Saturday, May 2, 2026 Archive

Archived Security Snapshot

Critical vulnerabilities, curated daily for security professionals

Archived Security Brief

Saturday's disclosures center on WordPress plugin flaws, Apache MINA buffer handling, and HP Framework vulnerabilities driving the critical category. Critical CVEs doubled to 16 from 8 the prior day, while high-priority CVEs held steady at 99. Notable entries include CVE-2026-37541 (CVSS 10) affecting Open Vehicle Monitoring System 3, CVE-2026-42778 and CVE-2026-42779 in Apache MINA, and CVE-2026-42472/42473 in HP Framework. Remote code execution and authentication bypass dominate the attack patterns, with web infrastructure, embedded systems, and enterprise frameworks most affected. Patch availability sits at 0% for the disclosed set, and 14 CVEs across WordPress, Microsoft, Linux Kernel, and SimpleHelp have confirmed active exploitation.

  • WordPress plugins, Apache MINA, and HP Framework lead critical disclosures with multiple CVSS 9.8 vulnerabilities
  • Critical CVEs increased 100% to 16, up from 8 the previous day
  • High-priority CVEs steady at 99, matching the prior day's count
  • Remote code execution and authentication bypass patterns dominate, affecting WordPress, Totolink NR1800X, and cannelloni v2
  • Patch availability at 0% across the 115 disclosed CVEs requires compensating controls
  • 14 actively exploited CVEs span WordPress, Microsoft Defender, Linux Kernel, SimpleHelp, and ConnectWise ScreenConnect

Immediate action: Prioritize review of WordPress installations, Apache MINA deployments, HP Framework instances, and embedded systems running OVMS3 or Totolink NR1800X for exposure assessment. With patch availability at 0% for the new disclosures, apply network segmentation, WAF rules, and monitoring while tracking vendor advisories; separately, address the 14 KEV entries affecting WordPress, Microsoft, Linux Kernel, and SimpleHelp using available vendor updates.

How to read this brief

CVSS score (e.g. 9.1) β€” severity from 0–10. Red marks critical (9+), orange high (7–8.9).

Exploitability β€” how hard the flaw is to attack, read from the CVSS vector:

  • Network / Adjacent / Local / Physical β€” how close an attacker must get. Network means reachable over the internet.
  • No / Low / High privileges β€” the access they need first. No privileges means no login required.
  • No interaction / User interaction β€” whether a victim has to do something (open a file, click a link). No interaction means fully automatable.

The lower the bar on all three, the easier to exploit at scale β€” β€œNetwork Β· No privileges Β· No interaction” is the worst case: hit from anywhere, no credentials, no victim action.

Actively exploited β€” confirmed under attack in the wild (CISA’s Known Exploited Vulnerabilities catalog). Prioritize these regardless of score.

EPSS Β· Nth percentile β€” FIRST.org’s estimated chance a flaw is exploited within 30 days. We flag it only in the top 10% β€” a statistical signal it’s unusually likely to be targeted, separate from whether attacks are confirmed.

πŸ’‘ Tip: Swipe CVE cards left to ⭐ star, right to ❌ remove

Section Navigation