● Daily security briefing
Tuesday, August 11, 2026
August 11 saw moderate advisory volume with 358 CERT/PSIRT advisories and 2,240 CVEs published, highlighted by three critical KEV additions: CVE-2026-68820 affecting Microsoft Windows Ancillary Function Driver for WinSock elevation of privilege, CVE-2026-20349 in Cisco Secure Firewall ASA and FTD heap overflow, and CVE-2026-72898 Metabase SQL injection. Additional high-priority exploited vulnerabilities include a JetBrains TeamCity code execution flaw (CERT-BUND), Cisco Secure Firewall SSL VPN denial of service, and static credential issues in Cisco Management Center, alongside multiple sudo vulnerabilities updates. Beyond KEV items, the day featured six critical CVSS 10.0 vulnerabilities spanning SAP Commerce Cloud, ColdFusion, LiquidJS, SIMATIC IoT2050, and related systems, which should be reviewed for impact to your environment.
15 critical7 high2 unknownacross the day’s notable advisories and CVEs
Added to the KEV catalog
Exploitation observed in the wild — remediate first.
- exploitedCVE-2026-68820CVE-2026-68820: Microsoft Windows Ancillary Function Driver for WinSock Use-After-Free Vulnerability
- exploitedCVE-2026-20349CVE-2026-20349: Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) Heap Inspection Vulnerability
- exploitedCVE-2026-72898CVE-2026-72898: Metabase SQL Injection Vulnerability
Notable advisories
Critical/high or exploited items from national CERTs and vendor PSIRTs.
- highexploitedmsrcCVE-2026-68820: Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
- highexploitedcisco-psirtCisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software Remote Access SSL VPN Denial of Service Vulnerability
- highexploitedcisco-psirtCisco Secure Firewall Management Center Software Static Credential Vulnerability
- criticalexploitedcert-bund[NEW] [high] JetBrains TeamCity: Vulnerability allows code execution
- unknownexploitedncsc-nlNCSC-2026-0281 [1.00] [M/H] Vulnerabilities patched in Arista VeloCloud Orchestrator On-Prem
- highexploitedcert-bund[UPDATE] [high] sudo: Multiple vulnerabilities
- unknownexploitedncsc-nlNCSC-2026-0284 [1.00] [M/H] Vulnerabilities patched in Microsoft Windows
- highexploitedcisaCISA Adds Three Known Exploited Vulnerabilities to Catalog
- criticalmsrcCVE-2026-65667: Microsoft Teams Elevation of Privilege Vulnerability
- criticalmsrcCVE-2026-56162: Azure SQL Database Elevation of Privilege Vulnerability
- criticalmsrcCVE-2026-63508: Microsoft Planetary Computer Pro Elevation of Privilege Vulnerability
- criticalmsrcCVE-2026-50515: Azure Service Bus Remote Code Execution Vulnerability
Notable CVEs
Highest-severity CVEs published this day from the NVD and GitHub Advisory firehose — the sharpest items behind the day’s numbers.
- highexploitedCVE-2026-20349CVSS 8.6A vulnerability in the Remote Access SSL VPN service for Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software co
- highexploitedCVE-2026-68820CVSS 7Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
- criticalCVE-2026-17061CVSS 10A Deserialization of Untrusted Data vulnerability affecting SIMULIA Execution Engine from Release 2023 through Release 2026 could lead to an unauthenticated remote code execution.
- criticalCVE-2026-48362CVSS 10ColdFusion is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could result in arbitrary code execution
- criticalCVE-2026-45618CVSS 10LiquidJS is a Shopify/GitHub Pages compatible template engine. Prior to version 10.26.0, it is possible to execute arbitrary code with crafted templates. Version 10.26.0 patches th
- criticalCVE-2026-58231CVSS 10SAP Commerce Cloud allows an unauthenticated attacker to abuse a default authentication client and submit specially crafted input to certain functions lacking sufficient validation
- criticalCVE-2026-58115CVSS 10A vulnerability has been identified in SIMATIC IoT2050 Advanced (6ES7647-0BA00-1YA2) (All versions < V4.3.4.1 running Industrial OS with Node-RED installed). Affected devices do no
- criticalCVE-2026-48056CVSS 10Streambert is a cross-platform Electron Desktop App to stream and download video content. Versions prior to 2.5.0 improperly validate executable paths supplied to the run-downloa
- criticalCVE-2026-71398CVSS 10Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. An attacker c
- criticalCVE-2026-27302CVSS 10Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. An attacker c
- criticalCVE-2026-48765CVSS 9.9TypeBot is a chatbot builder tool. Versions prior to 3.17.0 allow a low-privilege read collaborator to extract a workspace OAuth `credentialsId` from a readable bot configuration a
- criticalCVE-2026-72603CVSS 9.9An OS command injection vulnerability in wg-easy 15.3.0 allows users with the clients.create permission to execute arbitrary commands as root by injecting newline-delimited WireGua
Where the day’s advisories came from
Curated CERT and PSIRT sources — these add up to the 358 above.