boxscore/security

A daily page of record for published software vulnerabilities — the previous UTC day, closed and final. New here?

Sunday, September 27, 2026 · all times UTC← 2026-09-26 · archive

Security Box Score — September 27, 2026

CISA adds 2 to KEV; 151 CVEs published, led by AzuraCast (11).

151 CVEs published September 27, 2026: 10 critical, 61 high, 56 medium, 24 low; 2 in the KEV catalog at press time; 3 with a public exploit reference; 0 awaiting enrichment. Elevated volume. 25 rendered as box scores below; the remaining 126 in the results table.

Standings

League
MTDYTD2025 same span2025 full
CVEs published1338648365——
KEV catalog size1728

Publication counts reflect the record since May 20, 2026 (archive start); KEV figures are catalog-wide.

Prior-year comparisons begin when the archive covers a full year; archive begins May 20, 2026.

3120 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. C/H/M/L = YTD disclosures by severity band. KEV = catalog entries all-time / YTD. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100. Med CVSS / Med EPSS = medians over the vendor's YTD disclosures. Δ = this month-to-date minus the same day-span of last month.

Operating Systems & Platforms
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
linux21146205530263871311560.17.8.0019+606 ▲
microsoft10022901203199069216290311.17.8.0047+533 ▲
google5182686332105011831218090.37.5.0027+116 ▲
red hat2398685136040849200.06.6.0037+23 ▲
apple24656367165317148881.46.5.0019+202 ▲
freebsd04823673000.07.8.0016-32 ▼
canonical0421311135000.07.8.0019-15 ▼
suse1341721121000.07.5.0039+6 ▲
Network & Infrastructure
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
cisco97181537255159168.87.7.0046+51 ▲
ubiquiti665362810334.69.1.0050-17 ▼
palo alto networks9461426151324.34.7.0022-3 ▼
fortinet1141111017329717.17.2.0040+4 ▲
netgear23400277000.04.3.0027-7 ▼
f592671441527.78.7.0050+9 ▲
ivanti10246162025520.88.8.0152+7 ▲
sonicwall519784019421.18.3.0050-7 ▼
Open Source Ecosystems
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
apache137649148275208163320.37.5.0064-21 ▼
mozilla113301102126730900.08.8.0032+54 ▲
gitlab241007245811533.05.3.0034-1 ▼
drupal2694119668411.15.7.0027+9 ▲
github623211100000.07.4.0054+1 ▲
docker3121830000.08.4.0017+1 ▲
wordpress1614103350.08.7.0340-1 ▼
go440211000.05.9.0034+4 ▲
Enterprise Applications
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
oracle634290558116605631012840.17.8.0036-256 ▼
ibm398101719646733618610.17.5.0037+24 ▲
adobe2248308236437592150.67.5.0036+123 ▲
progress3641539100611.68.1.0046-16 ▼
zohocorp273762470000.08.1.0109+23 ▲
solarwinds3261853010415.49.1.0067+3 ▲
veeam01961030100.08.6.0042-13 ▼
servicenow5107300200.09.4.0036+1 ▲
Industrial & Embedded
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
d-link287322271212300.08.5.0170+12 ▲
siemens1552633103000.07.3.0026-6 ▼
synology1946510256000.05.6.0032+18 ▲
rockwell automation184353260000.08.6.0029+17 ▲
advantech172021710000.08.6.0071+17 ▲
schneider electric91821150000.08.5.0044+9 ▲
hikvision390540000.07.1.0038+3 ▲
abb291530000.07.2.0018+2 ▲
Other
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
dell1953663117014322210.37.2.0029+124 ▲
sourcecodester632320013894000.05.5.0043+15 ▲
openclaw8221541098121000.07.1.0031+82 ▲
nvidia5118521127370000.07.8.0040-1 ▼
spring017013608314000.06.5.0033-91 ▼
mongodb71169699604100.07.1.0038+27 ▲
itsourcecode371530037116000.02.1.0033+7 ▲
hewlett packard enterprise (hpe)1391481777486110.77.2.0044+136 ▲

Leaders (trailing 30 days unless noted)

