CVE-2026-9911: OpenWidget Parser Heap UAF and the Week-One Defender Playbook
A remote, unauthenticated heap use-after-free in OpenWidget 3.0.0–3.2.1 hands attackers code execution against ~14,200 internet-exposed instances. Here is the triage order defenders should be working through right now.