE-285 | Krayin laravel-crm admin-config-setup API Endpoint CanInstall.php authorization |
| CVE-2026-97165 | 5.3 | — | svenbluege.de | Event Gallery for Joomla | CWE-79 | Joomla Extension - svenbluege.de - Reflected XSS and open redirect in Event G… |
| CVE-2026-100868 | 5.3 | — | penpot | penpot | CWE-1327 | Penpot before 2.18.0 Unauthenticated WebSocket Access via MCP Bridge |
| CVE-2026-100887 | 5.3 | — | amirsanni | Mini-Inventory-and-Sales-Management-System | CWE-89 | amirsanni Mini-Inventory-and-Sales-Management-System Database Query Builder D… |
| CVE-2026-101033 | 5.3 | — | TomBursch | kitchenowl | CWE-639 | KitchenOwl through 0.7.10 IDOR via unchecked category ID |
| CVE-2026-101048 | 5.3 | — | cloudreve | cloudreve | CWE-863 | Cloudreve before 4.17.0 SSRF via Admin.Read OAuth scope |
| CVE-2026-101087 | 5.3 | — | nezhahq | nezha | CWE-918 | Nezha 2.0.10 through 2.3.2 SSRF Denylist Bypass IPv6 |
| CVE-2026-100747 | 5.1 | — | svenbluege.de | Event Gallery for Joomla | CWE-352 | Joomla Extension - svenbluege.de - CSRF in image upload in Event Gallery exte… |
| CVE-2026-100749 | 5.1 | — | svenbluege.de | Event Gallery for Joomla | CWE-352 | Joomla Extension - svenbluege.de - CSRF in backend cleanup actions in Event G… |
| CVE-2026-100866 | 4.8 | — | o2sh | onefetch | CWE-150 | onefetch through 2.28.1 Terminal Escape Sequence Injection |
| CVE-2026-100867 | 4.8 | — | spaceship-prompt | spaceship-prompt | CWE-150 | spaceship-prompt through 4.22.5 Terminal Escape Sequence Injection |
| CVE-2026-96283 | 3.3 | — | Red Hat | Red Hat Enterprise Linux 10 | CWE-862 | Flatpak: flatpak: flatpak-system-helper cross-user cancelpull orphans another… |
| CVE-2026-96282 | 3.1 | — | Red Hat | Red Hat Enterprise Linux 10 | CWE-59 | Flatpak: flatpak: extension metadata path traversal file existence oracle |
| CVE-2026-96284 | 2.5 | — | Red Hat | Red Hat Enterprise Linux 10 | CWE-59 | Flatpak: flatpak: arbitrary read-access to files in the system-helper context… |
| CVE-2026-101046 | 2.3 | — | fleetdm | fleet | CWE-89 | Fleet before 4.89.0 SQL Injection via ORDER BY Activity Endpoints |
| CVE-2026-101051 | 2.3 | — | cloudreve | cloudreve | CWE-22 | Cloudreve before 4.16.1 Path Traversal via Remote Download |
| CVE-2026-101057 | 2.3 | — | universal-tool-calling-protocol | python-utcp | CWE-319 | utcp-mcp before 1.1.3 SSRF via unvalidated MCP server URL |
| CVE-2026-101061 | 2.3 | — | universal-tool-calling-protocol | python-utcp | CWE-918 | utcp-gql and utcp-websocket before 1.1.1 SSRF via URL validation bypass |
| CVE-2026-101089 | 2.3 | — | nezhahq | nezha | CWE-522 | Nezha before 2.2.7 Information Disclosure via /api/v1/profile |
| CVE-2026-100873 | 2.1 | — | mathurvishal | CloudClassroom-PHP-Project | CWE-352 | mathurvishal CloudClassroom-PHP-Project cross-site request forgery |
| CVE-2026-100876 | 2.1 | — | mathurvishal | CloudClassroom-PHP-Project | CWE-287 | mathurvishal CloudClassroom-PHP-Project loginlinkstudent.php missing authenti… |
| CVE-2026-100877 | 2.1 | — | mathurvishal | CloudClassroom-PHP-Project | CWE-79 | mathurvishal CloudClassroom-PHP-Project registrationform.php cross site scrip… |
| CVE-2026-100878 | 2.1 | — | zhistaredu | StarTraining | CWE-285 | zhistaredu StarTraining authRole Endpoint SysUser.java SysUser.isAdmin author… |
| CVE-2026-100879 | 2.1 | — | zhistaredu | StarTraining | CWE-862 | zhistaredu StarTraining dataScope Endpoint SysRoleServiceImpl.java checkRoleA… |
| CVE-2026-100883 | 2.1 | — | Krayin | laravel-crm | CWE-266 | Krayin laravel-crm acl.php access control |
| CVE-2026-100884 | 2.1 | — | Krayin | laravel-crm | CWE-99 | Krayin laravel-crm attachment-download Endpoint acl.php resource injection |
| CVE-2026-100880 | 2.0 | — | zhistaredu | StarTraining | CWE-79 | zhistaredu StarTraining Upload Endpoint MimeTypeUtils.java cross site scripting |
| CVE-2026-100882 | 1.9 | — | Krayin | laravel-crm | CWE-79 | Krayin laravel-crm Admin Settings Endpoint index.blade.php cross site scripting |
| CVE-2026-100881 | 1.2 | — | zhistaredu | StarTraining | CWE-79 | zhistaredu StarTraining application.yml cross site scripting |
Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.
Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.
Day boundary. A day is a UTC calendar day. This page covers 2026-09-27 00:00:00–23:59:59 UTC. All times shown are UTC.
Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.
Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.
Machine-readable. This edition as JSON or CSV — the ranked results, transactions, and counts, for citation or ingestion. Frozen at publication; later changes appear as transactions on later editions.