Highest EPSS
CVEEPSS%ileCVSS
CVE-2026-85706.914399.810.0
CVE-2026-85046.488898.88.8
CVE-2026-76461.282798.19.8
CVE-2026-93616.196597.39.8
CVE-2026-87902.181797.18.1
CVE-2026-76460.140396.410.0
CVE-2026-86218.129396.210.0
CVE-2026-83549.107695.77.8
CVE-2026-83548.087695.010.0
CVE-2026-79756.075294.38.7
Highest CVSS
CVECVSSEPSSNote
CVE-2026-8570610.0.9143KEV
CVE-2026-7646010.0.1403KEV
CVE-2026-8621810.0.1293KEV
CVE-2026-8354810.0.0876KEV
CVE-2026-7565010.0.0395KEV
CVE-2026-8200410.0.0325
CVE-2026-8615210.0.0288
CVE-2026-8245610.0.0173
CVE-2026-8597810.0.0144
CVE-2026-7336910.0.0125
Most disclosures (vendor)
VendorCVEs
linux2115
microsoft1002
oracle634
google518
ibm398
apple246
red hat245
adobe224
dell196
apache147
Most KEV additions (YTD)
VendorKEV
microsoft31
cisco16
google9
apple8
fortinet7
linux6
adobe5
ivanti5
berriai4
checkpoint4
Most-affected ecosystems
EcosystemAdvisories
Maven93
Packagist18
npm16
PyPI14
crates.io9
Go2
RubyGems2
NuGet1
Fastest to KEV
CVEVendorDays
CVE-2026-58704Google0
CVE-2026-75650Adobe0
CVE-2026-83548SonicWall0
CVE-2026-83549SonicWall0
CVE-2026-85046Google0
CVE-2026-87491Google0
CVE-2026-93952Arista Networks0
CVE-2026-84869ConnectWise2
CVE-2026-86218N-able2
CVE-2026-87902WordPress2
Longest unpatched (KEV due date passed)
CVEVendorDueDays over
CVE-2021-27104n/a2021-11-171775
CVE-2021-27102n/a2021-11-171775
CVE-2021-27101n/a2021-11-171775
CVE-2021-27103n/a2021-11-171775
CVE-2021-21017Adobe2021-11-171775
CVE-2021-28550Adobe2021-11-171775
CVE-2021-42013Apache Software Foundation2021-11-171775
CVE-2021-41773Apache Software Foundation2021-11-171775
CVE-2021-30858Apple2021-11-171775
CVE-2021-30860Apple2021-11-171775

Transactions

ADDED TO KEV — CVE-2026-88771 (Citrix NetScaler ADC). Remediation due September 30, 2026.

ADDED TO KEV — CVE-2026-88772 (Citrix NetScaler ADC). Remediation due September 30, 2026.

EXPLOIT PUBLISHED — SourceCodester Drug Recommendation System: 7 CVEs (CVE-2026-92927, CVE-2026-93997, CVE-2026-94015, CVE-2026-94016, CVE-2026-94033, CVE-2026-94034, CVE-2026-94035). Public exploit references added.

EXPLOIT PUBLISHED — CVE-2026-93988 (webkul qloapps). Public exploit reference added.

RESCORED — CVE-2026-96276 (Red Hat Enterprise Linux 10). CVSS 9.8 → 6.5 (NVD).

