● Updated every 3 hours
Daily security briefing
One page per UTC day: KEV additions, notable CERT and PSIRT advisories and the exploitation outlook. Also delivered as a free email every morning — subscribe.
Advisory volume, last 45 days — amber marks a day with KEV additions.
Latest briefing
2026-08-26
Wednesday, Aug 26, 2026in progress6 advisories▼ 17567 CVEsAugust 26 saw moderate advisory activity with 67 CVEs published across multiple vendors and 6 CERT/PSIRT advisories issued, though no vulnerabilities were added to the KEV catalog today and no specific CVEs or advisories stood out as particularly notable. CSIRT teams should continue routine patch assessment cycles and maintain standard vulnerability monitoring given the steady publication volume. No critical zero-days or high-profile threats were flagged in today's aggregate data.
Read the full briefing →
August 2026
2026-08-25
Tuesday, Aug 25, 20261 KEV181 advisories▼ 253013 CVEs5 exploitedAugust 25 saw heavy advisory activity with 181 CERT/PSIRT advisories and 3,013 CVEs published, headlined by Gitea code injection vulnerability (CVE-2026-60004) added to CISA's KEV catalog. Multiple critical vulnerabilities dominated the landscape, including four CVSS 10.0 flaws in Adobe Campaign Classic and TOTOLINK routers, alongside critical NVIDIA OpenShell sandbox escape issues and Chainlit command injection allowing unauthenticated remote code execution. Beyond the newly cataloged Gitea issue, notable exploited vulnerabilities affecting Linux kernels, Oracle Fusion Middleware, and industrial systems like the Bendix EC80 Brake ECU were highlighted across CERT-Bund and CISA advisories, indicating sustained exploitation activity across enterprise and critical infrastructure targets.
2026-08-24
Monday, Aug 24, 20261 KEV206 advisories▲ 2034153 CVEs6 exploitedCSIRT teams should prioritize CVE-2026-21962, an Oracle HTTP Server and Oracle WebLogic Server proxy plug-in improper access control vulnerability added to the KEV catalog today. Activity was notably heavy with 4,153 CVEs published and 206 CERT/PSIRT advisories issued, including critical Oracle and Red Hat patches and multiple Linux kernel updates spanning DoS and code execution flaws. Several critical vulnerabilities demand immediate attention: CVE-2026-78167 (EFM ipTIME router, CVSS 10.0), CVE-2026-78169 (UTT HiPER gateway, CVSS 9.9), CVE-2026-66897 (LXD container escape, CVSS 9.9), and multiple WordPress and DrayTek router flaws rated 9.8-9.9 affecting authentication and privilege escalation. Notable exploited vulnerabilities include issues in Metabase, Zimbra, and 389-ds-base that warrant rapid assessment across enterprise environments.
2026-08-23
Sunday, Aug 23, 20263 advisories▲ 382 CVEs1 exploitedAugust 23rd saw moderate advisory activity with 82 CVEs published and three CERT/PSIRT advisories, though no new KEV additions were recorded. A Zimbra Collaboration Suite vulnerability tracked as NCSC-2026-0324 was flagged as exploited, warranting attention from affected organizations. Critical severity dominated the day's notable CVEs, including multiple privilege escalation and sanitization bypass issues: CVE-2026-78155 in StackGres operator (CVSS 9.9), CVE-2026-78050 in Comfast CF-N1-S (CVSS 9.9), and three critical HTML sanitization flaws in justhtml versions below 1.16.0 (CVSS 9.8 each). WordPress plugin vulnerabilities also ranked high, with object injection in PPWP (CVSS 8.8) and authorization bypass in Security Hardener (CVSS 8.8), plus a GitLab authentication issue affecting multiple versions (CVSS 8.5).
2026-08-22
Saturday, Aug 22, 20260 advisories▼ 188242 CVEsAugust 22 saw moderate advisory activity with 242 CVEs published but no CERT/PSIRT advisories or KEV additions. The most critical findings include CVE-2026-77946 affecting TRENDnet TEW-821DAP routers (CVSS 10.0), followed by two WordPress plugins with critical remote code injection and SSRF vulnerabilities: WS Form LITE (CVE-2026-4703) and Mailgun for WordPress (CVE-2026-78003). Additional high-severity issues were identified in the WPeMatico RSS plugin, NLTK's AllowlistUnpickler, AVideo, SiYuan note-taking software, and hashcat, spanning authentication bypass, RCE, arbitrary file deletion, and command injection vectors. Organizations should prioritize patching the WordPress plugins and TRENDnet firmware given their critical severity scores and likely exposure in typical enterprise environments.
