🔓 CVEs & KEV
The CVE roundup for today includes several high-severity vulnerabilities across container runtimes, APIs, and network devices.
- CVE-2026-46409 — CVSS 9.6 — OpenYak local API: unauthenticated CSRF chain leads to Remote Code Execution
- CVE-2026-50540 — CVSS 9.6 — Kata Containers: Config Path Annotation Arbitrary File Loading
- CVE-2026-47243 — CVSS 9.2 — Kata guest escape: runtime-rs guest-root to host-root escape via virtiofs
- CVE-2026-48169 — CVSS 8.8 — PraisonAI has Cross-Workspace IDOR and Privilege Escalation via Platform API
- CVE-2026-45808 — CVSS 7.1 — OpenBao's cross-namespace lease revocation via legacy sys/revoke path bypass
- CVE-2026-9031 — CVSS 6.8 — Authenticated Denial-of-Service in HTTPD Service in TP-Link Archer A6