Wednesday, March 11, 2026

Today's Security Snapshot

Critical vulnerabilities, curated daily for security professionals

đŸŽ¯ SSCV Profile

See how vulnerabilities affect your specific environment

CRS uses the System Security Context Vector (SSCV) Framework v1.0 to adjust CVSS scores based on your system's exposure level, network position, and business criticality. Learn more about SSCV Framework

Risk scores will be adjusted based on your selected environment

Today's Security Brief

Wednesday's vulnerability disclosures include 25 critical-severity CVEs, a fivefold increase from the prior day's 5, alongside 100 high-priority issues across enterprise infrastructure and application platforms. Notable critical flaws include CVE-2025-48611 (CVSS 10.0) in DeviceId.java, two CVSS 9.9 vulnerabilities in OneUptime Synthetic Monitors (CVE-2026-30887, CVE-2026-30957), and CVE-2026-0953 (CVSS 9.8) affecting WordPress. Linux kernel, HP configuration management, Appsmith, and Atlassian products also carry critical-rated vulnerabilities requiring prompt evaluation. Thirteen CVEs have confirmed active exploitation, spanning SolarWinds Web Help Desk, Roundcube Webmail, Ivanti Endpoint Manager, Broadcom VMware Aria Operations, and several Apple products. No patches have been confirmed available at this time, making compensating controls and network-level mitigations essential while vendors release fixes.

  • CVE-2025-48611 rated CVSS 10.0 in DeviceId.java and two CVSS 9.9 flaws in OneUptime Synthetic Monitors represent the highest-severity disclosures
  • Critical CVEs jumped to 25, up 400% from the prior day's 5, spanning Linux, HP, WordPress, Atlassian, and Appsmith
  • High-priority CVEs rose to 100, a 33% increase over the previous day's 75
  • Remote code execution and authentication bypass patterns affect WordPress, Linux kernel, and enterprise monitoring platforms including OneUptime and Appsmith
  • Patch availability stands at 0% across all disclosed CVEs — compensating controls and segmentation are recommended immediately
  • 13 actively exploited vulnerabilities affect SolarWinds, Roundcube, Ivanti, VMware Aria Operations, Qualcomm chipsets, and Apple products

Immediate action: Prioritize review of internet-facing deployments of OneUptime, WordPress, Roundcube Webmail, Ivanti EPM, and SolarWinds Web Help Desk, as these carry critical ratings or confirmed exploitation. With 0% patch availability reported, implement network segmentation, restrict administrative access, and deploy available WAF or IDS signatures as interim mitigations until vendor patches are released.

💡 Tip: Swipe CVE cards left to ⭐ star, right to ❌ remove

Section Navigation