Thursday, May 28, 2026 Archive

Archived Security Snapshot

Critical vulnerabilities, curated daily for security professionals

🎯 SSCV Profile

See how vulnerabilities affect your specific environment

CRS uses the System Security Context Vector (SSCV) Framework v1.0 to adjust CVSS scores based on your system's exposure level, network position, and business criticality. Learn more about SSCV Framework

Risk scores will be adjusted based on your selected environment

Archived Security Brief

Thursday's disclosures center on free5GC's open-source 5G core, with three CVSS 10 vulnerabilities affecting the SMF and core components, alongside critical flaws in IBM Aspera, IBM Langflow, and Synology BeeStation OS. Critical CVEs rose to 19 (up 19% from 16), while high-priority disclosures dropped sharply to 30 (down 68% from 95). Notable issues include CVE-2026-44329 (free5GC SMF, CVSS 10), CVE-2026-45087 (Dalfox, CVSS 10), and CVE-2026-46425 (Budibase, CVSS 9.9). Network function virtualization, low-code platforms, and file transfer infrastructure dominate today's attack surface, with authentication bypass and remote code execution as recurring patterns. Patch availability sits at 0% across yesterday's disclosures, warranting compensating controls and exposure reduction until vendor fixes ship.

  • free5GC 5G core infrastructure carries three CVSS 10 vulnerabilities (CVE-2026-44327, CVE-2026-44329, CVE-2026-44330) affecting SMF and core components
  • Critical CVEs increased 19% to 19 disclosures, with IBM Aspera and IBM Langflow joining the critical tier
  • High-priority CVEs declined 68% to 30, reflecting a narrower but more severe disclosure set
  • Authentication bypass and RCE patterns dominate, hitting Pi.Alert (CVE-2026-44887/44888), Budibase, and Synology BeeStation OS
  • Patch availability stands at 0%, requiring network segmentation and access restriction as primary mitigations
  • Seven actively exploited CVEs include Drupal Core, Trend Micro Apex One, and Nx tooling with confirmed in-the-wild activity

Immediate action: Prioritize isolation of free5GC deployments, IBM Aspera transfer nodes, and Synology BeeStation devices until vendor patches are released, and audit Pi.Alert and Budibase instances exposed to untrusted networks. With 0% patch availability across yesterday's critical disclosures, defenders should apply network-layer restrictions, monitor for exploitation indicators on the seven KEV-listed products, and track vendor advisories for incoming fixes.

πŸ’‘ Tip: Swipe CVE cards left to ⭐ star, right to ❌ remove

Section Navigation