Critical vulnerabilities, curated daily for security professionals
📊
Archived Security Brief
Monday's disclosures concentrate on network edge and enterprise communications platforms, led by multiple Ubiquiti UniFi OS flaws, a Cisco Unified Communications Manager defect, and PTC Windchill/FlexPLM. No new critical-rated (CVSS 9.0+) CVEs were recorded, down from 1 the prior day, while high-priority CVEs fell to 24 from 55, a 56% decrease. Notable entries include CVE-2026-34910, CVE-2026-34909, and CVE-2026-34908 affecting Ubiquiti UniFi OS, CVE-2026-20230 in Cisco Unified CM, and CVE-2026-12569 in PTC Windchill and FlexPLM, all scored 9.5. Six of these vulnerabilities carry confirmed active exploitation, spanning network appliances, IoT device servers, and PLM systems. No patches were available across the disclosed set at publication time, so affected organizations should prioritize monitoring and compensating controls until vendor fixes ship.
Zero new critical-rated CVEs, down 100% from 1 the prior day
24 high-priority CVEs, down 56% from 55 the prior day
Exploitation activity targets network and communications infrastructure, including Cisco Unified CM (CVE-2026-20230) and PTC Windchill/FlexPLM (CVE-2026-12569)
Patch availability stands at 0% across the disclosed set, leaving affected systems reliant on mitigations
Six vulnerabilities have confirmed active exploitation, also including Lantronix EDS5000 (CVE-2025-67038)
Immediate action: Prioritize Ubiquiti UniFi OS, Cisco Unified Communications Manager, PTC Windchill/FlexPLM, and Lantronix EDS5000 deployments, as these carry actively exploited vulnerabilities. With no patches currently available, restrict network exposure of these systems, apply vendor-recommended mitigations, and increase monitoring until fixes are released.
How to read this brief
CVSS score (e.g. 9.1) — severity from 0–10. Red marks critical (9+), orange high (7–8.9).
Exploitability — how hard the flaw is to attack, read from the CVSS vector:
Network / Adjacent / Local / Physical — how close an attacker must get. Network means reachable over the internet.
No / Low / High privileges — the access they need first. No privileges means no login required.
No interaction / User interaction — whether a victim has to do something (open a file, click a link). No interaction means fully automatable.
The lower the bar on all three, the easier to exploit at scale — “Network · No privileges · No interaction” is the worst case: hit from anywhere, no credentials, no victim action.
🔴 Actively exploited — confirmed under attack in the wild (CISA’s Known Exploited Vulnerabilities catalog). Prioritize these regardless of score.
EPSS · Nth percentile — FIRST.org’s estimated chance a flaw is exploited within 30 days. We flag it only in the top 10% — a statistical signal it’s unusually likely to be targeted, separate from whether attacks are confirmed.
💡 Tip: Swipe CVE cards left to ⭐ star, right to ❌ remove
A path traversal vulnerability in Ubiquiti UniFi OS allows network-adjacent attackers to read sensitive system files and potentially compromise user accounts.
An improper access control vulnerability in Ubiquiti UniFi OS devices allows network-adjacent attackers to modify system configurations without authorization.
PTC Windchill and FlexPLM are vulnerable to improper input validation, allowing for potential exploitation. This vulnerability is confirmed as actively exploited in the wild.
A server-side request forgery (SSRF) vulnerability in Cisco Unified Communications Manager allows unauthenticated remote attackers to perform arbitrary file operations and escalate privileges to root.
A high-severity security vulnerability has been identified in the yashpokharna2555 Restaurant Management System, potentially allowing for unauthorized system impact.
A critical vulnerability has been discovered in the D-Link DCS-935L network camera, potentially allowing attackers to gain unauthorized access to the device.
A security vulnerability has been detected in the Tenda JD12L router, requiring immediate investigation and remediation to prevent potential exploitation.
A security weakness has been identified in the itsourcecode Baptism Information Management System that could potentially allow for unauthorized system interaction.
A security vulnerability has been identified in the SourceCodester Class and Exam Timetabling System that requires immediate attention from system administrators.
A security vulnerability has been identified in the SourceCodester Class and Exam Timetabling System that may expose the application to unauthorized access or manipulation.
A security weakness has been identified in the ANTLR4 parser generator, potentially impacting applications that rely on its framework for processing input data.
A vulnerability has been identified in the SourceCodester Class and Exam Timetabling System, which may allow attackers to exploit flaws in the application's handling of user requests.
A security flaw has been discovered in the SourceCodester Class and Exam Timetabling System, potentially exposing the application to unauthorized exploitation.