Critical vulnerabilities, curated daily for security professionals
π
Archived Security Brief
Saturday's disclosure activity centered on a small set of high-severity vulnerabilities, while CISA's KEV catalog highlighted ongoing exploitation of Drupal Core (CVE-2026-9082), Microsoft Defender (CVE-2026-41091, CVE-2026-45498), and Trend Micro Apex One (CVE-2026-34926). The day brought zero critical CVEs (down 100% from 11 yesterday) and six high-priority CVEs (down 91% from 64), reflecting a typical weekend slowdown in disclosures. Notable KEV additions include Langflow (CVE-2025-34291) and a fresh Drupal Core flaw, alongside several legacy Microsoft and Adobe entries being revisited for exploitation tracking. Attack patterns remain focused on endpoint security products and content management platforms, with Defender and Apex One both showing actively exploited weaknesses. Patch availability for yesterday's disclosed CVEs sits at 0%, so defenders should prioritize compensating controls and vendor advisory monitoring over weekend patching cycles.
Microsoft Defender and Trend Micro Apex One both appear in KEV with CVSS 9.5 actively exploited flaws
Zero critical CVEs disclosed, down 100% from 11 the prior day
Six high-priority CVEs disclosed, down 91% from 64 the prior day
Patch availability at 0% for yesterday's high-priority disclosures
Ten CVEs flagged as actively exploited, unchanged from the prior day
Immediate action: Prioritize review of Microsoft Defender (CVE-2026-41091, CVE-2026-45498), Trend Micro Apex One (CVE-2026-34926), and Drupal Core (CVE-2026-9082) deployments, as these endpoint and CMS products are under active exploitation. With zero patches available for yesterday's high-priority CVEs, monitor vendor advisories closely and apply compensating controls such as network segmentation and enhanced logging until fixes ship.
How to read this brief
CVSS score (e.g. 9.1) β severity from 0β10. Red marks critical (9+), orange high (7β8.9).
Exploitability β how hard the flaw is to attack, read from the CVSS vector:
Network / Adjacent / Local / Physical β how close an attacker must get. Network means reachable over the internet.
No / Low / High privileges β the access they need first. No privileges means no login required.
No interaction / User interaction β whether a victim has to do something (open a file, click a link). No interaction means fully automatable.
The lower the bar on all three, the easier to exploit at scale β βNetwork Β· No privileges Β· No interactionβ is the worst case: hit from anywhere, no credentials, no victim action.
π΄ Actively exploited β confirmed under attack in the wild (CISAβs Known Exploited Vulnerabilities catalog). Prioritize these regardless of score.
EPSS Β· Nth percentile β FIRST.orgβs estimated chance a flaw is exploited within 30 days. We flag it only in the top 10% β a statistical signal itβs unusually likely to be targeted, separate from whether attacks are confirmed.
π‘ Tip: Swipe CVE cards left to β star, right to β remove
A time-of-check time-of-use (TOCTOU) vulnerability in the Trend Micro Apex One agent iCore service signature verification allows for local privilege escalation.