Saturday, February 14, 2026 Archive

Archived Security Snapshot

Critical vulnerabilities, curated daily for security professionals

Archived Security Brief

Saturday's vulnerability disclosures center on Microsoft products, with multiple Windows and Office CVEs carrying active exploitation status alongside critical flaws in WordPress plugins, Milvus vector database, and MojoPortal CMS. The day's 5 critical CVEs represent a 72% decrease from the prior day's 18, while 72 high-priority vulnerabilities reflect a 28% drop from 100. CVE-2025-69770 in MojoPortal CMS received the maximum CVSS 10.0 score, and CVE-2026-26190 targeting Milvus vector database and CVE-2026-1306 affecting WordPress both scored 9.8. SmarterTools SmarterMail appears three times among actively exploited vulnerabilities, and Microsoft Windows and Office account for seven KEV entries, indicating sustained attacker focus on enterprise infrastructure. Patch availability stands at 0%, requiring organizations to prioritize compensating controls and monitoring until vendor fixes are released.

  • MojoPortal CMS CVE-2025-69770 scores maximum CVSS 10.0; Milvus vector database and two WordPress vulnerabilities also rated 9.8
  • 5 critical CVEs disclosed, down 72% from prior day's 18 critical vulnerabilities
  • 72 high-priority CVEs reported, a 28% decrease from the previous day's 100
  • Microsoft Windows and Office account for 7 actively exploited CVEs, with SmarterTools SmarterMail contributing 3 additional KEV entries
  • 0% patch availability across all disclosed CVEs — no vendor-supplied fixes currently available
  • 21 CVEs flagged as actively exploited, including legacy issues in Linux kernel (2018) and FreePBX (2019)

Immediate action: Prioritize compensating controls for Microsoft Windows, Office, and SmarterTools SmarterMail environments, as these products represent the largest concentration of actively exploited vulnerabilities. With 0% patch availability, deploy network segmentation, enhanced monitoring, and access restrictions for affected systems — particularly MojoPortal CMS, Milvus, and WordPress instances — until vendor patches are released.

How to read this brief

CVSS score (e.g. 9.1) — severity from 0–10. Red marks critical (9+), orange high (7–8.9).

Exploitability — how hard the flaw is to attack, read from the CVSS vector:

  • Network / Adjacent / Local / Physical — how close an attacker must get. Network means reachable over the internet.
  • No / Low / High privileges — the access they need first. No privileges means no login required.
  • No interaction / User interaction — whether a victim has to do something (open a file, click a link). No interaction means fully automatable.

The lower the bar on all three, the easier to exploit at scale — “Network · No privileges · No interaction” is the worst case: hit from anywhere, no credentials, no victim action.

Actively exploited — confirmed under attack in the wild (CISA’s Known Exploited Vulnerabilities catalog). Prioritize these regardless of score.

EPSS · Nth percentile — FIRST.org’s estimated chance a flaw is exploited within 30 days. We flag it only in the top 10% — a statistical signal it’s unusually likely to be targeted, separate from whether attacks are confirmed.

💡 Tip: Swipe CVE cards left to ⭐ star, right to ❌ remove

Section Navigation