Sunday, March 29, 2026 Archive

Archived Security Snapshot

Critical vulnerabilities, curated daily for security professionals

Archived Security Brief

Sunday's disclosures include 10 actively exploited vulnerabilities targeting F5 BIG-IP, Apple products, Zimbra Collaboration Suite, and Craft CMS, all carrying CVSS 9.5 scores. Critical CVEs dropped to 7 (down 53% from Saturday's 15), while 98 high-priority vulnerabilities were disclosed (down 2%). Among the critical findings, CVE-2025-53521 affects F5 BIG-IP infrastructure, CVE-2025-43510 and CVE-2025-43520 target multiple Apple products, and CVE-2025-66376 impacts Synacor Zimbra mail servers. Attack patterns center on remote code execution across web application frameworks including Laravel Livewire, Craft CMS, and Langflow, alongside security tool compromise via CVE-2026-33634 in Aquasecurity Trivy. Patch availability currently stands at 0%, requiring defenders to prioritize compensating controls and network-level mitigations for exposed services.

  • F5 BIG-IP, Apple, and Zimbra among vendors with actively exploited CVSS 9.5 vulnerabilities requiring immediate attention
  • 7 critical CVEs disclosed (down 53% from prior day's 15), with 105 total vulnerabilities tracked
  • 98 high-priority CVEs disclosed (down 2% from 100), maintaining elevated volume
  • Remote code execution dominates attack patterns across Craft CMS, Laravel Livewire, Langflow, and Wing FTP Server
  • 0% patch availability across all disclosed CVEs β€” compensating controls and network segmentation are essential
  • 10 vulnerabilities confirmed under active exploitation, unchanged from the prior day

Immediate action: Prioritize network-level mitigations for internet-facing F5 BIG-IP, Zimbra, Wing FTP Server, and Craft CMS instances, as all have confirmed active exploitation with no patches currently available. Apply compensating controls such as WAF rules, access restrictions, and enhanced monitoring for Apple products, Laravel Livewire, and Langflow deployments until vendor patches are released.

How to read this brief

CVSS score (e.g. 9.1) β€” severity from 0–10. Red marks critical (9+), orange high (7–8.9).

Exploitability β€” how hard the flaw is to attack, read from the CVSS vector:

  • Network / Adjacent / Local / Physical β€” how close an attacker must get. Network means reachable over the internet.
  • No / Low / High privileges β€” the access they need first. No privileges means no login required.
  • No interaction / User interaction β€” whether a victim has to do something (open a file, click a link). No interaction means fully automatable.

The lower the bar on all three, the easier to exploit at scale β€” β€œNetwork Β· No privileges Β· No interaction” is the worst case: hit from anywhere, no credentials, no victim action.

Actively exploited β€” confirmed under attack in the wild (CISA’s Known Exploited Vulnerabilities catalog). Prioritize these regardless of score.

EPSS Β· Nth percentile β€” FIRST.org’s estimated chance a flaw is exploited within 30 days. We flag it only in the top 10% β€” a statistical signal it’s unusually likely to be targeted, separate from whether attacks are confirmed.

πŸ’‘ Tip: Swipe CVE cards left to ⭐ star, right to ❌ remove

Section Navigation