Tuesday, March 10, 2026 Archive

Archived Security Snapshot

Critical vulnerabilities, curated daily for security professionals

Archived Security Brief

Tuesday's vulnerability disclosures reveal critical flaws in Delta Electronics COMMGR2 (CVE-2026-3630, CVSS 9.8) and Progress Budibase (CVE-2026-30240, CVSS 9.6), alongside web-enabled controller vulnerabilities affecting building automation systems. The day's 80 CVEs include 5 critical-severity issues, up 150% from Monday's 2, and 75 high-priority vulnerabilities, a 23% increase. Industrial control systems and low-code development platforms are the primary attack surfaces, with remote code execution and authentication bypass patterns dominating the critical findings. Fourteen vulnerabilities have confirmed active exploitation, including long-standing flaws in GitLab, Ivanti Endpoint Manager, Broadcom VMware Aria Operations, and multiple Apple products. No patches are currently available for Tuesday's newly disclosed CVEs, making network segmentation and compensating controls essential for affected systems.

  • Delta Electronics COMMGR2 carries the highest severity (CVSS 9.8) among newly disclosed CVEs, affecting industrial communications infrastructure
  • Critical CVE count jumped to 5, a 150% increase from Monday's 2 critical disclosures
  • 75 high-priority vulnerabilities disclosed, up 23% from the prior day's 61
  • Remote code execution and authentication bypass flaws affect building automation controllers (wwwupdate.cgi, wwwupload.cgi) and Budibase server components
  • Patch availability stands at 0% for newly disclosed CVEs — compensating controls and network segmentation are immediately necessary
  • 14 actively exploited vulnerabilities span Ivanti EPM, VMware Aria Operations, SolarWinds Web Help Desk, Roundcube Webmail, and Qualcomm chipsets

Immediate action: Prioritize network isolation for Delta Electronics COMMGR2 systems and building automation controllers running vulnerable wwwupdate.cgi and wwwupload.cgi services, as no patches are currently available. Review exposure to actively exploited flaws in Ivanti Endpoint Manager, Broadcom VMware Aria Operations, SolarWinds Web Help Desk, and Roundcube Webmail, and apply any existing vendor mitigations or access restrictions immediately.

How to read this brief

CVSS score (e.g. 9.1) — severity from 0–10. Red marks critical (9+), orange high (7–8.9).

Exploitability — how hard the flaw is to attack, read from the CVSS vector:

  • Network / Adjacent / Local / Physical — how close an attacker must get. Network means reachable over the internet.
  • No / Low / High privileges — the access they need first. No privileges means no login required.
  • No interaction / User interaction — whether a victim has to do something (open a file, click a link). No interaction means fully automatable.

The lower the bar on all three, the easier to exploit at scale — “Network · No privileges · No interaction” is the worst case: hit from anywhere, no credentials, no victim action.

Actively exploited — confirmed under attack in the wild (CISA’s Known Exploited Vulnerabilities catalog). Prioritize these regardless of score.

EPSS · Nth percentile — FIRST.org’s estimated chance a flaw is exploited within 30 days. We flag it only in the top 10% — a statistical signal it’s unusually likely to be targeted, separate from whether attacks are confirmed.

💡 Tip: Swipe CVE cards left to ⭐ star, right to ❌ remove

Section Navigation