Critical vulnerabilities, curated daily for security professionals
π
Archived Security Brief
Yesterday's disclosures contained zero new critical vulnerabilities, a complete decrease from the prior day's 2 critical CVEs. High-priority vulnerabilities dropped substantially to 11, representing a 72% decrease from the previous 39. The actively exploited (KEV) count remains steady at 10 vulnerabilities, including legacy threats like CVE-2009-0556 affecting Microsoft Office alongside recent entries such as CVE-2026-20805 targeting Microsoft Windows and CVE-2026-20045 impacting Cisco Unified Communications Manager. Notable KEV additions include CVE-2025-37164 in HPE OneView, CVE-2025-68645 in Zimbra Collaboration Suite, and CVE-2024-37079 affecting VMware vCenter Server. Patch availability currently stands at 0%, requiring organizations to prioritize compensating controls and monitoring until vendor remediation becomes available.
Zero critical CVEs disclosed, down 100% from prior day's 2 critical vulnerabilities
11 high-priority vulnerabilities, a 72% decrease from the previous 39
Immediate action: Organizations running Microsoft Windows, Cisco Unified Communications Manager, HPE OneView, Zimbra Collaboration Suite, or VMware vCenter Server should immediately assess exposure to the 10 actively exploited vulnerabilities. With no patches currently available, implement network segmentation, enhanced logging, and access restrictions for affected systems until vendor fixes are released.
How to read this brief
CVSS score (e.g. 9.1) β severity from 0β10. Red marks critical (9+), orange high (7β8.9).
Exploitability β how hard the flaw is to attack, read from the CVSS vector:
Network / Adjacent / Local / Physical β how close an attacker must get. Network means reachable over the internet.
No / Low / High privileges β the access they need first. No privileges means no login required.
No interaction / User interaction β whether a victim has to do something (open a file, click a link). No interaction means fully automatable.
The lower the bar on all three, the easier to exploit at scale β βNetwork Β· No privileges Β· No interactionβ is the worst case: hit from anywhere, no credentials, no victim action.
π΄ Actively exploited β confirmed under attack in the wild (CISAβs Known Exploited Vulnerabilities catalog). Prioritize these regardless of score.
EPSS Β· Nth percentile β FIRST.orgβs estimated chance a flaw is exploited within 30 days. We flag it only in the top 10% β a statistical signal itβs unusually likely to be targeted, separate from whether attacks are confirmed.
π‘ Tip: Swipe CVE cards left to β star, right to β remove
Section Navigation
β οΈ
CISA Known Exploited Vulnerabilities
β οΈ CISA KEVURGENT
CVE-2009-0556
9.5
MicrosoftOffice
π΄ Actively exploited in the wild
Microsoft Office PowerPoint Code Injection Vulnerability - Active in CISA KEV catalog.
The Hustle β Email Marketing, Lead Generation, Optins, Popups plugin for WordPress is vulnerable to arbitrary file uploads due to incorrect file type validation in the action_import_module() function in all versions up to, and including, 7
Single Sign-On Portal System developed by WellChoose has a OS Command Injection vulnerability, allowing authenticated remote attackers to inject arbitrary OS commands and execute them on the server
Single Sign-On Portal System developed by WellChoose has a OS Command Injection vulnerability, allowing authenticated remote attackers to inject arbitrary OS commands and execute them on the server