Friday, March 20, 2026 Archive

Archived Security Snapshot

Critical vulnerabilities, curated daily for security professionals

Archived Security Brief

Friday's vulnerability disclosures reveal 31 critical-severity flaws across Microsoft, HP, Oracle, and Arch products, including a CVSS 10.0 remote code execution in Azure Cloud Shell (CVE-2026-32169) and multiple CVSS 9.8 issues in Microsoft Bing Images and Oracle Identity Manager. Critical CVE volume rose 158% from the prior day's 12 to 31, while high-priority disclosures increased 19% to 100. Notable entries include CVE-2026-32938 (CVSS 9.9) in SiYuan and CVE-2026-32767 (CVSS 9.8) targeting endpoint bypass in Arch products. Among the 16 actively exploited vulnerabilities are flaws in Microsoft SharePoint, Cisco FMC, Ivanti EPM, and Google Chromium V8, alongside several legacy CVEs in Apple, Hikvision, and Rockwell products still under active exploitation. No patches are currently available for the newly disclosed vulnerabilities, requiring defenders to prioritize compensating controls and monitoring.

  • Azure Cloud Shell CVE-2026-32169 rated CVSS 10.0 — highest severity disclosed this cycle, enabling remote code execution
  • 31 critical CVEs disclosed, a 158% increase from the prior day's 12, spanning Microsoft, HP, Oracle, and Arch products
  • 100 high-priority CVEs represent a 19% increase, bringing the total disclosure count to 131
  • Authentication bypass and remote code execution dominate attack patterns, affecting Microsoft Bing Images, Oracle Identity Manager, and SiYuan
  • 0% patch availability across newly disclosed vulnerabilities — no vendor fixes released at time of publication
  • 16 actively exploited vulnerabilities include flaws in SharePoint, Cisco FMC, Ivanti EPM, Chromium V8, and Zimbra

Immediate action: Prioritize reviewing exposure to Azure Cloud Shell, Microsoft Bing Images, Oracle Identity Manager, and HP products given the concentration of CVSS 9.0+ vulnerabilities. With zero patches currently available, implement network segmentation, restrict access to affected services, and increase monitoring for exploitation indicators across SharePoint, Cisco FMC, Ivanti EPM, and Chromium environments.

How to read this brief

CVSS score (e.g. 9.1) — severity from 0–10. Red marks critical (9+), orange high (7–8.9).

Exploitability — how hard the flaw is to attack, read from the CVSS vector:

  • Network / Adjacent / Local / Physical — how close an attacker must get. Network means reachable over the internet.
  • No / Low / High privileges — the access they need first. No privileges means no login required.
  • No interaction / User interaction — whether a victim has to do something (open a file, click a link). No interaction means fully automatable.

The lower the bar on all three, the easier to exploit at scale — “Network · No privileges · No interaction” is the worst case: hit from anywhere, no credentials, no victim action.

Actively exploited — confirmed under attack in the wild (CISA’s Known Exploited Vulnerabilities catalog). Prioritize these regardless of score.

EPSS · Nth percentile — FIRST.org’s estimated chance a flaw is exploited within 30 days. We flag it only in the top 10% — a statistical signal it’s unusually likely to be targeted, separate from whether attacks are confirmed.

💡 Tip: Swipe CVE cards left to ⭐ star, right to ❌ remove

Section Navigation