● Daily security briefing
Thursday, August 6, 2026
August 6th saw significant advisory activity with 221 CERT/PSIRT advisories and 2,981 CVEs published, though no new KEV additions were recorded. Critical issues dominated the landscape, including multiple exploited vulnerabilities in Atlassian products (Bamboo, Bitbucket, Confluence, Jira and others) and a newly disclosed code execution flaw in JetBrains TeamCity, alongside CISA alerts for ABB Ability Zenon exploitation. Microsoft released a substantial patch set with five critical Azure and Teams vulnerabilities including remote code execution in Azure Service Bus and elevation of privilege issues across multiple cloud services. Beyond enterprise software, multiple critical CVSS 10 vulnerabilities emerged in WordPress plugins and open-source tools, including unauthenticated RCE in Spider Analyser, malicious code in Premium SEO, and JWT authentication bypass issues, reflecting ongoing risks in widely-deployed web infrastructure.
23 critical1 highacross the day’s notable advisories and CVEs
Notable advisories
Critical/high or exploited items from national CERTs and vendor PSIRTs.
- highexploitedcert-bund[UPDATE] [high] Atlassian Bamboo, Bitbucket, Confluence, Fisheye, Crucible, Jira and Jira Service Management: Multiple vulnerabilities
- criticalexploitedcert-bund[NEW] [high] JetBrains TeamCity: Vulnerability allows code execution
- criticalexploitedcisaABB Ability Zenon
- criticalmsrcCVE-2026-56162: Azure SQL Database Elevation of Privilege Vulnerability
- criticalmsrcCVE-2026-65667: Microsoft Teams Elevation of Privilege Vulnerability
- criticalmsrcCVE-2026-63508: Microsoft Planetary Computer Pro Elevation of Privilege Vulnerability
- criticalmsrcCVE-2026-50515: Azure Service Bus Remote Code Execution Vulnerability
- criticalmsrcCVE-2026-50481: Azure Active Directory Elevation of Privilege Vulnerability
- criticalmsrcCVE-2026-59115: Microsoft Entra Provisioning Service Elevation of Privilege Vulnerability
- criticalmsrcCVE-2026-62830: Azure SRE Agent Elevation of Privilege Vulnerability
- criticalmsrcCVE-2026-62873: Microsoft 365 Admin Center Elevation of Privilege Vulnerability
- criticalmsrcCVE-2026-56161: Azure Logic Apps Information Disclosure Vulnerability
Notable CVEs
Highest-severity CVEs published this day from the NVD and GitHub Advisory firehose — the sharpest items behind the day’s numbers.
- criticalCVE-2026-65553CVSS 10Unauthenticated Remote Code Execution (RCE) in Spider Analyser – WordPress搜索引擎蜘蛛分析插件 <= 2.1.3 versions.
- criticalCVE-2026-14812CVSS 10The Premium SEO WordPress plugin is malicious: it ships an unauthenticated backdoor that creates a hidden administrator account and, in some builds, also enables remote code execut
- criticalCVE-2026-5430CVSS 10The JWT authentication mechanism accepts tokens signed with algorithms other than those explicitly configured or supported. This allows an attacker to craft a JWT with an unsupport
- criticalCVE-2026-11976CVSS 10The official MonsterInsights Pro update distribution bucket (`monster-insights.s3.amazonaws.com`) was compromised. Both the current release (10.2.2) and the version MonsterInsights
- criticalCVE-2026-66665CVSS 10Unauthenticated Arbitrary File Upload in Type Hub <= 2.0.6 versions.
- criticalCVE-2026-48086CVSS 9.9OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.2, a TENANT_ADMIN promotes themselves to platform-w
- criticalCVE-2026-65548CVSS 9.9Contributor Remote Code Execution (RCE) in Betheme <= 28.4.2 versions.
- criticalCVE-2026-67622CVSS 9.9Flowise through 3.1.4 contains an insecure direct object reference vulnerability in the OpenAI Assistants integration that allows authenticated attackers to access credentials belo
- criticalCVE-2026-48085CVSS 9.8OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.1, a fully provisioned OpenReception instance accep
- criticalCVE-2026-17032CVSS 9.8Multiple Supsystic Pro plugins were distributed with malicious code through the vendor's compromised update server, allowing unauthenticated attackers to deploy a second-stage payl
- criticalCVE-2026-70558CVSS 9.8Dinky's POST /download/uploadFromRsByLocal handler passes the caller-supplied path parameter directly to new File(path) and file.transferTo(dest) with no path validation. The route
- criticalCVE-2026-48087CVSS 9.8OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.2, the registration handler at `POST /api/auth/regi
Where the day’s advisories came from
Curated CERT and PSIRT sources — these add up to the 221 above.