Thursday, May 28, 2026 Archive

Archived Security Snapshot

Critical vulnerabilities, curated daily for security professionals

Archived Security Brief

Thursday's disclosures center on free5GC's open-source 5G core, with three CVSS 10 vulnerabilities affecting the SMF and core components, alongside critical flaws in IBM Aspera, IBM Langflow, and Synology BeeStation OS. Critical CVEs rose to 19 (up 19% from 16), while high-priority disclosures dropped sharply to 30 (down 68% from 95). Notable issues include CVE-2026-44329 (free5GC SMF, CVSS 10), CVE-2026-45087 (Dalfox, CVSS 10), and CVE-2026-46425 (Budibase, CVSS 9.9). Network function virtualization, low-code platforms, and file transfer infrastructure dominate today's attack surface, with authentication bypass and remote code execution as recurring patterns. Patch availability sits at 0% across yesterday's disclosures, warranting compensating controls and exposure reduction until vendor fixes ship.

  • free5GC 5G core infrastructure carries three CVSS 10 vulnerabilities (CVE-2026-44327, CVE-2026-44329, CVE-2026-44330) affecting SMF and core components
  • Critical CVEs increased 19% to 19 disclosures, with IBM Aspera and IBM Langflow joining the critical tier
  • High-priority CVEs declined 68% to 30, reflecting a narrower but more severe disclosure set
  • Authentication bypass and RCE patterns dominate, hitting Pi.Alert (CVE-2026-44887/44888), Budibase, and Synology BeeStation OS
  • Patch availability stands at 0%, requiring network segmentation and access restriction as primary mitigations
  • Seven actively exploited CVEs include Drupal Core, Trend Micro Apex One, and Nx tooling with confirmed in-the-wild activity

Immediate action: Prioritize isolation of free5GC deployments, IBM Aspera transfer nodes, and Synology BeeStation devices until vendor patches are released, and audit Pi.Alert and Budibase instances exposed to untrusted networks. With 0% patch availability across yesterday's critical disclosures, defenders should apply network-layer restrictions, monitor for exploitation indicators on the seven KEV-listed products, and track vendor advisories for incoming fixes.

How to read this brief

CVSS score (e.g. 9.1) — severity from 0–10. Red marks critical (9+), orange high (7–8.9).

Exploitability — how hard the flaw is to attack, read from the CVSS vector:

  • Network / Adjacent / Local / Physical — how close an attacker must get. Network means reachable over the internet.
  • No / Low / High privileges — the access they need first. No privileges means no login required.
  • No interaction / User interaction — whether a victim has to do something (open a file, click a link). No interaction means fully automatable.

The lower the bar on all three, the easier to exploit at scale — “Network · No privileges · No interaction” is the worst case: hit from anywhere, no credentials, no victim action.

Actively exploited — confirmed under attack in the wild (CISA’s Known Exploited Vulnerabilities catalog). Prioritize these regardless of score.

EPSS · Nth percentile — FIRST.org’s estimated chance a flaw is exploited within 30 days. We flag it only in the top 10% — a statistical signal it’s unusually likely to be targeted, separate from whether attacks are confirmed.

💡 Tip: Swipe CVE cards left to ⭐ star, right to ❌ remove

Section Navigation