2026-08-21
Friday, Aug 21, 20261 KEV188 advisories▼ 513716 CVEs5 exploitedCSIRT teams face a significant advisory load today with 188 CERT/PSIRT advisories and 3,716 CVEs published. The day's most critical threat is CVE-2026-73570, a Zimbra Collaboration Suite OS command injection vulnerability added to CISA's Known Exploited Vulnerabilities catalog, with active exploitation already confirmed in the wild. Multiple critical vulnerabilities were disclosed across infrastructure software including several CVSS 10.0 remote code execution flaws in Xinference and Azure SQL Database, plus five critical Incus container manager vulnerabilities (CVSS 9.9) affecting versions prior to 7.3.0. Additional notable advisories include updates to Linux Kernel vulnerabilities enabling denial of service attacks, new vulnerabilities in Apache CloudStack and PTC Windchill/FlexPLM, and a Cisco Crosswork Security Hardening release addressing multiple issues.
2026-08-20
Thursday, Aug 20, 20262 KEV239 advisories▲ 293360 CVEs8 exploitedActivity was heavy on August 20th with 3,360 CVEs published and 239 CERT/PSIRT advisories issued. Two TrueConf Server vulnerabilities were added to the Known Exploited Vulnerabilities catalog: CVE-2026-72530 (code injection) and CVE-2026-72529 (missing authentication), with a related security advisory already in circulation. Critical attention should go to multiple CVSS 10.0 Microsoft vulnerabilities affecting Azure Arc, Entra ID, Exchange Online, and Azure Managed Instance, alongside critical flaws in Azure SQL Database and Active Directory, all carrying active exploitation indicators. Notable advisories also covered Apache HTTP Server vulnerabilities, Linux kernel issues including Dirty Frag in Amazon Linux systems, and a new security measure bypass in MLflow, with ongoing tracking of Copy.fail variants in AWS environments.
2026-08-19
Wednesday, Aug 19, 20261 KEV210 advisories▲ 1543104 CVEs4 exploitedCISA added CVE-2026-64849, an MLflow server-side request forgery vulnerability, to the Known Exploited Vulnerabilities catalog on August 19th, joining multiple other actively exploited threats across critical infrastructure and enterprise software. A critical vulnerability in Citrix NetScaler ADC and Gateway (2026-010) and active threats targeting Siemens S7 Series PLCs demand immediate attention, while eight different critical CVSS 10.0 vulnerabilities were published affecting Cisco products, WordPress plugins, and embedded devices. Notable advisories also included multiple high-severity vulnerabilities in Atlassian products, Oracle WebLogic, and Cisco BroadWorks requiring prompt patching. With 3,104 CVEs published and 210 CERT/PSIRT advisories issued, this represents a typical high-volume advisory day with several items requiring urgent prioritization in SOC queues.
2026-08-18
Tuesday, Aug 18, 20264 KEV56 advisories▼ 1531229 CVEs4 exploitedTuesday saw significant advisory activity with 56 CERT/PSIRT releases and 1,229 CVEs published, including four vulnerabilities added to CISA's Known Exploited Vulnerabilities catalog: CVE-2026-33824 affecting Microsoft IKE services, CVE-2026-59310 in Broadcom VMware vCenter, CVE-2026-55040 in Microsoft SharePoint, and CVE-2026-65400 in Apple macOS. Multiple critical CVSS 10.0 vulnerabilities were disclosed across Oracle Hyperion products, Firefox, WordPress plugins, and network devices, with particular attention needed for CVE-2026-73343 (unauthenticated RCE in WP Compress) and CVE-2026-75874 (Firefox sandbox escape). Notable advisories include Microsoft's August monthly rollup, updates for VMware and Apple, and critical warnings for Siemens Simcenter Nastran and CISA Malcolm, alongside ongoing Linux kernel vulnerability disclosures.
