Thursday, March 19, 2026

Today's Security Snapshot

Critical vulnerabilities, curated daily for security professionals

đŸŽ¯ SSCV Profile

See how vulnerabilities affect your specific environment

CRS uses the System Security Context Vector (SSCV) Framework v1.0 to adjust CVSS scores based on your system's exposure level, network position, and business criticality. Learn more about SSCV Framework

Risk scores will be adjusted based on your selected environment

Today's Security Brief

Thursday's vulnerability disclosures include 12 critical-severity flaws affecting WordPress, Shinetheme Traveler, and Rymera Web WooCommerce plugins, alongside enterprise platforms like OpenProject and Glances. Critical CVEs rose 33% from the prior day while high-priority vulnerabilities decreased 16% to 84. CVE-2026-2991 (CVSS 9.8) targets WordPress core, CVE-2026-25449 (CVSS 9.8) affects Shinetheme Traveler, and CVE-2026-25873 (CVSS 9.8) impacts the Reward Server — all carrying the highest severity scores in this batch. Microsoft SharePoint, Ivanti Endpoint Manager, Broadcom VMware Aria Operations, and Google Chrome components are among 15 actively exploited vulnerabilities, reflecting broad targeting across enterprise infrastructure. No patches are currently available for these disclosures, requiring organizations to prioritize compensating controls and monitoring.

  • WordPress core and multiple WordPress plugins including WooCommerce Wholesale Lead Capture carry CVSS 9.0+ vulnerabilities with remote exploitation potential
  • 12 critical CVEs disclosed, a 33% increase from the prior day's 9 critical vulnerabilities
  • 84 high-priority CVEs tracked, down 16% from the prior day's 100
  • Remote code execution and authentication bypass patterns dominate, affecting jsPDF, OpenProject, Glances, and Profile Builder Pro
  • Patch availability stands at 0% — all 96 disclosed CVEs currently lack vendor-issued fixes
  • 15 actively exploited vulnerabilities span Microsoft SharePoint, Ivanti EPM, VMware Aria Operations, Google Chrome, and legacy Apple and Hikvision products

Immediate action: Prioritize network segmentation and access restrictions for Microsoft SharePoint, Ivanti Endpoint Manager, VMware Aria Operations, and Google Chrome environments where active exploitation is confirmed. With 0% patch availability across all 96 disclosed CVEs, deploy compensating controls including WAF rules, enhanced logging, and temporary access restrictions for affected WordPress installations and enterprise platforms until vendor patches are released.

💡 Tip: Swipe CVE cards left to ⭐ star, right to ❌ remove

Section Navigation