Critical vulnerabilities, curated daily for security professionals
📊
Archived Security Brief
Friday's disclosures center on cloud and collaboration infrastructure, with critical flaws in Azure DevOps, Microsoft Teams, Apache Cassandra, and Kubernetes affecting widely deployed enterprise environments. Critical CVE volume rose 82% to 20 from 11 the prior day, while high-priority issues held steady at 100. Notable entries include CVE-2026-33587 (CVSS 10) impacting Docker container isolation, CVE-2026-42826 (CVSS 10) in Azure DevOps, and CVE-2026-33109 (CVSS 9.9) in Apache Cassandra. Remote code execution, container escape, and secret exposure dominate the attack patterns, with cloud-native and DevOps toolchains carrying the heaviest exposure. No vendor patches are currently available across this set, requiring teams to rely on configuration hardening, network segmentation, and compensating controls until fixes ship.
Cloud and DevOps platforms lead exposure: Azure DevOps, Azure Cloud Shell, Kubernetes, and Apache Cassandra all carry CVSS 9.6+ flaws
Critical CVEs rose 82% day-over-day to 20, driven by container and cloud orchestration issues
High-priority CVEs held flat at 100, sustaining elevated remediation workload
Attack patterns concentrate on container escape (Docker CVE-2026-33587), secret exposure (Kubernetes CVE-2026-42880), and RCE in collaboration tools (Microsoft Teams CVE-2026-33823)
Patch availability sits at 0% across the disclosed set, leaving mitigation as the only near-term option
Five CVEs show active exploitation, including Palo Alto PAN, Ivanti EPMM, ConnectWise ScreenConnect, Windows, and Linux Kernel
Immediate action: Prioritize inventory and exposure assessment for Azure DevOps, Microsoft Teams, Apache Cassandra, Kubernetes, and Docker environments, alongside the actively exploited Palo Alto, Ivanti EPMM, and ConnectWise ScreenConnect deployments. With no patches yet available for the new critical CVEs, apply network segmentation, restrict administrative access, and enable enhanced logging on affected systems while monitoring vendor advisories for fix releases.
How to read this brief
CVSS score (e.g. 9.1) — severity from 0–10. Red marks critical (9+), orange high (7–8.9).
Exploitability — how hard the flaw is to attack, read from the CVSS vector:
Network / Adjacent / Local / Physical — how close an attacker must get. Network means reachable over the internet.
No / Low / High privileges — the access they need first. No privileges means no login required.
No interaction / User interaction — whether a victim has to do something (open a file, click a link). No interaction means fully automatable.
The lower the bar on all three, the easier to exploit at scale — “Network · No privileges · No interaction” is the worst case: hit from anywhere, no credentials, no victim action.
🔴 Actively exploited — confirmed under attack in the wild (CISA’s Known Exploited Vulnerabilities catalog). Prioritize these regardless of score.
EPSS · Nth percentile — FIRST.org’s estimated chance a flaw is exploited within 30 days. We flag it only in the top 10% — a statistical signal it’s unusually likely to be targeted, separate from whether attacks are confirmed.
💡 Tip: Swipe CVE cards left to ⭐ star, right to ❌ remove
Palo Alto NetworksPAN-OS (PA-Series and VM-Series firewalls)
Unauthenticated RCE in Palo Alto PAN-OS firewalls
A buffer overflow in the User-ID Authentication Portal lets an unauthenticated network attacker execute arbitrary code as root on PA-Series and VM-Series firewalls. Palo Alto Networks confirms limited exploitation in the wild against portals reachable from untrusted IP space.
A buffer overflow vulnerability in the User-ID™ Authentication Portal (aka Captive Portal) service of Palo Alto Networks PAN-OS software allows an unauthenticated attacker to execute arbitrary code with root privileges on the PA-Series and VM-Series firewalls by sending specially crafted packets.
The risk of this issue is greatly reduced if you secure access to the User-ID™ Authentication Portal per the best practice guidelines https://knowledgebase.paloaltonetworks.com/KCSArticleDetail by restricting access to only trusted internal IP addresses.
Prisma Access, Cloud NGFW and Panorama appliances are not impacted by this vulnerability.
⚠️ CISA KEVURGENT
CVE-2026-6973
9.5
IvantiEndpoint Manager Mobile (EPMM)
🔴 Actively exploited in the wild
Ivanti Endpoint Manager Mobile (EPMM) Improper Input Validation Vulnerability - Active in CISA KEV catalog.
⚠️ CISA KEVURGENT
CVE-2024-1708
9.5📜 Late Disclosure
ConnectWiseScreenConnect
🔴 Actively exploited in the wild
ConnectWise ScreenConnect Path Traversal Vulnerability - Active in CISA KEV catalog.
⚠️ CISA KEVURGENT
CVE-2026-32202
9.5
MicrosoftWindows
🔴 Actively exploited in the wild
Microsoft Windows Protection Mechanism Failure Vulnerability - Active in CISA KEV catalog.
⚠️ CISA KEVURGENT
CVE-2026-31431
9.5
LinuxKernel
🔴 Actively exploited in the wild
Linux Kernel Incorrect Resource Transfer Between Spheres Vulnerability - Active in CISA KEV catalog.