2026-08-17
Monday, Aug 17, 20261 KEV209 advisories▲ 2073000 CVEs2 exploitedCERT and PSIRT activity was robust today with 209 advisories issued and 3000 CVEs published, headlined by the addition of CVE-2025-62593 (Ray-Project code injection) to CISA's Known Exploited Vulnerabilities catalog. Critical issues dominate the landscape, particularly multiple vm2 sandbox escape vulnerabilities (CVE-2026-47686, GHSA-m283-3h24-438v, GHSA-m5w8-4gq2-6f8x, GHSA-cfcw-xp6x-25gj) with CVSS scores ranging from 9.8 to 10.0, along with perfect-score flaws in EFM ipTIME A3004T and Wavlink WN531P3/WN535M1 routers. Notable updates also cover Linux kernel vulnerabilities, AMD processor issues, and new critical flaws in Red Hat Enterprise Linux nodejs, Gitea, and ERPNext. Teams should prioritize patching vm2 implementations and reviewing exposure to the affected router and networking equipment models.
2026-08-16
Sunday, Aug 16, 20262 advisories▲ 1117 CVEsAugust 16th saw 117 CVEs published with no new KEV entries or CERT/PSIRT advisories of note, though eight critical vulnerabilities emerged across networking and software platforms. Edimax EW-7478APC router firmware 1.04 contains two critical weaknesses (CVE-2026-19959 and CVE-2026-19961, both CVSS 9.9) affecting WAN TCP/IP and wireless site survey functions, while Tenda AC10 routers and SiYuan before version 3.7.4 each carry separate critical flaws at CVSS 9.8. Multiple WordPress plugins also face critical vulnerabilities including arbitrary file upload in ProSolution WP Client and privilege escalation in Frontend Admin by DynamiApps. Organizations running these devices and plugins should prioritize patching efforts given the severity and breadth of exposed functionality.
2026-08-15
Saturday, Aug 15, 20261 advisories▼ 200926 CVEsThe security advisory landscape remained relatively quiet on the CERT/PSIRT front with just one advisory published, but 926 CVEs were disclosed today with eight critical vulnerabilities requiring immediate attention. Multiple WordPress plugins were flagged with critical authentication bypass and account takeover issues, including CVE-2026-19598 in Pods, CVE-2026-15341 in User Session Synchronizer, CVE-2026-15303 in 6Storage Rentals, CVE-2026-15826 in User Profile Builder, and CVE-2026-16142 in TrueBooker, all rated at CVSS 9.8. Additionally, SiYuan before v3.7.4 was disclosed with a critical authentication flaw (CVE-2026-73046), and two WordPress plugins—Link Library and RapiSafe—were found vulnerable to arbitrary file operations with CVSS ratings of 9.1. Teams should prioritize patching these WordPress plugin vulnerabilities given their widespread deployment and exploitation risk.
2026-08-14
Friday, Aug 14, 2026201 advisories▼ 402737 CVEs4 exploitedAugust 14 saw heavy advisory activity with 201 CERT/PSIRT advisories and 2,737 CVEs published, though no new KEV additions. Notable high-severity advisories included updates to HTTP/2 implementations and Linux Kernel vulnerabilities, alongside new guidance on BIND, Elasticsearch, and multiple Synacor Zimbra issues from CERT-Bund, plus advisories from CERT-FR covering IBM products and SUSE Linux kernel flaws. The day was dominated by critical vulnerabilities, including CVSS 10.0 SQL injection in SiYuan and unauthenticated RCE in MindsDB, alongside multiple CVSS 9.9-9.8 command injection and authentication bypass flaws in Tenable Security Center and IBM Db2 Mirror for i that warrant immediate prioritization.
2026-08-13
Thursday, Aug 13, 2026241 advisories▼ 443257 CVEs4 exploitedThursday, August 13 saw substantial advisory activity with 241 CERT/PSIRT advisories and 3,257 CVEs published, though no new KEV entries were added. Critical vulnerabilities dominated the landscape, including multiple CVSS 10.0 flaws in QA Analytics, WP BASE Booking, and the malicious Link Factory WordPress plugin, alongside critical issues in industrial control systems like Siemens LOGO! Soft Comfort and Haiwell IoT Cloud HMI Gateway tracked by CISA. Microsoft Windows received critical updates addressing multiple vulnerabilities, while Linux kernel flaws and Cisco ASA/Secure Firewall SSL VPN issues (CVE-202 referenced in AL26-018) were flagged as actively exploited. Teams should prioritize patching the CVSS 10.0 unauthenticated RCE vulnerabilities affecting QA Analytics and Budibase SQL injection, as well as reviewing their Windows and industrial control system inventory for the critical patches released today.
