● Daily security briefing
Sunday, August 16, 2026
August 16th saw 117 CVEs published with no new KEV entries or CERT/PSIRT advisories of note, though eight critical vulnerabilities emerged across networking and software platforms. Edimax EW-7478APC router firmware 1.04 contains two critical weaknesses (CVE-2026-19959 and CVE-2026-19961, both CVSS 9.9) affecting WAN TCP/IP and wireless site survey functions, while Tenda AC10 routers and SiYuan before version 3.7.4 each carry separate critical flaws at CVSS 9.8. Multiple WordPress plugins also face critical vulnerabilities including arbitrary file upload in ProSolution WP Client and privilege escalation in Frontend Admin by DynamiApps. Organizations running these devices and plugins should prioritize patching efforts given the severity and breadth of exposed functionality.
11 critical1 highacross the day’s notable advisories and CVEs
Notable CVEs
Highest-severity CVEs published this day from the NVD and GitHub Advisory firehose — the sharpest items behind the day’s numbers.
- criticalCVE-2026-19959CVSS 9.9A weakness has been identified in Edimax EW-7478APC 1.04. This affects the function formWanTcpipSetup of the file /goform/formWanTcpipSetup. This manipulation of the argument pppUs
- criticalCVE-2026-19961CVSS 9.9A vulnerability was detected in Edimax EW-7478APC 1.04. Affected is the function formWlSiteSurvey of the file /goform/formWlSiteSurvey. Performing a manipulation of the argument se
- criticalCVE-2026-73056CVSS 9.8SiYuan kernel versions before 3.7.4 contain an improper restriction of excessive authentication attempts vulnerability in the CheckAuth() middleware. The middleware accepts the API
- criticalCVE-2026-73061CVSS 9.8Scriban before 7.2.2 contains an access-modifier bypass vulnerability in TypedObjectAccessor that allows template code to write CLR object properties without setter-visibility chec
- criticalCVE-2026-19924CVSS 9.8A security vulnerability has been detected in Tenda AC10 16.03.10.09_multi_TDE01. This vulnerability affects the function R7WebsSecurityHandler of the component httpd. The manipula
- criticalCVE-2024-13784CVSS 9.8The Contact Form, Survey, Quiz & Popup Form Builder – ARForms plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.8.5 via deserializa
- criticalCVE-2026-16098CVSS 9.8The ProSolution WP Client plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 2.0.10 via the proSol_handleFileUpload function. This is
- criticalCVE-2026-18432CVSS 9.8The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.29.9. The vulnerability exists because `ActionUs
- criticalCVE-2026-18316CVSS 9.1The Solace Extra plugin for WordPress is vulnerable to unauthorized modification and loss of data due to a missing capability check on the import_zip() function in versions up to,
- criticalCVE-2026-74790CVSS 9.1Scriban before 7.0.0 caches TypedObjectAccessor by Type only without considering MemberFilter changes, allowing reused TemplateContext instances to expose members that should be hi
- criticalCVE-2026-14524CVSS 9.1The ProSolution WP Client plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the proSol_fileDeleteProcess function in all ver
- highCVE-2026-17123CVSS 8.8The Royal Elementor Addons plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including, 1.7.1064 via the Form Builder widget's 'webhook_url'
Highest exploitation probability
EPSS (FIRST.org) estimated probability of exploitation within 30 days, among CVEs published this day.
Where the day’s advisories came from
Curated CERT and PSIRT sources — these add up to the 2 above.