tag: Critical-Cve · 4 items
- Engineer — Act: Public PoC on GitHub for unauthenticated RCE in a ubiquitous web framework clears the bar for immediate action — upgrade Next.js to the patched release now, prioritizing any Windows-hosted deployments and any apps accepting untrusted image uploads.
- SOC/IR — Plan: With a public PoC and no KEV listing yet, build detections for suspicious AVIF uploads and Windows-style path traversal sequences (e.g. ..) in HTTP requests targeting Next.js routes before active exploitation begins.
- Leader — Plan: Two critical unauthenticated RCE flaws with public PoC in a widely-deployed framework warrant confirming this quarter that your engineering teams have inventoried Next.js usage and applied patches — flag for a status check if any customer-facing apps are affected.
- Signals: CVE-2026-75604 — CISA KEV: not listed, EPSS n/a, public PoC on GitHub
- Engineer — Plan: Five CVSS 10.0 flaws are severe on paper, but no KEV listing, PoC, or active exploitation is signaled — schedule patching of Crosswork Data Gateway, Crosswork Network Controller, Crosswork Planning, and Secure Workload this cycle rather than as emergency response.
- SOC/IR — Skip
- Leader — Skip
- Engineer — Act: Four KEV-listed critical vulns across platforms you likely run — patch macOS (CVE-2026-65400, CVSS 9.8), SharePoint, vCenter, and Microsoft IKE immediately; a public PoC exists for the macOS flaw, making exploitation trivial.
- SOC/IR — Act: Active exploitation of vCenter and SharePoint warrants an assume-breach sweep — hunt for post-exploitation activity (credential dumping, lateral movement) on these systems dating back at least 30 days, and tune detections for anomalous SharePoint API calls and vCenter admin actions.
- Leader — Act: KEV-listed active exploitation across macOS endpoints, SharePoint, and vCenter is a systemic risk event — confirm patch status and exposure scope with engineering this week, and be prepared to brief leadership if any of these systems host sensitive data or are business-critical.
- Signals: CVE-2026-65400 — CISA KEV: listed, EPSS 0.00, public PoC on GitHub
- Engineer — Act: cPanel/WHM is widely deployed by hosting providers and MSPs; CISA KEV listing plus EPSS 0.98 and public PoC confirm active exploitation risk. Patch to the vendor-released fixed version immediately and audit for signs of unauthorized access in cPanel/WHM logs.
- SOC/IR — Act: With a public PoC and KEV listing, opportunistic exploitation is underway — sweep for anomalous cPanel/WHM authentication events and unexpected admin account creation since the PoC publication date, and tune detections for unauthenticated access patterns on WHM ports.
- Leader — Plan: If your organization or any managed-hosting vendor uses cPanel/WHM, confirm patching status and request attestation this week; the KEV listing signals broad exploitation, but direct board escalation is warranted only if you host customer data on affected systems.
- Signals: CVE-2026-41940 — CISA KEV: listed, EPSS 0.98, public PoC on GitHub