StackRadar

CVE-2026-27904

High

Advisory

Published 26 Feb 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.005
39th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
792
of 17,787 indexed, latest versions
Container images
835
deployed by those charts
Fix available
1 of 2
affected packages

minimatch ReDoS: nested *() extglobs generate catastrophically backtracking regular expressions

Carried by container images the latest versions of 792 of 17,787 indexed charts deploy, on 835 images.

Affected packageAffected versionsFixed inImages
minimatchnpm0.3.0, 1.0.0, 2.0.10, 3.0.0+22 more3.1.4, 4.2.5, 5.1.8, 6.2.2+2 more835
node-minimatchdeb1.0.0-1, 3.0.4-3, 3.0.4-3+deb10u1build0.18.04.1, 3.0.4-4+3 moreno fix listed7
OSV records
DEBIAN-CVE-2026-27904GHSA-23c5-xmqv-rm74UBUNTU-CVE-2026-27904

Charts affected

792 by stars
ChartLatestAffected imagesRadar Score
component-storekubebb0.0.231 of 1See more

component-store kubebb 0.0.23

1 of the 1 container images this version deploys carry CVE-2026-27904.

Container imageDigestPackageFixed in
kubebb/component-store:latestfd8ecbd73213
minimatch@3.1.2
3.1.4

Open the chart page →

2,178
tampkubebb5.6.01 of 2See more

tamp kubebb 5.6.0

1 of the 2 container images this version deploys carry CVE-2026-27904.

Container imageDigestPackageFixed in
kubebb/tamp-portal:v5.6.0fadac6d52470
minimatch@3.0.4
3.1.4

Open the chart page →

4,664
tapm-componentkubebb5.7.11 of 3See more

tapm-component kubebb 5.7.1

1 of the 3 container images this version deploys carry CVE-2026-27904.

Container imageDigestPackageFixed in
refar/apm-portal:v5.7.1dcca8e4477a6
minimatch@3.0.4
3.1.4

Open the chart page →

10,264
tdsfkubebb5.7.01 of 3See more

tdsf kubebb 5.7.0

1 of the 3 container images this version deploys carry CVE-2026-27904.

Container imageDigestPackageFixed in
kubebb/tdsf-portal:v5.7.0258458311bc9
minimatch@3.0.4
3.1.4

Open the chart page →

6,490
u4a-componentkubebb0.2.101 of 8See more

u4a-component kubebb 0.2.10

1 of the 8 container images this version deploys carry CVE-2026-27904.

Container imageDigestPackageFixed in
kubebb/bff-server:v0.2.0-202312040fbb732379bc
minimatch@6.2.0
6.2.2

Open the chart page →

13,819
aperagkubeblocksVerified publisher0.0.0-nightly1 of 3See more

aperag kubeblocks 0.0.0-nightly

1 of the 3 container images this version deploys carry CVE-2026-27904.

Container imageDigestPackageFixed in
apecloud/aperag-frontend:v0.0.0-nightlyb3ae37840ace
minimatch@9.0.5
9.0.7

Open the chart page →

8,405
seerrkubernetes-homelab-helm-chartsVerified publisher0.1.21 of 1See more

seerr kubernetes-homelab-helm-charts 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-27904.

Container imageDigestPackageFixed in
ghcr.io/seerr-team/seerr:v3.2.0c4cbd5121236
minimatch@9.0.5
9.0.7

Open the chart page →

2,548
uptime-kumakubernetes-homelab-helm-chartsVerified publisher0.1.21 of 1See more

uptime-kuma kubernetes-homelab-helm-charts 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-27904.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.2.1-slim059b49d64739
minimatch@9.0.3
9.0.7

Open the chart page →

6,356
kube-mailkubernetes-replicator0.11.11 of 3See more

kube-mail kubernetes-replicator 0.11.1

1 of the 3 container images this version deploys carry CVE-2026-27904.

Container imageDigestPackageFixed in
quay.io/mittwald/kube-mail:latest04f1099241fc
minimatch@9.0.5
9.0.7

Open the chart page →

2,509
online-boutiquekubesphere-testVerified publisher0.1.02 of 11See more

online-boutique kubesphere-test 0.1.0

2 of the 11 container images this version deploys carry CVE-2026-27904.