Yesterday's Results

How to read these box scores · glossary

151 CVEs published. 25 box scores, 126 table rows — nothing truncated.

Citrix NetScaler ADC — A remote code execution vulnerability exists due to improper input validation, which can allow an unauthenticated attacker to execute arbitrary commands
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS   EPSS   %ile   KEV
   N   L   P   N   N   H   H   H    9.5      —      —   YES
AFFECTED
  Product  Versions     Fixed
  ADC      unspecified  —
  Gateway  unspecified  —
TIMELINE
  Sep 10  Reserved by CNA
  Sep 27  Added to CISA KEV, due Sep 30
  Sep 27  Published (CNA: NetScaler)
CWE-20 · CNA: NetScaler · CVSS v4.0 · 2 references · NVD status: Undergoing Analysis · KEV due September 30, 2026
Citrix NetScaler ADC — Memory overflow vulnerability leading to Remote Code Execution or Denial of Service
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS   EPSS   %ile   KEV
   N   H   N   N   N   H   H   H    9.5      —      —   YES
AFFECTED
  Product  Versions     Fixed
  ADC      unspecified  —
  Gateway  unspecified  —
TIMELINE
  Sep 10  Reserved by CNA
  Sep 27  Added to CISA KEV, due Sep 30
  Sep 27  Published (CNA: NetScaler)
CWE-119 · CNA: NetScaler · CVSS v4.0 · 2 references · NVD status: Undergoing Analysis · KEV due September 30, 2026
AzuraCast before 0.23.8 Command Injection via Streamer Username
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    8.7   .0372   89.4     —
AFFECTED
  Product    Versions     Fixed
  AzuraCast  unspecified  —
TIMELINE
  Sep 27  Reserved by CNA
  Sep 27  Published (CNA: VulnCheck)
CWE-78 · CNA: VulnCheck · CVSS v4.0 · 2 references · NVD status: Received
Progressive Robot Ltd hMailServer — Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') in hMailServer
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0173   76.7     —
AFFECTED
  Product      Versions  Fixed
  hMailServer  6.0.0 –   —
TIMELINE
  Sep 26  Reserved by CNA
  Sep 27  Published (CNA: GitLab)
CWE-95 · CNA: GitLab · CVSS v3.1 · 2 references · NVD status: Received
heymrun heym — heym before 0.0.91 Remote Code Execution via Expression Engine
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    8.7   .0069   50.7     —
AFFECTED
  Product  Versions     Fixed
  heym     unspecified  0.0.91
TIMELINE
  Sep 27  Reserved by CNA
  Sep 27  Published (CNA: VulnCheck)
CWE-94 · CNA: VulnCheck · CVSS v4.0 · 2 references · NVD status: Received
Project-MONAI MONAI — MONAI before 1.6.0 OS Command Injection via dataset_name_or_id
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   L   L   N   N   N   H   H   H    8.6   .0064   48.6     —
AFFECTED
  Product  Versions     Fixed
  MONAI    unspecified  1.6.0
TIMELINE
  Sep 27  Reserved by CNA
  Sep 27  Published (CNA: VulnCheck)
CWE-78 · CNA: VulnCheck · CVSS v4.0 · 2 references · NVD status: Received
wolfSSL wolfSSL — Client accepts unsolicited RawPublicKey server certificate type
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   P   N   N   L   H   N    8.3   .0055   43.9     —
AFFECTED
  Product  Versions  Fixed
  wolfSSL  5.6.0 –   —
TIMELINE
  Sep 10  Reserved by CNA
  Sep 27  Published (CNA: wolfSSL)
CWE-287 · CNA: wolfSSL · CVSS v4.0 · 1 reference · NVD status: Received
coollabsio Coolify GitHub App Setup redirect missing authentication
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   L   L   L    5.5   .0050   40.2     —
AFFECTED
  Product  Versions  Fixed
  Coolify  4.0 –     4.1.1
TIMELINE
  Sep 26  Reserved by CNA
  Sep 27  Published (CNA: VulDB)
CWE-287, CWE-306 · CNA: VulDB · CVSS v4.0 · 9 references · NVD status: Received
coollabsio Coolify Route-Level Middleware CanUpdateResource.php authorization
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   L   L   L    5.5   .0045   36.9     —
AFFECTED
  Product  Versions  Fixed
  Coolify  4.1.0 –   4.2.0
TIMELINE
  Sep 26  Reserved by CNA
  Sep 27  Published (CNA: VulDB)
CWE-862, CWE-863 · CNA: VulDB · CVSS v4.0 · 9 references · NVD status: Received
D-Link DIR-895L L2TP Control Channel tunnel.c tunnel_set_params out-of-bounds write
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    8.6   .0045   36.9     —
AFFECTED
  Product   Versions     Fixed
  DIR-895L  A1_102b07 –  —
TIMELINE
  Sep 26  Reserved by CNA
  Sep 27  Published (CNA: VulDB)
