● Daily security briefing
Friday, August 7, 2026
CSIRT teams faced a significant advisory volume on August 7th with 121 CERT/PSIRT advisories and 2,030 CVEs published, highlighted by the addition of CVE-2026-8037 (Progress LoadMaster Command Injection) to the Known Exploited Vulnerabilities catalog with an EPSS score of 0.848. Multiple critical Microsoft vulnerabilities emerged including CVE-2026-65667 and CVE-2026-56162 affecting Teams and Azure SQL Database respectively, both rated CVSS 10.0, alongside several other critical Azure and Plesk issues rated 9.9. Notable actively exploited advisories included updates on Progress software (AV26-552), Atlassian platforms, Linux Kernel Dirty Frag vulnerabilities, and newly disclosed Arista VeloCloud Orchestrator vulnerabilities enabling arbitrary code execution with root privileges. Teams should prioritize patching the Progress LoadMaster vulnerability and the critical Microsoft Azure issues given their exploit activity and attack surface.
13 critical9 high2 unknownacross the day’s notable advisories and CVEs
Added to the KEV catalog
Exploitation observed in the wild — remediate first.
Notable advisories
Critical/high or exploited items from national CERTs and vendor PSIRTs.
- unknownexploitedcccsN-able security advisory (AV26-769) - Update 2
- highexploitedcert-bund[UPDATE] [high] Atlassian Bamboo, Bitbucket, Confluence, Fisheye, Crucible, Jira and Jira Service Management: Multiple vulnerabilities
- criticalexploitedcccsProgress security advisory (AV26-552) – Update 2
- highexploitedcert-bund[UPDATE] [high] Linux Kernel (Dirty Frag): Multiple vulnerabilities allow gaining administrator rights
- unknownexploitedncsc-nlNCSC-2026-0275 [1.01] [M/H] Vulnerabilities patched in N-able N-central
- highexploitedcert-bund[NEW] [high] Arista VeloCloud Orchestrator: Vulnerability enables execution of arbitrary code with root privileges
- highexploitedcisaCISA Adds One Known Exploited Vulnerability to Catalog
- highcert-bund[UPDATE] [high] Linux Kernel: Multiple vulnerabilities
- highcert-bund[NEW] [high] Microsoft Power Apps: Vulnerability enables privilege escalation
- highcert-bund[NEW] [high] Red Hat Enterprise Linux (sssd, glib, c-ares): Multiple vulnerabilities
- highcert-bund[NEW] [high] Apache Portable Runtime (APR): Multiple vulnerabilities
- highcert-bund[NEW] [high] Apple macOS (Tahoe, Sonoma, and Sequoia): Multiple vulnerabilities
Notable CVEs
Highest-severity CVEs published this day from the NVD and GitHub Advisory firehose — the sharpest items behind the day’s numbers.
- criticalCVE-2026-65667CVSS 10Missing authorization in Microsoft Teams allows an unauthorized attacker to elevate privileges over a network.
- criticalCVE-2026-56162CVSS 10Improper authentication in Azure SQL Database allows an unauthorized attacker to elevate privileges over a network.
- criticalCVE-2026-63508CVSS 10Missing authentication for critical function in Microsoft Planetary Computer Pro allows an unauthorized attacker to elevate privileges over a network.
- criticalCVE-2026-59115CVSS 9.9'.../...//' in Microsoft Entra Provisioning Service (SyncFabric) allows an authorized attacker to elevate privileges over a network.
- criticalCVE-2026-50515CVSS 9.9Deserialization of untrusted data in Azure Service Bus allows an authorized attacker to execute code over a network.
- criticalCVE-2026-64637CVSS 9.9Improper privilege management in the XML-RPC API of Plesk before 18.0.80, allows an authenticated reseller to obtain an administrative session for the root user account.
- criticalCVE-2026-62830CVSS 9.9Missing authorization in Azure SRE Agent allows an authorized attacker to elevate privileges over a network.
- criticalCVE-2026-50481CVSS 9.9Modification of assumed-immutable data (maid) in Azure Active Directory allows an authorized attacker to elevate privileges over a network.
- criticalCVE-2026-14364CVSS 9.8The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to account takeover via improper password reset validation in all versions up to, and i
- criticalCVE-2026-63223CVSS 9.8GHSA-mmj4-63m4-r6h5: CodeIgniter: Uploaded file extension validation bypass in `is_image` and `mime_in` rules
- criticalCVE-2026-14365CVSS 9.8The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.2.3. This is due to the
- criticalCVE-2026-71558CVSS 9.8Heap type confusion vulnerability in Apache Fory C++ deserialization. This issue affects Apache Fory C++ versions from 0.14.0 before 1.5.0. A crafted input payload can bypass type
Highest exploitation probability
EPSS (FIRST.org) estimated probability of exploitation within 30 days, among CVEs published this day.
Where the day’s advisories came from
Curated CERT and PSIRT sources — these add up to the 121 above.