Critical vulnerabilities, curated daily for security professionals
đ¯ SSCV Profile
See how vulnerabilities affect your specific environment
CRS uses the System Security Context Vector (SSCV) Framework v1.0 to adjust CVSS scores based on your system's exposure level, network position, and business criticality. Learn more about SSCV Framework
Risk scores will be adjusted based on your selected environment
đ
Archived Security Brief
Saturday's disclosure activity centered on a small set of high-severity vulnerabilities, while CISA's KEV catalog highlighted ongoing exploitation of Drupal Core (CVE-2026-9082), Microsoft Defender (CVE-2026-41091, CVE-2026-45498), and Trend Micro Apex One (CVE-2026-34926). The day brought zero critical CVEs (down 100% from 11 yesterday) and six high-priority CVEs (down 91% from 64), reflecting a typical weekend slowdown in disclosures. Notable KEV additions include Langflow (CVE-2025-34291) and a fresh Drupal Core flaw, alongside several legacy Microsoft and Adobe entries being revisited for exploitation tracking. Attack patterns remain focused on endpoint security products and content management platforms, with Defender and Apex One both showing actively exploited weaknesses. Patch availability for yesterday's disclosed CVEs sits at 0%, so defenders should prioritize compensating controls and vendor advisory monitoring over weekend patching cycles.
Microsoft Defender and Trend Micro Apex One both appear in KEV with CVSS 9.5 actively exploited flaws
Zero critical CVEs disclosed, down 100% from 11 the prior day
Six high-priority CVEs disclosed, down 91% from 64 the prior day
Drupal Core CVE-2026-9082 and Langflow CVE-2025-34291 added to active exploitation tracking
Patch availability at 0% for yesterday's high-priority disclosures
Ten CVEs flagged as actively exploited, unchanged from the prior day
Immediate action: Prioritize review of Microsoft Defender (CVE-2026-41091, CVE-2026-45498), Trend Micro Apex One (CVE-2026-34926), and Drupal Core (CVE-2026-9082) deployments, as these endpoint and CMS products are under active exploitation. With zero patches available for yesterday's high-priority CVEs, monitor vendor advisories closely and apply compensating controls such as network segmentation and enhanced logging until fixes ship.
đĄ Tip: Swipe CVE cards left to â star, right to â remove
Section Navigation
â ī¸
CISA Known Exploited Vulnerabilities
â ī¸ CISA KEVURGENT
CVE-2026-9082
9.5
DrupalCore
â° Federal Deadline:May 26, 2026(4 days remaining)
Drupal Core SQL Injection Vulnerability - Active in CISA KEV catalog.
CVSS Base9.5
â
CRSSelect profile
â ī¸ CISA KEV
CVE-2008-4250
9.5đ Late Disclosure
MicrosoftWindows
â° Federal Deadline:June 2, 2026(11 days remaining)
Microsoft Windows Buffer Overflow Vulnerability - Active in CISA KEV catalog.
CVSS Base9.5
â
CRSSelect profile
â ī¸ CISA KEV
CVE-2009-1537
9.5đ Late Disclosure
MicrosoftDirectX
â° Federal Deadline:June 2, 2026(11 days remaining)
Microsoft DirectX NULL Byte Overwrite Vulnerability - Active in CISA KEV catalog.
CVSS Base9.5
â
CRSSelect profile
â ī¸ CISA KEV
CVE-2009-3459
9.5đ Late Disclosure
AdobeAcrobat and Reader
â° Federal Deadline:June 2, 2026(11 days remaining)
Adobe Acrobat and Reader Heap-Based Buffer Overflow Vulnerability - Active in CISA KEV catalog.
CVSS Base9.5
â
CRSSelect profile
â ī¸ CISA KEV
CVE-2010-0249
9.5đ Late Disclosure
MicrosoftInternet Explorer
â° Federal Deadline:June 2, 2026(11 days remaining)
Microsoft Internet Explorer Use-After-Free Vulnerability - Active in CISA KEV catalog.
CVSS Base9.5
â
CRSSelect profile
â ī¸ CISA KEV
CVE-2010-0806
9.5đ Late Disclosure
MicrosoftInternet Explorer
â° Federal Deadline:June 2, 2026(11 days remaining)
Microsoft Internet Explorer Use-After-Free Vulnerability - Active in CISA KEV catalog.
CVSS Base9.5
â
CRSSelect profile
â ī¸ CISA KEV
CVE-2026-41091
9.5
MicrosoftDefender
â° Federal Deadline:June 2, 2026(11 days remaining)
Microsoft Defender Link Following Vulnerability - Active in CISA KEV catalog.
CVSS Base9.5
â
CRSSelect profile
â ī¸ CISA KEV
CVE-2026-45498
9.5
MicrosoftDefender
â° Federal Deadline:June 2, 2026(11 days remaining)
Microsoft Defender Denial of Service Vulnerability - Active in CISA KEV catalog.
CVSS Base9.5
â
CRSSelect profile
â ī¸ CISA KEV
CVE-2025-34291
9.5
LangflowLangflow
â° Federal Deadline:June 3, 2026(12 days remaining)
Langflow Origin Validation Error Vulnerability - Active in CISA KEV catalog.
CVSS Base9.5
â
CRSSelect profile
â ī¸ CISA KEV
CVE-2026-34926
9.5
Trend MicroApex One
â° Federal Deadline:June 3, 2026(12 days remaining)
Trend Micro Apex One (On-Premise) Directory Traversal Vulnerability - Active in CISA KEV catalog.
CVSS Base9.5
â
CRSSelect profile
â ī¸
High Priority Updates
CVE-2025-71215
7đ
Trend MicroApex One
A time-of-check time-of-use (TOCTOU) vulnerability in the Trend Micro Apex One agent iCore service signature verification allows for local privilege escalation.
CVSS Base7
â
CRSSelect profile
CVE-2026-48237
7.1đ
HPUnknown
A high-severity vulnerability has been identified in HP products that may lead to unauthorized system access or compromise.
CVSS Base7.1
â
CRSSelect profile
CVE-2026-48238
7.1đ
HPUnknown
A high-severity vulnerability identified in HP products may allow for unauthorized system access or potential compromise.
CVSS Base7.1
â
CRSSelect profile
CVE-2026-48239
7.1đ
HPUnknown
A high-severity vulnerability has been identified in HP products, which could potentially lead to unauthorized access or system impact.
CVSS Base7.1
â
CRSSelect profile
CVE-2026-48240
7.1đ
HPUnknown
A high-severity vulnerability in HP products could allow for unauthorized access or other security impacts on the system.
CVSS Base7.1
â
CRSSelect profile
CVE-2026-48236
7.1đ
Open ISESTickets
Open ISES Tickets software versions prior to 3 contain a vulnerability that may allow for unauthorized access or system compromise.