Critical vulnerabilities, curated daily for security professionals
๐
Archived Security Brief
Sunday's vulnerability landscape is dominated by ten actively exploited CVEs spanning Microsoft Defender, Trend Micro Apex One, Drupal Core, and a cluster of long-standing Microsoft client-side flaws. No new Critical or High-priority CVEs were disclosed yesterday, matching the prior day's zero Critical count and reflecting a -100% change in High-priority disclosures. Notable exploited issues include CVE-2026-41091 and CVE-2026-45498 in Microsoft Defender, CVE-2026-34926 in Trend Micro Apex One, and CVE-2026-9082 in Drupal Core, all rated CVSS 9.5. Endpoint security platforms and content management systems remain the focal point for attackers, alongside continued opportunistic exploitation of decade-old Microsoft Internet Explorer and DirectX vulnerabilities against unpatched environments. With zero new disclosures requiring triage, defenders should redirect capacity toward verifying patch coverage on the exploited products listed below.
Microsoft Defender and Trend Micro Apex One headline active exploitation, signaling attacker focus on endpoint security tooling itself
Zero new Critical CVEs disclosed (unchanged from prior day)
Zero new High-priority CVEs disclosed (-100% from prior day's 6)
Exploitation patterns span modern enterprise security products (Defender, Apex One, Langflow) and legacy Microsoft client software (IE, DirectX, Windows)
Patch availability for newly disclosed CVEs is 0% because no new CVEs were published; patches exist for all 10 actively exploited items
Immediate action: Prioritize patch verification on Microsoft Defender (CVE-2026-41091, CVE-2026-45498), Trend Micro Apex One (CVE-2026-34926), Drupal Core (CVE-2026-9082), and Langflow (CVE-2025-34291), since these are confirmed under active exploitation. Vendor patches are available for all ten exploited CVEs, so today's effort should focus on coverage gap analysis and confirming deployment across endpoint security and public-facing web stacks.
How to read this brief
CVSS score (e.g. 9.1) โ severity from 0โ10. Red marks critical (9+), orange high (7โ8.9).
Exploitability โ how hard the flaw is to attack, read from the CVSS vector:
Network / Adjacent / Local / Physical โ how close an attacker must get. Network means reachable over the internet.
No / Low / High privileges โ the access they need first. No privileges means no login required.
No interaction / User interaction โ whether a victim has to do something (open a file, click a link). No interaction means fully automatable.
The lower the bar on all three, the easier to exploit at scale โ โNetwork ยท No privileges ยท No interactionโ is the worst case: hit from anywhere, no credentials, no victim action.
๐ด Actively exploited โ confirmed under attack in the wild (CISAโs Known Exploited Vulnerabilities catalog). Prioritize these regardless of score.
EPSS ยท Nth percentile โ FIRST.orgโs estimated chance a flaw is exploited within 30 days. We flag it only in the top 10% โ a statistical signal itโs unusually likely to be targeted, separate from whether attacks are confirmed.
๐ก Tip: Swipe CVE cards left to โญ star, right to โ remove