Monday, April 13, 2026 Archive

Archived Security Snapshot

Critical vulnerabilities, curated daily for security professionals

Archived Security Brief

Monday's vulnerability disclosures are concentrated around Totolink A7100RU routers, which account for the majority of 14 critical-severity CVEs β€” a 56% increase from Sunday's 9 critical disclosures. High-priority CVEs declined to 54, down 27% from the prior day's 74. Multiple Totolink A7100RU flaws (CVE-2026-6112 through CVE-2026-6139) carry CVSS 9.8 scores, alongside CVE-2019-25709 affecting CF Image Hosting Script. Two vulnerabilities are confirmed actively exploited: CVE-2026-5281 in Google Dawn and CVE-2026-3502 in TrueConf Client, both rated CVSS 9.5. No patches are currently available for any of the 68 disclosed vulnerabilities, requiring defenders to prioritize network-level mitigations and access controls.

  • Totolink A7100RU routers affected by 9+ critical CVSS 9.8 vulnerabilities spanning multiple attack vectors
  • 14 critical CVEs disclosed, up 56% from Sunday's 9 critical disclosures
  • 54 high-priority CVEs reported, down 27% from the prior day's 74
  • Google Dawn (CVE-2026-5281) and TrueConf Client (CVE-2026-3502) confirmed actively exploited at CVSS 9.5
  • Patch availability at 0% across all 68 disclosures β€” no vendor fixes currently released

Immediate action: Organizations using Totolink A7100RU routers should restrict administrative access and isolate affected devices behind network segmentation until patches are available. Google Dawn and TrueConf Client users should monitor vendor channels for emergency updates given confirmed exploitation. With zero patches available, apply compensating controls including WAF rules, access restrictions, and enhanced monitoring for all affected products.

How to read this brief

CVSS score (e.g. 9.1) β€” severity from 0–10. Red marks critical (9+), orange high (7–8.9).

Exploitability β€” how hard the flaw is to attack, read from the CVSS vector:

  • Network / Adjacent / Local / Physical β€” how close an attacker must get. Network means reachable over the internet.
  • No / Low / High privileges β€” the access they need first. No privileges means no login required.
  • No interaction / User interaction β€” whether a victim has to do something (open a file, click a link). No interaction means fully automatable.

The lower the bar on all three, the easier to exploit at scale β€” β€œNetwork Β· No privileges Β· No interaction” is the worst case: hit from anywhere, no credentials, no victim action.

Actively exploited β€” confirmed under attack in the wild (CISA’s Known Exploited Vulnerabilities catalog). Prioritize these regardless of score.

EPSS Β· Nth percentile β€” FIRST.org’s estimated chance a flaw is exploited within 30 days. We flag it only in the top 10% β€” a statistical signal it’s unusually likely to be targeted, separate from whether attacks are confirmed.

πŸ’‘ Tip: Swipe CVE cards left to ⭐ star, right to ❌ remove

Section Navigation