Friday, February 20, 2026 Archive

Archived Security Snapshot

Critical vulnerabilities, curated daily for security professionals

Archived Security Brief

Friday's vulnerability disclosures include two maximum-severity CVSS 10.0 flaws in Linux Cyber Protect (CVE-2025-30411, CVE-2025-30412) alongside a critical Microsoft Semantic Kernel Python SDK vulnerability (CVE-2026-26030, CVSS 9.9). The day's 24 critical CVEs represent a 20% increase over Thursday, with 100 high-priority issues marking a 22% rise across both categories. WordPress plugins account for the largest share of critical disclosures, with at least six distinct plugin vulnerabilities scoring CVSS 9.8, while authorization bypass flaws affect Databank Accreditation Software. Among 20 actively exploited vulnerabilities, multiple Microsoft Windows and Office flaws are under active attack alongside legacy issues in GitLab, Zimbra, and Sangoma FreePBX dating back several years. No patches are currently available for the disclosed vulnerabilities, requiring organizations to prioritize compensating controls and monitoring.

  • Two CVSS 10.0 vulnerabilities in Linux Cyber Protect (CVE-2025-30411, CVE-2025-30412) represent the highest-severity disclosures of the day
  • 24 critical CVEs disclosed, up 20% from Thursday's 20, with WordPress plugin flaws comprising the largest category
  • 100 high-priority CVEs (CVSS 7.0-8.9), a 22% increase over the prior day's 82
  • Microsoft Windows and Office account for six actively exploited vulnerabilities, with additional active exploitation targeting Dell RP4VMs, Apple OS, and Google Chromium
  • Patch availability stands at 0% across all 124 disclosed CVEs, necessitating compensating controls
  • 20 vulnerabilities confirmed under active exploitation, including legacy flaws in GitLab, Zimbra, and FreePBX spanning 2008-2025

Immediate action: Prioritize compensating controls for Linux Cyber Protect, Microsoft Windows and Office, and WordPress plugin deployments, as no patches are currently available for any of the 124 disclosed vulnerabilities. Monitor vendor advisories closely for patch releases on the two CVSS 10.0 Cyber Protect flaws and the six actively exploited Microsoft vulnerabilities, and consider temporarily restricting exposure of affected services where feasible.

How to read this brief

CVSS score (e.g. 9.1) — severity from 0–10. Red marks critical (9+), orange high (7–8.9).

Exploitability — how hard the flaw is to attack, read from the CVSS vector:

  • Network / Adjacent / Local / Physical — how close an attacker must get. Network means reachable over the internet.
  • No / Low / High privileges — the access they need first. No privileges means no login required.
  • No interaction / User interaction — whether a victim has to do something (open a file, click a link). No interaction means fully automatable.

The lower the bar on all three, the easier to exploit at scale — “Network · No privileges · No interaction” is the worst case: hit from anywhere, no credentials, no victim action.

Actively exploited — confirmed under attack in the wild (CISA’s Known Exploited Vulnerabilities catalog). Prioritize these regardless of score.

EPSS · Nth percentile — FIRST.org’s estimated chance a flaw is exploited within 30 days. We flag it only in the top 10% — a statistical signal it’s unusually likely to be targeted, separate from whether attacks are confirmed.

💡 Tip: Swipe CVE cards left to ⭐ star, right to ❌ remove

Section Navigation