Sunday, April 5, 2026 Archive

Archived Security Snapshot

Critical vulnerabilities, curated daily for security professionals

Archived Security Brief

Fortinet FortiClientEMS, HP, and NICO FTP carry critical-severity ratings at CVSS 9.8, while Langflow, Aquasecurity Trivy, Google Dawn, and TrueConf face confirmed active exploitation at CVSS 9.5. Sunday's disclosures include 3 critical and 73 high-priority CVEs, down 88% and 27% respectively from Saturday's counts. CVE-2026-35616 affects Fortinet FortiClientEMS, CVE-2026-33017 targets Langflow, and CVE-2026-33634 impacts Aquasecurity Trivy — all rated 9.5 or above. Attack patterns span endpoint management, DevSecOps tooling, browser rendering components, and communication platforms. No patches are currently available for any of the 76 disclosed vulnerabilities, requiring defenders to prioritize compensating controls and monitoring.

  • Fortinet FortiClientEMS (CVE-2026-35616, CVSS 9.8) disclosed with critical-severity rating affecting endpoint management infrastructure
  • Critical CVEs dropped to 3, down 88% from Saturday's 26, while 4 vulnerabilities have confirmed active exploitation
  • 73 high-priority CVEs disclosed, a 27% decrease from Saturday's 100
  • Exploitation targets span DevSecOps tools (Langflow, Trivy), browser components (Google Dawn), and communication platforms (TrueConf)
  • 0% patch availability across all 76 vulnerabilities — compensating controls and network segmentation are essential

Immediate action: Organizations running Fortinet FortiClientEMS, Langflow, Aquasecurity Trivy, Google Dawn, or TrueConf should assess exposure immediately and apply network segmentation or access restrictions. With no patches available for any disclosed vulnerability, implement monitoring for exploitation indicators and restrict access to affected services until vendor fixes are released.

How to read this brief

CVSS score (e.g. 9.1) — severity from 0–10. Red marks critical (9+), orange high (7–8.9).

Exploitability — how hard the flaw is to attack, read from the CVSS vector:

  • Network / Adjacent / Local / Physical — how close an attacker must get. Network means reachable over the internet.
  • No / Low / High privileges — the access they need first. No privileges means no login required.
  • No interaction / User interaction — whether a victim has to do something (open a file, click a link). No interaction means fully automatable.

The lower the bar on all three, the easier to exploit at scale — “Network · No privileges · No interaction” is the worst case: hit from anywhere, no credentials, no victim action.

Actively exploited — confirmed under attack in the wild (CISA’s Known Exploited Vulnerabilities catalog). Prioritize these regardless of score.

EPSS · Nth percentile — FIRST.org’s estimated chance a flaw is exploited within 30 days. We flag it only in the top 10% — a statistical signal it’s unusually likely to be targeted, separate from whether attacks are confirmed.

💡 Tip: Swipe CVE cards left to ⭐ star, right to ❌ remove

Section Navigation