Saturday, March 14, 2026 Archive

Archived Security Snapshot

Critical vulnerabilities, curated daily for security professionals

Archived Security Brief

Saturday's vulnerability disclosures include a maximum-severity sandbox escape in SandboxJS (CVE-2026-26954, CVSS 10.0) and critical remote code execution flaws in GNU inetutils telnetd (CVE-2026-32746) and HMS Networks Ewon industrial gateways (CVE-2026-25823, CVE-2026-25818). Nine critical vulnerabilities were disclosed, a 10% decrease from the prior day, alongside 100 high-priority issues holding steady. Actively exploited vulnerabilities rose 18% to 13, with confirmed exploitation targeting Ivanti Endpoint Manager (CVE-2026-1603), Broadcom VMware Aria Operations (CVE-2026-22719), and Qualcomm chipsets (CVE-2026-21385). Attack patterns center on remote code execution, authentication bypass, and privilege escalation across enterprise infrastructure, ICS/SCADA systems, and mobile platforms. No patches are currently available for Saturday's disclosures, requiring organizations to prioritize compensating controls and network segmentation.

  • Maximum-severity sandbox escape in SandboxJS (CVE-2026-26954, CVSS 10.0) enables arbitrary code execution outside sandboxed environments
  • 9 critical CVEs disclosed (down 10% from prior day), including RCE flaws in GNU inetutils telnetd and OneUptime monitoring platform
  • 100 high-priority CVEs maintained the same volume as the prior day, spanning enterprise and consumer products
  • ICS/SCADA exposure from HMS Networks Ewon Flexy and Cosy+ gateway vulnerabilities (CVSS 9.8 and 9.1) affecting industrial control environments
  • 0% patch availability across Saturday's disclosures — compensating controls and network isolation are the primary mitigation path
  • 13 actively exploited vulnerabilities confirmed, including Ivanti EPM, VMware Aria Operations, and multiple Apple products

Immediate action: Prioritize network segmentation for systems running SandboxJS, GNU inetutils telnetd, HMS Networks Ewon gateways, and Ivanti Endpoint Manager, as these represent the highest-risk attack surfaces from this disclosure cycle. With no patches currently available, implement compensating controls including WAF rules, access restrictions, and enhanced monitoring for exploitation indicators on affected platforms.

How to read this brief

CVSS score (e.g. 9.1) — severity from 0–10. Red marks critical (9+), orange high (7–8.9).

Exploitability — how hard the flaw is to attack, read from the CVSS vector:

  • Network / Adjacent / Local / Physical — how close an attacker must get. Network means reachable over the internet.
  • No / Low / High privileges — the access they need first. No privileges means no login required.
  • No interaction / User interaction — whether a victim has to do something (open a file, click a link). No interaction means fully automatable.

The lower the bar on all three, the easier to exploit at scale — “Network · No privileges · No interaction” is the worst case: hit from anywhere, no credentials, no victim action.

Actively exploited — confirmed under attack in the wild (CISA’s Known Exploited Vulnerabilities catalog). Prioritize these regardless of score.

EPSS · Nth percentile — FIRST.org’s estimated chance a flaw is exploited within 30 days. We flag it only in the top 10% — a statistical signal it’s unusually likely to be targeted, separate from whether attacks are confirmed.

💡 Tip: Swipe CVE cards left to ⭐ star, right to ❌ remove

Section Navigation