Critical vulnerabilities, curated daily for security professionals
π
Archived Security Brief
Sunday's disclosures center on high-severity flaws in enterprise infrastructure, with actively exploited weaknesses surfacing in Oracle WebLogic Server, SolarWinds Serv-U, and the Linux kernel. No critical CVEs (CVSS 9.0+) were disclosed, down from 10 the prior day, while high-priority vulnerabilities totaled 23, a 23% decrease from 30. Among the actively exploited issues are CVE-2024-21182 in Oracle WebLogic Server (CVSS 9.5), CVE-2026-28318 in SolarWinds Serv-U (CVSS 9.5), and CVE-2022-0492 in the Linux kernel (CVSS 9.5). The activity spans web application servers, file transfer software, container runtimes, and mobile platforms, with several entries tied to privilege escalation and remote code execution. Patch availability for today's set is limited, so teams should prioritize the exploited items and apply vendor mitigations where fixes are pending.
Oracle WebLogic Server, SolarWinds Serv-U, and the Linux kernel headline today's set with confirmed active exploitation
No new critical CVEs (CVSS 9.0+), down 100% from 10 the prior day
23 high-priority CVEs disclosed, a 23% decrease from 30
Privilege escalation and remote code execution patterns affect web servers, file transfer tools, and container runtimes
Patch availability stands at 0% for this set, requiring interim mitigations for unpatched issues
5 actively exploited vulnerabilities span Oracle, SolarWinds, Linux, Android Framework, and a Magento extension
Immediate action: Prioritize Oracle WebLogic Server, SolarWinds Serv-U, Linux kernel, Android Framework, and the Mirasvit Magento cache warmer, as all have confirmed active exploitation. With no patches currently available for today's disclosures, apply vendor-recommended workarounds, restrict exposed services, and monitor affected systems until fixes are released.
How to read this brief
CVSS score (e.g. 9.1) β severity from 0β10. Red marks critical (9+), orange high (7β8.9).
Exploitability β how hard the flaw is to attack, read from the CVSS vector:
Network / Adjacent / Local / Physical β how close an attacker must get. Network means reachable over the internet.
No / Low / High privileges β the access they need first. No privileges means no login required.
No interaction / User interaction β whether a victim has to do something (open a file, click a link). No interaction means fully automatable.
The lower the bar on all three, the easier to exploit at scale β βNetwork Β· No privileges Β· No interactionβ is the worst case: hit from anywhere, no credentials, no victim action.
π΄ Actively exploited β confirmed under attack in the wild (CISAβs Known Exploited Vulnerabilities catalog). Prioritize these regardless of score.
EPSS Β· Nth percentile β FIRST.orgβs estimated chance a flaw is exploited within 30 days. We flag it only in the top 10% β a statistical signal itβs unusually likely to be targeted, separate from whether attacks are confirmed.
π‘ Tip: Swipe CVE cards left to β star, right to β remove
A privilege escalation vulnerability in the Linux Kernel cgroup_release_agent_write function allows unprivileged users to escape container environments and gain elevated host privileges.
An integer overflow vulnerability in the Android Framework allows for potential unauthorized system access and is currently tracked in the CISA KEV catalog.
SolarWinds Serv-U is vulnerable to an uncontrolled resource consumption flaw allowing unauthenticated attackers to crash the service via specially crafted POST requests.
The Admin Columns plugin for WordPress is vulnerable to PHP Object Injection, which can lead to Remote Code Execution via unvalidated post meta values.
An authentication bypass vulnerability in the WordPress WP Captcha PRO plugin allows authenticated attackers to log in as any user, including administrators.
An improper link resolution vulnerability in Pardus About enables symlink attacks, potentially allowing for unauthorized file access or privilege escalation.
Ergosis SecuritySecurity Systems Computer Industry and Trade Inc
Ergosis Security systems are vulnerable to SQL Injection, allowing unauthorized database access through the improper neutralization of special elements in SQL commands.
Markdown Preview Enhanced contains vulnerabilities allowing for OS command injection and arbitrary JavaScript execution via untrusted markdown content.
Markdown Preview Enhanced contains a remote code execution vulnerability due to improper parsing of Bitfield fenced code blocks using unsafe JavaScript evaluation.
Markdown Preview Enhanced is vulnerable to remote code execution because it evaluates untrusted WaveDrom diagram data using the unsafe `eval()` function.
Rolantis Information Technologies Agentis is susceptible to a session fixation vulnerability that allows unauthorized attackers to hijack valid user sessions.
A Cross-site Scripting (XSS) vulnerability in Karel Electronics software allows attackers to inject malicious scripts into web pages generated by the application.
Dinibh Puzzle Software SolutionsDinibh Patrol Tracking System
An authorization bypass vulnerability in the Dinibh Patrol Tracking System allows authenticated users to exploit trusted identifiers and gain unauthorized system control.