Tuesday, March 24, 2026 Archive

Archived Security Snapshot

Critical vulnerabilities, curated daily for security professionals

Archived Security Brief

Tuesday's disclosures reveal 21 critical vulnerabilities, a 425% increase from Monday's 4, with HP AVideo accounting for six of the top critical entries including a CVSS 10.0 flaw (CVE-2026-33478). High-priority disclosures also climbed significantly to 100, up 113% from 47 the prior day, bringing the total to 121 CVEs requiring triage. WordPress plugin vulnerabilities (CVE-2026-4001, CVE-2026-4283) and a Tenda A15 router flaw (CVE-2026-4567) round out the critical tier, while 15 actively exploited vulnerabilities target Apple, Google Chrome, n8n, and Zimbra. No patches are currently available for the newly disclosed critical issues, requiring defenders to prioritize compensating controls and network-level mitigations.

  • HP AVideo platform has six critical vulnerabilities including a CVSS 10.0 (CVE-2026-33478) enabling full system compromise
  • Critical CVE count jumped to 21, up 425% from Monday's 4 disclosures
  • High-priority CVEs rose to 100, a 113% increase over the prior day's 47
  • Remote code execution and authentication bypass flaws affect WordPress plugins, Tenda routers, and Android ImageMagick libraries
  • Patch availability stands at 0% for newly disclosed critical vulnerabilities β€” compensating controls are essential
  • 15 actively exploited vulnerabilities target Apple, Google Chrome V8/Skia, n8n, Zimbra, and Wing FTP Server

Immediate action: Organizations running HP AVideo, WordPress with affected plugins, or Tenda A15 routers should apply network segmentation and restrict access immediately given the absence of patches. Review exposure to the 15 actively exploited vulnerabilities targeting Apple products, Google Chrome, n8n, Zimbra, and Wing FTP Server, and apply any available vendor updates for those KEV entries as a priority.

How to read this brief

CVSS score (e.g. 9.1) β€” severity from 0–10. Red marks critical (9+), orange high (7–8.9).

Exploitability β€” how hard the flaw is to attack, read from the CVSS vector:

  • Network / Adjacent / Local / Physical β€” how close an attacker must get. Network means reachable over the internet.
  • No / Low / High privileges β€” the access they need first. No privileges means no login required.
  • No interaction / User interaction β€” whether a victim has to do something (open a file, click a link). No interaction means fully automatable.

The lower the bar on all three, the easier to exploit at scale β€” β€œNetwork Β· No privileges Β· No interaction” is the worst case: hit from anywhere, no credentials, no victim action.

Actively exploited β€” confirmed under attack in the wild (CISA’s Known Exploited Vulnerabilities catalog). Prioritize these regardless of score.

EPSS Β· Nth percentile β€” FIRST.org’s estimated chance a flaw is exploited within 30 days. We flag it only in the top 10% β€” a statistical signal it’s unusually likely to be targeted, separate from whether attacks are confirmed.

πŸ’‘ Tip: Swipe CVE cards left to ⭐ star, right to ❌ remove

Section Navigation