CWE-119, CWE-787 · CNA: VulDB · CVSS v4.0 · 6 references · NVD status: Received
heymrun heym — Heym before 0.0.53 Remote Code Execution via eval() Sandbox Escape
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    8.7   .0045   36.3     —
AFFECTED
  Product  Versions     Fixed
  heym     unspecified  0.0.53
TIMELINE
  Sep 27  Reserved by CNA
  Sep 27  Published (CNA: VulnCheck)
CWE-94 · CNA: VulnCheck · CVSS v4.0 · 3 references · NVD status: Received
patriksimek vm2 — vm2 before 3.12.2 Authorization Bypass via Custom Resolver
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   P   N   N   H   H   H    9.5   .0040   31.6     —
AFFECTED
  Product  Versions     Fixed
  vm2      unspecified  3.12.2
TIMELINE
  Sep 26  Reserved by CNA
  Sep 27  Published (CNA: VulnCheck)
CWE-863 · CNA: VulnCheck · CVSS v4.0 · 5 references · NVD status: Deferred
AzuraCast before 0.23.6 Code Injection via Remote Relay Password
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    8.7   .0037   28.4     —
AFFECTED
  Product    Versions     Fixed
  AzuraCast  unspecified  0.23.6
TIMELINE
  Sep 27  Reserved by CNA
  Sep 27  Published (CNA: VulnCheck)
CWE-94 · CNA: VulnCheck · CVSS v4.0 · 2 references · NVD status: Received
wolfSSL wolfSSL — Trusted peer certificate match ignores public key, allowing forged CA clones
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   P   N   N   L   H   N    8.3   .0036   27.6     —
AFFECTED
  Product  Versions  Fixed
  wolfSSL  5.3.0 –   —
TIMELINE
  Sep 17  Reserved by CNA
  Sep 27  Published (CNA: wolfSSL)
CWE-295 · CNA: wolfSSL · CVSS v4.0 · 1 reference · NVD status: Received
http4k before 6.49.0.0 Host Header Routing Bypass via reverseProxy
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   P   N   N   N   N   N    6.3   .0034   25.3     —
AFFECTED
  Product  Versions     Fixed
  http4k   unspecified  6.49.0.0
  http4k   unspecified  5.42.0.0
  http4k   unspecified  4.51.0.0
TIMELINE
  Sep 26  Reserved by CNA
  Sep 27  Published (CNA: VulnCheck)
CWE-444 · CNA: VulnCheck · CVSS v4.0 · 4 references · NVD status: Received
AzuraCast before 0.23.4 Remote Code Execution via Liquidsoap string interpolation
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   P   H   H   H    8.6   .0034   24.4     —
AFFECTED
  Product    Versions     Fixed
  AzuraCast  unspecified  0.23.4
TIMELINE
  Sep 27  Reserved by CNA
  Sep 27  Published (CNA: VulnCheck)
CWE-94 · CNA: VulnCheck · CVSS v4.0 · 2 references · NVD status: Received
http4k before 6.48.0.0 Digest Authentication Replay Protection Bypass
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   P   N   N   H   N   N    8.2   .0032   22.5     —
AFFECTED
  Product  Versions     Fixed
  http4k   unspecified  6.48.0.0
  http4k   unspecified  5.42.0.0
  http4k   unspecified  4.51.0.0
TIMELINE
  Sep 26  Reserved by CNA
  Sep 27  Published (CNA: VulnCheck)
CWE-294 · CNA: VulnCheck · CVSS v4.0 · 4 references · NVD status: Received
patriksimek vm2 — vm2 before 3.12.2 Memory Disclosure via zlib Buffer Pool
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   P   N   N   N   N   N    6.9   .0032   22.0     —
AFFECTED
  Product  Versions     Fixed
  vm2      unspecified  3.12.2
TIMELINE
  Sep 26  Reserved by CNA
  Sep 27  Published (CNA: VulnCheck)
CWE-200 · CNA: VulnCheck · CVSS v4.0 · 4 references · NVD status: Deferred
Unknown WebFacing™ — WebFacing Email Accounts for cPanel 5.3 - 5.3.6 - Unauthenticated LFI via assets/index.php
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  L  N  N    5.3   .0031   21.3     —
AFFECTED
  Product     Versions  Fixed
  WebFacing™  5.3 –     —
TIMELINE
  Sep 1   Reserved by CNA
  Sep 27  Published (CNA: WPScan)
CWE-22 · CNA: WPScan · CVSS v3.1 · 1 reference · NVD status: Received
Edimax BR-6428nC Wireless Wizard formWizSurvey stack-based overflow
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   L   L   L    2.1   .0031   21.3     —
AFFECTED
  Product    Versions  Fixed
  BR-6428nC  1.16 –    —
TIMELINE
  Sep 26  Reserved by CNA
  Sep 27  Published (CNA: VulDB)
CWE-119, CWE-121 · CNA: VulDB · CVSS v4.0 · 5 references · NVD status: Received
wolfSSL wolfSSL — Heap use-after-free on read during bidirectional (D)TLS shutdown
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   H   P   L   N   N   N   L    2.3   .0028   18.7     —
AFFECTED
  Product  Versions  Fixed
