Wednesday, April 8, 2026 Archive

Archived Security Snapshot

Critical vulnerabilities, curated daily for security professionals

Archived Security Brief

Wednesday's vulnerability disclosures revealed 27 critical-severity CVEs, a 69% increase from the prior day, with HP products bearing the highest impact including a maximum-severity CVSS 10.0 code execution flaw (CVE-2026-39337). WordPress faced multiple critical vulnerabilities (CVE-2026-3296, CVE-2026-0740), while Google Web Fonts (CVE-2026-3535) and Apache ChurchCRM (CVE-2026-35573) also disclosed high-impact issues. Remote code execution and unauthorized access patterns dominate across enterprise collaboration tools, content management systems, and endpoint management platforms. No patches are currently available for any of the 127 disclosed vulnerabilities, and four CVEs have confirmed active exploitation including Fortinet FortiClient EMS and Google Dawn.

  • HP disclosed a maximum-severity CVSS 10.0 vulnerability (CVE-2026-39337) alongside multiple critical flaws affecting HP products
  • 27 critical CVEs disclosed, up 69% from 16 the prior day; 100 high-priority CVEs remain steady
  • WordPress, Google, Apache, and SiYuan also affected by critical-severity vulnerabilities scoring 9.0 or higher
  • Remote code execution and unauthorized access patterns dominate, targeting enterprise collaboration platforms and content management systems
  • Patch availability stands at 0% across all 127 disclosed CVEs, requiring compensating controls
  • 4 vulnerabilities have confirmed active exploitation, including Fortinet FortiClient EMS (CVE-2026-35616) and Google Dawn (CVE-2026-5281)

Immediate action: Prioritize risk assessment for HP products, WordPress installations, and Fortinet FortiClient EMS deployments, applying network-level mitigations such as access restrictions and monitoring where patches are unavailable. With zero patches currently available across all disclosed vulnerabilities, organizations should implement compensating controls, increase monitoring for exploitation indicators, and prepare for rapid patching as vendor updates are released.

How to read this brief

CVSS score (e.g. 9.1) — severity from 0–10. Red marks critical (9+), orange high (7–8.9).

Exploitability — how hard the flaw is to attack, read from the CVSS vector:

  • Network / Adjacent / Local / Physical — how close an attacker must get. Network means reachable over the internet.
  • No / Low / High privileges — the access they need first. No privileges means no login required.
  • No interaction / User interaction — whether a victim has to do something (open a file, click a link). No interaction means fully automatable.

The lower the bar on all three, the easier to exploit at scale — “Network · No privileges · No interaction” is the worst case: hit from anywhere, no credentials, no victim action.

Actively exploited — confirmed under attack in the wild (CISA’s Known Exploited Vulnerabilities catalog). Prioritize these regardless of score.

EPSS · Nth percentile — FIRST.org’s estimated chance a flaw is exploited within 30 days. We flag it only in the top 10% — a statistical signal it’s unusually likely to be targeted, separate from whether attacks are confirmed.

💡 Tip: Swipe CVE cards left to ⭐ star, right to ❌ remove

Section Navigation