Friday, September 18, 2026 Archive

Archived Security Snapshot

Critical vulnerabilities, curated daily for security professionals

Archived Security Brief

Sandbox escape flaws in patriksimek vm2 and maximum-severity issues across Microsoft cloud services lead yesterday's disclosures, with four vm2 CVEs scored 9.9 or 10 alongside CVE-2026-69843 in Microsoft Fabric and CVE-2026-62874 in Azure Billing at CVSS 10. Twenty-eight critical CVEs were disclosed, up 47% from the prior day's 19, while high-priority disclosures fell 29% to 62 for a total of 90. Also notable are CVE-2026-54734 in Prebid prebid-server-java at CVSS 10, CVE-2026-85885 in Microsoft 365 Copilot at 9.9, and CVE-2026-67100 in HCL BigFix Service Management at 9.8. The pattern favors code execution through untrusted input handling: JavaScript sandbox escapes, server-side ad exchange processing, and AI assistant integrations, all of which sit on paths that accept attacker-supplied content by design. Six CVEs carry confirmed active exploitation, including CVE-2026-76460 in Cisco Identity Services Engine (CVSS 10) and two JFrog Artifactory flaws, so verify version status with each vendor and restrict management interface access on identity, email gateway, and artifact repository systems first.

  • Four patriksimek vm2 sandbox escapes (CVE-2026-92941 at CVSS 10, CVE-2026-92938, CVE-2026-92939 and CVE-2026-92948 at 9.9) affect any service running untrusted JavaScript in-process
  • 28 critical CVEs (CVSS 9.0+), up 47% from 19 the prior day
  • 62 high-priority CVEs (CVSS 7.0-8.9), down 29% from 87
  • Attack patterns center on remote code execution and privilege escalation through untrusted input: vm2 sandbox escape, Prebid prebid-server-java (CVE-2026-54734, CVSS 10), and Microsoft 365 Copilot (CVE-2026-85885, CVSS 9.9)
  • Check Microsoft Fabric (CVE-2026-69843), Azure Billing (CVE-2026-62874), HCL BigFix Service Management (CVE-2026-67100), and any Node.js service embedding vm2 first
  • Six CVEs have confirmed active exploitation, spanning Cisco ISE and Secure Email Gateway, JFrog Artifactory, Acronis Backup, and Google Pixel

Immediate action: Prioritize the actively exploited systems: Cisco Identity Services Engine and Secure Email Gateway, JFrog Artifactory, Acronis Backup, and Google Pixel, followed by internet-reachable Microsoft cloud tenants and any Node.js application embedding vm2 for untrusted code execution. Confirm the fixed version and current fix status in each vendor's advisory before scheduling maintenance, since the affected version ranges vary by deployment and release channel. Where a fix is not yet deployable, restrict network access to management interfaces and review logs on the exploited products for signs of prior access.

How to read this brief

CVSS score (e.g. 9.1) — severity from 0–10. Red marks critical (9+), orange high (7–8.9).

Exploitability — how hard the flaw is to attack, read from the CVSS vector:

  • Network / Adjacent / Local / Physical — how close an attacker must get. Network means reachable over the internet.
  • No / Low / High privileges — the access they need first. No privileges means no login required.
  • No interaction / User interaction — whether a victim has to do something (open a file, click a link). No interaction means fully automatable.

The lower the bar on all three, the easier to exploit at scale — “Network · No privileges · No interaction” is the worst case: hit from anywhere, no credentials, no victim action.

Actively exploited — confirmed under attack in the wild (CISA’s Known Exploited Vulnerabilities catalog). Prioritize these regardless of score.

EPSS · Nth percentile — FIRST.org’s estimated chance a flaw is exploited within 30 days. We flag it only in the top 10% — a statistical signal it’s unusually likely to be targeted, separate from whether attacks are confirmed.

💡 Tip: Swipe CVE cards left to ⭐ star, right to ❌ remove

Section Navigation