The Week in Security
Other had 25 vulnerabilities this week including Axios Security (CVSS 9.9 CRITICAL) (CVSS 9.9). Mozilla Firefox had 4 vulnerabilities this week including Firefox Security (CVSS 9.8 CRITICAL) (CVSS 9.8). Linux Kernel had 6 vulnerabilities this week including Linux Kernel Security (CVSS 9.8 CRITICAL) (CVSS 9.8).
We tracked 35 vulnerabilities this week. 17 scored 9.0 or above. If you only have time for one thing today, scroll to "What To Do This Week" at the bottom.
Other Had a Rough Week
25 vulnerabilities across Other products this week. The worst: CVE-2025-62718 (CVSS 9.9) lets attackers run code on your systems. Patch now if you run Other.
- CVE-2025-62718: Axios Security (CVSS 9.9 CRITICAL) (CVSS 9.9)
- CVE-2025-62718: Axios Security (CVSS 9.9 CRITICAL) (CVSS 9.9)
- CVE-2025-62718: Axios Security (CVSS 9.9 CRITICAL) (CVSS 9.9)
- CVE-2025-62718: Axios Security (CVSS 9.9 CRITICAL) (CVSS 9.9)
- CVE-2025-62718: Axios Security (CVSS 9.9 CRITICAL) (CVSS 9.9)
- CVE-2026-11718: Mcp Toolbox For Databases Security (CVSS 9.1 CRITICAL) (CVSS 9.1)
- CVE-2026-11718: Mcp Toolbox For Databases Security (CVSS 9.1 CRITICAL) (CVSS 9.1)
- CVE-2026-11718: Mcp Toolbox For Databases Security (CVSS 9.1 CRITICAL) (CVSS 9.1)
- CVE-2026-11717: Mcp Toolbox For Databases Security (CVSS 9.1 CRITICAL) (CVSS 9.1)
- CVE-2026-11717: Mcp Toolbox For Databases Security (CVSS 9.1 CRITICAL) (CVSS 9.1)
- CVE-2026-11717: Mcp Toolbox For Databases Security (CVSS 9.1 CRITICAL) (CVSS 9.1)
- CVE-2026-76259: Splunk Security (CVSS 8.8 HIGH) (CVSS 8.8)
- CVE-2026-65768: Teams Path Traversal (CVSS 8.8 HIGH) (CVSS 8.8)
- CVE-2026-65767: Teams Security (CVSS 8.8 HIGH) (CVSS 8.8)
- CVE-2026-65767: Teams Security (CVSS 8.8 HIGH) (CVSS 8.8)
- CVE-2026-65767: Teams Security (CVSS 8.8 HIGH) (CVSS 8.8)
- CVE-2025-62593: Ray Code Injection (CVSS 8.8 HIGH) (CVSS 8.8)
- CVE-2025-62593: Ray Code Injection (CVSS 8.8 HIGH) (CVSS 8.8)
- CVE-2025-62593: Ray Code Injection (CVSS 8.8 HIGH) (CVSS 8.8)
- CVE-2025-66824: Trueconf Server Security (CVSS 8.7 HIGH) (CVSS 8.7)
- CVE-2026-13368: Fireware Security (CVSS 8.1 HIGH) (CVSS 8.1)
- CVE-2025-46291: Macos Security (CVSS 7.8 HIGH) (CVSS 7.8)
- CVE-2026-76262: Splunk Security (CVSS 7.5 HIGH) (CVSS 7.5)
- CVE-2026-68821: App Installer Security (CVSS 7.3 HIGH) (CVSS 7.3)
- CVE-2026-76251: Splunk Security (CVSS 7.1 HIGH) (CVSS 7.1)
Mozilla Firefox: 4 Critical Flaws at Once
4 vulnerabilities across Mozilla Firefox products this week. The worst: CVE-2026-74944 (CVSS 9.8) lets attackers run code on your systems. Patch now if you run Mozilla Firefox.
- CVE-2026-74944: Firefox Security (CVSS 9.8 CRITICAL) (CVSS 9.8)
- CVE-2026-74943: Firefox Security (CVSS 9.8 CRITICAL) (CVSS 9.8)
- CVE-2026-74940: Firefox Security (CVSS 9.8 CRITICAL) (CVSS 9.8)
- CVE-2026-74936: Firefox Security (CVSS 9.8 CRITICAL) (CVSS 9.8)
Linux Kernel Patches 6 Vulnerabilities
6 vulnerabilities across Linux Kernel products this week. The worst: CVE-2024-58240 (CVSS 9.8) lets attackers run code on your systems. Patch now if you run Linux Kernel.
- CVE-2024-58240: Linux Kernel Security (CVSS 9.8 CRITICAL) (CVSS 9.8)
- CVE-2024-58240: Linux Kernel Security (CVSS 9.8 CRITICAL) (CVSS 9.8)
- CVE-2026-63797: Linux Kernel Security (CVSS 8.4 HIGH) (CVSS 8.4)
- CVE-2024-50125: Linux Kernel Security (CVSS 8.0 HIGH) (CVSS 8.0)
- CVE-2026-53143: Linux Kernel Security (CVSS 7.8 HIGH) (CVSS 7.8)
- CVE-2026-46033: Linux Kernel Security (CVSS 7.1 HIGH) (CVSS 7.1)
By the Numbers
| Total CVEs analyzed | 35 |
| Critical (9.0+) | 17 |
| High (7.0-8.9) | 18 |
| Remote code execution | 34 |
| Authentication bypass | 1 |
| Cross-site scripting | 0 |
| SQL injection | 0 |
What To Do This Week
One action item per vendor. Start at the top and work down.
- Other: Update immediately. 11 critical-severity issues patched this week.
- Mozilla Firefox: Update immediately. 4 critical-severity issues patched this week.
- Linux Kernel: Update immediately. 2 critical-severity issues patched this week.