PatchDayAlert
Daily Digest · 2 min read · 5 CVEs · Issue 22 By PatchDayAlert

Cisco Secure Workload scores a perfect 10.0: unauth cross-tenant takeover

Also: a use-after-free in Chrome's DOM engine (CVSS 8.8), a no-click heap overflow in Microsoft Defender's scan engine (CVSS 8.1), an Azure privesc via symlink, and a Splunk session cookie leak.

Patch now
1
Within 24h
1
This week
3
Exploited
0
Cisco Secure WorkloadNetwork ApplianceGoogle ChromeChromiumWindowsMacOSLinuxMicrosoft DefenderMicrosoft Malware Protection EngineMicrosoft Windows Admin CenterAzure PortalCloud

Nothing exploited in the wild yet, but a CVSS 10.0 in Cisco Secure Workload (CVE-2026-20223) deserves your attention right now. An unauthenticated attacker can hit internal REST APIs and grab full Site Admin privileges across tenant boundaries, no credentials, no user interaction. That's joined by a Defender engine RCE and a Chrome sandbox code execution, so don't let the 'no active exploitation' status lull you into waiting.


Today's CVEs

Sorted by urgency

02

CVE-2026-9126

NVD
8.8
CVSS
Patch this week HIGH
Google ChromeChromiumWindowsMacOSLinux

A use-after-free bug in Chrome's DOM engine lets an attacker run code inside the browser sandbox if a user visits a malicious page. The attack requires user interaction (visiting a crafted page), and code execution is sandboxed, which limits the blast radius. Still, sandbox escapes get chained regularly, so don't sit on this one.

Affected estate
Anyone managing Chrome or Chromium-based browsers (Edge, Brave, etc.) on desktops or kiosks
How to check
Open chrome://version in the browser, or query installed browser versions via your endpoint management tool (Intune, SCCM, Jamf, etc.).
Included because
remote; user interaction required; sandboxed execution; widely deployed browser
Action
Push Chrome 148.0.7778.179 or newer through your browser update channel or endpoint management platform.
Why it matters
A crafted web page can trigger code execution inside the sandbox, which attackers commonly chain with sandbox escapes for full compromise.
Source
Chrome Releases Blog / Chromium bug tracker

Evidence trail

03

CVE-2026-45584

NVD
8.1
CVSS
Patch within 24h HIGH
Microsoft DefenderMicrosoft Malware Protection EngineWindows

A heap-based buffer overflow in the Microsoft Malware Protection Engine lets an attacker run code over the network without any authentication. Because Defender's engine auto-scans incoming files and network content, a specially crafted payload could trigger this just by being received. No user click needed.

Affected estate
Anyone running Microsoft Defender (Windows Defender, Defender for Endpoint, or any product using the Microsoft Malware Protection Engine)
How to check
Run 'Get-MpComputerStatus | Select AMEngineVersion' in PowerShell and compare against the fixed version in Microsoft's advisory. Alternatively, check via SCCM or Intune compliance reports.
Included because
unauthenticated; network-exploitable; no user interaction; ubiquitous product; CVSS 8.1
Action
Confirm the engine auto-updated. If your environment blocks automatic definition and engine updates, manually trigger 'Update-MpSignature' or deploy via WSUS/SCCM.
Why it matters
The Malware Protection Engine processes untrusted content automatically, so an attacker can trigger this bug just by sending a crafted file to a protected host.
Source
Microsoft Security Response Center (MSRC)

Evidence trail

04

CVE-2026-42834

NVD
7.8
CVSS
Patch this week HIGH
Microsoft Windows Admin CenterAzure PortalWindowsCloud

A symlink-following bug in Azure Portal's Windows Admin Center lets a local attacker who already has some level of access escalate to higher privileges. This requires local access and an authenticated session, so it's not remotely exploitable on its own. It's a privilege escalation play, most dangerous if an attacker already has a foothold.

Affected estate
Anyone using Windows Admin Center through the Azure Portal
How to check
In the Azure Portal, go to the Windows Admin Center extension settings and check the installed version. Compare against Microsoft's advisory for the fixed version.
Included because
local access required; authenticated; privilege escalation; Azure management tool
Action
Update the Windows Admin Center Azure extension to the patched version via the Azure Portal.
Why it matters
A local attacker with existing access can escalate to higher privileges by exploiting symlink handling, expanding a partial compromise into a full one.
Source
Microsoft Security Response Center (MSRC)

Evidence trail

05

CVE-2026-20239

NVD
7.5
CVSS
Patch this week HIGH
Splunk EnterpriseSplunk Cloud PlatformWindowsLinux

If a Splunk user has a role with access to the _internal index, they can view session cookies and response bodies containing sensitive data. This is an information disclosure bug that requires an authenticated user with specific index permissions, so it's not open to the internet. That said, stolen session cookies can lead to session hijacking and lateral movement inside Splunk.

Affected estate
Splunk Enterprise admins running versions below 10.2.2 or 10.0.5, and Splunk Cloud Platform customers on older release tracks
How to check
Run 'splunk version' on your Splunk Enterprise instance, or check Settings > Server Settings > General in the Splunk Web UI. For Splunk Cloud, check your instance version in the Splunk Cloud admin console.
Included because
authenticated access required; information disclosure; session hijack risk; common SIEM product
Action
Upgrade to the fixed Splunk version. Review and restrict roles that have access to the _internal index.
Why it matters
Exposed session cookies let an authenticated user hijack other sessions, potentially escalating to admin-level access within your Splunk deployment.
Source
Splunk Security Advisory

Evidence trail


One email, every Wednesday morning.

Subscribe