2026-08-12
Wednesday, Aug 12, 2026285 advisories▼ 732499 CVEs12 exploitedAugust 12 was a heavy advisory day with 285 CERT/PSIRT advisories and 2,499 CVEs published, though no new KEV additions were recorded. Microsoft's August 2026 security update and multiple Cisco product vulnerabilities dominated advisory output, with particular focus on Cisco ASA and Secure Firewall Threat Defense issues that enable denial of service attacks. The day featured eight critical CVEs, primarily concentrated in LXD containerization software (CVE-2026-63294, CVE-2026-63298, CVE-2026-63300, CVE-2026-66898, and CVE-2026-63299) involving root command execution and authorization bypass risks, alongside critical issues in IBM DOORS Next (CVE-2024-27253) and a markdown processing library (CVE-2026-73299).
2026-08-11
Tuesday, Aug 11, 20263 KEV358 advisories▲ 1952240 CVEs10 exploitedAugust 11 saw moderate advisory volume with 358 CERT/PSIRT advisories and 2,240 CVEs published, highlighted by three critical KEV additions: CVE-2026-68820 affecting Microsoft Windows Ancillary Function Driver for WinSock elevation of privilege, CVE-2026-20349 in Cisco Secure Firewall ASA and FTD heap overflow, and CVE-2026-72898 Metabase SQL injection. Additional high-priority exploited vulnerabilities include a JetBrains TeamCity code execution flaw (CERT-BUND), Cisco Secure Firewall SSL VPN denial of service, and static credential issues in Cisco Management Center, alongside multiple sudo vulnerabilities updates. Beyond KEV items, the day featured six critical CVSS 10.0 vulnerabilities spanning SAP Commerce Cloud, ColdFusion, LiquidJS, SIMATIC IoT2050, and related systems, which should be reviewed for impact to your environment.
2026-08-10
Monday, Aug 10, 2026163 advisories▲ 1612284 CVEs3 exploitedAugust 10 saw heavy advisory volume with 163 CERT/PSIRT notices and 2,284 CVEs published, though no KEV additions were recorded. Critical attention should focus on two perfect-score SQL injection vulnerabilities in Metabase (CVE-2026-72899 and CVE-2026-72898) allowing unauthenticated remote attacks, alongside multiple critical flaws in Dokploy affecting versions through 0.29.13 and a critical ERPNext vulnerability. Notable advisories include CISA's alert on Gunra ransomware exploitation, updates to ClamAV addressing multiple denial-of-service and information disclosure issues, and high-severity patches for HTTP/2 implementations, Sonatype Nexus Repository Manager, Bouncy Castle, and libssh2. CVE-2025-8088 carries the highest exploitation probability at 0.945 EPSS score, warranting prioritization alongside the critical Metabase and Dokploy issues.
2026-08-09
Sunday, Aug 9, 20262 advisories▼ 390 CVEsAugust 9 saw moderate advisory activity with 90 CVEs published and 2 CERT/PSIRT advisories issued, though no KEV additions or critical vendor guidance was released. The day was dominated by a cluster of critical vulnerabilities affecting consumer networking equipment: seven command injection flaws (CVE-2026-71987 through CVE-2026-71993, all CVSS 9.8) were discovered in MSI Radix AXE6600 router firmware version v781521 across multiple interfaces, alongside a critical flaw (CVE-2026-19348, CVSS 9.8) in Shenzhen Aitemi M300 Wi-Fi Repeater firmware. Organizations using these consumer-grade devices in enterprise or critical environments should prioritize assessment and patching efforts given the high severity and widespread impact potential of these command injection vulnerabilities.
2026-08-08
Saturday, Aug 8, 20265 advisories▼ 11698 CVEsFriday saw 98 CVEs published with no new KEV entries, though eight critical vulnerabilities demand immediate attention. D-Link DWR-M961 routers are the primary concern, with seven critical flaws (CVE-2026-71958, CVE-2026-71957, CVE-2026-71956, CVE-2026-71955, CVE-2026-71954, CVE-2026-71953, CVE-2026-71952) all scoring 9.8 CVSS affecting hardware version C1 on multiple firmware versions. Additionally, MSI Radix AXE6600 routers contain a critical command injection vulnerability (CVE-2026-71983, CVSS 9.8) in WPS functionality on firmware v781521. Organizations running these consumer and prosumer router models should prioritize firmware updates immediately.
