Sunday, April 12, 2026 Archive

Archived Security Snapshot

Critical vulnerabilities, curated daily for security professionals

Archived Security Brief

Yesterday's disclosures include a CVSS 10.0 vulnerability in the Sonos Era 300 (CVE-2026-4149) alongside two critical AWS flaws affecting AWS CLI and aws-mcp-server (CVE-2026-5059, CVE-2026-5058), both scoring 9.8. Critical CVEs dropped to 9, down 55% from the prior day's 20, while high-priority disclosures fell 26% to 74. Five separate critical vulnerabilities (CVE-2026-6112 through CVE-2026-6116) target the Totolink A7100RU router, all rated CVSS 9.8, indicating a broad attack surface in that device. Two vulnerabilities are under active exploitation—Google Dawn (CVE-2026-5281) and TrueConf Client (CVE-2026-3502)—both rated 9.5. No patches are currently available for any of the 83 disclosed CVEs, requiring defenders to rely on compensating controls and network-level mitigations.

  • Sonos Era 300 carries the day's only CVSS 10.0 rating (CVE-2026-4149), representing the highest-severity disclosure
  • Critical CVEs at 9, down 55% from 20 the prior day; high-priority CVEs at 74, down 26% from 100
  • Two AWS services affected at CVSS 9.8: AWS CLI Command (CVE-2026-5059) and aws-mcp-server (CVE-2026-5058)
  • Five distinct command injection or RCE vulnerabilities target the Totolink A7100RU router (CVE-2026-6112 through CVE-2026-6116)
  • Patch availability stands at 0% across all 83 disclosed CVEs—compensating controls are the only current option
  • Two CVEs under confirmed active exploitation: Google Dawn and TrueConf Client, both at CVSS 9.5

Immediate action: Prioritize network segmentation and access restrictions for Sonos Era 300 devices, Totolink A7100RU routers, and any systems using AWS CLI or aws-mcp-server. With zero patches available across all disclosures, apply compensating controls such as WAF rules, network isolation, and enhanced monitoring for exploitation indicators on Google Dawn and TrueConf Client.

How to read this brief

CVSS score (e.g. 9.1) — severity from 0–10. Red marks critical (9+), orange high (7–8.9).

Exploitability — how hard the flaw is to attack, read from the CVSS vector:

  • Network / Adjacent / Local / Physical — how close an attacker must get. Network means reachable over the internet.
  • No / Low / High privileges — the access they need first. No privileges means no login required.
  • No interaction / User interaction — whether a victim has to do something (open a file, click a link). No interaction means fully automatable.

The lower the bar on all three, the easier to exploit at scale — “Network · No privileges · No interaction” is the worst case: hit from anywhere, no credentials, no victim action.

Actively exploited — confirmed under attack in the wild (CISA’s Known Exploited Vulnerabilities catalog). Prioritize these regardless of score.

EPSS · Nth percentile — FIRST.org’s estimated chance a flaw is exploited within 30 days. We flag it only in the top 10% — a statistical signal it’s unusually likely to be targeted, separate from whether attacks are confirmed.

💡 Tip: Swipe CVE cards left to ⭐ star, right to ❌ remove

Section Navigation