Wednesday, March 25, 2026 Archive

Archived Security Snapshot

Critical vulnerabilities, curated daily for security professionals

Archived Security Brief

Wednesday's vulnerability disclosures are headlined by multiple critical Mozilla Firefox and Thunderbird flaws, including two perfect CVSS 10.0 sandbox escapes (CVE-2026-4688, CVE-2026-4725) and several additional 9.8-rated issues spanning privilege escalation and code execution. The day's 30 critical CVEs represent a 43% increase over Tuesday, while the 100 high-priority disclosures held steady. A critical WordPress vulnerability (CVE-2026-4001, CVSS 9.8) and a GitHub Actions workflow flaw (CVE-2026-33475, CVSS 9.1) round out the most severe new disclosures. Among the 14 actively exploited vulnerabilities, Apple products account for five entries and Google Chromium and Skia carry two, alongside ongoing exploitation of Craft CMS, Laravel Livewire, Zimbra, and Wing FTP Server. No patches are currently available for today's disclosed CVEs, making network-level mitigations and monitoring essential in the interim.

  • Two Mozilla Firefox/Thunderbird sandbox escape vulnerabilities rated CVSS 10.0, with six additional critical Mozilla flaws scoring 9.8
  • 30 critical CVEs disclosed, up 43% from Tuesday's 21
  • 100 high-priority CVEs, unchanged from the prior day
  • WordPress RCE (CVE-2026-4001) and GitHub Actions workflow compromise (CVE-2026-33475) affect widely deployed platforms
  • 0% patch availability across all disclosed CVEs — no vendor fixes released yet
  • 14 actively exploited vulnerabilities spanning Apple, Google Chromium, Zimbra, Craft CMS, and Laravel Livewire

Immediate action: Prioritize Mozilla Firefox and Thunderbird updates as soon as patches become available, given the two CVSS 10.0 sandbox escapes and multiple 9.8-rated flaws. Review exposure to WordPress, GitHub Actions, and the actively exploited products — Apple, Chromium, Zimbra, Craft CMS, and Wing FTP Server — and apply compensating controls such as WAF rules and network segmentation until vendor patches are released.

How to read this brief

CVSS score (e.g. 9.1) — severity from 0–10. Red marks critical (9+), orange high (7–8.9).

Exploitability — how hard the flaw is to attack, read from the CVSS vector:

  • Network / Adjacent / Local / Physical — how close an attacker must get. Network means reachable over the internet.
  • No / Low / High privileges — the access they need first. No privileges means no login required.
  • No interaction / User interaction — whether a victim has to do something (open a file, click a link). No interaction means fully automatable.

The lower the bar on all three, the easier to exploit at scale — “Network · No privileges · No interaction” is the worst case: hit from anywhere, no credentials, no victim action.

Actively exploited — confirmed under attack in the wild (CISA’s Known Exploited Vulnerabilities catalog). Prioritize these regardless of score.

EPSS · Nth percentile — FIRST.org’s estimated chance a flaw is exploited within 30 days. We flag it only in the top 10% — a statistical signal it’s unusually likely to be targeted, separate from whether attacks are confirmed.

💡 Tip: Swipe CVE cards left to ⭐ star, right to ❌ remove

Section Navigation