● Daily security briefing
Friday, August 14, 2026
August 14 saw heavy advisory activity with 201 CERT/PSIRT advisories and 2,737 CVEs published, though no new KEV additions. Notable high-severity advisories included updates to HTTP/2 implementations and Linux Kernel vulnerabilities, alongside new guidance on BIND, Elasticsearch, and multiple Synacor Zimbra issues from CERT-Bund, plus advisories from CERT-FR covering IBM products and SUSE Linux kernel flaws. The day was dominated by critical vulnerabilities, including CVSS 10.0 SQL injection in SiYuan and unauthenticated RCE in MindsDB, alongside multiple CVSS 9.9-9.8 command injection and authentication bypass flaws in Tenable Security Center and IBM Db2 Mirror for i that warrant immediate prioritization.
12 critical10 high2 unknownacross the day’s notable advisories and CVEs
Notable advisories
Critical/high or exploited items from national CERTs and vendor PSIRTs.
- highexploitedcert-bund[UPDATE] [high] http/2 implementations: Vulnerability allows denial of service
- highexploitedcert-bund[UPDATE] [high] Linux Kernel: Multiple vulnerabilities
- unknownexploitedcert-fr-avisMultiple vulnerabilities in IBM products (August 14, 2026)
- unknownexploitedcert-fr-avisMultiple vulnerabilities in SUSE Linux kernel (August 14, 2026)
- highcert-bund[UPDATE] [high] Synacor Zimbra: Multiple vulnerabilities
- highcert-bund[NEW] [high] Synacor Zimbra: Multiple vulnerabilities
- highcert-bund[NEW] [high] Internet Systems Consortium BIND: Multiple vulnerabilities
- highcert-bund[NEW] [high] Elasticsearch: Multiple vulnerabilities
- highcert-bund[NEW] [high] Golang Go: Multiple vulnerabilities
- highcert-bund[NEW] [high] vllm: Multiple vulnerabilities
- highcert-bund[UPDATE] [high] Linux Kernel: Multiple Vulnerabilities
- highcert-bund[NEW] [high] BigBlueButton: Vulnerability enables disclosure of information
Notable CVEs
Highest-severity CVEs published this day from the NVD and GitHub Advisory firehose — the sharpest items behind the day’s numbers.
- criticalCVE-2026-72811CVSS 10SiYuan versions <= v3.7.2 contain a SQL injection vulnerability in the backlink/mention search query (kernel/model/backlink.go), which concatenates stored block metadata (title, na
- criticalCVE-2026-73678CVSS 10MindsDB Minds Platform version 26.1.0 and earlier contains an unauthenticated remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary OS comm
- criticalCVE-2026-19188CVSS 10A critical OS command injection vulnerability has been identified in the Haiwell IoT Cloud HMI Gateway product. The vulnerability exists in the Net Check feature accessible via t
- criticalCVE-2026-19626CVSS 9.9A remote code execution vulnerability exists in Tenable Security Center's report generation functionality. An authenticated, non-administrative user could exploit this issue by sup
- criticalCVE-2026-19681CVSS 9.9An authenticated command injection vulnerability exists in Security Center related to file upload processing. An attacker could exploit this issue by uploading a specially crafted
- criticalCVE-2026-17186CVSS 9.9IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to execute arbitrary CL commands due to improper neutralization of special elements in a command.
- criticalCVE-2026-19682CVSS 9.9A command injection vulnerability exists in Security Center where a remote, unauthenticated attacker could exploit this issue to execute arbitrary commands on the underlying operat
- criticalCVE-2026-17182CVSS 9.8IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to bypass authentication and obtain or alter sensitive information due to improper validation of request URI pa
- criticalCVE-2026-50027CVSS 9.8mcp-memory-service is a semantic memory layer for AI applications. Prior to 10.67.1, all HTTP routes under /api/documents/* in mcp-memory-service are served without any authenticat
- criticalCVE-2026-48528CVSS 9.8Metacat is data repository software that helps researchers preserve, share, and discover data. Metacat versions 2.0.0 through 3.4.0 contain an unauthenticated SQL injection vulnera
- criticalCVE-2026-73849CVSS 9.8Emlog is an open source website building system. In 2.6.26 and earlier, install.php accepts action=reinstall without authentication and deliberately skips the already-installed che
- criticalCVE-2026-17184CVSS 9.8IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to execute arbitrary code due to external control of file name or path.
Where the day’s advisories came from
Curated CERT and PSIRT sources — these add up to the 201 above.