Saturday, February 7, 2026

Today's Security Snapshot

Critical vulnerabilities, curated daily for security professionals

đŸŽ¯ SSCV Profile

See how vulnerabilities affect your specific environment

CRS uses the System Security Context Vector (SSCV) Framework v1.0 to adjust CVSS scores based on your system's exposure level, network position, and business criticality. Learn more about SSCV Framework

Risk scores will be adjusted based on your selected environment

Today's Security Brief

Saturday's security landscape is dominated by 16 actively exploited CISA KEV vulnerabilities spanning Cisco Unified Communications, Zimbra, VMware vCenter, and Microsoft Office. A critical wave of SandboxJS escape vulnerabilities threatens JavaScript sandboxing, while Fortinet FortiClientEMS faces an unauthenticated SQL injection flaw. Supply chain risks emerge with malicious code embedded in the popular eslint-config-prettier package and command injection in React Native CLI. With only 27% of patches available, most organizations remain exposed.

  • 16 CISA KEV actively exploited vulnerabilities including Cisco, Zimbra, VMware vCenter, and Microsoft Office
  • 4 SandboxJS sandbox escape CVEs enable attackers to break out of JavaScript sandboxes via multiple techniques
  • Fortinet FortiClientEMS unauthenticated SQL injection (CVE-2026-21643) allows remote code execution
  • Supply chain attacks: malicious code in eslint-config-prettier and command injection in React Native CLI
  • SmarterTools SmarterMail targeted by 3 separate KEV vulnerabilities including auth bypass
  • Only 27% of patches currently available — most vulnerabilities remain unpatched

Immediate action: Immediately patch Cisco Unified Communications, Zimbra ZCS, and VMware vCenter Server. Audit any projects using eslint-config-prettier and React Native CLI for supply chain compromise. Review SmarterMail deployments for authentication bypass. Apply Fortinet FortiClientEMS updates as soon as patches are released.

💡 Tip: Swipe CVE cards left to ⭐ star, right to ❌ remove

Section Navigation