High
The Roundcube SQL injection is not in the CISA catalog
CVE-2026-48842 is a pre-authentication SQL injection in Roundcube virtuser_query, fixed in May 2026. A public PoC exists. CISA has not listed it, so ThreatWire does not mark Active Exploitation.
Published 2m ago
Critical
Three Authlib signature bugs are not one patch
CVE-2026-28802, CVE-2026-27962, and CVE-2026-96760 are separate Authlib signature failures. Two have releases. The newest, through 1.7.2, does not.
Published 2m ago
High
Two MongoDB driver bugs are not confirmed code execution
CVE-2026-96748 lets an untrusted hostname add a server to a PyMongo client. CVE-2026-96746 can crash the C driver. Both are scored 8.3. Neither NVD text is arbitrary code execution, and neither is in the CISA catalog.
Published 2m ago
Critical
Reading the Next.js ImageResponse advisory
CVE-2026-94545 is a Satori escaping bug that Vercel says can become code execution in Node.js next/og. The only published numeric score is 5.3. Next.js 16.3.6 is the fix. A public PoC exists.
Published 1h ago
How ThreatWire records a vulnerability
The status on a ThreatWire card is an editorial claim. Unknown stays unknown until a public source confirms a PoC, an exploit, or active use.
Published 29h ago