Friday, March 20, 2026

Today's Security Snapshot

Critical vulnerabilities, curated daily for security professionals

đŸŽ¯ SSCV Profile

See how vulnerabilities affect your specific environment

CRS uses the System Security Context Vector (SSCV) Framework v1.0 to adjust CVSS scores based on your system's exposure level, network position, and business criticality. Learn more about SSCV Framework

Risk scores will be adjusted based on your selected environment

Today's Security Brief

Friday's vulnerability disclosures reveal 31 critical-severity flaws across Microsoft, HP, Oracle, and Arch products, including a CVSS 10.0 remote code execution in Azure Cloud Shell (CVE-2026-32169) and multiple CVSS 9.8 issues in Microsoft Bing Images and Oracle Identity Manager. Critical CVE volume rose 158% from the prior day's 12 to 31, while high-priority disclosures increased 19% to 100. Notable entries include CVE-2026-32938 (CVSS 9.9) in SiYuan and CVE-2026-32767 (CVSS 9.8) targeting endpoint bypass in Arch products. Among the 16 actively exploited vulnerabilities are flaws in Microsoft SharePoint, Cisco FMC, Ivanti EPM, and Google Chromium V8, alongside several legacy CVEs in Apple, Hikvision, and Rockwell products still under active exploitation. No patches are currently available for the newly disclosed vulnerabilities, requiring defenders to prioritize compensating controls and monitoring.

  • Azure Cloud Shell CVE-2026-32169 rated CVSS 10.0 — highest severity disclosed this cycle, enabling remote code execution
  • 31 critical CVEs disclosed, a 158% increase from the prior day's 12, spanning Microsoft, HP, Oracle, and Arch products
  • 100 high-priority CVEs represent a 19% increase, bringing the total disclosure count to 131
  • Authentication bypass and remote code execution dominate attack patterns, affecting Microsoft Bing Images, Oracle Identity Manager, and SiYuan
  • 0% patch availability across newly disclosed vulnerabilities — no vendor fixes released at time of publication
  • 16 actively exploited vulnerabilities include flaws in SharePoint, Cisco FMC, Ivanti EPM, Chromium V8, and Zimbra

Immediate action: Prioritize reviewing exposure to Azure Cloud Shell, Microsoft Bing Images, Oracle Identity Manager, and HP products given the concentration of CVSS 9.0+ vulnerabilities. With zero patches currently available, implement network segmentation, restrict access to affected services, and increase monitoring for exploitation indicators across SharePoint, Cisco FMC, Ivanti EPM, and Chromium environments.

💡 Tip: Swipe CVE cards left to ⭐ star, right to ❌ remove

Section Navigation