Container imageDigestPackageFixed in
gcr.io/google-samples/microservices-demo/currencyservice:v0.2.349d458a3650f
minimatch@3.0.4
3.1.4
gcr.io/google-samples/microservices-demo/paymentservice:v0.2.36eb201217a8f
minimatch@3.0.4
3.1.4

Open the chart page →

26,018
sample-bookinfokubesphere-testVerified publisher1.0.01 of 4See more

sample-bookinfo kubesphere-test 1.0.0

1 of the 4 container images this version deploys carry CVE-2026-27904.

Container imageDigestPackageFixed in
kubesphere/examples-bookinfo-ratings-v1:1.13.0f1b5bf878196
minimatch@3.0.4
3.1.4

Open the chart page →

9,378
kubevious-agentkubevious1.0.41 of 1See more

kubevious-agent kubevious 1.0.4

1 of the 1 container images this version deploys carry CVE-2026-27904.

Container imageDigestPackageFixed in
kubevious/parser:1.0.151acf1a1f0b47
minimatch@3.0.4
3.1.4

Open the chart page →

1,927
workload-operatorkubevious0.0.31 of 1See more

workload-operator kubevious 0.0.3

1 of the 1 container images this version deploys carry CVE-2026-27904.

Container imageDigestPackageFixed in
kubevious/workload-operator:1.0.20b0f4c507eb6
minimatch@3.1.2
3.1.4

Open the chart page →

2,008
penpotkubitodevVerified publisher1.2.11 of 5See more

penpot kubitodev 1.2.1

1 of the 5 container images this version deploys carry CVE-2026-27904.

Container imageDigestPackageFixed in
penpotapp/exporter:2.2.15c835ffd87ab
minimatch@5.1.6
5.1.8

Open the chart page →

16,877
kubiya-runnerkubiya-helm-chartsOfficialVerified publisher0.9.42 of 9See more

kubiya-runner kubiya-helm-charts 0.9.4

2 of the 9 container images this version deploys carry CVE-2026-27904.

Container imageDigestPackageFixed in
ghcr.io/kubiyabot/agent-manager:v0.4.13757bdd779345
minimatch@9.0.5
9.0.7
ghcr.io/kubiyabot/workflow-engine:v1.46.2560a16a56d4e
minimatch@9.0.3
9.0.7

Open the chart page →

20,204
multitenantkvalitetsitVerified publisher2.2.181 of 1See more

multitenant kvalitetsit 2.2.18

1 of the 1 container images this version deploys carry CVE-2026-27904.

Container imageDigestPackageFixed in
kvalitetsit/kithosting-networkpolicytests:0.0.12b99cfa3c5df
minimatch@3.0.4
3.1.4

Open the chart page →

1,614
kyso-frontkyso1.0.01 of 1See more

kyso-front kyso 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-27904.

Container imageDigestPackageFixed in
kyso/kyso-front:lateste52595c5c16f
minimatch@3.1.2
3.1.4

Open the chart page →

2,685
landing-pagelanding-pageVerified publisher0.1.01 of 1See more

landing-page landing-page 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-27904.

Container imageDigestPackageFixed in
felipecs8/landing-page:v1db6d44e325a1
minimatch@9.0.5
9.0.7

Open the chart page →

1,119
jellyseerrlbenicio-communityVerified publisher0.1.01 of 1See more

jellyseerr lbenicio-community 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-27904.

Container imageDigestPackageFixed in
fallenbagel/jellyseerr:latest4538137bc5af
minimatch@3.1.2
3.1.4

Open the chart page →

3,555
stremiolbenicio-communityVerified publisher0.1.11 of 2See more

stremio lbenicio-community 0.1.1

1 of the 2 container images this version deploys carry CVE-2026-27904.

