CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

● Daily security briefing

Monday, August 17, 2026

CERT and PSIRT activity was robust today with 209 advisories issued and 3000 CVEs published, headlined by the addition of CVE-2025-62593 (Ray-Project code injection) to CISA's Known Exploited Vulnerabilities catalog. Critical issues dominate the landscape, particularly multiple vm2 sandbox escape vulnerabilities (CVE-2026-47686, GHSA-m283-3h24-438v, GHSA-m5w8-4gq2-6f8x, GHSA-cfcw-xp6x-25gj) with CVSS scores ranging from 9.8 to 10.0, along with perfect-score flaws in EFM ipTIME A3004T and Wavlink WN531P3/WN535M1 routers. Notable updates also cover Linux kernel vulnerabilities, AMD processor issues, and new critical flaws in Red Hat Enterprise Linux nodejs, Gitea, and ERPNext. Teams should prioritize patching vm2 implementations and reviewing exposure to the affected router and networking equipment models.

Last updated 03:11 UTC

CERT / PSIRT advisories
209
CVEs published
3000
Added to KEV
1
Known exploited
2

13 critical11 highacross the day’s notable advisories and CVEs

Added to the KEV catalog

Exploitation observed in the wild — remediate first.

Notable advisories

Critical/high or exploited items from national CERTs and vendor PSIRTs.

Notable CVEs

Highest-severity CVEs published this day from the NVD and GitHub Advisory firehose — the sharpest items behind the day’s numbers.

Highest exploitation probability

EPSS (FIRST.org) estimated probability of exploitation within 30 days, among CVEs published this day.

Where the day’s advisories came from

Curated CERT and PSIRT sources — these add up to the 209 above.

plus 384 CVE records from the NVD/GHSA firehose — not counted above

Get this briefing by email. One free message every morning after 06:00 UTC — same data, zero noise, one-click unsubscribe. Subscribe. Tracking specific products instead? Watch them from any product page and get alerted only when they ship a new advisory.