Friday, May 22, 2026 Archive

Archived Security Snapshot

Critical vulnerabilities, curated daily for security professionals

Archived Security Brief

Friday's vulnerability landscape is led by three maximum-severity (CVSS 10) flaws in Ubiquiti UniFi OS and multiple critical WordPress plugin issues affecting widely deployed infrastructure. Critical CVE volume rose 10% to 11, while high-priority disclosures climbed 45% to 64, indicating broader product impact across the disclosure cycle. Notable critical entries include CVE-2026-34908/34909/34910 in Ubiquiti UniFi OS, CVE-2026-48207 in Apache Fory PyFory, and CVE-2026-5433 in Honeywell Control Network. Attack patterns skew toward remote code execution and authentication bypass against network appliances, endpoint security platforms, and content management systems. Patches are not yet broadly published for today's disclosures, so defenders should prioritize compensating controls and monitor vendor advisories closely.

  • Three CVSS 10 vulnerabilities in Ubiquiti UniFi OS (CVE-2026-34908, 34909, 34910) affecting network infrastructure
  • Critical CVEs up 10% day-over-day to 11, including WordPress plugin flaws CVE-2026-6960 and CVE-2026-5118 at CVSS 9.8
  • High-priority disclosures up 45% to 64, reflecting wider product exposure across vendors
  • Trend Micro Apex One Management Console hit by twin CVSS 9.8 flaws (CVE-2025-71210, CVE-2025-71211) enabling remote compromise
  • Apache Fory PyFory deserialization issue (CVE-2026-48207, CVSS 9.8) threatens Python-based data pipelines
  • 10 actively exploited CVEs tracked, including CVE-2026-42897 in Microsoft and CVE-2026-34926 in Trend Micro Apex One

Immediate action: Prioritize Ubiquiti UniFi OS, Trend Micro Apex One, and WordPress plugin environments for immediate review, as these carry the highest combination of severity and exposure. With 0% patch availability reported for today's disclosures, restrict management interface exposure, apply vendor-provided mitigations, and monitor advisories for forthcoming fixes.

How to read this brief

CVSS score (e.g. 9.1) โ€” severity from 0โ€“10. Red marks critical (9+), orange high (7โ€“8.9).

Exploitability โ€” how hard the flaw is to attack, read from the CVSS vector:

  • Network / Adjacent / Local / Physical โ€” how close an attacker must get. Network means reachable over the internet.
  • No / Low / High privileges โ€” the access they need first. No privileges means no login required.
  • No interaction / User interaction โ€” whether a victim has to do something (open a file, click a link). No interaction means fully automatable.

The lower the bar on all three, the easier to exploit at scale โ€” โ€œNetwork ยท No privileges ยท No interactionโ€ is the worst case: hit from anywhere, no credentials, no victim action.

Actively exploited โ€” confirmed under attack in the wild (CISAโ€™s Known Exploited Vulnerabilities catalog). Prioritize these regardless of score.

EPSS ยท Nth percentile โ€” FIRST.orgโ€™s estimated chance a flaw is exploited within 30 days. We flag it only in the top 10% โ€” a statistical signal itโ€™s unusually likely to be targeted, separate from whether attacks are confirmed.

๐Ÿ’ก Tip: Swipe CVE cards left to โญ star, right to โŒ remove

Section Navigation