Wednesday, April 1, 2026 Archive

Archived Security Snapshot

Critical vulnerabilities, curated daily for security professionals

Archived Security Brief

Yesterday's disclosures reveal 17 critical vulnerabilities spanning WordPress, FastGPT, NocoBase, and multiple AI/developer tooling platforms. Critical CVEs rose 21% from the prior day while high-priority vulnerabilities saw a sharp 47% increase to 100. CVE-2026-34162 in FastGPT carries a perfect CVSS 10.0 score, CVE-2026-34156 in NocoBase rates 9.9, and CVE-2026-3300 affects WordPress at 9.8. Attack patterns are dominated by remote code execution and authentication bypass across web application frameworks, content management systems, and healthcare interoperability standards (HL7 HAPI FHIR). No patches are currently available for disclosed vulnerabilities, and 8 CVEs have confirmed active exploitation including Citrix NetScaler, Apple products, Craft CMS, and Laravel Livewire.

  • FastGPT CVE-2026-34162 (CVSS 10.0) and NocoBase CVE-2026-34156 (CVSS 9.9) represent the highest-severity disclosures affecting AI and no-code platforms
  • 17 critical CVEs disclosed, up 21% from the prior day's 14
  • 100 high-priority CVEs disclosed, up 47% from the prior day's 68
  • RCE and authentication bypass patterns dominate, affecting WordPress, SiYuan, GitHub Actions, and HL7 HAPI FHIR healthcare infrastructure
  • 0% patch availability across all 117 disclosed vulnerabilities — no vendor fixes currently released
  • 8 actively exploited vulnerabilities include Citrix NetScaler, Apple products, Craft CMS, Laravel Livewire, Langflow, and Aquasecurity Trivy

Immediate action: Prioritize risk assessment for FastGPT, NocoBase, WordPress, and Citrix NetScaler deployments, applying network-level mitigations such as WAF rules and access restrictions where patches are unavailable. Monitor vendor advisories closely for patch releases across all 117 CVEs, as 0% currently have fixes available, and verify that actively exploited components including Apple products, Craft CMS, and Laravel Livewire are isolated or updated as remediation becomes available.

How to read this brief

CVSS score (e.g. 9.1) — severity from 0–10. Red marks critical (9+), orange high (7–8.9).

Exploitability — how hard the flaw is to attack, read from the CVSS vector:

  • Network / Adjacent / Local / Physical — how close an attacker must get. Network means reachable over the internet.
  • No / Low / High privileges — the access they need first. No privileges means no login required.
  • No interaction / User interaction — whether a victim has to do something (open a file, click a link). No interaction means fully automatable.

The lower the bar on all three, the easier to exploit at scale — “Network · No privileges · No interaction” is the worst case: hit from anywhere, no credentials, no victim action.

Actively exploited — confirmed under attack in the wild (CISA’s Known Exploited Vulnerabilities catalog). Prioritize these regardless of score.

EPSS · Nth percentile — FIRST.org’s estimated chance a flaw is exploited within 30 days. We flag it only in the top 10% — a statistical signal it’s unusually likely to be targeted, separate from whether attacks are confirmed.

💡 Tip: Swipe CVE cards left to ⭐ star, right to ❌ remove

Section Navigation