Wednesday, February 25, 2026 Archive

Archived Security Snapshot

Critical vulnerabilities, curated daily for security professionals

Archived Security Brief

Wednesday's vulnerability disclosures include 21 critical and 79 high-priority CVEs across enterprise infrastructure, cloud platforms, and endpoint software. Critical CVEs nearly doubled from the prior day (up 91%), while high-priority disclosures rose 16%. A perfect CVSS 10.0 vulnerability in Enclave enclave-vm leads the critical findings, joined by CVE-2026-24849 (CVSS 9.9) in HP OpenEMR and four SolarWinds Serv-U flaws rated CVSS 9.1. Multiple Microsoft Windows and Office vulnerabilities are confirmed under active exploitation, along with targeted campaigns against Apple OS, Google Chromium, Roundcube Webmail, and Zimbra Collaboration Suite. No patches are currently available for the disclosed vulnerabilities, requiring defenders to prioritize compensating controls and network segmentation for affected systems.

  • CVE-2026-27597 receives a perfect CVSS 10.0 score affecting Enclave enclave-vm, requiring immediate risk assessment
  • Critical CVEs surged to 21, a 91% increase over the prior day's 11 critical disclosures
  • High-priority CVEs rose to 79, up 16% from 68 the previous day
  • Multiple remote code execution and privilege escalation flaws affect SolarWinds Serv-U (4 CVEs at CVSS 9.1), HP OpenEMR, and HP FreeScout
  • Patch availability stands at 0% across all 100 disclosed CVEs, leaving defenders reliant on mitigations
  • 19 CVEs have confirmed active exploitation, including 5 Microsoft Windows flaws, Roundcube Webmail, and Google Chromium

Immediate action: Prioritize compensating controls for Microsoft Windows and Office systems, SolarWinds Serv-U, Roundcube Webmail, and Google Chromium, all of which have confirmed active exploitation with no patches currently available. Monitor vendor advisories closely for patch releases on the CVSS 10.0 Enclave VM flaw and the four SolarWinds Serv-U vulnerabilities, and restrict network exposure to affected services until fixes are issued.

How to read this brief

CVSS score (e.g. 9.1) — severity from 0–10. Red marks critical (9+), orange high (7–8.9).

Exploitability — how hard the flaw is to attack, read from the CVSS vector:

  • Network / Adjacent / Local / Physical — how close an attacker must get. Network means reachable over the internet.
  • No / Low / High privileges — the access they need first. No privileges means no login required.
  • No interaction / User interaction — whether a victim has to do something (open a file, click a link). No interaction means fully automatable.

The lower the bar on all three, the easier to exploit at scale — “Network · No privileges · No interaction” is the worst case: hit from anywhere, no credentials, no victim action.

Actively exploited — confirmed under attack in the wild (CISA’s Known Exploited Vulnerabilities catalog). Prioritize these regardless of score.

EPSS · Nth percentile — FIRST.org’s estimated chance a flaw is exploited within 30 days. We flag it only in the top 10% — a statistical signal it’s unusually likely to be targeted, separate from whether attacks are confirmed.

💡 Tip: Swipe CVE cards left to ⭐ star, right to ❌ remove

Section Navigation