Wednesday, May 6, 2026 Archive

Archived Security Snapshot

Critical vulnerabilities, curated daily for security professionals

Archived Security Brief

Wednesday's disclosures center on widespread web platform and edge device exposure, with WordPress plugins, D-Link routers, and Eclipse developer tooling driving the critical caseload. Critical CVEs fell 57% to 15 while high-priority issues rose 42% to 92, indicating broader but less severe activity than the prior day. Notable entries include CVE-2026-7411 (CVSS 10) in Eclipse BaSyx Java Server SDK, CVE-2026-7853 and CVE-2026-7854 (CVSS 9.8) in D-Link DI series routers, and CVE-2026-27960 (CVSS 9.8) in Intel OpenCTI Platform. Remote code execution and unauthenticated access patterns dominate, affecting industrial automation, network edge equipment, and threat-intelligence infrastructure. Patch availability remains at 0% for the disclosed set, and eight CVEs carry confirmed active exploitation including issues in Samsung MagicINFO, SimpleHelp, and ConnectWise ScreenConnect.

  • Eclipse BaSyx Java Server SDK CVE-2026-7411 carries a maximum CVSS 10 score, with parallel exposure in Eclipse Equinox OSGi (CVE-2023-54342, CVE-2023-54344)
  • Critical CVEs decreased 57% day-over-day to 15, reflecting a narrower critical caseload than Tuesday's 35
  • High-priority CVEs increased 42% to 92, signaling broader exposure across the CVSS 7.0-8.9 band
  • Unauthenticated remote code execution affects D-Link DI routers (CVE-2026-7853, CVE-2026-7854) and EFM ipTIME NAS1dual (CVE-2026-7834), alongside multiple WordPress plugin flaws
  • Patch availability stands at 0% across the disclosed set, requiring compensating controls for exposed WordPress, D-Link, and Intel OpenCTI deployments
  • Eight CVEs are actively exploited, including Samsung MagicINFO 9 Server, SimpleHelp, ConnectWise ScreenConnect, and a Microsoft Windows issue (CVE-2026-32202)

Immediate action: Prioritize isolation and monitoring of Eclipse BaSyx, D-Link DI, WordPress, and Intel OpenCTI deployments while reviewing exposure on actively exploited Samsung MagicINFO, SimpleHelp, and ConnectWise ScreenConnect instances. With patch availability at 0% for the new disclosures, apply network segmentation, restrict administrative interfaces, and enable enhanced logging until vendor fixes are released.

How to read this brief

CVSS score (e.g. 9.1) β€” severity from 0–10. Red marks critical (9+), orange high (7–8.9).

Exploitability β€” how hard the flaw is to attack, read from the CVSS vector:

  • Network / Adjacent / Local / Physical β€” how close an attacker must get. Network means reachable over the internet.
  • No / Low / High privileges β€” the access they need first. No privileges means no login required.
  • No interaction / User interaction β€” whether a victim has to do something (open a file, click a link). No interaction means fully automatable.

The lower the bar on all three, the easier to exploit at scale β€” β€œNetwork Β· No privileges Β· No interaction” is the worst case: hit from anywhere, no credentials, no victim action.

Actively exploited β€” confirmed under attack in the wild (CISA’s Known Exploited Vulnerabilities catalog). Prioritize these regardless of score.

EPSS Β· Nth percentile β€” FIRST.org’s estimated chance a flaw is exploited within 30 days. We flag it only in the top 10% β€” a statistical signal it’s unusually likely to be targeted, separate from whether attacks are confirmed.

πŸ’‘ Tip: Swipe CVE cards left to ⭐ star, right to ❌ remove

Section Navigation