  wolfSSL  4.4.0 –   —
TIMELINE
  Jul 10  Reserved by CNA
  Sep 27  Published (CNA: wolfSSL)
CWE-416 · CNA: wolfSSL · CVSS v4.0 · 1 reference · NVD status: Received
Project-MONAI MONAI — MONAI before 1.5.2 Remote Code Execution via Pickle Deserialization
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   H   P   H   P   H   H   H    8.8   .0027   17.3     —
AFFECTED
  Product  Versions     Fixed
  MONAI    unspecified  1.5.2
TIMELINE
  Sep 27  Reserved by CNA
  Sep 27  Published (CNA: VulnCheck)
CWE-502 · CNA: VulnCheck · CVSS v4.0 · 2 references · NVD status: Received
heymrun heym — heym before 0.0.109 Server-Side Request Forgery via Workflow Nodes
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   H   P   L   N   H   H   N    7.6   .0027   17.0     —
AFFECTED
  Product  Versions     Fixed
  heym     unspecified  0.0.109
TIMELINE
  Sep 27  Reserved by CNA
  Sep 27  Published (CNA: VulnCheck)
CWE-918 · CNA: VulnCheck · CVSS v4.0 · 2 references · NVD status: Received
patriksimek vm2 — vm2 before 3.12.2 Host Process Termination via Construct Trap
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   P   N   N   N   N   H    8.9   .0026   15.9     —
AFFECTED
  Product  Versions     Fixed
  vm2      unspecified  3.12.2
TIMELINE
  Sep 26  Reserved by CNA
  Sep 27  Published (CNA: VulnCheck)
CWE-248 · CNA: VulnCheck · CVSS v4.0 · 2 references · NVD status: Deferred
AzuraCast before 0.23.8 DQL Injection via sortOrder
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   N   N    8.7   .0026   15.3     —
AFFECTED
  Product    Versions     Fixed
  AzuraCast  unspecified  0.23.8
TIMELINE
  Sep 27  Reserved by CNA
  Sep 27  Published (CNA: VulnCheck)
CWE-89 · CNA: VulnCheck · CVSS v4.0 · 2 references · NVD status: Received
Remainder (ranked, continued)
CVECVSSEPSS %ileVendorProductCWETitle
CVE-2026-1008597.115.1heymrunheymCWE-918Heym before 0.0.106 Credential Exfiltration via URL Override
CVE-2026-891028.314.7wolfSSLwolfSSLCWE-295OCSP stapling v2 multi accepts non-CA chain certificates as issuers
CVE-2026-1008635.314.2heymrunheymCWE-918Heym before 0.0.91 SSRF via image fetching and IPv6 validation
CVE-2026-1008538.213.8AzuraCastAzuraCastCWE-862AzuraCast before 0.23.8 On-Demand Download Endpoint Authorization Bypass
CVE-2026-1007258.313.5http4khttp4kCWE-200http4k before 6.48.0.0 Cookie Scoping Bypass via BasicCookieStorage
CVE-2026-1008497.113.5AzuraCastAzuraCastCWE-918AzuraCast before 0.23.8 SSRF Filter Bypass via Hostname and Private IPs
CVE-2026-891336.312.1wolfSSLwolfSSLCWE-295NameConstraints not enforced across unconstrained intermediate CA
CVE-2026-944172.312.1wolfSSLwolfSSLCWE-299CRL check skipped when OCSP enabled and certificate has no OCSP URL
CVE-2026-1008337.612.0edgelesssyscontrastCWE-20Contrast before 1.23.1 Image Substitution via Policy Generation
CVE-2026-1008504.811.9AzuraCastAzuraCastCWE-918AzuraCast before 0.23.8 SSRF and Local File Read via Remote Playlist
CVE-2026-1008388.611.4edgelesssyscontrastCWE-59Contrast before 1.19.1 CopyFile Policy Symlink Subversion
CVE-2026-1008359.110.9edgelesssyscontrastCWE-295Contrast before 1.16.0 Remote Attestation Relay Attack
CVE-2026-891346.310.9wolfSSLwolfSSLCWE-295Subject CN name-constraint check bypassed when non-DNS SAN present
CVE-2026-1008376.310.4edgelesssyscontrastCWE-1289Edgeless Systems Contrast through 1.20.0 Credential Leak via Registry Suffix …
CVE-2026-1008557.19.8AzuraCastAzuraCastCWE-862AzuraCast before 0.23.6 Missing Permission Check via /play
CVE-2026-1008408.59.7Project-MONAIMONAICWE-95MONAI through 1.6.0 Remote Code Execution via bundle configuration
CVE-2026-1008517.29.7AzuraCastAzuraCastCWE-200AzuraCast before 0.23.8 Broken Access Control via GET /api/station/{id}/vue/p…
CVE-2026-891356.39.7wolfSSLwolfSSLCWE-295Failed X509_verify_cert leaves unverified CA in shared CertManager
CVE-2025-714238.59.5edgelesssyscontrastCWE-532Edgelesssys Contrast before 1.12.2 Workload Secrets Information Disclosure
CVE-2026-1008626.98.1heymrunheymCWE-312heym before 0.0.91 Multiple Secrets Plaintext Storage
CVE-2026-933046.38.2wolfSSLwolfSSLCWE-696(D)TLS 1.2 client accepts early ChangeCipherSpec before ClientKeyExchange
CVE-2025-714258.57.7edgelesssyscontrastCWE-532Contrast before 1.8.1 Information Disclosure via Logging
CVE-2026-1008438.57.6Project-MONAIMONAICWE-502MONAI before 1.6.0 Remote Code Execution via algo_from_pickle
