Monday, April 27, 2026 Archive

Archived Security Snapshot

Critical vulnerabilities, curated daily for security professionals

Archived Security Brief

Monday's disclosures center on network infrastructure and enterprise utilities, with critical remote code execution flaws affecting Totolink routers and LG IP device management software. Critical CVEs increased to 2 (up 100% from yesterday) and high-priority CVEs rose to 61 (up 97%), reflecting a substantially heavier disclosure volume. Notable critical issues include CVE-2026-7037 (CVSS 9.8) in the Totolink A8000RU router and CVE-2026-42363 (CVSS 9.3) in the LG GV-IP Device Utility. Attack patterns skew toward remote code execution and authentication weaknesses in network-edge devices, alongside exploitation activity targeting Microsoft SharePoint, Apache ActiveMQ, and SimpleHelp. With patch availability at 0% for the disclosed set, defenders should prioritize compensating controls and network segmentation while vendor fixes are pending.

  • Totolink A8000RU router affected by CVE-2026-7037 (CVSS 9.8), the day's highest-severity disclosure
  • Critical CVEs rose to 2, a 100% increase from the prior day's single disclosure
  • High-priority CVEs climbed to 61, a 97% increase from yesterday's 31
  • Remote code execution and authentication bypass flaws dominate, impacting Totolink, LG, SharePoint, and ActiveMQ
  • Patch availability sits at 0% across the 63 disclosed vulnerabilities, requiring interim mitigations
  • 13 CVEs carry confirmed active exploitation, including SharePoint, PaperCut, JetBrains TeamCity, and SimpleHelp

Immediate action: Prioritize Totolink A8000RU and LG GV-IP Device Utility deployments for isolation and monitoring, and accelerate review of SharePoint, Apache ActiveMQ, PaperCut, SimpleHelp, and JetBrains TeamCity instances given confirmed exploitation. With no vendor patches available for today's disclosures, apply network segmentation, restrict management interfaces, and increase logging on affected systems until fixes ship.

How to read this brief

CVSS score (e.g. 9.1) β€” severity from 0–10. Red marks critical (9+), orange high (7–8.9).

Exploitability β€” how hard the flaw is to attack, read from the CVSS vector:

  • Network / Adjacent / Local / Physical β€” how close an attacker must get. Network means reachable over the internet.
  • No / Low / High privileges β€” the access they need first. No privileges means no login required.
  • No interaction / User interaction β€” whether a victim has to do something (open a file, click a link). No interaction means fully automatable.

The lower the bar on all three, the easier to exploit at scale β€” β€œNetwork Β· No privileges Β· No interaction” is the worst case: hit from anywhere, no credentials, no victim action.

Actively exploited β€” confirmed under attack in the wild (CISA’s Known Exploited Vulnerabilities catalog). Prioritize these regardless of score.

EPSS Β· Nth percentile β€” FIRST.org’s estimated chance a flaw is exploited within 30 days. We flag it only in the top 10% β€” a statistical signal it’s unusually likely to be targeted, separate from whether attacks are confirmed.

πŸ’‘ Tip: Swipe CVE cards left to ⭐ star, right to ❌ remove

Section Navigation