Monday, March 23, 2026

Today's Security Snapshot

Critical vulnerabilities, curated daily for security professionals

đŸŽ¯ SSCV Profile

See how vulnerabilities affect your specific environment

CRS uses the System Security Context Vector (SSCV) Framework v1.0 to adjust CVSS scores based on your system's exposure level, network position, and business criticality. Learn more about SSCV Framework

Risk scores will be adjusted based on your selected environment

Today's Security Brief

Monday's vulnerability disclosures highlight widespread risk across Apple, Google, Broadcom, and Qualcomm products, with 17 CVEs under active exploitation. The day saw 4 critical-severity vulnerabilities (up 100% from Sunday's 2) and 47 high-priority CVEs (down 49% from 93). Critical flaws include CVE-2026-3587 (CVSS 10.0) affecting Linux-based operating systems, CVE-2026-4567 (CVSS 9.8) in Tenda A15 routers, and CVE-2019-25614 (CVSS 9.8) targeting STOR FTP Server. Actively exploited vulnerabilities span Broadcom VMware Aria Operations, Qualcomm chipsets, Google Chrome V8, and multiple Apple products including iOS and iPadOS. No patches are currently available for the disclosed CVEs, requiring organizations to prioritize compensating controls and monitoring.

  • CVE-2026-3587 (CVSS 10.0) affects Linux-based operating systems — the highest severity rating possible, requiring immediate risk assessment
  • 4 critical-severity CVEs disclosed, a 100% increase from Sunday's 2 critical vulnerabilities
  • 47 high-priority CVEs (CVSS 7.0-8.9), down 49% from Sunday's 93, narrowing the scope of urgent triage
  • Active exploitation confirmed across Broadcom VMware Aria Operations, Qualcomm chipsets, Google Chrome V8/Skia, and Apple iOS/iPadOS
  • 0% patch availability across all 51 disclosed CVEs — compensating controls and network segmentation are essential
  • 17 CVEs flagged as actively exploited, including legacy vulnerabilities such as CVE-2017-7921 in Hikvision products

Immediate action: Prioritize risk assessment for Linux-based systems (CVE-2026-3587), Broadcom VMware Aria Operations, Qualcomm-powered devices, and Apple products including iOS and iPadOS, as these face active exploitation with no patches currently available. Implement compensating controls such as network segmentation, access restrictions, and enhanced monitoring for affected systems until vendor patches are released.

💡 Tip: Swipe CVE cards left to ⭐ star, right to ❌ remove

Section Navigation