Thursday, January 15, 2026 Archive

Archived Security Snapshot

Critical vulnerabilities, curated daily for security professionals

Archived Security Brief

Yesterday's vulnerability disclosures revealed 5 critical CVEs, representing an 86% decrease from the prior day's 37 critical findings. High-priority vulnerabilities remained steady at 100, unchanged from the previous reporting period. Five actively exploited vulnerabilities require attention, including CVE-2025-14847 affecting MongoDB, CVE-2026-20805 targeting Microsoft Windows, and CVE-2025-37164 in HPE OneView. Notable critical vulnerabilities include CVE-2026-22686 and CVE-2026-23550, both scoring CVSS 10.0, affecting Enclave JavaScript sandbox and Modular DS respectively, along with CVE-2025-14301 impacting WooCommerce integrations. Patch availability stands at 0%, necessitating compensating controls and monitoring until vendor updates become available.

  • 5 critical CVEs disclosed, down 86% from 37 the prior day
  • 100 high-priority CVEs, unchanged from previous reporting period
  • 5 actively exploited vulnerabilities affecting MongoDB, Microsoft Windows, HPE OneView, and Gogs
  • 0% patch availability for disclosed vulnerabilities
  • WordPress plugins (Integration Opvius AI, News and Blog Designer Bundle) and enterprise systems (MongoDB Server, HPE OneView) among affected products

Immediate action: Organizations running MongoDB, Microsoft Windows, HPE OneView, Gogs, or affected WordPress plugins should implement network segmentation and enhanced monitoring as compensating controls. With no patches currently available, prioritize vulnerability scanning to identify exposed assets and establish alerting for vendor security bulletins.

How to read this brief

CVSS score (e.g. 9.1) — severity from 0–10. Red marks critical (9+), orange high (7–8.9).

Exploitability — how hard the flaw is to attack, read from the CVSS vector:

  • Network / Adjacent / Local / Physical — how close an attacker must get. Network means reachable over the internet.
  • No / Low / High privileges — the access they need first. No privileges means no login required.
  • No interaction / User interaction — whether a victim has to do something (open a file, click a link). No interaction means fully automatable.

The lower the bar on all three, the easier to exploit at scale — “Network · No privileges · No interaction” is the worst case: hit from anywhere, no credentials, no victim action.

Actively exploited — confirmed under attack in the wild (CISA’s Known Exploited Vulnerabilities catalog). Prioritize these regardless of score.

EPSS · Nth percentile — FIRST.org’s estimated chance a flaw is exploited within 30 days. We flag it only in the top 10% — a statistical signal it’s unusually likely to be targeted, separate from whether attacks are confirmed.

💡 Tip: Swipe CVE cards left to ⭐ star, right to ❌ remove

Section Navigation