Friday, February 27, 2026 Archive

Archived Security Snapshot

Critical vulnerabilities, curated daily for security professionals

Archived Security Brief

Friday's vulnerability disclosures include a CVSS 10.0 flaw in Copeland XWEB Pro (CVE-2026-21718) and a CVSS 9.9 Google Cloud service vulnerability (CVE-2026-27941), alongside critical issues in Xerox FreeFlow Core, Langflow, and EverShop. Critical CVEs jumped to 18, a 125% increase from the prior day's 8, while 100 high-priority vulnerabilities held steady. Remote code execution and authentication bypass patterns dominate the critical findings, affecting enterprise infrastructure from Totolink routers to OpenStack Vitrage deployments. Cisco Catalyst SD-WAN and multiple Microsoft Windows components are confirmed under active exploitation across 18 KEV entries. Patch availability remains at 0%, requiring organizations to prioritize compensating controls and network segmentation for affected systems.

  • CVSS 10.0 vulnerability in Copeland XWEB Pro (CVE-2026-21718) and CVSS 9.9 Google Cloud service flaw (CVE-2026-27941) require immediate risk assessment
  • 18 critical CVEs disclosed, up 125% from 8 the prior day, spanning Microsoft, Xerox, HP, and Langflow products
  • 100 high-priority CVEs remained consistent with the prior day's volume across the disclosure pipeline
  • Remote code execution and authentication bypass flaws affect Totolink N300RH routers, EverShop e-commerce, and OpenStack Vitrage
  • 0% patch availability across all disclosed vulnerabilities — compensating controls and network isolation are essential
  • 18 actively exploited vulnerabilities include Cisco Catalyst SD-WAN (CVSS 10.0), multiple Microsoft Windows components, and Roundcube Webmail

Immediate action: Prioritize network segmentation and access restrictions for Copeland XWEB Pro, Google Cloud services, Cisco Catalyst SD-WAN, and Microsoft Windows systems confirmed under active exploitation. With 0% patch availability, implement compensating controls including WAF rules, privilege reduction, and enhanced monitoring for all affected products until vendor patches are released.

How to read this brief

CVSS score (e.g. 9.1) — severity from 0–10. Red marks critical (9+), orange high (7–8.9).

Exploitability — how hard the flaw is to attack, read from the CVSS vector:

  • Network / Adjacent / Local / Physical — how close an attacker must get. Network means reachable over the internet.
  • No / Low / High privileges — the access they need first. No privileges means no login required.
  • No interaction / User interaction — whether a victim has to do something (open a file, click a link). No interaction means fully automatable.

The lower the bar on all three, the easier to exploit at scale — “Network · No privileges · No interaction” is the worst case: hit from anywhere, no credentials, no victim action.

Actively exploited — confirmed under attack in the wild (CISA’s Known Exploited Vulnerabilities catalog). Prioritize these regardless of score.

EPSS · Nth percentile — FIRST.org’s estimated chance a flaw is exploited within 30 days. We flag it only in the top 10% — a statistical signal it’s unusually likely to be targeted, separate from whether attacks are confirmed.

💡 Tip: Swipe CVE cards left to ⭐ star, right to ❌ remove

Section Navigation