Back to trending CVEs

Week of March 23, 2026

Trending* CVEs over the last 7 days (from March 16, 2026 to March 23, 2026)

1
CVE-2026-3888Canonical / Ubuntu 16.04 Lts
New
SYRN Score49
CVSS7.8
Activity93
Published03/17/2026
StatusHighly Active

Local privilege escalation in snapd on Linux allows local attackers to get root privilege by re-creating snap's private /tmp directory when systemd-tmpfiles is configured to automatically clean up this directory. This issue affects Ubuntu 16.04 LTS, 18.04 LTS, 20.04 LTS, 22.04 LTS, and 24.04 LTS.

2
CVE-2026-20131Cisco Systems / Secure Firewall Management Center
KEVRansomware
SYRN Score97
CVSS10.0
Activity75
Published03/04/2026
StatusHighly Active

A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to execute arbitrary Java code as root on an affected device. This vulnerability is due to insecure deserialization of a user-supplied Java byte stream. An attacker could exploit this vulnerability by sending a crafted serialized Java object to the web-based management interface of an affected device. A successful exploit could allow the attacker to execute arbitrary code on the device and elevate privileges to root. Note: If the FMC management interface does not have public internet access, the attack surface that is associated with this vulnerability is reduced.

3
CVE-2026-32746Gnu / Inetutils
SYRN Score69
CVSS9.8
Activity64
Published03/13/2026
StatusHighly Active

telnetd in GNU inetutils through 2.7 allows an out-of-bounds write in the LINEMODE SLC (Set Local Characters) suboption handler because add_slc does not check whether the buffer is full.

4
CVE-2026-21992Oracle Corporation / Identity Manager
New
SYRN Score77
CVSS9.8
Activity44
Published03/20/2026
StatusHighly Active

Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: REST WebServices) and Oracle Web Services Manager product of Oracle Fusion Middleware (component: Web Services Security). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Identity Manager and Oracle Web Services Manager. Successful attacks of this vulnerability can result in takeover of Oracle Identity Manager and Oracle Web Services Manager. Note: Oracle Web Services Manager is installed with an Oracle Fusion Middleware Infrastructure. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

5
CVE-2026-20643Apple / Ipados
New
SYRN Score38
CVSS5.4
Activity33
Published03/17/2026
StatusHighly Active

A cross-origin issue in the Navigation API was addressed with improved input validation. This issue is fixed in Background Security Improvements for iOS 26.3.1, iPadOS 26.3.1, macOS 26.3.1, and macOS 26.3.2. Processing maliciously crafted web content may bypass Same Origin Policy.

6
CVE-2026-20963Microsoft / Microsoft SharePoint
KEV
SYRN Score93
CVSS8.8
Activity30
Published01/13/2026
StatusHighly Active

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

7
CVE-2026-33017Langflow-ai / Langflow
New
SYRN Score82
CVSS9.3
Activity28
Published03/20/2026
StatusHighly Active

Langflow is a tool for building and deploying AI-powered agents and workflows. In versions prior to 1.9.0, the POST /api/v1/build_public_tmp/{flow_id}/flow endpoint allows building public flows without requiring authentication. When the optional data parameter is supplied, the endpoint uses attacker-controlled flow data (containing arbitrary Python code in node definitions) instead of the stored flow data from the database. This code is passed to exec() with zero sandboxing, resulting in unauthenticated remote code execution. This is distinct from CVE-2025-3248, which fixed /api/v1/validate/code by adding authentication. The build_public_tmp endpoint is designed to be unauthenticated (for public flows) but incorrectly accepts attacker-supplied flow data containing arbitrary executable code. This issue has been fixed in version 1.9.0.

8
CVE-2025-47813Wftpserver / Wing Ftp Server
KEV
SYRN Score92
CVSS4.3
Activity24
Published07/10/2025
StatusActive

loginok.html in Wing FTP Server before 7.4.4 discloses the full local installation path of the application when using a long value in the UID cookie.

9
CVE-2026-21385Qualcomm / 5G Fixed Wireless Access Platform
KEV
SYRN Score92
CVSS7.8
Activity23
Published03/02/2026
StatusActive

Memory corruption while using alignments for memory allocation.

10
CVE-2025-66376Synacor / Zimbra Collaboration Suite
KEV
SYRN Score91
CVSS7.2
Activity22
Published01/05/2026
StatusActive

Zimbra Collaboration (ZCS) 10 before 10.0.18 and 10.1 before 10.1.13 allows Classic UI stored XSS via Cascading Style Sheets (CSS) @import directives in an HTML e-mail message.

* Trending is based on the number of sightings collected from SYRN's threat intelligence sources over the given period.

Monitor these vulnerabilities and get alerted when new threats target your stack.

Get Started Free