Thursday, April 30, 2026 Archive

Archived Security Snapshot

Critical vulnerabilities, curated daily for security professionals

Archived Security Brief

Thursday's disclosures center on networking equipment and developer infrastructure, with multiple Tenda router models, Jenkins GitHub Plugin, and cPanel/WHM hosting platforms exposed to remote compromise. Eight critical CVEs were disclosed yesterday, down 50% from the prior day, alongside 100 high-priority issues matching the previous day's volume. Notable entries include CVE-2026-41940 affecting cPanel/WHM login (CVSS 9.8), CVE-2026-42523 in Jenkins GitHub Plugin (CVSS 9.0), and CVE-2026-36841 in TOTOLINK N200RE V5 (CVSS 9.8). Attack patterns are dominated by remote code execution and authentication bypass affecting hosting platforms, CI/CD systems, and consumer-grade networking gear. No vendor patches were available at disclosure, requiring compensating controls and accelerated mitigation planning.

  • Networking and hosting infrastructure dominate with Tenda, TOTOLINK, and cPanel/WHM exposed to unauthenticated remote attacks
  • 8 critical CVEs disclosed, a 50% decrease from the prior day's 16
  • 100 high-priority CVEs disclosed, unchanged from the prior day
  • Remote code execution and authentication bypass patterns affect Jenkins GitHub Plugin, Wazuh, and TOTOLINK routers
  • 0% patch availability across critical disclosures, requiring network segmentation and access restrictions
  • 12 actively exploited vulnerabilities span Microsoft Defender, ConnectWise ScreenConnect, JetBrains TeamCity, and PaperCut NG/MF

Immediate action: Prioritize isolation and access controls for cPanel/WHM hosting environments, Jenkins GitHub Plugin instances, and Tenda/TOTOLINK consumer routers exposed to untrusted networks. With no patches currently available for the critical disclosures, focus on network segmentation, WAF rules, and monitoring while tracking actively exploited issues in Microsoft Defender, ConnectWise ScreenConnect, and JetBrains TeamCity for immediate remediation.

How to read this brief

CVSS score (e.g. 9.1) β€” severity from 0–10. Red marks critical (9+), orange high (7–8.9).

Exploitability β€” how hard the flaw is to attack, read from the CVSS vector:

  • Network / Adjacent / Local / Physical β€” how close an attacker must get. Network means reachable over the internet.
  • No / Low / High privileges β€” the access they need first. No privileges means no login required.
  • No interaction / User interaction β€” whether a victim has to do something (open a file, click a link). No interaction means fully automatable.

The lower the bar on all three, the easier to exploit at scale β€” β€œNetwork Β· No privileges Β· No interaction” is the worst case: hit from anywhere, no credentials, no victim action.

Actively exploited β€” confirmed under attack in the wild (CISA’s Known Exploited Vulnerabilities catalog). Prioritize these regardless of score.

EPSS Β· Nth percentile β€” FIRST.org’s estimated chance a flaw is exploited within 30 days. We flag it only in the top 10% β€” a statistical signal it’s unusually likely to be targeted, separate from whether attacks are confirmed.

πŸ’‘ Tip: Swipe CVE cards left to ⭐ star, right to ❌ remove

Section Navigation