● Daily security briefing
Saturday, August 15, 2026
The security advisory landscape remained relatively quiet on the CERT/PSIRT front with just one advisory published, but 926 CVEs were disclosed today with eight critical vulnerabilities requiring immediate attention. Multiple WordPress plugins were flagged with critical authentication bypass and account takeover issues, including CVE-2026-19598 in Pods, CVE-2026-15341 in User Session Synchronizer, CVE-2026-15303 in 6Storage Rentals, CVE-2026-15826 in User Profile Builder, and CVE-2026-16142 in TrueBooker, all rated at CVSS 9.8. Additionally, SiYuan before v3.7.4 was disclosed with a critical authentication flaw (CVE-2026-73046), and two WordPress plugins—Link Library and RapiSafe—were found vulnerable to arbitrary file operations with CVSS ratings of 9.1. Teams should prioritize patching these WordPress plugin vulnerabilities given their widespread deployment and exploitation risk.
12 criticalacross the day’s notable advisories and CVEs
Notable CVEs
Highest-severity CVEs published this day from the NVD and GitHub Advisory firehose — the sharpest items behind the day’s numbers.
- criticalCVE-2026-73046CVSS 9.8SiYuan before v3.7.4 improperly restricts excessive authentication attempts in the CheckAuth() middleware. The HTTP Basic Authentication branch, which guards nearly the entire /api
- criticalCVE-2026-19598CVSS 9.8The Pods – Custom Content Types and Fields plugin for WordPress is vulnerable to Privilege Escalation via Authorization Bypass in all versions up to, and including, 3.3.9. The vuln
- criticalCVE-2026-15341CVSS 9.8The User Session Synchronizer plugin for WordPress is vulnerable to Authentication Bypass leading to Account Takeover in all versions up to, and including, 1.4.0. The `synchronize_
- criticalCVE-2026-15303CVSS 9.8The 6Storage Rentals plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.27.0. This is due to the six_storage_create_wp_user() AJAX hand
- criticalCVE-2026-15826CVSS 9.8The User Profile Builder plugin for WordPress is vulnerable to Authentication Bypass via Type Confusion in versions up to, and including, 3.16.4. This is due to the wppb_log_in_use
- criticalCVE-2026-16142CVSS 9.8The TrueBooker plugin for WordPress is vulnerable to Account Takeover in all versions up to, and including, 1.2.6. This is due to the add_front_user_update() AJAX handler being reg
- criticalCVE-2026-18855CVSS 9.1The Link Library plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the ll_delete_link_fields function in all versions up to,
- criticalCVE-2026-14484CVSS 9.1The RapiSafe – Secure Multi File Upload for Contact Form 7 plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the handleAjaxR
- criticalCVE-2026-73042CVSS 9SiYuan before v3.7.4 fails to properly escape database menu metadata in HTML interpolation, allowing stored values to execute script when users open group, view, or field-edit menu
- criticalCVE-2026-73043CVSS 9SiYuan versions before v3.7.4 contain a remote code execution vulnerability in the Template calculation operator, which renders user-authored Go templates and stores output verbati
- criticalCVE-2026-73050CVSS 9SiYuan versions before v3.7.4 fail to validate or escape the color field in attribute-view select options, allowing stored cross-site scripting through eight unescaped render sites
- criticalCVE-2026-73044CVSS 9SiYuan versions before v3.7.4 fail to validate or escape table column width values, allowing stored cross-site scripting injection into style attributes. Attackers can inject malic
Where the day’s advisories came from
Curated CERT and PSIRT sources — these add up to the 1 above.