2026-08-07
Friday, Aug 7, 20261 KEV121 advisories▼ 1002030 CVEs7 exploitedCSIRT teams faced a significant advisory volume on August 7th with 121 CERT/PSIRT advisories and 2,030 CVEs published, highlighted by the addition of CVE-2026-8037 (Progress LoadMaster Command Injection) to the Known Exploited Vulnerabilities catalog with an EPSS score of 0.848. Multiple critical Microsoft vulnerabilities emerged including CVE-2026-65667 and CVE-2026-56162 affecting Teams and Azure SQL Database respectively, both rated CVSS 10.0, alongside several other critical Azure and Plesk issues rated 9.9. Notable actively exploited advisories included updates on Progress software (AV26-552), Atlassian platforms, Linux Kernel Dirty Frag vulnerabilities, and newly disclosed Arista VeloCloud Orchestrator vulnerabilities enabling arbitrary code execution with root privileges. Teams should prioritize patching the Progress LoadMaster vulnerability and the critical Microsoft Azure issues given their exploit activity and attack surface.
2026-08-06
Thursday, Aug 6, 2026221 advisories▲ 262981 CVEs3 exploitedAugust 6th saw significant advisory activity with 221 CERT/PSIRT advisories and 2,981 CVEs published, though no new KEV additions were recorded. Critical issues dominated the landscape, including multiple exploited vulnerabilities in Atlassian products (Bamboo, Bitbucket, Confluence, Jira and others) and a newly disclosed code execution flaw in JetBrains TeamCity, alongside CISA alerts for ABB Ability Zenon exploitation. Microsoft released a substantial patch set with five critical Azure and Teams vulnerabilities including remote code execution in Azure Service Bus and elevation of privilege issues across multiple cloud services. Beyond enterprise software, multiple critical CVSS 10 vulnerabilities emerged in WordPress plugins and open-source tools, including unauthenticated RCE in Spider Analyser, malicious code in Premium SEO, and JWT authentication bypass issues, reflecting ongoing risks in widely-deployed web infrastructure.
2026-08-05
Wednesday, Aug 5, 20261 KEV195 advisories▲ 402408 CVEs3 exploited195 CERT/PSIRT advisories, 2,408 CVEs published, 1 added to the CISA KEV catalog.
2026-08-04
Tuesday, Aug 4, 20263 KEV155 advisories▼ 642045 CVEs3 exploited155 CERT/PSIRT advisories, 2,045 CVEs published, 3 added to the CISA KEV catalog.
2026-08-03
Monday, Aug 3, 20261 KEV219 advisories▲ 2183988 CVEs3 exploited219 CERT/PSIRT advisories, 3,988 CVEs published, 1 added to the CISA KEV catalog.
2026-08-02
Sunday, Aug 2, 20261 advisories±067 CVEs1 CERT/PSIRT advisory, 67 CVEs published, no new KEV additions.
2026-08-01
Saturday, Aug 1, 20261 advisories▼ 203148 CVEs1 CERT/PSIRT advisory, 148 CVEs published, no new KEV additions.
July 2026
2026-07-31
Friday, Jul 31, 2026204 advisories▲ 294268 CVEs2 exploited204 CERT/PSIRT advisories, 4,268 CVEs published, no new KEV additions.
2026-07-30
Thursday, Jul 30, 2026175 advisories▲ 31973 CVEs2 exploitedOn July 30, 2026, security advisory activity was notable, with 174 advisories issued and 1,920 CVEs published. Among the critical advisories, significant vulnerabilities were reported for NASA's Core Flight System Health & Safety Application, MikroTik RouterOS, and several products from Toptech Systems, Watchfire, MZ Automation, and Johnson Controls. Additionally, several critical CVEs were highlighted, including a CVSS score of 10 for an arbitrary file write vulnerability in Flyto2 Core and an incorrect authorization issue in Adobe Campaign Classic. Other critical vulnerabilities with high CVSS scores were identified in IBM Langflow OSS and webMethods Integration, as well as SQL injection vulnerabilities affecting various systems. Overall, while CERT/PSIRT output was quiet, the day was marked by several critical vulnerabilities that warrant attention from security teams.
2026-07-29
Wednesday, Jul 29, 20261 KEV172 advisories▼ 1133325 CVEs2 exploitedOn July 29, 2026, the security advisory landscape saw the addition of a significant known exploited vulnerability, CVE-2026-20316, related to a hard-coded password issue in Cisco Secure Firewall Management Center. Notable advisories included multiple vulnerabilities across various platforms, such as high-severity issues in Xen, VMware products, Apache Traffic Server, BlackBerry UEM Management Console, Mozilla Firefox, and Adobe Creative Cloud. The day also featured several critical CVEs, including CVE-2026-16326 and CVE-2026-58162, both scoring 10 on the CVSS scale, highlighting severe security risks in consul-mcp-server and Apache Traffic Server, respectively. Overall, while CERT/PSIRT output was relatively quiet, the volume of published CVEs, totaling 3,325, underscores ongoing security challenges.
