Patch Everything: Cisco CVSS 10.0 Leads the Densest Critical-Vulnerability Week of 2026
The Vulnerability Avalanche
This week delivered a concentration of critical vulnerabilities across every layer of the enterprise stack that demands emergency triage. The headline: CVE-2026-20127, a CVSS 10.0 authentication bypass in Cisco Catalyst SD-WAN Controller/Manager, has been in CISA KEV since February 25 — meaning exploitation has been active for at least 8 days. A second flaw (CVE-2026-20129, CVSS 9.8) grants netadmin privileges. Together, they give attackers full control of your WAN fabric — every branch, every tunnel, every policy.
But Cisco is just the tip. Three additional CISA KEV entries landed this week: VMware Aria Operations (CVE-2026-22719, CVSS 8.1, unauthenticated command injection during migration workflows) and Qualcomm chipsets (CVE-2026-21385, Android). VMware's flaw is particularly insidious — it's exploitable during support-assisted product migration, precisely when post-Broadcom organizations have relaxed controls.
ICS/SCADA: Three CVSS 10.0 Advisories
Industrial control systems received devastating disclosures this week:
| System | CVE(s) | CVSS | Vulnerability |
|---|---|---|---|
| Copeland XWEB Pro | CVE-2026-21718/24663 | 10.0 | Auth bypass + OS command injection |
| Johnson Controls Frick Controls | 6 CVEs | 9.8 | OS command injection + hardcoded email credentials |
| InSAT MasterSCADA BUK-TS | CVE-2026-21410 | 9.8 | SQL + OS command injection |
Developer Toolchain Under Fire
A cluster of CVSS 9.8-9.9 RCEs hit developer tools simultaneously: Rollup JS bundler (CVE-2026-27606, path traversal to RCE), Kubernetes PersistentVolumes (CVE-2025-62878, CVSS 9.9), n8n workflow automation (CVE-2026-27495, CVSS 9.9), Langflow AI tool (CVE-2026-27966, prompt injection to Python REPL RCE), and OpenSSL (CVE-2025-15467, buffer overflow across v3.0-3.6). The Cloudflare CIRCL crypto library (CVE-2026-1229, CVSS 9.8) silently produces incorrect P-384 elliptic curve values — signatures may verify when they shouldn't.
Browser and Mobile Fleet
Mozilla released five security advisories covering 40+ CVEs at CVSS 9.8-10.0 across Firefox and Thunderbird. Android's March 2026 bulletin includes CVE-2026-0006 (CVSS 9.8), a zero-click RCE requiring no user interaction. Every unpatched browser and Android device is a multi-vector target.
Authentication bypass is the dominant vulnerability class this week — appearing in Cisco SD-WAN, CrushFTP, Copeland, WordPress, and more. This isn't bad luck; it's an industry-wide failure in security engineering fundamentals.
What to do
Patch Cisco Catalyst SD-WAN Controller/Manager for CVE-2026-20127 and CVE-2026-20129 immediately; if delayed, isolate management interfaces and audit logs since February 25
Patch VMware Aria Operations for CVE-2026-22719; disable migration endpoints not actively in use
Push Firefox/Thunderbird updates and Android March 2026 security update via MDM by end of week
Run emergency SCA scan for Rollup (≥4.59.0), n8n (≥2.10.1), OpenSSL (3.0-3.6 branches), and Cloudflare CIRCL (≥1.6.3) across all codebases and CI/CD pipelines
Apply CISA ICS advisories for Copeland, Johnson Controls, and InSAT MasterSCADA; verify OT/IT network segmentation enforcement