Wednesday, March 11, 2026 Archive

Archived Security Snapshot

Critical vulnerabilities, curated daily for security professionals

Archived Security Brief

Wednesday's vulnerability disclosures include 25 critical-severity CVEs, a fivefold increase from the prior day's 5, alongside 100 high-priority issues across enterprise infrastructure and application platforms. Notable critical flaws include CVE-2025-48611 (CVSS 10.0) in DeviceId.java, two CVSS 9.9 vulnerabilities in OneUptime Synthetic Monitors (CVE-2026-30887, CVE-2026-30957), and CVE-2026-0953 (CVSS 9.8) affecting WordPress. Linux kernel, HP configuration management, Appsmith, and Atlassian products also carry critical-rated vulnerabilities requiring prompt evaluation. Thirteen CVEs have confirmed active exploitation, spanning SolarWinds Web Help Desk, Roundcube Webmail, Ivanti Endpoint Manager, Broadcom VMware Aria Operations, and several Apple products. No patches have been confirmed available at this time, making compensating controls and network-level mitigations essential while vendors release fixes.

  • CVE-2025-48611 rated CVSS 10.0 in DeviceId.java and two CVSS 9.9 flaws in OneUptime Synthetic Monitors represent the highest-severity disclosures
  • Critical CVEs jumped to 25, up 400% from the prior day's 5, spanning Linux, HP, WordPress, Atlassian, and Appsmith
  • High-priority CVEs rose to 100, a 33% increase over the previous day's 75
  • Remote code execution and authentication bypass patterns affect WordPress, Linux kernel, and enterprise monitoring platforms including OneUptime and Appsmith
  • Patch availability stands at 0% across all disclosed CVEs — compensating controls and segmentation are recommended immediately
  • 13 actively exploited vulnerabilities affect SolarWinds, Roundcube, Ivanti, VMware Aria Operations, Qualcomm chipsets, and Apple products

Immediate action: Prioritize review of internet-facing deployments of OneUptime, WordPress, Roundcube Webmail, Ivanti EPM, and SolarWinds Web Help Desk, as these carry critical ratings or confirmed exploitation. With 0% patch availability reported, implement network segmentation, restrict administrative access, and deploy available WAF or IDS signatures as interim mitigations until vendor patches are released.

How to read this brief

CVSS score (e.g. 9.1) — severity from 0–10. Red marks critical (9+), orange high (7–8.9).

Exploitability — how hard the flaw is to attack, read from the CVSS vector:

  • Network / Adjacent / Local / Physical — how close an attacker must get. Network means reachable over the internet.
  • No / Low / High privileges — the access they need first. No privileges means no login required.
  • No interaction / User interaction — whether a victim has to do something (open a file, click a link). No interaction means fully automatable.

The lower the bar on all three, the easier to exploit at scale — “Network · No privileges · No interaction” is the worst case: hit from anywhere, no credentials, no victim action.

Actively exploited — confirmed under attack in the wild (CISA’s Known Exploited Vulnerabilities catalog). Prioritize these regardless of score.

EPSS · Nth percentile — FIRST.org’s estimated chance a flaw is exploited within 30 days. We flag it only in the top 10% — a statistical signal it’s unusually likely to be targeted, separate from whether attacks are confirmed.

💡 Tip: Swipe CVE cards left to ⭐ star, right to ❌ remove

Section Navigation