Container imageDigestPackageFixed in
stremio/server:latest3dc145603def
minimatch@3.1.2
3.1.4

Open the chart page →

2,600
uptime-kumalbenicio-communityVerified publisher0.1.11 of 1See more

uptime-kuma lbenicio-community 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-27904.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.3.29aeb4e51d038
minimatch@9.0.3
9.0.7

Open the chart page →

33,242
dashboardleechistest1.0.01 of 1See more

dashboard leechistest 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-27904.

Container imageDigestPackageFixed in
sysnet4admin/dashboard:bluec5bd3bb1b5a6
minimatch@9.0.5
9.0.7

Open the chart page →

1,344
kinesaliteleprechaun-charts0.1.21 of 1See more

kinesalite leprechaun-charts 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-27904.

Container imageDigestPackageFixed in
instructure/kinesalite:latest34400d82f28f
minimatch@3.1.2
3.1.4

Open the chart page →

4,232
lgtv2mqttleprechaun-charts0.1.11 of 1See more

lgtv2mqtt leprechaun-charts 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-27904.

Container imageDigestPackageFixed in
ghcr.io/leprechaun/lgtv2mqtt:latestac2e11c41ffb
minimatch@3.0.4
3.1.4

Open the chart page →

1,062
linkdinglinkding0.2.31 of 1See more

linkding linkding 0.2.3

1 of the 1 container images this version deploys carry CVE-2026-27904.

Container imageDigestPackageFixed in
sissbruecker/linkding:1.41.0-plusa222fb777e1f
minimatch@9.0.5
9.0.7

Open the chart page →

37,942
node-redlmatfyVerified publisher0.1.61 of 1See more

node-red lmatfy 0.1.6

1 of the 1 container images this version deploys carry CVE-2026-27904.

Container imageDigestPackageFixed in
nodered/node-red:4.1.10-minimald73ae167cb9b
minimatch@9.0.5
9.0.7

Open the chart page →

1,809
zigbee2mqttlmatfyVerified publisher0.1.141 of 2See more

zigbee2mqtt lmatfy 0.1.14

1 of the 2 container images this version deploys carry CVE-2026-27904.

Container imageDigestPackageFixed in
koenkk/zigbee2mqtt:2.7.260a295b40f4e
minimatch@10.1.1
10.2.3

Open the chart page →

1,391
weather-app-chartlocal-weatherapp0.1.01 of 4See more

weather-app-chart local-weatherapp 0.1.0

1 of the 4 container images this version deploys carry CVE-2026-27904.

Container imageDigestPackageFixed in
youssef11gaber10/deployment-ui-react:latestba6853e35c60
minimatch@5.0.1
5.1.8

Open the chart page →

5,905
uptime-kumaloeken-at-homeVerified publisher2.3.21 of 1See more

uptime-kuma loeken-at-home 2.3.2

1 of the 1 container images this version deploys carry CVE-2026-27904.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.3.29aeb4e51d038
minimatch@9.0.3
9.0.7

Open the chart page →

33,242
devspace-cloudloftVerified publisher0.3.31 of 8See more

devspace-cloud loft 0.3.3

1 of the 8 container images this version deploys carry CVE-2026-27904.

Container imageDigestPackageFixed in
devspacecloud/ui:0.3.3deef55ff29a7
minimatch@3.0.4
3.1.4

Open the chart page →

9,880
redisinsightlogic3579Verified publisher3.4.01 of 1See more

redisinsight logic3579 3.4.0

1 of the 1 container images this version deploys carry CVE-2026-27904.

Container imageDigestPackageFixed in
redis/redisinsight:3.485562d67a912
minimatch@9.0.5
9.0.7

Open the chart page →

1,490
logtidelogtideVerified publisher2.1.142 of 4See more

logtide logtide 2.1.14

2 of the 4 container images this version deploys carry CVE-2026-27904.

Container imageDigestPackageFixed in
ghcr.io/logtide-dev/logtide-backend:1.0.265463e02f887
minimatch@9.0.5
9.0.7
ghcr.io/logtide-dev/logtide-frontend:1.0.22a7da1451f86
minimatch@9.0.5
9.0.7

Open the chart page →

2,774
nubladolsst-sqre0.9.231 of 5See more

nublado lsst-sqre 0.9.23

1 of the 5 container images this version deploys carry CVE-2026-27904.

