Tuesday, April 28, 2026 Archive

Archived Security Snapshot

Critical vulnerabilities, curated daily for security professionals

Archived Security Brief

Tuesday's disclosures center on Apache infrastructure components, with multiple critical flaws in Apache Camel and Apache MINA driving the day's volume. Critical CVEs reached 32 (up from 2 the prior day) while high-priority disclosures climbed to 100 from 61. Notable entries include CVE-2026-33453 (CVSS 10) in Apache Camel, CVE-2026-41635 (CVSS 9.8) in Apache MINA, and CVE-2026-41462 (CVSS 9.8) in ProjeQtor. Remote code execution and unauthenticated access patterns dominate the critical tier, with networking gear from Totolink and firmware-level flaws expanding the attack surface. No patches are currently published for the disclosed set, requiring compensating controls and exposure reduction until vendor fixes ship.

  • Apache Camel and Apache MINA account for the bulk of critical disclosures, including a CVSS 10 flaw in Camel (CVE-2026-33453)
  • Critical CVEs jumped to 32, a 1500% increase from the prior day's 2
  • High-priority CVEs rose 64% to 100, indicating broad disclosure volume across vendors
  • Remote code execution and authentication bypass patterns affect Apache messaging frameworks, ProjeQtor, and Totolink A8000RU routers
  • Patch availability sits at 0% for the disclosed set, leaving mitigation and isolation as the primary defensive options
  • 11 vulnerabilities are confirmed actively exploited, spanning Apache ActiveMQ, Kentico Xperience, PaperCut, and SimpleHelp

Immediate action: Prioritize inventory and exposure review for Apache Camel, Apache MINA, ProjeQtor, and Totolink A8000RU deployments, and isolate management interfaces for ActiveMQ, Kentico, PaperCut, SimpleHelp, and Quest KACE pending vendor guidance. With no patches currently available for the new critical set, apply network segmentation, restrict external reachability, and monitor for indicators of exploitation against the actively exploited products.

How to read this brief

CVSS score (e.g. 9.1) — severity from 0–10. Red marks critical (9+), orange high (7–8.9).

Exploitability — how hard the flaw is to attack, read from the CVSS vector:

  • Network / Adjacent / Local / Physical — how close an attacker must get. Network means reachable over the internet.
  • No / Low / High privileges — the access they need first. No privileges means no login required.
  • No interaction / User interaction — whether a victim has to do something (open a file, click a link). No interaction means fully automatable.

The lower the bar on all three, the easier to exploit at scale — “Network · No privileges · No interaction” is the worst case: hit from anywhere, no credentials, no victim action.

Actively exploited — confirmed under attack in the wild (CISA’s Known Exploited Vulnerabilities catalog). Prioritize these regardless of score.

EPSS · Nth percentile — FIRST.org’s estimated chance a flaw is exploited within 30 days. We flag it only in the top 10% — a statistical signal it’s unusually likely to be targeted, separate from whether attacks are confirmed.

💡 Tip: Swipe CVE cards left to ⭐ star, right to ❌ remove

Section Navigation