Thursday, April 16, 2026 Archive

Archived Security Snapshot

Critical vulnerabilities, curated daily for security professionals

Archived Security Brief

Thursday's vulnerability disclosures are dominated by Cisco and WordPress, with Cisco Identity Services Engine and Webex carrying three CVSS 9.9 flaws that could enable full administrative compromise of enterprise network infrastructure. The day's 17 critical vulnerabilities represent a 26% decrease from Wednesday's 23, while 100 high-priority CVEs held steady. CVE-2026-20147 and CVE-2026-20180 target Cisco ISE, CVE-2026-20184 affects Cisco Webex, and CVE-2026-6296 impacts Google Chrome at CVSS 9.6, alongside three WordPress plugin vulnerabilities scoring 9.8. Eight actively exploited vulnerabilities span Microsoft and Adobe products, including legacy flaws in Exchange Server, SharePoint, and Acrobat Reader still being weaponized in the wild. Patch availability stands at 0%, leaving defenders reliant on compensating controls and network segmentation until vendor fixes are released.

  • Cisco ISE and Webex account for three CVSS 9.9 vulnerabilities enabling potential full control of identity and collaboration infrastructure
  • 17 critical CVEs disclosed, down 26% from Wednesday's 23, with Google Chrome, Cisco, and WordPress as primary targets
  • 100 high-priority CVEs unchanged from the prior day, sustaining elevated remediation workload
  • Remote code execution and authentication bypass patterns dominate across Cisco ISE, WordPress plugins, and Chrome
  • Patch availability at 0% across all disclosed CVEs โ€” no vendor fixes currently available
  • 8 actively exploited vulnerabilities affect Microsoft Office, Exchange, SharePoint, Windows, and Adobe Acrobat

Immediate action: Prioritize network segmentation and access restrictions for Cisco ISE, Webex, and any internet-facing WordPress deployments until patches are released. Review exposure to the eight actively exploited Microsoft and Adobe vulnerabilities, applying any existing patches for the older KEV entries and monitoring vendor channels for updates on newly disclosed flaws.

How to read this brief

CVSS score (e.g. 9.1) โ€” severity from 0โ€“10. Red marks critical (9+), orange high (7โ€“8.9).

Exploitability โ€” how hard the flaw is to attack, read from the CVSS vector:

  • Network / Adjacent / Local / Physical โ€” how close an attacker must get. Network means reachable over the internet.
  • No / Low / High privileges โ€” the access they need first. No privileges means no login required.
  • No interaction / User interaction โ€” whether a victim has to do something (open a file, click a link). No interaction means fully automatable.

The lower the bar on all three, the easier to exploit at scale โ€” โ€œNetwork ยท No privileges ยท No interactionโ€ is the worst case: hit from anywhere, no credentials, no victim action.

Actively exploited โ€” confirmed under attack in the wild (CISAโ€™s Known Exploited Vulnerabilities catalog). Prioritize these regardless of score.

EPSS ยท Nth percentile โ€” FIRST.orgโ€™s estimated chance a flaw is exploited within 30 days. We flag it only in the top 10% โ€” a statistical signal itโ€™s unusually likely to be targeted, separate from whether attacks are confirmed.

๐Ÿ’ก Tip: Swipe CVE cards left to โญ star, right to โŒ remove

Section Navigation