Container imageDigestPackageFixed in
lsstsqre/sciplat-hub:latest5e0ade6bed1c
minimatch@3.0.3
3.1.4

Open the chart page →

5,786
nublado2lsst-sqre0.8.51 of 2See more

nublado2 lsst-sqre 0.8.5

1 of the 2 container images this version deploys carry CVE-2026-27904.

Container imageDigestPackageFixed in
lsstsqre/nublado2:2.0.1b75bf8aaafa4
minimatch@3.0.4
node-minimatch@3.0.4-4
3.1.4
no fix listed

Open the chart page →

17,779
opendistro-eslsst-sqre1.4.11 of 3See more

opendistro-es lsst-sqre 1.4.1

1 of the 3 container images this version deploys carry CVE-2026-27904.

Container imageDigestPackageFixed in
amazon/opendistro-for-elasticsearch-kibana:1.4.05126e2e79a1f
minimatch@3.0.4
3.1.4

Open the chart page →

7,929
squareonelsst-sqre0.4.11 of 1See more

squareone lsst-sqre 0.4.1

1 of the 1 container images this version deploys carry CVE-2026-27904.

Container imageDigestPackageFixed in
lsstsqre/squareone:0.4.09ded78e7fe03
minimatch@3.0.4
3.1.4

Open the chart page →

2,247
frontendluiscajl0.1.71 of 1See more

frontend luiscajl 0.1.7

1 of the 1 container images this version deploys carry CVE-2026-27904.

Container imageDigestPackageFixed in
lavandadelpatio/frontend:latest501c3f31e0bc
minimatch@3.0.4
3.1.4

Open the chart page →

3,651
hyperglassm0nsterrr-hyperglassVerified publisher4.2.11 of 2See more

hyperglass m0nsterrr-hyperglass 4.2.1

1 of the 2 container images this version deploys carry CVE-2026-27904.

Container imageDigestPackageFixed in
ghcr.io/m0nsterrr/hyperglass:v2.0.4f7b5d20c5e42
minimatch@9.0.4
9.0.7

Open the chart page →

4,647
m9sweeperm9sweeperVerified publisher1.6.01 of 6See more

m9sweeper m9sweeper 1.6.0

1 of the 6 container images this version deploys carry CVE-2026-27904.

Container imageDigestPackageFixed in
ghcr.io/m9sweeper/dash:1.6.02e27cdff8344
minimatch@3.1.2
3.1.4

Open the chart page →

9,774
magistralamagistrala-devopsVerified publisher0.16.21 of 42See more

magistrala magistrala-devops 0.16.2

1 of the 42 container images this version deploys carry CVE-2026-27904.

Container imageDigestPackageFixed in
ghcr.io/absmach/magistrala/ui-smq:latestea7e7f0e293e
minimatch@9.0.5
9.0.7

Open the chart page →

24,400
docker-mailservermailserverVerified publisher0.2.651 of 9See more

docker-mailserver mailserver 0.2.65

1 of the 9 container images this version deploys carry CVE-2026-27904.

Container imageDigestPackageFixed in
ghcr.io/jeboehm/fetchmailmgr:0.3.2126c4691b28a4
minimatch@9.0.5
9.0.7

Open the chart page →

10,897
nodecg-chartmarathon-charts0.1.51 of 2See more

nodecg-chart marathon-charts 0.1.5

1 of the 2 container images this version deploys carry CVE-2026-27904.

Container imageDigestPackageFixed in
ghcr.io/rodg/nodecg-base:latest31be4bf87070
minimatch@3.1.2
3.1.4

Open the chart page →

7,315
kubevismario-fVerified publisher2.0.11 of 1See more

kubevis mario-f 2.0.1

1 of the 1 container images this version deploys carry CVE-2026-27904.

Container imageDigestPackageFixed in
ghcr.io/mario-f/kubevis:v1.4.0763daf9caf8e
minimatch@3.0.4
3.1.4

Open the chart page →

5,287
mauticmautic-chartVerified publisher1.0.21 of 3See more

mautic mautic-chart 1.0.2

1 of the 3 container images this version deploys carry CVE-2026-27904.