CVE-2026-968967.27.2UnknownMalcure Malware Shield — Removal, Repair, MonitorCWE-862Malcure Malware Shield < 19.9.7 - Multisite Subsite Admin+ Arbitrary File Wri…
CVE-2026-1008615.37.0heymrunheymCWE-918heym before 0.0.105 SSRF via credential-controlled base URLs
CVE-2026-1008487.16.6AzuraCastAzuraCastCWE-918AzuraCast before 0.23.8 Server-Side Request Forgery via Remote Relay URL
CVE-2026-924365.36.5UnknownMailchimp for WooCommerceCWE-639Mailchimp for WooCommerce < 6.3 - Unauthenticated Customer Email and Cart Dis…
CVE-2026-866098.85.9UnknownDownload ManagerCWE-79Download Manager Pro < 7.5.6 - Unauthenticated Stored XSS via Email Lock Subs…
CVE-2025-714245.14.9edgelesssyscontrastCWE-693Edgeless Systems Contrast before 1.9.1 Insecure Volume Mount
CVE-2026-1008545.34.4AzuraCastAzuraCastCWE-862AzuraCast before 0.23.6 Metadata Injection via Liquidsoap API
CVE-2026-816557.53.7UnknownAd InserterCWE-94Ad Inserter 2.8.12 - 2.8.18 - Subscriber+ RCE / Stored XSS via Global Custom …
CVE-2026-850026.83.7UnknownEmbedPressCWE-79EmbedPress < 4.6.7 - Contributor+ Stored XSS via Instagram Carousel Block Att…
CVE-2026-890066.83.7UnknownWPeMatico RSS Feed FetcherCWE-79WPeMatico RSS Feed Fetcher < 2.8.27 - Contributor+ Stored XSS via Feed Import
CVE-2026-968956.83.7UnknownWP YouTube LyteCWE-79WP YouTube Lyte < 1.7.31 - Contributor+ Stored XSS via Embed Block Attributes
CVE-2026-968996.83.7UnknownOptima Express IDXCWE-79Optima Express 8.6.0 - 8.7.5 - Author+ Stored XSS via faq_script
CVE-2026-973196.83.7UnknownPowerPress Podcasting plugin by BlubrryCWE-79PowerPress < 11.17.2 - Contributor+ Stored XSS via Podcast Player Block
CVE-2026-868414.73.5UnknownOnline Scheduling and Appointment Booking SystemCWE-502Bookly 23.2 - 28.2 - Bookly Administrator+ PHP Object Injection via Diagnosti…
CVE-2026-1008398.43.4edgelesssyscontrastCWE-94Contrast before 1.18.0 AML Injection Remote Code Execution
CVE-2026-1008427.33.4Project-MONAIMONAICWE-95MONAI through 1.6.0 _get_fake_spatial_shape eval() Sandbox Bypass via Attribu…
CVE-2026-1008365.33.3edgelesssyscontrastCWE-129Edgeless Systems Contrast through 1.20.0 Denial of Service via ciphertextCont…
CVE-2026-929955.33.2UnknownVerge3D Publishing and E-CommerceCWE-200Verge3D <= 4.13.0 - Unauthenticated Product Download Disclosure via v3d_downl…
CVE-2025-714267.12.8edgelesssyscontrastCWE-285Contrast before 1.4.1 Coordinator Impersonation via Unauthenticated Recovery
CVE-2026-828415.32.7UnknownUpdraftPlus: WP Backup & Migration PluginCWE-200UpdraftPlus 1.23.8 - 1.26.7 - Subscriber+ Remote Storage Credential Disclosur…
CVE-2026-968975.32.5UnknownOptima Express IDXCWE-862Optima Express 8.5.0 - 8.7.5 - Unauthenticated Author Account Creation & Appl…
CVE-2026-1008458.52.5Project-MONAIMONAICWE-502MONAI before 1.6.0 Remote Code Execution via NumpyReader
CVE-2026-972275.92.3UnknownNextScripts: Social Networks Auto-PosterCWE-862NextScripts: Social Networks Auto-Poster < 4.4.8 - Authenticated Social Accou…
CVE-2026-890014.92.3UnknownWPeMatico RSS Feed FetcherCWE-269WPeMatico RSS Feed Fetcher < 2.8.27 - Contributor+ Post Publication and Autho…
CVE-2026-890004.12.3UnknownWPeMatico RSS Feed FetcherCWE-918WPeMatico RSS Feed Fetcher < 2.8.27 - Contributor+ SSRF via Campaign Run
CVE-2026-890034.12.3UnknownWPeMatico RSS Feed FetcherCWE-918WPeMatico RSS Feed Fetcher < 2.8.27 - Contributor+ SSRF via Campaign Preview
CVE-2026-868393.82.3UnknownOnline Scheduling and Appointment Booking SystemCWE-639Bookly < 28.3 - Staff+ Appointment and Payment Disclosure, Modification and D…
CVE-2026-1008418.51.9Project-MONAIMONAICWE-502MONAI through 1.6.0 PersistentDataset Remote Code Execution via Pickle Cache
CVE-2026-1008606.81.4heymrunheymCWE-636heym before 0.0.105 Authentication Bypass via Redis Node
CVE-2026-944192.30.1wolfSSLwolfSSLCWE-287Client session cache reference poisoning allows resumption with wrong server
CVE-2025-714226.90.1edgelesssyscontrastCWE-347Contrast before 1.12.1 Insecure LUKS2 Persistent Storage
CVE-2026-944182.30.0wolfSSLwolfSSLCWE-347Signature failure masked by date error under WOLFSSL_SMALL_CERT_VERIFY
CVE-2026-887739.3—Citrix NetScalerADCCWE-444HTTP Request Smuggling
CVE-2026-1008869.3—SeetongT8108CWE-287Seetong T8108/T8108P/T8116/T8232 Debug Service improper authentication
CVE-2026-1010659.3—obot-platformobotCWE-306Obot Quickstart Docker Deployment Unauthenticated Admin Access
