Sunday, April 19, 2026 Archive

Archived Security Snapshot

Critical vulnerabilities, curated daily for security professionals

Archived Security Brief

Sunday's vulnerability landscape centers on 7 critical CVEs affecting Arch Linux packages and Kubernetes orchestration platforms, alongside 46 high-priority issues across enterprise software. Critical disclosures dropped 59% from the prior day's 17, while high-severity CVEs fell 41% from 78. Notable entries include CVE-2026-40484 (CVSS 9.1) in Arch Multiple Products, CVE-2026-40324 (CVSS 9.1) in Kubernetes, and CVE-2026-40493 (CVSS 9.8) impacting multiple products. The disclosure set skews toward remote code execution and privilege escalation patterns affecting container and Linux distribution ecosystems. Patch availability sits at 0% across today's batch, warranting compensating controls and network segmentation until vendor fixes arrive.

  • Arch Linux and Kubernetes anchor the critical set with CVE-2026-40484 and CVE-2026-40324 (both CVSS 9.1)
  • Critical CVEs down 59% to 7 from yesterday's 17
  • High-priority CVEs down 41% to 46 from yesterday's 78
  • Multiple CVSS 9.8 remote code execution flaws (CVE-2026-40493, CVE-2026-40492, CVE-2026-40494) require attention
  • Patch availability at 0% — mitigations and monitoring required while fixes are developed
  • 9 actively exploited CVEs tracked, primarily affecting Microsoft Office, Exchange, SharePoint, and Adobe Acrobat

Immediate action: Prioritize isolation and monitoring of Arch Linux systems and Kubernetes clusters, and audit Microsoft Exchange, SharePoint, and Adobe Acrobat deployments given continued exploitation activity. With 0% patch availability on today's critical disclosures, apply network segmentation, restrict exposed services, and track vendor advisories for upcoming fixes.

How to read this brief

CVSS score (e.g. 9.1) — severity from 0–10. Red marks critical (9+), orange high (7–8.9).

Exploitability — how hard the flaw is to attack, read from the CVSS vector:

  • Network / Adjacent / Local / Physical — how close an attacker must get. Network means reachable over the internet.
  • No / Low / High privileges — the access they need first. No privileges means no login required.
  • No interaction / User interaction — whether a victim has to do something (open a file, click a link). No interaction means fully automatable.

The lower the bar on all three, the easier to exploit at scale — “Network · No privileges · No interaction” is the worst case: hit from anywhere, no credentials, no victim action.

Actively exploited — confirmed under attack in the wild (CISA’s Known Exploited Vulnerabilities catalog). Prioritize these regardless of score.

EPSS · Nth percentile — FIRST.org’s estimated chance a flaw is exploited within 30 days. We flag it only in the top 10% — a statistical signal it’s unusually likely to be targeted, separate from whether attacks are confirmed.

💡 Tip: Swipe CVE cards left to ⭐ star, right to ❌ remove

Section Navigation