CVE Watch: Top 10 CVEs — Severity, Impact & Patch Status

CVE IDSeverityCVSSProductImpactSource
CVE-2026-9082Critical6.5 (NVD) / 20/25 DrupalDrupal Core (PostgreSQL)Unauthenticated SQL injection → data theft, potential RCE; CISA KEV; 15,000+ exploit attemptsTenable
CVE-2026-41089Critical9.8Windows Netlogon (Server 2022/2025, Win11)Unauthenticated wormable RCE on domain controllers; stack buffer overflowZDI
CVE-2026-42898Critical9.9Microsoft Dynamics 365 On-PremisesAuth’d user RCE with scope change; cross-component exploitation possibleArctic Wolf
CVE-2026-41096CriticalCriticalWindows DNS Client (all Windows)Malicious DNS response → heap overflow → unauthenticated RCE on all Windows systemsCCB Belgium
CVE-2026-41091High7.8Microsoft Defender AntivirusRedSun zero-day; privilege escalation to SYSTEM via link-following; exploited in wildSecurityWeek
CVE-2026-45498Medium4.0Microsoft Defender AntivirusUnDefend zero-day; DoS → silent blocking of Defender signature updates; exploited in wildSecurityWeek
CVE-2026-41103Critical9.1Microsoft SSO for Atlassian Jira/ConfluenceUnauthenticated network-based EoP; no user interaction required; “Exploitation More Likely”Lansweeper
CVE-2026-7359HighHighGoogle Chrome (< 147.0.7727.138)Use-after-free in ANGLE/WebGPU; sandbox escape via crafted HTML pageHelp AG
CVE-2024-9643CriticalCriticalFour-Faith F3x36 Industrial RoutersHardcoded credential auth bypass; mass exploitation mid-May; botnet foldingSecurityWeek
CVE-2026-40365CriticalCriticalMicrosoft SharePoint ServerAuthenticated network-based RCE on internet-facing SharePoint serversMicrosoft/LinkedIn