Friday, February 20, 2026

Today's Security Snapshot

Critical vulnerabilities, curated daily for security professionals

đŸŽ¯ SSCV Profile

See how vulnerabilities affect your specific environment

CRS uses the System Security Context Vector (SSCV) Framework v1.0 to adjust CVSS scores based on your system's exposure level, network position, and business criticality. Learn more about SSCV Framework

Risk scores will be adjusted based on your selected environment

Today's Security Brief

Friday's vulnerability disclosures include two maximum-severity CVSS 10.0 flaws in Linux Cyber Protect (CVE-2025-30411, CVE-2025-30412) alongside a critical Microsoft Semantic Kernel Python SDK vulnerability (CVE-2026-26030, CVSS 9.9). The day's 24 critical CVEs represent a 20% increase over Thursday, with 100 high-priority issues marking a 22% rise across both categories. WordPress plugins account for the largest share of critical disclosures, with at least six distinct plugin vulnerabilities scoring CVSS 9.8, while authorization bypass flaws affect Databank Accreditation Software. Among 20 actively exploited vulnerabilities, multiple Microsoft Windows and Office flaws are under active attack alongside legacy issues in GitLab, Zimbra, and Sangoma FreePBX dating back several years. No patches are currently available for the disclosed vulnerabilities, requiring organizations to prioritize compensating controls and monitoring.

  • Two CVSS 10.0 vulnerabilities in Linux Cyber Protect (CVE-2025-30411, CVE-2025-30412) represent the highest-severity disclosures of the day
  • 24 critical CVEs disclosed, up 20% from Thursday's 20, with WordPress plugin flaws comprising the largest category
  • 100 high-priority CVEs (CVSS 7.0-8.9), a 22% increase over the prior day's 82
  • Microsoft Windows and Office account for six actively exploited vulnerabilities, with additional active exploitation targeting Dell RP4VMs, Apple OS, and Google Chromium
  • Patch availability stands at 0% across all 124 disclosed CVEs, necessitating compensating controls
  • 20 vulnerabilities confirmed under active exploitation, including legacy flaws in GitLab, Zimbra, and FreePBX spanning 2008-2025

Immediate action: Prioritize compensating controls for Linux Cyber Protect, Microsoft Windows and Office, and WordPress plugin deployments, as no patches are currently available for any of the 124 disclosed vulnerabilities. Monitor vendor advisories closely for patch releases on the two CVSS 10.0 Cyber Protect flaws and the six actively exploited Microsoft vulnerabilities, and consider temporarily restricting exposure of affected services where feasible.

💡 Tip: Swipe CVE cards left to ⭐ star, right to ❌ remove

Section Navigation