2026-07-28
Tuesday, Jul 28, 2026285 advisories▲ 1015980 CVEs2 exploitedOn July 28, 2026, the security advisory landscape was marked by a significant number of advisories, with 285 from CERT/PSIRT and 5,980 CVEs published. Notable advisories included critical vulnerabilities in Siemens products such as the SIMATIC S7-PLCSIM Advanced and Desigo CC, as well as ABB's KNX Update Tool. Additionally, a high-severity update for Red Hat OpenShift Service Mesh was released, addressing a vulnerability that allows code execution. Among the notable CVEs, several critical vulnerabilities were highlighted, including CVE-2026-11756, a deserialization issue in the 3DEXPERIENCE platform, and CVE-2026-16498, a cross-tenant credential reuse vulnerability in terraform-mcp-server.
2026-07-27
Monday, Jul 27, 20262 KEV184 advisories▲ 1844173 CVEs3 exploitedOn July 27, 2026, the security advisory landscape saw the addition of two significant Known Exploited Vulnerabilities (KEVs): CVE-2025-68686, which affects Fortinet FortiOS, and CVE-2026-16812, a command injection vulnerability in Arista VeloCloud Orchestrator. CISA has also updated its catalog to include these vulnerabilities, highlighting their potential exploitation. In addition to the KEVs, several critical advisories were released, including multiple vulnerabilities in Microsoft Windows products and an unpatched critical cross-site scripting vulnerability in Zabbix. Notable CVEs published today include CVE-2026-48030 in Pheditor and CVE-2026-63077 in JetBrains TeamCity, both rated critical and warranting immediate attention from security teams. Overall, while CERT/PSIRT output was relatively quiet, the volume of notable CVEs underscores the need for vigilance.
2026-07-26
Sunday, Jul 26, 20260 advisories±012 CVEsOn July 26, 2026, there were no new advisories from CERT or PSIRT, but 12 CVEs were published, highlighting several significant vulnerabilities. Notably, CVE-2026-15962, a high-severity issue with a CVSS score of 8.8, affects the Fluent Forms Pro Add On Pack plugin for WordPress and is vulnerable to PHP Object Injection. Additionally, CVE-2026-17497, with a CVSS score of 8.3, impacts NoteGen versions prior to 0.32.0, allowing the Tauri shell plugin to execute shell commands in an insecure manner. Another critical vulnerability, CVE-2026-17496, also in NoteGen, poses risks by rendering AI chat responses with potentially dangerous configurations. Lastly, CVE-2026-63720, rated at 7.5, affects datamodel-code-generator versions prior to 0.70.0, enabling code injection attacks.
2026-07-25
Saturday, Jul 25, 20260 advisories▼ 199284 CVEsOn July 25, 2026, there were no new advisories from CERT or PSIRT, but a total of 284 CVEs were published, including several notable vulnerabilities. The most critical is CVE-2026-66012, a missing authorization vulnerability in SiYuan prior to version 3.7.2, rated with a CVSS score of 10. Additionally, CVE-2026-10818 affects the WPForms Pro plugin for WordPress, allowing arbitrary file uploads, while CVE-2026-66374 in Knot Resolver prior to 6.4.1 enables remote code execution through a heap-based buffer overflow. Lastly, CVE-2026-66373 in Redis before version 8.8.0 poses a risk of remote code execution under specific conditions.
2026-07-24
Friday, Jul 24, 2026199 advisories▼ 923816 CVEs1 exploitedOn July 24, 2026, security advisory activity included 199 advisories from various CERT and PSIRT sources, alongside the publication of 3,816 new CVEs. Notable advisories featured vulnerabilities in Check Point Security Management products, multiple vulnerabilities in the Linux Kernel, and issues in cPanel and CyberPanel. Critical CVEs of concern included CVE-2026-56163, which involves missing authentication in Microsoft Azure Kubernetes Service, and CVE-2026-58275, which allows unauthorized privilege escalation in Azure DNS. Other critical vulnerabilities were reported in Microsoft Exchange Online and Azure App Service, all rated with a CVSS score of 10.
