Wednesday, January 7, 2026 Archive

Archived Security Snapshot

Critical vulnerabilities, curated daily for security professionals

Archived Security Brief

Wednesday's brief contains 14 critical vulnerabilities, unchanged from the prior day's count. High-priority CVEs increased substantially to 88, a 49% rise from yesterday's 59 disclosures. Two actively exploited vulnerabilities require attention: CVE-2023-52163 affecting Digiever DS-2105 Pro and CVE-2025-14847 impacting MongoDB Server. Notable critical disclosures include CVE-2025-30996 (CVSS 9.9) in Themify WordPress plugins, multiple WordPress privilege escalation flaws (CVE-2025-14996, CVE-2025-15001), and CVE-2025-15471 affecting TRENDnet devices. Patch availability currently stands at 0%, requiring organizations to implement compensating controls until vendor fixes become available.

  • 14 critical CVEs disclosed, unchanged from prior day
  • 88 high-priority CVEs represent a 49% increase from yesterday's 59
  • 2 actively exploited vulnerabilities affecting Digiever and MongoDB systems
  • 0% patch availability necessitates temporary mitigations
  • WordPress ecosystem heavily impacted with multiple privilege escalation flaws
  • TRENDnet and TECNO Mobile devices among affected network/mobile products

Immediate action: Organizations using WordPress with Themify, AS Password Field, or FS Registration Password plugins should restrict administrative access and monitor for unauthorized account changes. MongoDB Server and Digiever DS-2105 Pro deployments require immediate review given active exploitation, with network segmentation recommended until patches are released.

How to read this brief

CVSS score (e.g. 9.1) — severity from 0–10. Red marks critical (9+), orange high (7–8.9).

Exploitability — how hard the flaw is to attack, read from the CVSS vector:

  • Network / Adjacent / Local / Physical — how close an attacker must get. Network means reachable over the internet.
  • No / Low / High privileges — the access they need first. No privileges means no login required.
  • No interaction / User interaction — whether a victim has to do something (open a file, click a link). No interaction means fully automatable.

The lower the bar on all three, the easier to exploit at scale — “Network · No privileges · No interaction” is the worst case: hit from anywhere, no credentials, no victim action.

Actively exploited — confirmed under attack in the wild (CISA’s Known Exploited Vulnerabilities catalog). Prioritize these regardless of score.

EPSS · Nth percentile — FIRST.org’s estimated chance a flaw is exploited within 30 days. We flag it only in the top 10% — a statistical signal it’s unusually likely to be targeted, separate from whether attacks are confirmed.

💡 Tip: Swipe CVE cards left to ⭐ star, right to ❌ remove

Section Navigation