Monday, March 23, 2026 Archive

Archived Security Snapshot

Critical vulnerabilities, curated daily for security professionals

Archived Security Brief

Monday's vulnerability disclosures highlight widespread risk across Apple, Google, Broadcom, and Qualcomm products, with 17 CVEs under active exploitation. The day saw 4 critical-severity vulnerabilities (up 100% from Sunday's 2) and 47 high-priority CVEs (down 49% from 93). Critical flaws include CVE-2026-3587 (CVSS 10.0) affecting Linux-based operating systems, CVE-2026-4567 (CVSS 9.8) in Tenda A15 routers, and CVE-2019-25614 (CVSS 9.8) targeting STOR FTP Server. Actively exploited vulnerabilities span Broadcom VMware Aria Operations, Qualcomm chipsets, Google Chrome V8, and multiple Apple products including iOS and iPadOS. No patches are currently available for the disclosed CVEs, requiring organizations to prioritize compensating controls and monitoring.

  • CVE-2026-3587 (CVSS 10.0) affects Linux-based operating systems β€” the highest severity rating possible, requiring immediate risk assessment
  • 4 critical-severity CVEs disclosed, a 100% increase from Sunday's 2 critical vulnerabilities
  • 47 high-priority CVEs (CVSS 7.0-8.9), down 49% from Sunday's 93, narrowing the scope of urgent triage
  • Active exploitation confirmed across Broadcom VMware Aria Operations, Qualcomm chipsets, Google Chrome V8/Skia, and Apple iOS/iPadOS
  • 0% patch availability across all 51 disclosed CVEs β€” compensating controls and network segmentation are essential
  • 17 CVEs flagged as actively exploited, including legacy vulnerabilities such as CVE-2017-7921 in Hikvision products

Immediate action: Prioritize risk assessment for Linux-based systems (CVE-2026-3587), Broadcom VMware Aria Operations, Qualcomm-powered devices, and Apple products including iOS and iPadOS, as these face active exploitation with no patches currently available. Implement compensating controls such as network segmentation, access restrictions, and enhanced monitoring for affected systems until vendor patches are released.

How to read this brief

CVSS score (e.g. 9.1) β€” severity from 0–10. Red marks critical (9+), orange high (7–8.9).

Exploitability β€” how hard the flaw is to attack, read from the CVSS vector:

  • Network / Adjacent / Local / Physical β€” how close an attacker must get. Network means reachable over the internet.
  • No / Low / High privileges β€” the access they need first. No privileges means no login required.
  • No interaction / User interaction β€” whether a victim has to do something (open a file, click a link). No interaction means fully automatable.

The lower the bar on all three, the easier to exploit at scale β€” β€œNetwork Β· No privileges Β· No interaction” is the worst case: hit from anywhere, no credentials, no victim action.

Actively exploited β€” confirmed under attack in the wild (CISA’s Known Exploited Vulnerabilities catalog). Prioritize these regardless of score.

EPSS Β· Nth percentile β€” FIRST.org’s estimated chance a flaw is exploited within 30 days. We flag it only in the top 10% β€” a statistical signal it’s unusually likely to be targeted, separate from whether attacks are confirmed.

πŸ’‘ Tip: Swipe CVE cards left to ⭐ star, right to ❌ remove

Section Navigation