2026-07-23
Thursday, Jul 23, 2026291 advisories▲ 195880 CVEs6 exploitedOn July 23, 2026, the security advisory landscape was marked by several critical advisories and notable vulnerabilities. Key advisories included a critical update from Microsoft addressing vulnerabilities in SharePoint and a significant advisory from Check Point regarding multiple vulnerabilities in their products. Additionally, the Debian security update DSA-6399-1 for WordPress was noted, along with a high-severity phishing campaign targeting Zimbra users. Among the notable CVEs, several critical vulnerabilities were reported, including CVE-2026-47668 in DbGate, CVE-2026-59555 in Participants Database, and CVE-2026-6516 affecting ManageEngine ADAudit Plus, all rated with a CVSS score of 10. Overall, while CERT/PSIRT output was relatively quiet, the day saw a substantial number of published CVEs, totaling 5,880.
2026-07-22
Wednesday, Jul 22, 20262 KEV272 advisories▼ 73013 CVEs4 exploitedOn July 22, 2026, security advisory activity was notably active, with 272 advisories and 3,013 CVEs published. Significant additions to the Known Exploited Vulnerabilities (KEV) catalog include CVE-2026-50522, a deserialization vulnerability in Microsoft SharePoint, and CVE-2026-16232, an improper authentication vulnerability in Check Point SmartConsole. Critical advisories were issued for vulnerabilities in Check Point, Mitel, SolarWinds, and Oracle, with multiple critical vulnerabilities identified in Oracle's Platform Security for Java. Additionally, several high-profile CVEs were reported, including CVE-2026-60366 and CVE-2026-60369, both critical vulnerabilities in Oracle Fusion Middleware.
2026-07-21
Tuesday, Jul 21, 20264 KEV279 advisories▲ 975408 CVEs6 exploitedToday's security advisory activity included the addition of four new Known Exploited Vulnerabilities (KEVs), notably CVE-2026-60137 and CVE-2026-63030, both affecting WordPress Core, as well as CVE-2021-27137 related to DD-WRT and CVE-2026-0770 concerning Langflow. The most critical advisories released today include Microsoft's July 2026 monthly rollup and a Siemens CADRA advisory, both marked as critical and exploited. Additionally, CISA has added four vulnerabilities to its catalog, highlighting ongoing threats. Among notable CVEs, several critical vulnerabilities were published, including CVE-2026-65008 in Grav and CVE-2026-13439 affecting a WordPress plugin, both posing significant risks. Overall, while CERT/PSIRT output was quiet, the volume of notable CVEs underscores the need for vigilance.
2026-07-20
Monday, Jul 20, 2026182 advisories▲ 1803029 CVEsOn July 20, 2026, the security advisory landscape saw significant activity with 182 advisories published by various CERT and PSIRT teams, alongside 3,029 new CVEs. Noteworthy critical advisories included updates from ServiceNow (AV26-693) and IBM (AV26-715), while several high-severity advisories addressed vulnerabilities in the Linux kernel and Golang. Among the notable CVEs, several critical vulnerabilities were identified, including CVE-2026-46412 in the @beproduct/nestjs-auth module and CVE-2026-44359 in the Meshtastic networking solution, both rated with a CVSS score of 10. Other critical vulnerabilities with scores of 9.9 and 9.8 were also reported, highlighting ongoing security challenges across various software platforms.
2026-07-19
Sunday, Jul 19, 20262 advisories▲ 1471 CVEsOn July 19, 2026, the CERT/PSIRT output was relatively quiet, with only two advisories released. However, a significant number of vulnerabilities were published, totaling 471 CVEs. Notable high-severity vulnerabilities include CVE-2026-12484, which affects keras-team/keras version 3.15.0 and allows unsafe deserialization of attacker-controlled data, and CVE-2026-16221, impacting fast-uri versions from 2.3.1 to 4.1.0. Additional high-severity vulnerabilities were identified in the SourceCodester Class and Exam Timetabling System (CVE-2026-16228 and CVE-2026-16227), as well as in newpanjing simpleui (CVE-2026-16210) and Gerapy (CVE-2026-16209).
2026-07-18
Saturday, Jul 18, 20261 advisories▼ 17882 CVEsOn July 18, 2026, there was one advisory published by a CERT/PSIRT, but no new additions to the Known Exploited Vulnerabilities (KEV) list. Among the 82 CVEs published today, two critical vulnerabilities stand out: CVE-2026-16117, affecting @fastify/http-proxy, which fails to rewrite the request prefix, and CVE-2026-47865, an authentication bypass in VMware Avi Load Balancer that could be exploited by a malicious user. Additionally, several high-severity vulnerabilities were reported, including multiple issues in Shibby Tomato 1.28 and a permissions flaw in SurrealDB. Teams should prioritize reviewing these vulnerabilities for potential impact on their environments.
