Wednesday, March 4, 2026 Archive

Archived Security Snapshot

Critical vulnerabilities, curated daily for security professionals

Archived Security Brief

Wednesday's vulnerability disclosures include two CVSS 10.0 flaws affecting HP FreeScout (CVE-2026-28289) and the MedEx module for OpenEMR (CVE-2026-24898), both enabling full system compromise. The day's 13 critical CVEs represent a 24% decrease from the prior day, while 100 high-priority vulnerabilities mark a 45% increase over Tuesday's count. Additional critical issues target Apache Ranger (CVE-2025-59059), D-Link DIR routers (CVE-2026-3485), and a Microsoft 365 WordPress SSO plugin (CVE-2026-2628), all carrying CVSS 9.8 scores. Attack patterns center on remote code execution and authentication bypass across healthcare, networking, and enterprise collaboration platforms, with 13 CVEs confirmed under active exploitation including flaws in Apple OS, Google Chromium, Roundcube Webmail, and VMware Aria Operations. No patches are currently available for today's disclosed vulnerabilities, requiring organizations to implement compensating controls and monitor vendor advisories.

  • Two CVSS 10.0 vulnerabilities in HP FreeScout and OpenEMR MedEx module allow full system compromise
  • 13 critical CVEs disclosed, down 24% from Tuesday's 17, spanning healthcare, networking, and enterprise software
  • 100 high-priority CVEs represent a 45% increase over the prior day's 69
  • RCE and authentication bypass dominate attack patterns across D-Link routers, Apache Ranger, Froxlor, and AliasVault
  • 0% patch availability across all 113 disclosed CVEs β€” compensating controls and network segmentation recommended
  • 13 actively exploited vulnerabilities include Apple OS, Google Chromium, Roundcube Webmail, and VMware Aria Operations

Immediate action: Prioritize network segmentation and access restrictions for HP FreeScout, OpenEMR MedEx, D-Link DIR routers, and Apache Ranger deployments given maximum-severity scores and no available patches. Monitor vendor security advisories for patch releases on all 13 actively exploited vulnerabilities, particularly Apple OS, Google Chromium, and VMware Aria Operations, and apply updates immediately upon availability.

How to read this brief

CVSS score (e.g. 9.1) β€” severity from 0–10. Red marks critical (9+), orange high (7–8.9).

Exploitability β€” how hard the flaw is to attack, read from the CVSS vector:

  • Network / Adjacent / Local / Physical β€” how close an attacker must get. Network means reachable over the internet.
  • No / Low / High privileges β€” the access they need first. No privileges means no login required.
  • No interaction / User interaction β€” whether a victim has to do something (open a file, click a link). No interaction means fully automatable.

The lower the bar on all three, the easier to exploit at scale β€” β€œNetwork Β· No privileges Β· No interaction” is the worst case: hit from anywhere, no credentials, no victim action.

Actively exploited β€” confirmed under attack in the wild (CISA’s Known Exploited Vulnerabilities catalog). Prioritize these regardless of score.

EPSS Β· Nth percentile β€” FIRST.org’s estimated chance a flaw is exploited within 30 days. We flag it only in the top 10% β€” a statistical signal it’s unusually likely to be targeted, separate from whether attacks are confirmed.

πŸ’‘ Tip: Swipe CVE cards left to ⭐ star, right to ❌ remove

Section Navigation