Thursday, April 2, 2026 Archive

Archived Security Snapshot

Critical vulnerabilities, curated daily for security professionals

Archived Security Brief

Thursday's vulnerability disclosures include a CVSS 10.0 flaw in Canonical Juju and multiple critical Cisco and Google Chrome vulnerabilities requiring immediate attention. The day's 28 critical CVEs represent a 65% increase from the prior day's 17, alongside a steady 100 high-priority vulnerabilities. Notable disclosures include CVE-2026-4370 (Canonical Juju, CVSS 10.0), CVE-2026-20093 and CVE-2026-20160 (Cisco management platforms, both CVSS 9.8), and three Google Chrome flaws each scoring CVSS 9.6. Attack patterns center on code injection, remote code execution, and management interface compromise across enterprise infrastructure. With 0% patch availability reported at disclosure time, organizations should monitor vendor advisories closely and apply mitigations as they become available.

  • Canonical Juju CVE-2026-4370 rated CVSS 10.0 β€” highest severity score possible, affecting infrastructure orchestration
  • 28 critical CVEs disclosed, a 65% increase from the prior day's 17 critical vulnerabilities
  • 100 high-priority CVEs (CVSS 7.0–8.9), unchanged from the prior day
  • Cisco IMC and Smart Software Manager each have CVSS 9.8 RCE flaws; three Google Chrome vulnerabilities scored 9.6
  • Patch availability at 0% across disclosed CVEs β€” vendor advisories pending for most critical issues
  • 8 actively exploited vulnerabilities include Craft CMS, Laravel Livewire, Apple products, and Langflow

Immediate action: Prioritize monitoring vendor advisories for Canonical Juju, Cisco IMC, Cisco Smart Software Manager, and Google Chrome, as these carry the highest severity scores. With no patches currently available, apply any published workarounds or network-level mitigations and restrict access to affected management interfaces until fixes are released.

How to read this brief

CVSS score (e.g. 9.1) β€” severity from 0–10. Red marks critical (9+), orange high (7–8.9).

Exploitability β€” how hard the flaw is to attack, read from the CVSS vector:

  • Network / Adjacent / Local / Physical β€” how close an attacker must get. Network means reachable over the internet.
  • No / Low / High privileges β€” the access they need first. No privileges means no login required.
  • No interaction / User interaction β€” whether a victim has to do something (open a file, click a link). No interaction means fully automatable.

The lower the bar on all three, the easier to exploit at scale β€” β€œNetwork Β· No privileges Β· No interaction” is the worst case: hit from anywhere, no credentials, no victim action.

Actively exploited β€” confirmed under attack in the wild (CISA’s Known Exploited Vulnerabilities catalog). Prioritize these regardless of score.

EPSS Β· Nth percentile β€” FIRST.org’s estimated chance a flaw is exploited within 30 days. We flag it only in the top 10% β€” a statistical signal it’s unusually likely to be targeted, separate from whether attacks are confirmed.

πŸ’‘ Tip: Swipe CVE cards left to ⭐ star, right to ❌ remove

Section Navigation