CVE-2026-1010849.3—obot-platformobotCWE-639obot before v0.21.1 Authorization Bypass via /mcp-connect
CVE-2026-1010909.3—nezhahqnezhaCWE-601Nezha through 2.2.3 Host Header Injection via OAuth2 redirect_uri
CVE-2026-1010458.9—fleetdmfleetCWE-78Fleet Homebrew Cask OS Command Injection via Metadata
CVE-2026-887758.8—Citrix NetScalerADC—Memory overflow vulnerability leading to unpredictable or erroneous behavior …
CVE-2026-887768.8—Citrix NetScalerADC—Memory overflow vulnerability leading to unpredictable or erroneous behavior …
CVE-2026-887778.8—Citrix NetScalerADC—Memory overflow vulnerability leading to unpredictable or erroneous behavior …
CVE-2026-887788.8—Citrix NetScalerADCCWE-342TCP Initial Sequence Number (ISN) prediction
CVE-2026-1008708.7—SyliusSyliusCWE-640Sylius before 1.12.25, 1.13.17, 1.14.20, 2.1.16, and 2.2.9 Admin Password Res…
CVE-2026-1008718.7—SyliusSyliusCWE-287Sylius before 1.12.25, 1.13.17, 1.14.20, 2.1.16, and 2.2.9 JWT Audience Confu…
CVE-2026-1008728.7—SyliusSyliusCWE-345Sylius 2.x before 2.1.16 and 2.2.9 Payment Amount Overwrite
CVE-2026-1010628.7—obot-platformobotCWE-863Obot before v0.23.0 Authentication Bypass via OAuth Dynamic Client Registration
CVE-2026-1010608.4—universal-tool-calling-protocolpython-utcpCWE-918python-utcp before 1.1.4 SSRF via unvalidated HTTP redirects
CVE-2026-1010438.3—pnpmpnpmCWE-201pnpm 11.0.0 before 11.11.0 Environment Variable Exfiltration via Proxy Settings
CVE-2026-1010498.3—heymrunheymCWE-287Heym before 0.0.53 Slack Webhook Signature Verification Bypass
CVE-2026-1010508.3—heymrunheymCWE-287Heym before 0.0.53 Authentication Bypass via Telegram Webhook
CVE-2026-1010648.3—obot-platformobotCWE-918Obot before v0.23.0 Server-Side Request Forgery via MCP
CVE-2026-1008698.2—SyliusSyliusCWE-863Sylius 2.x before 2.1.16 and 2.2.9 Arbitrary Payment Action via Shop API
CVE-2026-962807.5—Red HatRed Hat Enterprise Linux 10CWE-197Flatpak: flatpak: buffer overflow in oci delta stream path names on 32-bit sy…
CVE-2026-1010427.4—parse-communityparse-serverCWE-287Parse Server 9.0.0 Authentication Bypass via Unverified Provider Identity
CVE-2026-1010327.3—denisidoronaviCWE-78navi through 2.24.0 OS Command Injection via Cheatsheet Variables
CVE-2026-1010447.1—pnpmpnpmCWE-22pacquet before 12.0.0-alpha.5 Path Traversal via lockfile alias
CVE-2026-1010587.1—universal-tool-calling-protocolpython-utcpCWE-918python-utcp before 1.1.12 SSRF via Remote HTTP Manual
CVE-2026-1010597.1—universal-tool-calling-protocolpython-utcpCWE-918utcp-http before 1.1.4 OAuth2 tokenUrl Trust Boundary Bypass
CVE-2026-1010857.1—nezhahqnezhaCWE-197Nezha before 2.3.8 Denial of Service via Alert Rule
CVE-2026-1010867.1—nezhahqnezhaCWE-269Nezha Dashboard before 2.3.5 Task Type Validation Bypass
CVE-2026-887747.0—Citrix NetScalerADC—Feature policy bypass due to improper HTTP URL based expression usage
CVE-2026-971647.0—svenbluege.deEvent Gallery for JoomlaCWE-22Joomla Extension - svenbluege.de - Path Traversal in Clear Cache task in Even…
CVE-2026-1007486.9—svenbluege.deEvent Gallery for JoomlaCWE-352Joomla Extension - svenbluege.de - CSRF in various cart actions in Event Gall…
CVE-2026-1008886.9—Trusted Domain ProjectOpenDKIMCWE-787Trusted Domain Project OpenDKIM DKIM Signature Header Selection dkim-canon.c …
CVE-2026-1008896.9—Trusted Domain ProjectOpenDKIMCWE-193Trusted Domain Project OpenDKIM Decoder util.c dkim_qp_decode off-by-one
CVE-2026-1010476.9—fleetdmfleetCWE-862Fleet before 4.87.0 Unauthenticated iOS App Download via Predictable URLs
CVE-2026-1010566.9—cloudrevecloudreveCWE-863Cloudreve before 4.16.1 Authentication Bypass via Cached Context Hint
CVE-2026-1010636.9—obot-platformobotCWE-862Obot before v0.23.0 Authentication Bypass via Registry API
CVE-2026-962796.5—Red HatRed Hat Enterprise Linux 10CWE-59Flatpak: flatpak: path traversal issue in oci archive extraction via hardlinks
CVE-2026-1010416.3—vulnerability-lookupvulnerability-lookupCWE-20Vulnerability-Lookup - Race Condition in Account Recovery Token Consumption A…
CVE-2026-962816.2—Red HatRed Hat Enterprise Linux 10CWE-284Flatpak: flatpak: unprivileged active user can bypass anti-downgrade checks f…
CVE-2026-1010886.0—nezhahqnezhaCWE-367Nezha before 2.3.1 Denial of Service via Concurrent Server Delete
