● Daily security briefing
Thursday, August 13, 2026
Thursday, August 13 saw substantial advisory activity with 241 CERT/PSIRT advisories and 3,257 CVEs published, though no new KEV entries were added. Critical vulnerabilities dominated the landscape, including multiple CVSS 10.0 flaws in QA Analytics, WP BASE Booking, and the malicious Link Factory WordPress plugin, alongside critical issues in industrial control systems like Siemens LOGO! Soft Comfort and Haiwell IoT Cloud HMI Gateway tracked by CISA. Microsoft Windows received critical updates addressing multiple vulnerabilities, while Linux kernel flaws and Cisco ASA/Secure Firewall SSL VPN issues (CVE-202 referenced in AL26-018) were flagged as actively exploited. Teams should prioritize patching the CVSS 10.0 unauthenticated RCE vulnerabilities affecting QA Analytics and Budibase SQL injection, as well as reviewing their Windows and industrial control system inventory for the critical patches released today.
20 critical3 high1 mediumacross the day’s notable advisories and CVEs
Notable advisories
Critical/high or exploited items from national CERTs and vendor PSIRTs.
- highexploitedcert-bund[UPDATE] [high] Linux Kernel: Multiple vulnerabilities
- highexploitedcccsAL26-018 - Vulnerability affecting Cisco ASA and Secure Firewall Threat Defense Software Remote Access SSL VPN - CVE-2026-20349
- mediumexploitedcert-bund[UPDATE] [medium] Linux Kernel: Multiple vulnerabilities allow Denial of Service
- criticalexploitedcert-bund[UPDATE] [critical] Microsoft Windows: Multiple Vulnerabilities
- criticalcisaHaiwell IoT Cloud HMI Gateway
- criticalcisaSiemens Simcenter Femap
- highcert-bund[NEW] [high] Absolute Secure Access: Multiple vulnerabilities enable Denial of Service
- criticalcisaSiemens LOGO! Soft Comfort
- criticalcisaAVEVA Enterprise SCADA
- criticalcisaFlow Neuroscience FL-100
- criticalcisaSiemens Siveillance Video
- criticalcisaANDRITZ HIPASE-250 and 250 SCALA
Notable CVEs
Highest-severity CVEs published this day from the NVD and GitHub Advisory firehose — the sharpest items behind the day’s numbers.
- criticalCVE-2026-27544CVSS 10Unauthenticated Remote Code Execution (RCE) in QA Analytics <= 5.2.0.0 versions.
- criticalCVE-2026-61962CVSS 10Unauthenticated Arbitrary Code Execution in WP BASE Booking <= 6.3.0 versions.
- criticalCVE-2026-59500CVSS 10CWE-287: Improper Authentication
- criticalCVE-2026-15413CVSS 10The Link Factory WordPress plugin is a backdoor. Distributed as a "homepage sentence publisher", it exposes an operator-controlled REST API under /wp-json/link-factory/v1/ - authen
- criticalCVE-2026-72851CVSS 10Budibase before 3.40.0 contains an unauthenticated SQL injection vulnerability in webhook-triggered automations with EXECUTE_QUERY steps. Attackers can POST attacker-controlled JSO
- criticalCVE-2026-72841CVSS 9.9luci-app-openvpn fails to properly validate the instance_name2 parameter during file upload, allowing authenticated users to perform path traversal and write arbitrary files outsid
- criticalCVE-2026-73656CVSS 9.9Trigger.dev is a platform for building and deploying fully managed AI agents and workflows. Prior to 4.5.6, POST /api/v1/deployments/:deploymentId/background-workers calls CreateDe
- criticalCVE-2026-72842CVSS 9.9luci-app-lxc contains an ACL inconsistency vulnerability that allows low-privileged authenticated LuCI users to access backend container management routes without proper authorizat
- criticalCVE-2026-72839CVSS 9.8filebrowser through 2.63.16 fails to properly restrict scope and permissions when self-signup is enabled with default CreateUserDir setting. Unauthenticated attackers can register
- criticalCVE-2026-17482CVSS 9.8IBM Documentation Offline 1.0.0 through 1.4.1 could allow a remote attacker to execute arbitrary code due to improper control of file paths.
- criticalCVE-2026-19747CVSS 9.8A weakness has been identified in Tenda CH7, CH7G, CH10, CP3, CP3 Pro, CP7, TC3B14C, TC3B15C, TC3T14C and TC3T15C up to 20260625. This impacts the function CAte::HandleCmd of the f
- criticalCVE-2026-73649CVSS 9.8Velocity.js is a JavaScript implementation of the Apache Velocity template engine. Prior to 2.1.7, the earlier fix for CVE-2026-44966 filtered constructor, __proto__, and prototype
Highest exploitation probability
EPSS (FIRST.org) estimated probability of exploitation within 30 days, among CVEs published this day.
Where the day’s advisories came from
Curated CERT and PSIRT sources — these add up to the 241 above.