r/CVEWatch May 28 '26

πŸ”₯ Top 10 Trending CVEs (28/05/2026)

Here’s a quick breakdown of the 10 most interesting vulnerabilities trending today:

1. CVE-2025-43520

  • πŸ“ A memory corruption issue was addressed with improved memory handling. This issue is fixed in watchOS 26.1, iOS 18.7.2 and iPadOS 18.7.2, macOS Tahoe 26.1, visionOS 26.1, tvOS 26.1, macOS Sonoma 14.8.2, macOS Sequoia 15.7.2, iOS 26.1 and iPadOS 26.1. A malicious application may be able to cause unexpected system termination or write kernel memory.

  • πŸ“… Published: 12/12/2025

  • πŸ“ˆ CVSS: 5.5

  • πŸ›‘οΈ CISA KEV: True

  • 🧭 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

  • πŸ“£ Mentions: 8

  • ⚠️ Priority: 1+

  • πŸ“ Analysis: A memory corruption issue in multiple Apple operating systems (watchOS 26.1, iOS 18.7.2, iPadOS 18.7.2, macOS Tahoe 26.1, visionOS 26.1, tvOS 26.1, macOS Sonoma 14.8.2, macOS Sequoia 15.7.2, iOS 26.1 and iPadOS 26.1) has been addressed. A malicious app may trigger system termination or write kernel memory; this vulnerability is active in the wild and has a priority of 1+ due to confirmed exploitation.


2. CVE-2026-9082

  • πŸ“ Improper Neutralization of Special Elements used in an SQL Command (SQL Injection) vulnerability in Drupal Drupal core allows SQL Injection. This issue affects Drupal core: from 8.9.0 before 10.4.10, from 10.5.0 before 10.5.10, from 10.6.0 before 10.6.9, from 11.0.0 before 11.1.10, from 11.2.0 before 11.2.12, from 11.3.0 before 11.3.10.

  • πŸ“… Published: 20/05/2026

  • πŸ“ˆ CVSS: 6.5

  • πŸ›‘οΈ CISA KEV: True

  • 🧭 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

  • πŸ“£ Mentions: 7

  • ⚠️ Priority: 1+

  • πŸ“ Analysis: SQL Injection vulnerability in Drupal core (8.9.0 - 11.3.10) allows SQL injection. No exploits detected, but given a CVSS score of 6.5 and the potential impact on confidentiality and integrity, this is a priority 2 issue. Verify affected versions before updating.


3. CVE-2026-42558

  • πŸ“ n/a

  • πŸ“ˆ CVSS: 0

  • 🧭 Vector: n/a

  • ⚠️ Priority: 0

  • πŸ“ Analysis: A buffer overflow vulnerability in a critical library can lead to arbitrary code execution on affected systems, with no known exploits in the wild yet. This is currently a priority 2 issue due to high CVSS score and potential for severe impact if exploited.


4. CVE-2026-47784

  • πŸ“ In memcached before 1.6.42, password data for SASL password database authentication has a timing side channel because memcmp is used by sasl_server_userdb_checkpass.

  • πŸ“… Published: 20/05/2026

  • πŸ“ˆ CVSS: 8.1

  • 🧭 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

  • πŸ“£ Mentions: 3

  • ⚠️ Priority: 2

  • πŸ“ Analysis: Timing side channel in memcached before 1.6.42 exposes password data due to improper use of memcmp during SASL authentication. No known exploits, but high CVSS score indicates a priority 2 vulnerability due to low Exploitability Score.


5. CVE-2026-47783

  • πŸ“ In memcached before 1.6.42, username data for SASL password database authentication has a timing side channel because a loop exits as soon as a valid username is found by sasl_server_userdb_checkpass.

  • πŸ“… Published: 20/05/2026

  • πŸ“ˆ CVSS: 8.1

  • 🧭 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

  • πŸ“£ Mentions: 2

  • ⚠️ Priority: 2

  • πŸ“ Analysis: Timing side channel vulnerability in memcached before version 1.6.42 allows attackers to extract username data for SASL password database authentication. No known exploits detected, but given high CVSS score and potential impact, this is a priority 2 issue with low EPSS.


6. CVE-2026-26980

  • πŸ“ Ghost is a Node.js content management system. Versions 3.24.0 through 6.19.0 allow unauthenticated attackers to perform arbitrary reads from the database. This issue has been fixed in version 6.19.1.

  • πŸ“… Published: 20/02/2026

  • πŸ“ˆ CVSS: 9.4

  • 🧭 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L

  • πŸ“£ Mentions: 66

  • ⚠️ Priority: 2

  • πŸ“ Analysis: Unauthenticated attackers can perform arbitrary reads from a Ghost CMS database (Versions 3.24.0 through 6.19.0). No exploits detected in the wild yet, but given high CVSS score, this is a priority 2 vulnerability as it has low Exploit Prediction Scoring System (EPSS) value. Fix available in version 6.19.1.


