Thursday, January 8, 2026 Archive

Archived Security Snapshot

Critical vulnerabilities, curated daily for security professionals

Archived Security Brief

Yesterday's vulnerability disclosures included 18 critical-severity CVEs, representing a 29% increase from the prior day's 14 critical findings. High-priority vulnerabilities (CVSS 7.0-8.9) totaled 97, a 10% increase from 88 previously tracked. Four actively exploited vulnerabilities were added to CISA's Known Exploited Vulnerabilities catalog, including CVE-2023-52163 affecting Digiever DS-2105 Pro, CVE-2025-14847 in MongoDB Server, CVE-2009-0556 targeting Microsoft Office, and CVE-2025-37164 in HP OneView. Notable critical CVEs include CVE-2019-25296 enabling arbitrary file uploads in the WP Cost Estimation WordPress plugin, CVE-2025-15018 allowing privilege escalation in the Optional Email WordPress plugin, and CVE-2025-12543 affecting the Undertow HTTP server. Patch availability currently stands at 0%, requiring organizations to implement compensating controls until vendor remediation is released.

  • 18 critical CVEs disclosed (29% increase from prior day's 14)
  • 97 high-priority CVEs tracked (10% increase from 88)
  • 4 actively exploited vulnerabilities added to KEV catalog affecting Digiever, MongoDB, Microsoft Office, and HP OneView
  • 0% patch availability for newly disclosed vulnerabilities
  • WordPress plugins WP Cost Estimation and Optional Email contain critical authentication bypass and file upload flaws

Immediate action: Organizations using MongoDB Server, HP OneView, Microsoft Office, and Digiever surveillance systems should prioritize reviewing exposure to actively exploited vulnerabilities. With no patches currently available for newly disclosed critical CVEs, implement network segmentation and enhanced monitoring for affected WordPress installations and Undertow HTTP server deployments.

How to read this brief

CVSS score (e.g. 9.1) β€” severity from 0–10. Red marks critical (9+), orange high (7–8.9).

Exploitability β€” how hard the flaw is to attack, read from the CVSS vector:

  • Network / Adjacent / Local / Physical β€” how close an attacker must get. Network means reachable over the internet.
  • No / Low / High privileges β€” the access they need first. No privileges means no login required.
  • No interaction / User interaction β€” whether a victim has to do something (open a file, click a link). No interaction means fully automatable.

The lower the bar on all three, the easier to exploit at scale β€” β€œNetwork Β· No privileges Β· No interaction” is the worst case: hit from anywhere, no credentials, no victim action.

Actively exploited β€” confirmed under attack in the wild (CISA’s Known Exploited Vulnerabilities catalog). Prioritize these regardless of score.

EPSS Β· Nth percentile β€” FIRST.org’s estimated chance a flaw is exploited within 30 days. We flag it only in the top 10% β€” a statistical signal it’s unusually likely to be targeted, separate from whether attacks are confirmed.

πŸ’‘ Tip: Swipe CVE cards left to ⭐ star, right to ❌ remove

Section Navigation