CVE-2012-1854
Microsoft Visual Basic for Applications Insecure Library Loading Vulnerability - Active in CISA KEV catalog.
Critical vulnerabilities, curated daily for security professionals
Monday's vulnerability landscape centers on Digiwin EasyFlow .NET and industrial control systems, with two CVSS 9.8 flaws in Digiwin products and a critical issue affecting SD-330AC and AMC Manager devices. The brief includes 3 critical vulnerabilities (down 57% from 7) and 22 high-priority CVEs (down 52% from 46), reflecting a quieter disclosure cycle. Key critical entries include CVE-2026-5963 and CVE-2026-5964 affecting Digiwin EasyFlow .NET, alongside CVE-2026-32956 impacting SD-330AC and AMC Manager processing. Business application platforms and industrial control systems dominate today's attack surface, with 9 CVEs showing confirmed active exploitation across Microsoft, Adobe, and Apache products. No patches are currently available for the disclosed critical vulnerabilities, warranting defensive monitoring and compensating controls until fixes are released.
Immediate action: Prioritize asset inventory and network isolation for Digiwin EasyFlow .NET deployments and SD-330AC/AMC Manager industrial devices pending vendor patches. Organizations running Microsoft Exchange, SharePoint, Windows, Adobe Acrobat, or Apache ActiveMQ should verify current patch levels given confirmed exploitation of the 9 KEV entries. No patches are available for today's critical CVEs, so apply network segmentation and enhanced monitoring until fixes are published.
CVSS score (e.g. 9.1) β severity from 0β10. Red marks critical (9+), orange high (7β8.9).
Exploitability β how hard the flaw is to attack, read from the CVSS vector:
The lower the bar on all three, the easier to exploit at scale β βNetwork Β· No privileges Β· No interactionβ is the worst case: hit from anywhere, no credentials, no victim action.
Actively exploited β confirmed under attack in the wild (CISAβs Known Exploited Vulnerabilities catalog). Prioritize these regardless of score.
EPSS Β· Nth percentile β FIRST.orgβs estimated chance a flaw is exploited within 30 days. We flag it only in the top 10% β a statistical signal itβs unusually likely to be targeted, separate from whether attacks are confirmed.