Container imageDigestPackageFixed in
mautic/mautic:7-apacheeb8cc73d97e1
minimatch@10.1.1
10.2.3

Open the chart page →

8,303
maxcrm-chartsmaxcrm-chartsVerified publisher1.1.2011 of 4See more

maxcrm-charts maxcrm-charts 1.1.201

1 of the 4 container images this version deploys carry CVE-2026-27904.

Container imageDigestPackageFixed in
chatwoot/chatwoot:v3.1.0d530ab8c1753
minimatch@3.0.4
3.1.4

Open the chart page →

5,940
eoloplantmca-eoloplaner0.1.01 of 7See more

eoloplant mca-eoloplaner 0.1.0

1 of the 7 container images this version deploys carry CVE-2026-27904.

Container imageDigestPackageFixed in
hugohg34/server:0.0.2503e5d8960ff
minimatch@5.0.1
5.1.8

Open the chart page →

29,588
backstagemcwarmanVerified publisher0.10.101 of 2See more

backstage mcwarman 0.10.10

1 of the 2 container images this version deploys carry CVE-2026-27904.

Container imageDigestPackageFixed in
ghcr.io/mcwarman/backstage-sample-app/backend:main07aba09a594f
minimatch@9.0.5
9.0.7

Open the chart page →

9,668
kommandermesosphere-stable0.39.21 of 29See more

kommander mesosphere-stable 0.39.2

1 of the 29 container images this version deploys carry CVE-2026-27904.

Container imageDigestPackageFixed in
mesosphere/kommander:6.100.13917e82333a9
minimatch@3.0.4
3.1.4

Open the chart page →

68,284
opsportalmesosphere-stable0.9.51 of 3See more

opsportal mesosphere-stable 0.9.5

1 of the 3 container images this version deploys carry CVE-2026-27904.

Container imageDigestPackageFixed in
mesosphere/kommander:6.100.13917e82333a9
minimatch@3.0.4
3.1.4

Open the chart page →

7,027
littlelink-servermhamzahkhanVerified publisher1.0.01 of 1See more

littlelink-server mhamzahkhan 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-27904.

Container imageDigestPackageFixed in
ghcr.io/techno-tim/littlelink-server:latest735a1fcd078b
minimatch@9.0.3
9.0.7