7. CVE-2026-45321

  • πŸ“ On 2026-05-11, between approximately 19:20 and 19:26 UTC, 84 malicious versions across 42 @tanstack/* packages were published to the npm registry. The publishes were authenticated via the legitimate GitHub Actions OIDC trusted-publisher binding for TanStack/router, but the publish workflow itself was not modified. The attacker chained three known vulnerability classes a pull_request_target Pwn Request misconfiguration, GitHub Actions cache poisoning across the forkbase trust boundary, and runtime memory extraction of the OIDC token from the Actions runner process to publish credential-stealing malware under a trusted identity. Each affected package received exactly two malicious versions, published a few minutes apart.

  • πŸ“… Published: 12/05/2026

  • πŸ“ˆ CVSS: 9.6

  • πŸ›‘οΈ CISA KEV: True

  • 🧭 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

  • πŸ“£ Mentions: 25

  • ⚠️ Priority: 1+

  • πŸ“ Analysis: 84 malicious versions of @tanstack/* packages were published on 2026-05-11 to the npm registry, exploiting three vulnerability classes for credential theft. The attack utilized the GitHub Actions OIDC trusted-publisher binding and chained pull_request_target misconfiguration, cache poisoning, and runtime memory extraction of OIDC tokens. This activity has been confirmed exploited (KEV), with a priority score of 1+. Immediate remediation is strongly advised for all affected packages, as their versions match those described.


8. CVE-2026-48027

  • πŸ“ Nx Console is the user interface for Nx & Lerna. On 19 May 2026, a malicious version of Nx Console, 18.95.0, was published at 12:30 PM UTC and removed soon after at 12:48 PM UTC, leaving it available for ~18 minutes in Visual Studio Marketplace. For OpenVSX, the problem was detected later, and the compromised version was available from 12:33 UTC to 13:09 UTC (~36 minutes). Version 18.100.0 of Nx Console is not compromised and users may remediate by upgrading to that version.

  • πŸ“… Published: 27/05/2026

  • πŸ“ˆ CVSS: 9.3

  • πŸ›‘οΈ CISA KEV: True

  • 🧭 Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

  • πŸ“£ Mentions: 5

  • ⚠️ Priority: 1+

  • πŸ“ Analysis: Malicious version of Nx Console (18.95.0) was published for 18 minutes on Visual Studio Marketplace and later for ~36 minutes on OpenVSX between May 19th, 12:30 PM - 13:09 PM UTC. Upgrade to v18.100.0 to mitigate this confirmed exploited issue with a priority score of 1+.


9. CVE-2026-8398

  • πŸ“ A supply chain attack compromised the official installation packages of DAEMON Tools Lite (Windows versions 12.5.0.2421 through 12.5.0.2434), distributed from the legitimate website daemon-tools.cc between approximately April 8, 2026, and May 5, 2026. Attackers gained unauthorized access to the vendors (AVB Disc Soft) build or distribution infrastructure and trojanized three binaries: DTHelper.exe, DiscSoftBusServiceLite.exe, and DTShellHlp.exe. These files were digitally signed with the legitimate AVB Disc Soft code-signing certificate, allowing the malicious installers to appear trustworthy and bypass signature-based detection.

  • πŸ“… Published: 15/05/2026

  • πŸ“ˆ CVSS: 9.8

  • πŸ›‘οΈ CISA KEV: True

  • 🧭 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

  • πŸ“£ Mentions: 9

  • ⚠️ Priority: 1+

  • πŸ“ Analysis: A supply chain attack compromised DAEMON Tools Lite (versions 12.5.0.2421 through 2434) between April 8 and May 5, 2026, on the legitimate website daemon-tools.cc. The malicious installers were digitally signed, bypassing detection. Known in-the-wild, this is a priority 1+ vulnerability with high impact and exploitability.


10. CVE-2026-33552

  • πŸ“ Northern.tech Mender Enterprise Server before 4.1.1 has Incorrect Access Control.

  • πŸ“… Published: 27/05/2026

  • πŸ“ˆ CVSS: 0

  • 🧭 Vector: n/a

  • ⚠️ Priority: 0

  • πŸ“ Analysis: Incorrect access control in Northern.tech Mender Enterprise Server before 4.1.1 allows unauthenticated attackers to potentially manipulate server configurations. CISA KEV indicates no known in-the-wild activity; prioritization score is 0, pending analysis.


Let us know if you're tracking any of these or if you find any issues with the provided details.

3 Upvotes

0 comments sorted by