CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

● Daily security briefing

Monday, August 10, 2026

August 10 saw heavy advisory volume with 163 CERT/PSIRT notices and 2,284 CVEs published, though no KEV additions were recorded. Critical attention should focus on two perfect-score SQL injection vulnerabilities in Metabase (CVE-2026-72899 and CVE-2026-72898) allowing unauthenticated remote attacks, alongside multiple critical flaws in Dokploy affecting versions through 0.29.13 and a critical ERPNext vulnerability. Notable advisories include CISA's alert on Gunra ransomware exploitation, updates to ClamAV addressing multiple denial-of-service and information disclosure issues, and high-severity patches for HTTP/2 implementations, Sonatype Nexus Repository Manager, Bouncy Castle, and libssh2. CVE-2025-8088 carries the highest exploitation probability at 0.945 EPSS score, warranting prioritization alongside the critical Metabase and Dokploy issues.

Last updated 04:40 UTC

CERT / PSIRT advisories
163
CVEs published
2284
Added to KEV
0
Known exploited
3

13 critical10 high1 unknownacross the day’s notable advisories and CVEs

Notable advisories

Critical/high or exploited items from national CERTs and vendor PSIRTs.

Notable CVEs

Highest-severity CVEs published this day from the NVD and GitHub Advisory firehose — the sharpest items behind the day’s numbers.

Highest exploitation probability

EPSS (FIRST.org) estimated probability of exploitation within 30 days, among CVEs published this day.

Where the day’s advisories came from

Curated CERT and PSIRT sources — these add up to the 163 above.

plus 727 CVE records from the NVD/GHSA firehose — not counted above

Get this briefing by email. One free message every morning after 06:00 UTC — same data, zero noise, one-click unsubscribe. Subscribe. Tracking specific products instead? Watch them from any product page and get alerted only when they ship a new advisory.