Remote code execution in framework
CVE-2026-10001Action: Apply the supported framework patch and retest the public checkout route.
SMB + MSP decision engine · deterministic by default
Turn two ordinary CSV exports into a defensible first-12 remediation list. No account, no API key, and no upload: files stay in this browser.
Use a vulnerability CSV and, optionally, an asset CSV. Familiar column names are normalized safely; unknown or missing values are shown as lower confidence, never silently guessed.
Ranked by a repeatable score, then explained in plain evidence.
CVE-2026-10001Action: Apply the supported framework patch and retest the public checkout route.
CVE-2026-10003Action: Apply the emergency vendor fix and rotate exposed service credentials.
CVE-2026-10002Action: Upgrade the gateway and validate privileged sign-in controls.
CVE-2026-10008Action: Install the gateway hotfix and validate remote access availability.
CVE-2026-10006Action: Deploy the vendor update and run an order-path regression test.
CVE-2026-10005Action: Upgrade the component and test egress restrictions.
CVE-2026-10009Action: Patch the portal package and test the employee workflow.
CVE-2026-10007Action: Update the integration library and test token audience validation.
CVE-2026-10004Action: Patch during the approved maintenance window and verify least privilege.
CVE-2026-10012Action: Deploy the endpoint update in the next managed ring.
CVE-2026-10010Action: Update the backup agent and check job integrity.
CVE-2026-10011Action: Apply the update and verify worker isolation.