Wednesday, May 13, 2026 Archive

Archived Security Snapshot

Critical vulnerabilities, curated daily for security professionals

Archived Security Brief

Wednesday's disclosures center on enterprise cloud and identity infrastructure, with Microsoft Dynamics, Azure Logic Apps, and AWS multi-product vulnerabilities leading the critical findings. Critical CVEs rose sharply to 39 from 12 the prior day (225% increase), while high-priority issues climbed to 100 from 81 (23% increase). Notable critical entries include CVE-2026-42898 (CVSS 9.9) in Microsoft Dynamics, CVE-2026-42823 (CVSS 9.9) in Azure Logic Apps, and CVE-2026-41096 (CVSS 9.8) affecting Microsoft Windows DNS. The disclosure set is dominated by remote code execution and authentication weaknesses across cloud platforms, enterprise SSO, and ERP systems including SAP Enterprise Search and Adobe Connect. With 0% patch availability reported and one Linux Kernel vulnerability (CVE-2026-31431) confirmed under active exploitation, defenders should prioritize compensating controls and monitor vendor advisories closely.

  • Microsoft ecosystem heavily impacted: Windows DNS, Dynamics, Azure Logic Apps, and SSO Plugin all received critical-rated CVEs
  • Critical CVE count jumped to 39, a 225% increase over the prior day's 12
  • High-priority CVEs reached 100, up 23% from 81 the previous day
  • Remote code execution and authentication bypass patterns dominate across cloud, ERP, and identity platforms (AWS, SAP, Adobe Connect)
  • Patch availability stands at 0% across the disclosed set, requiring compensating controls and monitoring
  • One actively exploited vulnerability: CVE-2026-31431 (CVSS 9.5) in the Linux Kernel

Immediate action: Prioritize inventory and exposure assessment for Microsoft Dynamics, Azure Logic Apps, Windows DNS, AWS services, SAP Enterprise Search, and Adobe Connect, and apply vendor mitigations as they become available. With 0% patch availability at disclosure, focus on network segmentation, access restrictions, and detection coverage for the Linux Kernel KEV (CVE-2026-31431) until fixes ship.

How to read this brief

CVSS score (e.g. 9.1) — severity from 0–10. Red marks critical (9+), orange high (7–8.9).

Exploitability — how hard the flaw is to attack, read from the CVSS vector:

  • Network / Adjacent / Local / Physical — how close an attacker must get. Network means reachable over the internet.
  • No / Low / High privileges — the access they need first. No privileges means no login required.
  • No interaction / User interaction — whether a victim has to do something (open a file, click a link). No interaction means fully automatable.

The lower the bar on all three, the easier to exploit at scale — “Network · No privileges · No interaction” is the worst case: hit from anywhere, no credentials, no victim action.

Actively exploited — confirmed under attack in the wild (CISA’s Known Exploited Vulnerabilities catalog). Prioritize these regardless of score.

EPSS · Nth percentile — FIRST.org’s estimated chance a flaw is exploited within 30 days. We flag it only in the top 10% — a statistical signal it’s unusually likely to be targeted, separate from whether attacks are confirmed.

💡 Tip: Swipe CVE cards left to ⭐ star, right to ❌ remove

Section Navigation