Friday, May 29, 2026 Archive

Archived Security Snapshot

Critical vulnerabilities, curated daily for security professionals

Archived Security Brief

Oracle dominates Friday's disclosures with multiple near-maximum-severity flaws across REST Data Services, iAssets, and Universal Work Queue, joined by a perfect-score SandboxJS sandbox escape that exposes server-side JavaScript execution. The brief covers 19 critical CVEs, unchanged from the prior day, and 58 high-priority CVEs, a 93% increase over yesterday's 30. CVE-2026-46840 (CVSS 10, Oracle REST Data Services) and CVE-2026-43898 (CVSS 10, SandboxJS) headline the critical set, with CVE-2026-46775 (CVSS 9.9, Oracle REST Data Services) and a string of CVSS 9.8 WordPress plugin flaws including CVE-2026-3655 and CVE-2026-8809 close behind. Remote code execution and authentication bypass patterns predominate, concentrated in enterprise middleware, identity infrastructure, and the WordPress plugin ecosystem. No patches are currently reflected for the disclosed set, so affected operators should prioritize compensating controls and vendor advisory monitoring; five vulnerabilities, including flaws in Drupal Core and GitHub Actions OIDC, have confirmed active exploitation.

  • Oracle accounts for several near-maximum-severity flaws, led by CVE-2026-46840 (CVSS 10, REST Data Services) and CVE-2026-46775 (CVSS 9.9), plus iAssets and Universal Work Queue (both CVSS 9.9)
  • 19 critical CVEs (CVSS 9.0+), unchanged from the prior day
  • 58 high-priority CVEs (CVSS 7.0-8.9), a 93% increase from 30 yesterday
  • Remote code execution and authentication bypass dominate, including the CVSS 10 SandboxJS escape (CVE-2026-43898) and CVSS 9.8 WordPress plugin flaws (CVE-2026-3655, CVE-2026-8809)
  • Patch availability stands at 0% across the disclosed set, leaving Oracle middleware and WordPress plugin deployments exposed pending vendor fixes
  • Five vulnerabilities show confirmed active exploitation, spanning Drupal Core, LiteSpeed cPanel, GitHub Actions OIDC, and Nx

Immediate action: Prioritize Oracle REST Data Services, iAssets, and Universal Work Queue instances along with SandboxJS deployments and the affected WordPress plugins, restricting external access and applying compensating controls where exposure exists. With no patches reflected for the disclosed set, monitor vendor advisories closely and expedite remediation for the five actively exploited issues, including Drupal Core and GitHub Actions OIDC, as fixes become available.

How to read this brief

CVSS score (e.g. 9.1) β€” severity from 0–10. Red marks critical (9+), orange high (7–8.9).

Exploitability β€” how hard the flaw is to attack, read from the CVSS vector:

  • Network / Adjacent / Local / Physical β€” how close an attacker must get. Network means reachable over the internet.
  • No / Low / High privileges β€” the access they need first. No privileges means no login required.
  • No interaction / User interaction β€” whether a victim has to do something (open a file, click a link). No interaction means fully automatable.

The lower the bar on all three, the easier to exploit at scale β€” β€œNetwork Β· No privileges Β· No interaction” is the worst case: hit from anywhere, no credentials, no victim action.

Actively exploited β€” confirmed under attack in the wild (CISA’s Known Exploited Vulnerabilities catalog). Prioritize these regardless of score.

EPSS Β· Nth percentile β€” FIRST.org’s estimated chance a flaw is exploited within 30 days. We flag it only in the top 10% β€” a statistical signal it’s unusually likely to be targeted, separate from whether attacks are confirmed.

πŸ’‘ Tip: Swipe CVE cards left to ⭐ star, right to ❌ remove

Section Navigation