Thursday, March 19, 2026 Archive

Archived Security Snapshot

Critical vulnerabilities, curated daily for security professionals

Archived Security Brief

Thursday's vulnerability disclosures include 12 critical-severity flaws affecting WordPress, Shinetheme Traveler, and Rymera Web WooCommerce plugins, alongside enterprise platforms like OpenProject and Glances. Critical CVEs rose 33% from the prior day while high-priority vulnerabilities decreased 16% to 84. CVE-2026-2991 (CVSS 9.8) targets WordPress core, CVE-2026-25449 (CVSS 9.8) affects Shinetheme Traveler, and CVE-2026-25873 (CVSS 9.8) impacts the Reward Server — all carrying the highest severity scores in this batch. Microsoft SharePoint, Ivanti Endpoint Manager, Broadcom VMware Aria Operations, and Google Chrome components are among 15 actively exploited vulnerabilities, reflecting broad targeting across enterprise infrastructure. No patches are currently available for these disclosures, requiring organizations to prioritize compensating controls and monitoring.

  • WordPress core and multiple WordPress plugins including WooCommerce Wholesale Lead Capture carry CVSS 9.0+ vulnerabilities with remote exploitation potential
  • 12 critical CVEs disclosed, a 33% increase from the prior day's 9 critical vulnerabilities
  • 84 high-priority CVEs tracked, down 16% from the prior day's 100
  • Remote code execution and authentication bypass patterns dominate, affecting jsPDF, OpenProject, Glances, and Profile Builder Pro
  • Patch availability stands at 0% — all 96 disclosed CVEs currently lack vendor-issued fixes
  • 15 actively exploited vulnerabilities span Microsoft SharePoint, Ivanti EPM, VMware Aria Operations, Google Chrome, and legacy Apple and Hikvision products

Immediate action: Prioritize network segmentation and access restrictions for Microsoft SharePoint, Ivanti Endpoint Manager, VMware Aria Operations, and Google Chrome environments where active exploitation is confirmed. With 0% patch availability across all 96 disclosed CVEs, deploy compensating controls including WAF rules, enhanced logging, and temporary access restrictions for affected WordPress installations and enterprise platforms until vendor patches are released.

How to read this brief

CVSS score (e.g. 9.1) — severity from 0–10. Red marks critical (9+), orange high (7–8.9).

Exploitability — how hard the flaw is to attack, read from the CVSS vector:

  • Network / Adjacent / Local / Physical — how close an attacker must get. Network means reachable over the internet.
  • No / Low / High privileges — the access they need first. No privileges means no login required.
  • No interaction / User interaction — whether a victim has to do something (open a file, click a link). No interaction means fully automatable.

The lower the bar on all three, the easier to exploit at scale — “Network · No privileges · No interaction” is the worst case: hit from anywhere, no credentials, no victim action.

Actively exploited — confirmed under attack in the wild (CISA’s Known Exploited Vulnerabilities catalog). Prioritize these regardless of score.

EPSS · Nth percentile — FIRST.org’s estimated chance a flaw is exploited within 30 days. We flag it only in the top 10% — a statistical signal it’s unusually likely to be targeted, separate from whether attacks are confirmed.

💡 Tip: Swipe CVE cards left to ⭐ star, right to ❌ remove

Section Navigation