FreeScout contains a flaw in the user-setup endpoint where invite hashes do not expire, allowing unauthenticated attackers to perform permanent account takeovers.
Insecure Permissions vulnerability in grokability snipe-it v.8.4.0 and before and fixed after 2026-03-10 commit 676a9958 allows a remote attacker to execute arbitrary code via the app/Http/Controllers/Api/UploadedFilesController.php component
A Server-Side Template Injection (SSTI) vulnerability in Open Notebook v1.8.3 allows authenticated users to execute arbitrary Python code and OS commands within the Docker container.
Origin Validation Error vulnerability in TUBITAK BILGEM Software Technologies Research Institute Liderahenk allows Accessing Functionality Not Properly Constrained by ACLs.
This issue affects Liderahenk: from 2.0.1 before 2.0.2.
A Cross-Site Request Forgery (CSRF) vulnerability in DivvyDrive versions 4.8.2.9 through 4.8.3.1 allows unauthorized actions to be performed on behalf of authenticated users.
URL redirection to untrusted site ('open redirect') vulnerability in DivvyDrive Information Technologies Inc. DivvyDrive allows Parameter Injection.
This issue affects DivvyDrive: from 4.8.2.9 before 4.8.3.2.
A Use-After-Free (UAF) vulnerability in the PresentationAPI of Google Chrome allows for potential arbitrary code execution via a specially crafted web page.
Use after free in DOM in Google Chrome prior to 148
CVE-2026-7921
8.8
GoogleChrome prior
Use after free in Passwords in Google Chrome prior to 148
CVE-2026-7928
8.8
GoogleChrome on
Use after free in WebRTC in Google Chrome on Windows prior to 148
CVE-2026-7938
8.8
GoogleChrome prior
Use after free in CSS in Google Chrome prior to 148
CVE-2026-7940
8.8
GoogleChrome prior
Use after free in V8 in Google Chrome prior to 148
CVE-2026-7974
8.8
GoogleChrome prior
Use after free in Blink in Google Chrome prior to 148
CVE-2026-7980
8.8
GoogleChrome prior
Use after free in WebAudio in Google Chrome prior to 148
CVE-2026-7984
8.8
GoogleChrome prior
Use after free in ReadingMode in Google Chrome prior to 148
CVE-2026-7987
8.8
GoogleChrome prior
Use after free in WebRTC in Google Chrome prior to 148
CVE-2026-7991
8.8
GoogleChrome prior
Use after free in UI in Google Chrome prior to 148
CVE-2026-8002
8.8
GoogleChrome on
Use after free in Audio in Google Chrome on Mac prior to 148
CVE-2026-8016
8.8
GoogleChrome prior
Use after free in WebRTC in Google Chrome prior to 148
CVE-2026-7900
8.3
GoogleChrome prior
Heap buffer overflow in ANGLE in Google Chrome prior to 148
CVE-2026-7911
8.3
GoogleChrome on
Use after free in Aura in Google Chrome on Windows prior to 148
CVE-2026-7917
8.3
GoogleChrome on
Use after free in Fullscreen in Google Chrome on Windows prior to 148
CVE-2026-7918
8.3
GoogleChrome prior
Use after free in GPU in Google Chrome prior to 148
CVE-2026-7919
8.3
GoogleChrome prior
Use after free in Aura in Google Chrome prior to 148
CVE-2026-7920
8.3
GoogleChrome prior
Use after free in Skia in Google Chrome prior to 148
CVE-2026-7922
8.3
GoogleChrome prior
Use after free in ServiceWorker in Google Chrome prior to 148
CVE-2026-7956
8.3
GoogleChrome prior
Use after free in Navigation in Google Chrome prior to 148
CVE-2026-7970
8.3
GoogleChrome prior
Use after free in TopChrome in Google Chrome prior to 148
CVE-2026-7975
8.3
GoogleChrome prior
Use after free in DevTools in Google Chrome prior to 148
CVE-2026-7985
8.3
GoogleChrome prior
Use after free in GPU in Google Chrome prior to 148
CVE-2026-8001
8.3
GoogleChrome on
Use After Free in Printing in Google Chrome on Linux, Mac, ChromeOS prior to 148
CVE-2026-7896
8.8
GoogleChrome prior
Integer overflow in Blink in Google Chrome prior to 148
CVE-2026-7899
8.8
GoogleChrome prior
Out of bounds read and write in V8 in Google Chrome prior to 148
CVE-2026-7902
8.8
GoogleChrome prior
Out of bounds memory access in V8 in Google Chrome prior to 148
CVE-2026-7903
8.8
GoogleChrome on
Integer overflow in ANGLE in Google Chrome on Mac,Windows prior to 148
CVE-2026-7927
8.8
GoogleChrome prior
Type Confusion in Runtime in Google Chrome prior to 148
CVE-2026-7930
8.8
GoogleChrome prior
Insufficient validation of untrusted input in Cookies in Google Chrome prior to 148
CVE-2026-7951
8.8
GoogleChrome prior
Out of bounds write in WebRTC in Google Chrome prior to 148
CVE-2026-7957
8.8
GoogleChrome on
Out of bounds write in Media in Google Chrome on Mac, iOS prior to 148
CVE-2026-7973
8.8
GoogleChrome on
Integer overflow in Dawn in Google Chrome on Windows prior to 148
CVE-2026-7988
8.8
GoogleChrome prior
