● Daily security briefing
Monday, August 10, 2026
August 10 saw heavy advisory volume with 163 CERT/PSIRT notices and 2,284 CVEs published, though no KEV additions were recorded. Critical attention should focus on two perfect-score SQL injection vulnerabilities in Metabase (CVE-2026-72899 and CVE-2026-72898) allowing unauthenticated remote attacks, alongside multiple critical flaws in Dokploy affecting versions through 0.29.13 and a critical ERPNext vulnerability. Notable advisories include CISA's alert on Gunra ransomware exploitation, updates to ClamAV addressing multiple denial-of-service and information disclosure issues, and high-severity patches for HTTP/2 implementations, Sonatype Nexus Repository Manager, Bouncy Castle, and libssh2. CVE-2025-8088 carries the highest exploitation probability at 0.945 EPSS score, warranting prioritization alongside the critical Metabase and Dokploy issues.
13 critical10 high1 unknownacross the day’s notable advisories and CVEs
Notable advisories
Critical/high or exploited items from national CERTs and vendor PSIRTs.
- unknownexploitedcert-fr-avisMultiple vulnerabilities in ClamAV (August 10, 2026)
- criticalexploitedcisa#StopRansomware: Gunra Ransomware
- highexploitedcert-bund[UPDATE] [high] http/2 implementations: Vulnerability allows denial of service
- highcert-bund[NEW] [high] Sonatype Nexus Repository Manager: Multiple vulnerabilities
- highcert-bund[NEW] [high] Bouncy Castle: Multiple vulnerabilities
- highcert-bund[NEW] [high] libssh2: Multiple vulnerabilities
- highcert-bund[NEW] [high] ClamAV: Multiple vulnerabilities allow Denial of Service and disclosure of information
- highcert-bund[UPDATE] [high] Node.js: Multiple vulnerabilities
- highcert-bund[UPDATE] [high] VMware Tanzu Spring Framework: Multiple vulnerabilities
- highcert-bund[UPDATE] [high] jq: Multiple vulnerabilities
- highcert-bund[UPDATE] [high] GnuTLS: Multiple vulnerabilities
- highcert-bund[UPDATE] [high] CPython: Multiple vulnerabilities
Notable CVEs
Highest-severity CVEs published this day from the NVD and GitHub Advisory firehose — the sharpest items behind the day’s numbers.
- criticalCVE-2026-72899CVSS 10Metabase allows an unauthenticated attacker to inject arbitrary SQL via a publicly shared card or dashboard that exposes a field-filter (dimension) parameter.
- criticalCVE-2026-72898CVSS 10Metabase allows a remote, unauthenticated attacker to inject arbitrary SQL via the '/reset_password' database endpoint and gain administrator access to the connected Metabase insta
- criticalCVE-2026-14450CVSS 9.9A flaw was found in the MaaS API. This vulnerability allows any pod within the cluster to bypass the Kuadrant AuthPolicy gateway by forging HTTP headers, specifically `X-MaaS-Usern
- criticalCVE-2026-72911CVSS 9.9ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.118.0 and 16.29.0, the validate_template and render_template calls in erpnext/accounts/doctype/proc
- criticalCVE-2026-72886CVSS 9.9Dokploy is a free, self-hostable Platform as a Service (PaaS). From 0.29.2 until 0.29.13, schedule.create and schedule.update in apps/dokploy/server/api/routers/schedule.ts derive
- criticalCVE-2026-72882CVSS 9.9Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.28.8 and earlier, an authenticated user who can create or update file mounts for a service can inject shell meta
- criticalCVE-2026-72902CVSS 9.9Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, Dokploy allows an authenticated user to execute arbitrary commands on a local or SSH-connected targ
- criticalCVE-2026-72880CVSS 9.9Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the apiCreateCertificate schema in packages/server/src/db/schema/certificate.ts accepts a client-su
- criticalCVE-2026-72901CVSS 9.9Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, Dokploy allows an authenticated low-privilege member to execute arbitrary commands on the control-p
- criticalCVE-2026-72876CVSS 9.9Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, swarm.getNodes, swarm.getNodeInfo, swarm.getNodeApps, and swarm.getAppInfos in apps/dokploy/server/
- criticalCVE-2026-72872CVSS 9.9Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, application.saveBitbucketProvider stores bitbucketOwner and bitbucketRepository without validation
- criticalCVE-2026-18948CVSS 9.9A flaw was found in Feast. The system improperly deserializes user-defined functions (UDFs) stored in its registry, which are serialized using the 'dill' library. This allows a rem
Highest exploitation probability
EPSS (FIRST.org) estimated probability of exploitation within 30 days, among CVEs published this day.
Where the day’s advisories came from
Curated CERT and PSIRT sources — these add up to the 163 above.