CVE-2026-1008745.5—mathurvishalCloudClassroom-PHP-ProjectCWE-74mathurvishal CloudClassroom-PHP-Project addnewstudent.php sql injection
CVE-2026-1008755.5—mathurvishalCloudClassroom-PHP-ProjectCWE-74mathurvishal CloudClassroom-PHP-Project updatedetailsfromfaculty.php sql inje…
CVE-2026-1008855.5—Krayinlaravel-crmCWE-285Krayin laravel-crm admin-config-setup API Endpoint CanInstall.php authorization
CVE-2026-971655.3—svenbluege.deEvent Gallery for JoomlaCWE-79Joomla Extension - svenbluege.de - Reflected XSS and open redirect in Event G…
CVE-2026-1008685.3—penpotpenpotCWE-1327Penpot before 2.18.0 Unauthenticated WebSocket Access via MCP Bridge
CVE-2026-1008875.3—amirsanniMini-Inventory-and-Sales-Management-SystemCWE-89amirsanni Mini-Inventory-and-Sales-Management-System Database Query Builder D…
CVE-2026-1010335.3—TomBurschkitchenowlCWE-639KitchenOwl through 0.7.10 IDOR via unchecked category ID
CVE-2026-1010485.3—cloudrevecloudreveCWE-863Cloudreve before 4.17.0 SSRF via Admin.Read OAuth scope
CVE-2026-1010875.3—nezhahqnezhaCWE-918Nezha 2.0.10 through 2.3.2 SSRF Denylist Bypass IPv6
CVE-2026-1007475.1—svenbluege.deEvent Gallery for JoomlaCWE-352Joomla Extension - svenbluege.de - CSRF in image upload in Event Gallery exte…
CVE-2026-1007495.1—svenbluege.deEvent Gallery for JoomlaCWE-352Joomla Extension - svenbluege.de - CSRF in backend cleanup actions in Event G…
CVE-2026-1008664.8—o2shonefetchCWE-150onefetch through 2.28.1 Terminal Escape Sequence Injection
CVE-2026-1008674.8—spaceship-promptspaceship-promptCWE-150spaceship-prompt through 4.22.5 Terminal Escape Sequence Injection
CVE-2026-962833.3—Red HatRed Hat Enterprise Linux 10CWE-862Flatpak: flatpak: flatpak-system-helper cross-user cancelpull orphans another…
CVE-2026-962823.1—Red HatRed Hat Enterprise Linux 10CWE-59Flatpak: flatpak: extension metadata path traversal file existence oracle
CVE-2026-962842.5—Red HatRed Hat Enterprise Linux 10CWE-59Flatpak: flatpak: arbitrary read-access to files in the system-helper context…
CVE-2026-1010462.3—fleetdmfleetCWE-89Fleet before 4.89.0 SQL Injection via ORDER BY Activity Endpoints
CVE-2026-1010512.3—cloudrevecloudreveCWE-22Cloudreve before 4.16.1 Path Traversal via Remote Download
CVE-2026-1010572.3—universal-tool-calling-protocolpython-utcpCWE-319utcp-mcp before 1.1.3 SSRF via unvalidated MCP server URL
CVE-2026-1010612.3—universal-tool-calling-protocolpython-utcpCWE-918utcp-gql and utcp-websocket before 1.1.1 SSRF via URL validation bypass
CVE-2026-1010892.3—nezhahqnezhaCWE-522Nezha before 2.2.7 Information Disclosure via /api/v1/profile
CVE-2026-1008732.1—mathurvishalCloudClassroom-PHP-ProjectCWE-352mathurvishal CloudClassroom-PHP-Project cross-site request forgery
CVE-2026-1008762.1—mathurvishalCloudClassroom-PHP-ProjectCWE-287mathurvishal CloudClassroom-PHP-Project loginlinkstudent.php missing authenti…
CVE-2026-1008772.1—mathurvishalCloudClassroom-PHP-ProjectCWE-79mathurvishal CloudClassroom-PHP-Project registrationform.php cross site scrip…
CVE-2026-1008782.1—zhistareduStarTrainingCWE-285zhistaredu StarTraining authRole Endpoint SysUser.java SysUser.isAdmin author…
CVE-2026-1008792.1—zhistareduStarTrainingCWE-862zhistaredu StarTraining dataScope Endpoint SysRoleServiceImpl.java checkRoleA…
CVE-2026-1008832.1—Krayinlaravel-crmCWE-266Krayin laravel-crm acl.php access control
CVE-2026-1008842.1—Krayinlaravel-crmCWE-99Krayin laravel-crm attachment-download Endpoint acl.php resource injection
CVE-2026-1008802.0—zhistareduStarTrainingCWE-79zhistaredu StarTraining Upload Endpoint MimeTypeUtils.java cross site scripting
CVE-2026-1008821.9—Krayinlaravel-crmCWE-79Krayin laravel-crm Admin Settings Endpoint index.blade.php cross site scripting
CVE-2026-1008811.2—zhistareduStarTrainingCWE-79zhistaredu StarTraining application.yml cross site scripting

Methodology

Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.

Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.

Day boundary. A day is a UTC calendar day. This page covers 2026-09-27 00:00:00–23:59:59 UTC. All times shown are UTC.

Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.

Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.

Machine-readable. This edition as JSON or CSV — the ranked results, transactions, and counts, for citation or ingestion. Frozen at publication; later changes appear as transactions on later editions.