CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

● Daily security briefing

Thursday, August 13, 2026

Thursday, August 13 saw substantial advisory activity with 241 CERT/PSIRT advisories and 3,257 CVEs published, though no new KEV entries were added. Critical vulnerabilities dominated the landscape, including multiple CVSS 10.0 flaws in QA Analytics, WP BASE Booking, and the malicious Link Factory WordPress plugin, alongside critical issues in industrial control systems like Siemens LOGO! Soft Comfort and Haiwell IoT Cloud HMI Gateway tracked by CISA. Microsoft Windows received critical updates addressing multiple vulnerabilities, while Linux kernel flaws and Cisco ASA/Secure Firewall SSL VPN issues (CVE-202 referenced in AL26-018) were flagged as actively exploited. Teams should prioritize patching the CVSS 10.0 unauthenticated RCE vulnerabilities affecting QA Analytics and Budibase SQL injection, as well as reviewing their Windows and industrial control system inventory for the critical patches released today.

Last updated 05:04 UTC

CERT / PSIRT advisories
241
CVEs published
3257
Added to KEV
0
Known exploited
4

20 critical3 high1 mediumacross the day’s notable advisories and CVEs

Notable advisories

Critical/high or exploited items from national CERTs and vendor PSIRTs.

Notable CVEs

Highest-severity CVEs published this day from the NVD and GitHub Advisory firehose — the sharpest items behind the day’s numbers.

Highest exploitation probability

EPSS (FIRST.org) estimated probability of exploitation within 30 days, among CVEs published this day.

Where the day’s advisories came from

Curated CERT and PSIRT sources — these add up to the 241 above.

plus 627 CVE records from the NVD/GHSA firehose — not counted above

Get this briefing by email. One free message every morning after 06:00 UTC — same data, zero noise, one-click unsubscribe. Subscribe. Tracking specific products instead? Watch them from any product page and get alerted only when they ship a new advisory.