Friday, March 27, 2026 Archive

Archived Security Snapshot

Critical vulnerabilities, curated daily for security professionals

Archived Security Brief

Friday's vulnerability disclosures include a maximum-severity flaw in ORY Oathkeeper (CVE-2026-33494, CVSS 10.0) alongside critical issues in Incus (CVE-2026-33945, CVE-2026-33897, both CVSS 9.9) and OneUptime (CVE-2026-33396, CVSS 9.9). The day saw 11 critical CVEs, down 8% from Thursday, while 100 high-priority vulnerabilities held steady. HP products account for multiple critical entries (CVE-2026-33942, CVE-2026-4809), and WordPress (CVE-2026-4484) and SiYuan (CVE-2026-33669, CVE-2026-33670) each carry CVSS 9.8 scores. Nine vulnerabilities have confirmed active exploitation, notably affecting Apple products, Zimbra Collaboration Suite, Craft CMS, and Laravel Livewire. No patches are currently available for disclosed vulnerabilities, requiring organizations to prioritize compensating controls and monitoring.

  • ORY Oathkeeper CVE-2026-33494 rated CVSS 10.0 — maximum severity authorization bypass
  • 11 critical CVEs disclosed, down 8% from prior day; Incus and OneUptime each have CVSS 9.9 flaws
  • 100 high-priority CVEs unchanged from Thursday, maintaining elevated disclosure volume
  • Remote code execution and authorization bypass patterns dominate, affecting HP, WordPress, and SiYuan
  • 0% patch availability across disclosed vulnerabilities — compensating controls essential
  • 9 actively exploited vulnerabilities target Apple products, Zimbra, Craft CMS, Langflow, and Trivy

Immediate action: Prioritize reviewing exposure to ORY Oathkeeper, Incus, OneUptime, and SiYuan deployments, and apply network-level restrictions where patches are unavailable. For the nine actively exploited vulnerabilities, verify compensating controls are in place for Apple products, Zimbra, Craft CMS, Laravel Livewire, Langflow, and Trivy, and monitor vendor channels for incoming patches.

How to read this brief

CVSS score (e.g. 9.1) — severity from 0–10. Red marks critical (9+), orange high (7–8.9).

Exploitability — how hard the flaw is to attack, read from the CVSS vector:

  • Network / Adjacent / Local / Physical — how close an attacker must get. Network means reachable over the internet.
  • No / Low / High privileges — the access they need first. No privileges means no login required.
  • No interaction / User interaction — whether a victim has to do something (open a file, click a link). No interaction means fully automatable.

The lower the bar on all three, the easier to exploit at scale — “Network · No privileges · No interaction” is the worst case: hit from anywhere, no credentials, no victim action.

Actively exploited — confirmed under attack in the wild (CISA’s Known Exploited Vulnerabilities catalog). Prioritize these regardless of score.

EPSS · Nth percentile — FIRST.org’s estimated chance a flaw is exploited within 30 days. We flag it only in the top 10% — a statistical signal it’s unusually likely to be targeted, separate from whether attacks are confirmed.

💡 Tip: Swipe CVE cards left to ⭐ star, right to ❌ remove

Section Navigation