7 Critical CVEs Hit Simultaneously — Your Largest Concurrent Patch Emergency of 2026
The Patch Pileup
This is the most concentrated critical vulnerability window of 2026. Seven distinct high-severity vulnerabilities require immediate action across browser, mobile, web framework, network appliance, and AI toolchain attack surfaces — and several are already under active exploitation.
Immediate Priority Patches
| Vulnerability | CVSS | Exploitation | Affected Systems | Patch Deadline |
|---|---|---|---|---|
| Next.js CVE-2025-55182 | 10.0 | Active — 766 targets (UAT-10608) | Self-hosted Next.js | Now + rotate secrets |
| Cisco IMC CVE-2026-20093 | 9.8 | Patch available | Cisco IMC | Now |
| Langflow CVE-2026-33017 | 9.3 | Active — exploits in <20 hours | Langflow instances | April 8 (CISA KEV) |
| Chrome CVE-2026-5281 | High | Active zero-day | All Chrome platforms | Now |
| DarkSword iOS kit | Critical | Public on GitHub | iOS 18.4–18.7 | 48 hours |
| ShareFile CVE-2026-2699/2701 | Critical | 30,000+ servers exposed | ShareFile 5.x | Now or take offline |
| CrewAI (4 CVEs) | TBD | No patch available | CrewAI deployments | Remove/isolate now |
Next.js: CVSS 10.0, Mass Exploitation in Progress
Threat actor UAT-10608 has automated scanning and credential harvesting against self-hosted Next.js instances, hitting 766 confirmed targets. The attack chain delivers RCE that harvests AWS secrets, SSH keys, Stripe API keys, and GitHub tokens. Patching alone is insufficient — rotate every secret on any host that ran a vulnerable Next.js instance. Treat those hosts as compromised.
DarkSword: Nation-State iOS Exploit Kit Goes Commodity
The DarkSword exploit kit was publicly dumped on GitHub last month, chaining six iOS vulnerabilities to deploy three malware families: GhostBlade, GhostKnife, and GhostSaber. This was previously a nation-state-grade capability. It is now available to any threat actor with basic technical skills. Apple's decision to reverse its patching policy — backporting iOS 26 defenses to all iOS 18 devices, not just hardware unable to run iOS 26 — signals the severity. Push iOS 18.7.7 via MDM immediately and block unpatched devices from corporate resources.
Chrome Zero-Day #4: WebGPU Attack Surface Proves Persistent
CVE-2026-5281 is a use-after-free in Dawn (WebGPU implementation). With four actively exploited zero-days in 2026 — already half of 2025's total — Chrome's newer rendering subsystems (WebGPU, Skia, V8) are proving to be a reliable exploitation surface. Push Chrome 146.0.7680.178 fleet-wide and verify within 48 hours.
CrewAI: No Patch, Full Compromise Chain
CrewAI has four CVEs including a silent fallback from Docker to an insecure sandbox that enables arbitrary code execution. Combined with SSRF and file-read vulnerabilities, the chain runs from prompt injection to full host compromise. There is no patch. Remove or fully isolate CrewAI from all environments. Verify Docker is actually running — the silent degradation means your sandbox may not be real.
The common pattern across these CVEs: attackers are exploiting trust boundaries — trust that npm packages are safe, that Chrome's new rendering engine is hardened, that iOS patches aren't needed, and that AI tool sandboxes actually work.
What to do
Push Chrome 146.0.7680.178 to all managed endpoints and verify 100% deployment within 48 hours
Patch all self-hosted Next.js instances for CVE-2025-55182, then rotate every secret on affected hosts
Push iOS 18.7.7 via MDM and block unpatched devices from corporate resources
Remove or fully isolate CrewAI from all environments — no patch exists
Scan for Progress ShareFile 5.x across your environment and third-party vendors; patch or take offline immediately
Patch Cisco IMC (CVE-2026-20093) and SSM On-Prem (CVE-2026-20160); segment management interfaces