Sunday, March 15, 2026 Archive

Archived Security Snapshot

Critical vulnerabilities, curated daily for security professionals

Archived Security Brief

Sunday's disclosures highlight 13 actively exploited vulnerabilities affecting enterprise infrastructure from Ivanti, Broadcom VMware, Qualcomm, and Apple. No new critical-severity CVEs were published, a sharp drop from Saturday's 9, while 40 high-priority vulnerabilities were disclosed, down 60% from the prior day's 100. Notably, CVE-2026-1603 targets Ivanti Endpoint Manager, CVE-2026-22719 affects VMware Aria Operations, and CVE-2026-25108 impacts Soliton FileZen, all carrying CVSS 9.5 scores under active exploitation. Attack patterns include remote code execution and authentication bypass across endpoint management platforms, network appliances, and mobile chipsets. No patches are currently available for Sunday's disclosures, requiring defenders to apply compensating controls and monitor vendor advisories closely.

  • Ivanti Endpoint Manager (CVE-2026-1603) and VMware Aria Operations (CVE-2026-22719) under active exploitation with CVSS 9.5 scores
  • Zero critical CVEs disclosed, down from 9 the prior day (-100%)
  • 40 high-priority vulnerabilities published, a 60% decrease from Saturday's 100
  • RCE and authentication bypass patterns dominate across endpoint management, automation platforms (n8n), and Qualcomm chipsets
  • 0% patch availability across Sunday's disclosures; compensating controls recommended
  • 13 vulnerabilities confirmed actively exploited, including legacy issues in Hikvision and Rockwell products dating to 2017 and 2021

Immediate action: Prioritize reviewing exposure to Ivanti Endpoint Manager, VMware Aria Operations, Soliton FileZen, and Apple products, as all have confirmed active exploitation at CVSS 9.5. With no patches currently available, apply network segmentation, restrict administrative access, and monitor vendor channels for emergency updates.

How to read this brief

CVSS score (e.g. 9.1) — severity from 0–10. Red marks critical (9+), orange high (7–8.9).

Exploitability — how hard the flaw is to attack, read from the CVSS vector:

  • Network / Adjacent / Local / Physical — how close an attacker must get. Network means reachable over the internet.
  • No / Low / High privileges — the access they need first. No privileges means no login required.
  • No interaction / User interaction — whether a victim has to do something (open a file, click a link). No interaction means fully automatable.

The lower the bar on all three, the easier to exploit at scale — “Network · No privileges · No interaction” is the worst case: hit from anywhere, no credentials, no victim action.

Actively exploited — confirmed under attack in the wild (CISA’s Known Exploited Vulnerabilities catalog). Prioritize these regardless of score.

EPSS · Nth percentile — FIRST.org’s estimated chance a flaw is exploited within 30 days. We flag it only in the top 10% — a statistical signal it’s unusually likely to be targeted, separate from whether attacks are confirmed.

💡 Tip: Swipe CVE cards left to ⭐ star, right to ❌ remove

Section Navigation