Type Confusion in WebRTC in Google Chrome prior to 148
CVE-2026-7992
8.8
GoogleChrome on
Insufficient validation of untrusted input in UI in Google Chrome on Linux, ChromeOS prior to 148
CVE-2026-7995
8.8
GoogleChrome prior
Out of bounds read in AdFilter in Google Chrome prior to 148
CVE-2026-8000
8.8
GoogleChrome on
Insufficient validation of untrusted input in ChromeDriver in Google Chrome on Windows prior to 148
CVE-2026-41143
8.8
HPat line
YesWiki is a wiki system written in PHP
CVE-2026-32207
8.8
AzureMachine Learning
Improper neutralization of input during web page generation ('cross-site scripting') in Azure Machine Learning allows an unauthorized attacker to perform spoofing over a network
CVE-2026-35435
8.6
AzureAI Foundry
Improper access control in Azure AI Foundry M365 published agents allows an unauthorized attacker to elevate privileges over a network
CVE-2026-7905
8.3
GoogleChrome on
Insufficient validation of untrusted input in Media in Google Chrome on Android prior to 148
CVE-2026-7914
8.3
GoogleChrome on
Type Confusion in Accessibility in Google Chrome on Windows prior to 148
CVE-2026-7916
8.3
GoogleChrome prior
Insufficient data validation in InterestGroups in Google Chrome prior to 148
CVE-2026-7923
8.3
GoogleChrome prior
Out of bounds write in Skia in Google Chrome prior to 148
CVE-2026-7963
8.3
GoogleChrome prior
Inappropriate implementation in ServiceWorker in Google Chrome prior to 148
CVE-2026-7967
8.3
GoogleChrome prior
Insufficient validation of untrusted input in Navigation in Google Chrome prior to 148
CVE-2026-34327
8.2
MicrosoftPartner Center
Externally controlled reference to a resource in another sphere in Microsoft Partner Center allows an unauthorized attacker to perform spoofing over a network
CVE-2026-7978
8.1
GoogleChrome on
Inappropriate implementation in Companion in Google Chrome on Mac prior to 148
CVE-2026-7981
8.1
GoogleChrome prior
Out of bounds read in Codecs in Google Chrome prior to 148
CVE-2026-8018
8.1
GoogleChrome prior
Insufficient policy enforcement in DevTools in Google Chrome prior to 148
CVE-2026-41105
8.1
AzureNotification Service
Server-side request forgery (ssrf) in Azure Notification Service allows an authorized attacker to elevate privileges over a network
CVE-2026-7913
7.8
GoogleChrome on
Insufficient policy enforcement in DevTools in Google Chrome on Android prior to 148
CVE-2026-20034
8.8
CiscoUnity Connection
A vulnerability in the web-based management interface of Cisco Unity Connection could allow an authenticated, remote attacker to execute arbitrary code on an affected device
CVE-2026-5127
8.8
WordPressis vulnerable
The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for WordPress is vulnerable to Deserialization of Untrusted Data in versions up to, and including, 4
CVE-2026-6692
8.8
WordPressis vulnerable
The Slider Revolution plugin for WordPress is vulnerable to Arbitrary File Upload in versions 7
CVE-2026-7252
8.1
WordPressis vulnerable
The WP-Optimize – Cache, Compress images, Minify & Clean database to boost page speed & performance plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the unscheduled_original_file_deletion function in all versions up to, and including, 4
A vulnerability has been found in Totolink X5000R 9
CVE-2026-41505
8.7
UnknownMultiple Products
RELATE is a web-based courseware package
CVE-2026-44116
8.6
OpenClawMultiple Products
OpenClaw before 2026
CVE-2026-42047
8.6
InforMultiple Products
Inngest is a platform for running event-driven and scheduled background functions with queueing, retries, and step orchestration
CVE-2026-42449
8.5
MCPMultiple Products
n8n-MCP is an MCP server that provides AI assistants access to n8n node documentation, properties, and operations
CVE-2025-14341
8.3
DivvyDriveMultiple Products
Improperly controlled modification of Dynamically-Determined object attributes, Allocation of resources without limits or throttling vulnerability in DivvyDrive Information Technologies Inc
CVE-2026-41490
8.3
DeltaMultiple Products
Dagster is an orchestration platform for the development, production, and observation of data assets
CVE-2026-41669
8.2
UnknownMultiple Products
Admidio is an open-source user management solution
CVE-2026-41670
8.2
UnknownMultiple Products
Admidio is an open-source user management solution
CVE-2026-43585
8.1
OpenClawMultiple Products
OpenClaw before 2026
CVE-2025-9661
8.1
OneMultiple Products
OS command injection vulneravility in the management gui (maintenance utility) of Hitachi Virtual Storage Platform One Block 23, 24, 26 and 28