2026-07-17
Friday, Jul 17, 2026179 advisories▼ 381951 CVEs1 exploitedOn July 17, 2026, security advisory activity was robust, with 179 advisories published by various CERT and PSIRT teams and 1,951 new CVEs released. Notable advisories included vulnerabilities fixed in Microsoft Office (NCSC-2026-0237) and multiple high-severity vulnerabilities affecting Microsoft Office 365, the Linux Kernel, Ubuntu Linux, nginx-ui, Mozilla Firefox, and Google Chrome. Additionally, several critical CVEs were highlighted, particularly those related to IBM Langflow OSS, which included multiple remote code execution vulnerabilities and privilege escalation issues, with CVSS scores reaching as high as 10. The day saw no new additions to the Known Exploited Vulnerabilities (KEV) list.
2026-07-16
Thursday, Jul 16, 20263 KEV217 advisories▼ 592169 CVEs4 exploitedOn July 16, 2026, security advisory activity included the addition of three significant vulnerabilities to the Known Exploited Vulnerabilities (KEV) catalog, specifically CVE-2026-25089 and CVE-2026-39808, both affecting Fortinet FortiSandbox, and CVE-2026-58644 related to Microsoft SharePoint. Critical advisories were issued for multiple Fortinet vulnerabilities and a monthly rollup from Microsoft, alongside advisories for Rockwell Automation products and SALTO ProAccess Space. In total, 217 advisories were published, with 2169 new CVEs, including notable critical vulnerabilities such as CVE-2026-45336 affecting HireFlow and CVE-2026-46512 impacting Frogman. The day was marked by a focus on critical vulnerabilities, underscoring the need for immediate attention from security teams.
2026-07-15
Wednesday, Jul 15, 20262 KEV276 advisories▲ 2463317 CVEs9 exploitedOn July 15, 2026, the security advisory landscape was marked by the addition of two significant vulnerabilities to the Known Exploited Vulnerabilities (KEV) catalog: CVE-2026-46817 affecting Oracle E-Business Suite and CVE-2023-4346 related to the KNX Protocol. Notably, several critical advisories were released, including vulnerabilities in Microsoft SharePoint Server (CVE-2026-56164 and CVE-2026-55040), and multiple issues in SonicWall Secure Mobile Access and Microsoft Windows. Additionally, a large number of notable CVEs were published today, with several critical vulnerabilities identified, such as CVE-2026-52887 in NocoBase and CVE-2026-50148 in Metabase, both rated with a CVSS score of 10. Overall, while CERT/PSIRT outputs were relatively quiet, the volume of published CVEs indicates a busy day for security teams.
2026-07-14
Tuesday, Jul 14, 20264 KEV30 advisories▼ 1401051 CVEs12 exploitedOn July 14, 2026, the security advisory landscape was marked by the addition of four critical vulnerabilities to the Known Exploited Vulnerabilities (KEV) catalog, including CVE-2026-15409 and CVE-2026-15410, both affecting SonicWall SMA1000 Appliances. Additionally, Microsoft reported critical vulnerabilities in Active Directory Federation Services (CVE-2026-56155) and SharePoint Server (CVE-2026-56164), both of which are being actively exploited. A total of 30 advisories were released today, alongside 1,051 new CVEs, highlighting significant security concerns across various platforms. Notably, several other critical vulnerabilities were identified, including CVE-2026-56451 in Opcenter X and CVE-2026-62422 in JetBrains YouTrack, emphasizing the need for immediate attention from security teams.
2026-07-13
Monday, Jul 13, 20261 KEV170 advisories1997 CVEs2 exploitedOn July 13, 2026, the security advisory landscape was marked by the addition of one known exploited vulnerability to the CISA catalog, specifically CVE-2008-4128, a Cross-Site Request Forgery vulnerability in Cisco IOS. Notable advisories included critical guidance on improving router hygiene to mitigate threats from Russian state-sponsored actors, along with multiple high-severity updates for the Linux Kernel and Node.js addressing various vulnerabilities. Additionally, several critical CVEs were published, including CVE-2026-57811 and CVE-2026-57719, both rated at CVSS 10 for severe code injection and file upload issues, respectively. Overall, while CERT/PSIRT output was relatively quiet, the volume of published CVEs highlights ongoing security concerns across multiple platforms.