Open the chart page →

887

Container images carrying it

835 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
josepht05/titajo-docker:v1.0.0d94024965d78
minimatch@3.1.2
3.1.4
1
josh5/unmanic:0.2.64d49c4816260
minimatch@9.0.3
9.0.7
1
junktext/getting-started:1.0.5a70936c04aed
minimatch@3.0.4
3.1.4
1
junktext/getting-started:1.0.34d44adf5a4da2
minimatch@3.0.4
3.1.4
1
jupyterhub/configurable-http-proxy:3.0.0c36cf3cc1c99
minimatch@3.0.3
3.1.4
1
jupyterhub/jupyterhub:5.4.63974ba945e65
minimatch@9.0.3
node-minimatch@9.0.3-4build5
9.0.7
no fix listed
1
jupyterhub/k8s-singleuser-sample:0.11.1e3e6f3051df8
minimatch@3.0.4
3.1.4
1
kaushaln1/helm_node_app:lateste9f2d5dfdba0
minimatch@9.0.5
9.0.7
1
keyoxide/keyoxide:stable96f27a71269d
minimatch@3.0.4
3.1.4
1
kobotoolbox/kpi:2.022.24dbcacc01bccd4
minimatch@3.1.2
3.1.4
1
koenkk/zigbee2mqtt:2.7.260a295b40f4e
minimatch@10.1.1
10.2.3
1
konradkleine/docker-registry-frontend:v2181aad54ee64
minimatch@2.0.10
3.1.4
1
koumoul/capture:17108d47be3b2
minimatch@3.0.4
3.1.4
1
koumoul/openapi-viewer:18eeca2e8285b
minimatch@3.0.4
3.1.4
1
ktitilayo2/nodejswebapp:latest8bac28058688
minimatch@3.1.2
3.1.4
1
kubebb/bff-server:v0.2.0-202312040fbb732379bc
minimatch@6.2.0
6.2.2
1
kubebb/component-store:latestfd8ecbd73213
minimatch@3.1.2
3.1.4
1
kubebb/tamp-portal:v5.6.0fadac6d52470
minimatch@3.0.4
3.1.4
1
kubebb/tdsf-portal:v5.7.0258458311bc9
minimatch@3.0.4
3.1.4
1
kubeflownotebookswg/centraldashboard:v1.6.137300551dea6
minimatch@3.0.4
3.1.4
1
kubeflownotebookswg/centraldashboard:v1.9.2af55c22ef5de
minimatch@3.1.2
3.1.4
1
kubesphere/examples-bookinfo-ratings-v1:1.13.0f1b5bf878196
minimatch@3.0.4
3.1.4
1
kubevious/backend:1.2.22d9ba6eb46b6
minimatch@3.1.2
3.1.4
1
kubevious/collector:1.2.1f58226f9d84e
minimatch@3.1.2
3.1.4
1
kubevious/guard:1.2.19bf567704de2
minimatch@3.1.2
3.1.4
1
kubevious/parser:1.0.151acf1a1f0b47
minimatch@3.0.4
3.1.4
1
kubevious/parser:1.2.299ae7a5168c2
minimatch@5.0.1
5.1.8
1
kubevious/workload-operator:1.0.20b0f4c507eb6
minimatch@3.1.2
3.1.4
1
kvalitetsit/kithosting-networkpolicytests:0.0.12b99cfa3c5df
minimatch@3.0.4
3.1.4
1
kyleslugg/klusterview:latestba8c36dfdfbd
minimatch@3.1.2
3.1.4
1
kyso/kyso-front:lateste52595c5c16f
minimatch@3.1.2
3.1.4
1
laly9999/node-app:1dd0e503913e1
minimatch@9.0.5
9.0.7
1
laly9999/node-app-dockerized:latest75ae77a20c6c
minimatch@5.0.1
5.1.8
1
langgenius/dify-agent-local-sandbox:1.16.1bf8027ddccf3
minimatch@9.0.5
9.0.7
1
langgenius/dify-api:1.16.1dcefa5f7c47c
minimatch@9.0.5
9.0.7
1
langgenius/dify-ee-enterprise-frontend:3.9.8-ubi98dd9de6b6190
minimatch@3.1.2
3.1.4
1
langgenius/dify-ee-web:3.9.8-ubi9ba1dd1d0bcea
minimatch@3.1.2
3.1.4
1
langgenius/dify-sandbox:0.2.124e65e8a351a2
minimatch@9.0.3
9.0.7
1
langgenius/dify-web:1.16.187dd47e4e28f
minimatch@9.0.5
9.0.7
1
langgenius/dify-web:0.6.11a2a294743634
minimatch@9.0.3
9.0.7
1
langgenius/dify-web:1.10.1-fix.1c306ac577912
minimatch@9.0.5
9.0.7
1
langgenius/dify-web:1.0.0d64914ff0d6d
minimatch@9.0.5
9.0.7
1
lavandadelpatio/frontend:latest501c3f31e0bc
minimatch@3.0.4
3.1.4
1
leeyoongti/first-app:1.0.021d66cb76352
minimatch@3.0.4
3.1.4
1
leonardomulticloud/svc-vault-frontend:v1.0.0e42a341e0299
minimatch@5.1.6
5.1.8
1
library/ghost:6.25.12654b1e90413
minimatch@5.1.6
5.1.8
1
library/ghost:4.37.0767230c0f263
minimatch@3.0.5
3.1.4
1
library/ghost:5.79.083f7bf209844
minimatch@5.1.0
5.1.8
1
library/ghost:6.22.0-alpine3.23ac533a6988ee
minimatch@5.1.6
5.1.8
1
library/kibana:7.17.150172f1c538e7
minimatch@3.1.2
3.1.4
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.