Tuesday, March 3, 2026

Today's Security Snapshot

Critical vulnerabilities, curated daily for security professionals

đŸŽ¯ SSCV Profile

See how vulnerabilities affect your specific environment

CRS uses the System Security Context Vector (SSCV) Framework v1.0 to adjust CVSS scores based on your system's exposure level, network position, and business criticality. Learn more about SSCV Framework

Risk scores will be adjusted based on your selected environment

Today's Security Brief

Yesterday's disclosures revealed 17 critical vulnerabilities affecting Changing IDExpert Windows Logon Agent, e-Excellence U-Office Force, MongoDB, and multiple WordPress-related products. Critical CVEs jumped sharply from 3 to 17 compared to the prior day, while high-priority vulnerabilities rose from 15 to 69, reflecting a broad increase in disclosure volume. Notable critical entries include CVE-2026-2999 and CVE-2026-3000 targeting Changing IDExpert authentication agents, CVE-2026-3431 affecting MongoDB tool endpoints, and CVE-2026-2628 impacting a Microsoft 365 Entra ID SSO WordPress plugin. Attack patterns center on authentication bypass and remote code execution across identity providers, web ordering systems, and enterprise collaboration tools. No patches are currently available for yesterday's disclosures; 11 actively exploited vulnerabilities span Apple, Microsoft, Google Chromium, GitLab, and Roundcube Webmail.

  • Changing IDExpert Windows Logon Agent hit with two CVSS 9.8 authentication vulnerabilities (CVE-2026-2999, CVE-2026-3000) affecting enterprise identity management
  • Critical CVE count rose to 17, a 467% increase over the prior day's 3 critical disclosures
  • High-priority vulnerabilities reached 69, up 360% from the previous day's 15
  • Remote code execution and authentication bypass dominate critical findings across MongoDB, WordPress plugins, and HP Simple Food Order System
  • Patch availability stands at 0% for newly disclosed vulnerabilities — no vendor fixes released yet
  • 11 actively exploited vulnerabilities include Apple OS, Google Chromium, GitLab, and Roundcube Webmail

Immediate action: Prioritize reviewing exposure to Changing IDExpert Windows Logon Agent, MongoDB tool endpoints, and Microsoft 365 Entra ID SSO plugin environments, as these carry CVSS 9.8 scores with no patches available. For the 11 actively exploited vulnerabilities affecting Apple, Chromium, GitLab, and Roundcube, verify that existing mitigations or prior patches are applied and monitor vendor channels for updates on newly disclosed issues.

💡 Tip: Swipe CVE cards left to ⭐ star, right to ❌ remove

Section Navigation