Friday, January 9, 2026 Archive

Archived Security Snapshot

Critical vulnerabilities, curated daily for security professionals

Archived Security Brief

Yesterday's disclosure activity identified 43 critical-severity CVEs, representing a 139% increase compared to the prior day's 18 critical findings. High-priority vulnerabilities remained relatively stable at 100, showing only a 3% increase from the previous 97. Four actively exploited vulnerabilities require immediate attention, including CVE-2023-52163 affecting Digiever DS-2105 Pro devices, CVE-2025-14847 impacting MongoDB Server, CVE-2009-0556 targeting Microsoft Office, and CVE-2025-37164 affecting HP OneView. Notable critical disclosures include CVE-2019-25296 in the WP Cost Estimation WordPress plugin enabling arbitrary file uploads, CVE-2025-66913 in JimuReport, and CVE-2017-20216 affecting FLIR thermal cameras. Patch availability currently stands at 0%, indicating organizations should prioritize compensating controls and monitoring until vendor remediation becomes available.

  • 43 critical CVEs disclosed, up 139% from prior day's 18 critical findings
  • 100 high-priority CVEs identified, a 3% increase from 97 the previous day
  • 4 actively exploited vulnerabilities affecting Digiever, MongoDB, Microsoft Office, and HP OneView
  • 0% patch availability requires compensating controls and enhanced monitoring
  • WordPress plugins, JimuReport, FLIR cameras, and file handling components among affected systems

Immediate action: Organizations running MongoDB Server, HP OneView, Microsoft Office, or Digiever surveillance devices should prioritize review and implement network segmentation or access restrictions for affected systems. With no patches currently available for disclosed vulnerabilities, focus on detection capabilities, logging, and compensating controls until vendor updates are released.

How to read this brief

CVSS score (e.g. 9.1) — severity from 0–10. Red marks critical (9+), orange high (7–8.9).

Exploitability — how hard the flaw is to attack, read from the CVSS vector:

  • Network / Adjacent / Local / Physical — how close an attacker must get. Network means reachable over the internet.
  • No / Low / High privileges — the access they need first. No privileges means no login required.
  • No interaction / User interaction — whether a victim has to do something (open a file, click a link). No interaction means fully automatable.

The lower the bar on all three, the easier to exploit at scale — “Network · No privileges · No interaction” is the worst case: hit from anywhere, no credentials, no victim action.

Actively exploited — confirmed under attack in the wild (CISA’s Known Exploited Vulnerabilities catalog). Prioritize these regardless of score.

EPSS · Nth percentile — FIRST.org’s estimated chance a flaw is exploited within 30 days. We flag it only in the top 10% — a statistical signal it’s unusually likely to be targeted, separate from whether attacks are confirmed.

💡 Tip: Swipe CVE cards left to ⭐ star, right to ❌ remove

Section Navigation