Thursday, February 5, 2026 Archive

Archived Security Snapshot

Critical vulnerabilities, curated daily for security professionals

Archived Security Brief

Thursday's disclosures include 9 critical vulnerabilities (CVSS 9.0+), down from 22 the prior day. High-priority CVE volume increased to 100 entries. Notably, 15 vulnerabilities are actively exploited in the wild, affecting SolarWinds Web Help Desk, Cisco Unified Communications Manager, Zimbra Collaboration Suite, and Linux kernel. Two maximum-severity flaws (CVSS 10.0) were disclosed: CVE-2026-1633 in Synectix LAN 232 TRIO serial adapters and CVE-2025-59818 involving authenticated RCE via file uploads. Additional critical entries include CVE-2025-13375 (CVSS 9.8) in IBM Common Cryptographic Architecture and CVE-2026-25526 (CVSS 9.8) in HubSpot JinJava template engine. Patch availability stands at 24%, requiring organizations to prioritize compensating controls for unpatched systems.

  • 15 actively exploited CVEs including SolarWinds, Cisco, Zimbra, and Linux kernel vulnerabilities
  • 2 maximum-severity (CVSS 10.0) vulnerabilities: Synectix serial adapters and authenticated file upload RCE
  • 9 critical CVEs disclosed, down from 22 the prior day
  • 100 high-priority vulnerabilities requiring assessment
  • 24% patch availability necessitates compensating controls for affected systems

Immediate action: Organizations using SolarWinds Web Help Desk, Cisco Unified Communications Manager, Zimbra, or Linux systems should implement network segmentation and enhanced monitoring immediately. Prioritize patching IBM CCA, HubSpot JinJava, and SiYuan installations. For Synectix serial adapters, isolate devices on management VLANs until firmware updates are applied.

How to read this brief

CVSS score (e.g. 9.1) β€” severity from 0–10. Red marks critical (9+), orange high (7–8.9).

Exploitability β€” how hard the flaw is to attack, read from the CVSS vector:

  • Network / Adjacent / Local / Physical β€” how close an attacker must get. Network means reachable over the internet.
  • No / Low / High privileges β€” the access they need first. No privileges means no login required.
  • No interaction / User interaction β€” whether a victim has to do something (open a file, click a link). No interaction means fully automatable.

The lower the bar on all three, the easier to exploit at scale β€” β€œNetwork Β· No privileges Β· No interaction” is the worst case: hit from anywhere, no credentials, no victim action.

Actively exploited β€” confirmed under attack in the wild (CISA’s Known Exploited Vulnerabilities catalog). Prioritize these regardless of score.

EPSS Β· Nth percentile β€” FIRST.org’s estimated chance a flaw is exploited within 30 days. We flag it only in the top 10% β€” a statistical signal it’s unusually likely to be targeted, separate from whether attacks are confirmed.

πŸ’‘ Tip: Swipe CVE cards left to ⭐ star, right to ❌ remove

Section Navigation