Thursday, May 14, 2026 Archive

Archived Security Snapshot

Critical vulnerabilities, curated daily for security professionals

Archived Security Brief

Thursday's disclosures center on multiple maximum-severity Node.js vm2 sandbox escape vulnerabilities affecting server-side JavaScript execution environments. Critical CVE volume dropped to 16 from 39 the prior day (-59%), while high-priority CVEs held steady at 100. Notable critical items include CVE-2026-44005, CVE-2026-43997, and CVE-2026-44006 (all CVSS 10) targeting Node.js vm2, CVE-2026-44442 (CVSS 9.9) in ERPNext, and CVE-2026-41050 (CVSS 9.9) in Rancher Fleet. Attack patterns are dominated by sandbox escape and remote code execution, with secondary clusters in WordPress plugins (CVE-2026-6271, CVE-2026-6510) and mail security gateways. Patch availability sits at 0% for today's disclosures, so defenders should rely on compensating controls and vendor advisories until fixes ship.

  • Node.js vm2 library hit with multiple CVSS 10 sandbox escape vulnerabilities (CVE-2026-44005, CVE-2026-43997, CVE-2026-44006)
  • 16 critical CVEs disclosed, down 59% from prior day's 39
  • 100 high-priority CVEs disclosed, unchanged from prior day
  • Remote code execution and sandbox escape dominate, with ERPNext (CVE-2026-44442) and Rancher Fleet (CVE-2026-41050) also affected
  • 0% patch availability across today's critical disclosures; mitigations required pending vendor fixes
  • 1 actively exploited vulnerability in Linux Kernel (CVE-2026-31431, CVSS 9.5) carried over from prior reporting

Immediate action: Prioritize inventory and isolation of any Node.js services using the vm2 sandbox library, as three CVSS 10 escapes enable code execution on host systems; WordPress plugin and ERPNext deployments should also be reviewed for exposure. With no patches available for today's critical issues, apply network segmentation, restrict untrusted input to vm2-based workloads, and monitor vendor advisories for fix releases.

How to read this brief

CVSS score (e.g. 9.1) โ€” severity from 0โ€“10. Red marks critical (9+), orange high (7โ€“8.9).

Exploitability โ€” how hard the flaw is to attack, read from the CVSS vector:

  • Network / Adjacent / Local / Physical โ€” how close an attacker must get. Network means reachable over the internet.
  • No / Low / High privileges โ€” the access they need first. No privileges means no login required.
  • No interaction / User interaction โ€” whether a victim has to do something (open a file, click a link). No interaction means fully automatable.

The lower the bar on all three, the easier to exploit at scale โ€” โ€œNetwork ยท No privileges ยท No interactionโ€ is the worst case: hit from anywhere, no credentials, no victim action.

Actively exploited โ€” confirmed under attack in the wild (CISAโ€™s Known Exploited Vulnerabilities catalog). Prioritize these regardless of score.

EPSS ยท Nth percentile โ€” FIRST.orgโ€™s estimated chance a flaw is exploited within 30 days. We flag it only in the top 10% โ€” a statistical signal itโ€™s unusually likely to be targeted, separate from whether attacks are confirmed.

๐Ÿ’ก Tip: Swipe CVE cards left to โญ star, right to โŒ remove

Section Navigation