Friday, May 29, 2026

Today's Security Snapshot

Critical vulnerabilities, curated daily for security professionals

đŸŽ¯ SSCV Profile

See how vulnerabilities affect your specific environment

CRS uses the System Security Context Vector (SSCV) Framework v1.0 to adjust CVSS scores based on your system's exposure level, network position, and business criticality. Learn more about SSCV Framework

Risk scores will be adjusted based on your selected environment

Today's Security Brief

Oracle dominates Friday's disclosures with multiple near-maximum-severity flaws across REST Data Services, iAssets, and Universal Work Queue, joined by a perfect-score SandboxJS sandbox escape that exposes server-side JavaScript execution. The brief covers 19 critical CVEs, unchanged from the prior day, and 58 high-priority CVEs, a 93% increase over yesterday's 30. CVE-2026-46840 (CVSS 10, Oracle REST Data Services) and CVE-2026-43898 (CVSS 10, SandboxJS) headline the critical set, with CVE-2026-46775 (CVSS 9.9, Oracle REST Data Services) and a string of CVSS 9.8 WordPress plugin flaws including CVE-2026-3655 and CVE-2026-8809 close behind. Remote code execution and authentication bypass patterns predominate, concentrated in enterprise middleware, identity infrastructure, and the WordPress plugin ecosystem. No patches are currently reflected for the disclosed set, so affected operators should prioritize compensating controls and vendor advisory monitoring; five vulnerabilities, including flaws in Drupal Core and GitHub Actions OIDC, have confirmed active exploitation.

  • Oracle accounts for several near-maximum-severity flaws, led by CVE-2026-46840 (CVSS 10, REST Data Services) and CVE-2026-46775 (CVSS 9.9), plus iAssets and Universal Work Queue (both CVSS 9.9)
  • 19 critical CVEs (CVSS 9.0+), unchanged from the prior day
  • 58 high-priority CVEs (CVSS 7.0-8.9), a 93% increase from 30 yesterday
  • Remote code execution and authentication bypass dominate, including the CVSS 10 SandboxJS escape (CVE-2026-43898) and CVSS 9.8 WordPress plugin flaws (CVE-2026-3655, CVE-2026-8809)
  • Patch availability stands at 0% across the disclosed set, leaving Oracle middleware and WordPress plugin deployments exposed pending vendor fixes
  • Five vulnerabilities show confirmed active exploitation, spanning Drupal Core, LiteSpeed cPanel, GitHub Actions OIDC, and Nx

Immediate action: Prioritize Oracle REST Data Services, iAssets, and Universal Work Queue instances along with SandboxJS deployments and the affected WordPress plugins, restricting external access and applying compensating controls where exposure exists. With no patches reflected for the disclosed set, monitor vendor advisories closely and expedite remediation for the five actively exploited issues, including Drupal Core and GitHub Actions OIDC, as fixes become available.

💡 Tip: Swipe CVE cards left to ⭐ star, right to ❌ remove

Section Navigation