Saturday, April 11, 2026 Archive

Archived Security Snapshot

Critical vulnerabilities, curated daily for security professionals

Archived Security Brief

Friday's disclosures reveal significant exposure across AWS services, with CVE-2026-40175 (CVSS 10.0) enabling IMDSv2 bypass and CVE-2026-5058/CVE-2026-5059 (CVSS 9.8) affecting AWS CLI and aws-mcp-server. Twenty critical vulnerabilities were disclosed, a 39% decrease from the prior day's 33, while 100 high-priority CVEs held steady. Additional critical flaws include CVE-2026-4149 (CVSS 10.0) in Sonos Era 300 smart speakers, CVE-2026-5412 (CVSS 9.9) in Canonical Juju, and CVE-2026-34621 (CVSS 9.6) in Adobe Acrobat Reader. Remote code execution and authentication bypass patterns dominate, spanning cloud infrastructure, consumer IoT, and document processing software. No patches are currently available for any disclosed vulnerabilities, requiring defenders to prioritize compensating controls and network-level mitigations.

  • Three AWS services affected by critical vulnerabilities: IMDSv2 bypass (CVSS 10.0), CLI command injection (CVSS 9.8), and MCP server flaw (CVSS 9.8)
  • 20 critical CVEs disclosed, down 39% from the prior day's 33; two carry maximum CVSS 10.0 scores
  • 100 high-priority CVEs unchanged from the prior day, maintaining elevated disclosure volume
  • RCE and authentication bypass dominate attack patterns across Sonos IoT devices, Adobe Acrobat Reader, Canonical Juju, and Totolink routers
  • Zero patches available across all 120 disclosed vulnerabilities — compensating controls required
  • 2 actively exploited vulnerabilities identified in Google Dawn and TrueConf Client (both CVSS 9.5)

Immediate action: Prioritize AWS environments for immediate review — audit IMDSv2 configurations, restrict AWS CLI and MCP server access, and apply network segmentation around Sonos Era 300 and Totolink A7100RU devices. With no patches currently available for any of the 120 disclosed CVEs, implement WAF rules, disable unnecessary services, and monitor for exploitation indicators on Google Dawn and TrueConf Client.

How to read this brief

CVSS score (e.g. 9.1) — severity from 0–10. Red marks critical (9+), orange high (7–8.9).

Exploitability — how hard the flaw is to attack, read from the CVSS vector:

  • Network / Adjacent / Local / Physical — how close an attacker must get. Network means reachable over the internet.
  • No / Low / High privileges — the access they need first. No privileges means no login required.
  • No interaction / User interaction — whether a victim has to do something (open a file, click a link). No interaction means fully automatable.

The lower the bar on all three, the easier to exploit at scale — “Network · No privileges · No interaction” is the worst case: hit from anywhere, no credentials, no victim action.

Actively exploited — confirmed under attack in the wild (CISA’s Known Exploited Vulnerabilities catalog). Prioritize these regardless of score.

EPSS · Nth percentile — FIRST.org’s estimated chance a flaw is exploited within 30 days. We flag it only in the top 10% — a statistical signal it’s unusually likely to be targeted, separate from whether attacks are confirmed.

💡 Tip: Swipe CVE cards left to ⭐ star, right to ❌ remove

Section Navigation