Sunday, March 1, 2026 Archive

Archived Security Snapshot

Critical vulnerabilities, curated daily for security professionals

Archived Security Brief

Sunday's disclosures are dominated by 17 actively exploited vulnerabilities targeting Microsoft Windows, Office, Apple OS, and Google Chromium, all carrying CVSS 9.5 scores. No new critical CVEs were disclosed, a sharp drop from the prior day's 24, while high-priority vulnerabilities fell 64% to 35. Notable KEV entries include CVE-2026-21513 and CVE-2026-21525 affecting Microsoft Windows, CVE-2026-20700 targeting Apple OS, and CVE-2026-2441 in Google Chromium. Attack patterns center on remote code execution and privilege escalation across enterprise operating systems, productivity suites, and collaboration platforms including Roundcube Webmail and Zimbra. No patches are currently available for the disclosed vulnerabilities, requiring defenders to prioritize compensating controls and monitoring.

  • 17 actively exploited vulnerabilities confirmed across Microsoft Windows, Apple OS, Google Chromium, and Roundcube Webmail — all rated CVSS 9.5
  • Critical CVE count dropped to 0, down 100% from the prior day's 24 disclosures
  • High-priority CVEs fell 64% to 35, reflecting typical weekend disclosure volume reduction
  • Remote code execution and privilege escalation patterns dominate across enterprise OS platforms, email clients (Roundcube, Zimbra), and collaboration tools (GitLab)
  • Patch availability stands at 0% — no vendor fixes currently released for today's disclosed vulnerabilities
  • Legacy CVEs resurfacing in KEV list include CVE-2008-0015 (Microsoft Windows) and CVE-2020-7796 (Zimbra Collaboration Suite)

Immediate action: Prioritize compensating controls for Microsoft Windows, Apple OS, and Google Chromium environments where active exploitation is confirmed but patches are unavailable. Review network segmentation and access restrictions for Roundcube Webmail, Zimbra, and GitLab instances given confirmed exploitation of CVE-2025-49113, CVE-2020-7796, and CVE-2021-22175. Monitor vendor security advisories closely for forthcoming patch releases and apply them immediately upon availability.

How to read this brief

CVSS score (e.g. 9.1) — severity from 0–10. Red marks critical (9+), orange high (7–8.9).

Exploitability — how hard the flaw is to attack, read from the CVSS vector:

  • Network / Adjacent / Local / Physical — how close an attacker must get. Network means reachable over the internet.
  • No / Low / High privileges — the access they need first. No privileges means no login required.
  • No interaction / User interaction — whether a victim has to do something (open a file, click a link). No interaction means fully automatable.

The lower the bar on all three, the easier to exploit at scale — “Network · No privileges · No interaction” is the worst case: hit from anywhere, no credentials, no victim action.

Actively exploited — confirmed under attack in the wild (CISA’s Known Exploited Vulnerabilities catalog). Prioritize these regardless of score.

EPSS · Nth percentile — FIRST.org’s estimated chance a flaw is exploited within 30 days. We flag it only in the top 10% — a statistical signal it’s unusually likely to be targeted, separate from whether attacks are confirmed.

💡 Tip: Swipe CVE cards left to ⭐ star, right to ❌ remove

Section Navigation