Saturday, February 28, 2026 Archive

Archived Security Snapshot

Critical vulnerabilities, curated daily for security professionals

Archived Security Brief

Yesterday's disclosures reveal 24 critical vulnerabilities affecting a broad range of products including HP FreeFlow and scripting components, WeGIA Web Manager, Xerox FreeFlow Core, and Copeland XWEB Pro β€” both scoring a perfect CVSS 10. Critical CVEs rose 33% from the prior day while high-priority vulnerabilities held steady at 97 (down 3%). Notable entries include CVE-2026-28409 in WeGIA Web Manager and CVE-2026-21718 in Copeland XWEB Pro, both with maximum severity scores, alongside multiple CVSS 9.8 flaws in SODOLA firmware, Totolink routers, and Vikunja project management software. Microsoft Windows and Office account for the majority of the 17 actively exploited vulnerabilities, with legacy flaws in Zimbra, GitLab, and Roundcube Webmail also under active exploitation. Patch availability currently sits at 0%, making compensating controls and network segmentation essential while vendors release fixes.

  • Two maximum-severity CVSS 10 vulnerabilities disclosed in WeGIA Web Manager (CVE-2026-28409) and Copeland XWEB Pro (CVE-2026-21718)
  • 24 critical CVEs disclosed, a 33% increase from the prior day's 18
  • 97 high-priority CVEs, a slight 3% decrease from the prior day's 100
  • Remote code execution and authentication bypass patterns dominate, affecting HP, Xerox FreeFlow Core, Totolink routers, SODOLA firmware, and OpenStack Vitrage
  • 0% patch availability across all 121 disclosed CVEs β€” no vendor fixes currently released
  • 17 actively exploited vulnerabilities spanning Microsoft Windows, Office, Apple OS, Google Chromium, and Roundcube Webmail

Immediate action: Prioritize mitigation for Microsoft Windows and Office systems, which represent the largest cluster of actively exploited vulnerabilities, and isolate any internet-facing Copeland XWEB Pro, WeGIA, and Roundcube Webmail instances. With 0% patch availability, apply network segmentation, restrict access to affected services, and monitor vendor advisories closely for upcoming fixes.

How to read this brief

CVSS score (e.g. 9.1) β€” severity from 0–10. Red marks critical (9+), orange high (7–8.9).

Exploitability β€” how hard the flaw is to attack, read from the CVSS vector:

  • Network / Adjacent / Local / Physical β€” how close an attacker must get. Network means reachable over the internet.
  • No / Low / High privileges β€” the access they need first. No privileges means no login required.
  • No interaction / User interaction β€” whether a victim has to do something (open a file, click a link). No interaction means fully automatable.

The lower the bar on all three, the easier to exploit at scale β€” β€œNetwork Β· No privileges Β· No interaction” is the worst case: hit from anywhere, no credentials, no victim action.

Actively exploited β€” confirmed under attack in the wild (CISA’s Known Exploited Vulnerabilities catalog). Prioritize these regardless of score.

EPSS Β· Nth percentile β€” FIRST.org’s estimated chance a flaw is exploited within 30 days. We flag it only in the top 10% β€” a statistical signal it’s unusually likely to be targeted, separate from whether attacks are confirmed.

πŸ’‘ Tip: Swipe CVE cards left to ⭐ star, right to ❌ remove

Section Navigation