Monday, January 26, 2026 Archive

Archived Security Snapshot

Critical vulnerabilities, curated daily for security professionals

Archived Security Brief

Yesterday's disclosures contained zero new critical vulnerabilities, a complete decrease from the prior day's 2 critical CVEs. High-priority vulnerabilities dropped substantially to 11, representing a 72% decrease from the previous 39. The actively exploited (KEV) count remains steady at 10 vulnerabilities, including legacy threats like CVE-2009-0556 affecting Microsoft Office alongside recent entries such as CVE-2026-20805 targeting Microsoft Windows and CVE-2026-20045 impacting Cisco Unified Communications Manager. Notable KEV additions include CVE-2025-37164 in HPE OneView, CVE-2025-68645 in Zimbra Collaboration Suite, and CVE-2024-37079 affecting VMware vCenter Server. Patch availability currently stands at 0%, requiring organizations to prioritize compensating controls and monitoring until vendor remediation becomes available.

  • Zero critical CVEs disclosed, down 100% from prior day's 2 critical vulnerabilities
  • 11 high-priority vulnerabilities, a 72% decrease from the previous 39
  • 10 actively exploited vulnerabilities spanning Microsoft, Cisco, HPE, Zimbra, and VMware products
  • 0% patch availability necessitates compensating controls and enhanced monitoring
  • Enterprise infrastructure heavily represented: vCenter Server, Unified Communications Manager, OneView, and Zimbra

Immediate action: Organizations running Microsoft Windows, Cisco Unified Communications Manager, HPE OneView, Zimbra Collaboration Suite, or VMware vCenter Server should immediately assess exposure to the 10 actively exploited vulnerabilities. With no patches currently available, implement network segmentation, enhanced logging, and access restrictions for affected systems until vendor fixes are released.

How to read this brief

CVSS score (e.g. 9.1) β€” severity from 0–10. Red marks critical (9+), orange high (7–8.9).

Exploitability β€” how hard the flaw is to attack, read from the CVSS vector:

  • Network / Adjacent / Local / Physical β€” how close an attacker must get. Network means reachable over the internet.
  • No / Low / High privileges β€” the access they need first. No privileges means no login required.
  • No interaction / User interaction β€” whether a victim has to do something (open a file, click a link). No interaction means fully automatable.

The lower the bar on all three, the easier to exploit at scale β€” β€œNetwork Β· No privileges Β· No interaction” is the worst case: hit from anywhere, no credentials, no victim action.

Actively exploited β€” confirmed under attack in the wild (CISA’s Known Exploited Vulnerabilities catalog). Prioritize these regardless of score.

EPSS Β· Nth percentile β€” FIRST.org’s estimated chance a flaw is exploited within 30 days. We flag it only in the top 10% β€” a statistical signal it’s unusually likely to be targeted, separate from whether attacks are confirmed.

πŸ’‘ Tip: Swipe CVE cards left to ⭐ star, right to ❌ remove

Section Navigation