● Daily security briefing
Monday, August 17, 2026
CERT and PSIRT activity was robust today with 209 advisories issued and 3000 CVEs published, headlined by the addition of CVE-2025-62593 (Ray-Project code injection) to CISA's Known Exploited Vulnerabilities catalog. Critical issues dominate the landscape, particularly multiple vm2 sandbox escape vulnerabilities (CVE-2026-47686, GHSA-m283-3h24-438v, GHSA-m5w8-4gq2-6f8x, GHSA-cfcw-xp6x-25gj) with CVSS scores ranging from 9.8 to 10.0, along with perfect-score flaws in EFM ipTIME A3004T and Wavlink WN531P3/WN535M1 routers. Notable updates also cover Linux kernel vulnerabilities, AMD processor issues, and new critical flaws in Red Hat Enterprise Linux nodejs, Gitea, and ERPNext. Teams should prioritize patching vm2 implementations and reviewing exposure to the affected router and networking equipment models.
13 critical11 highacross the day’s notable advisories and CVEs
Added to the KEV catalog
Exploitation observed in the wild — remediate first.
Notable advisories
Critical/high or exploited items from national CERTs and vendor PSIRTs.
- highexploitedcisaCISA Adds One Known Exploited Vulnerability to Catalog
- highexploitedcert-bund[UPDATE] [high] Linux Kernel: Multiple vulnerabilities
- highcert-bund[NEW] [high] Red Hat Enterprise Linux (nodejs:24): Multiple vulnerabilities
- criticalcert-bund[NEW] [critical] vm2: Multiple vulnerabilities
- highcert-bund[NEW] [high] Gitea: Multiple vulnerabilities
- highcert-bund[UPDATE] [high] Linux Kernel: Multiple Vulnerabilities
- highcert-bund[UPDATE] [high] Linux Kernel: Multiple Vulnerabilities
- highcert-bund[UPDATE] [high] AMD Processor: Multiple vulnerabilities
- highcert-bund[UPDATE] [high] Linux Kernel: Multiple vulnerabilities
- highcert-bund[UPDATE] [high] Linux Kernel: Multiple vulnerabilities
- highcert-bund[UPDATE] [high] Linux Kernel: Multiple vulnerabilities
- highcert-bund[NEW] [high] Red Hat Enterprise Linux (pcp): Multiple vulnerabilities
Notable CVEs
Highest-severity CVEs published this day from the NVD and GitHub Advisory firehose — the sharpest items behind the day’s numbers.
- criticalCVE-2026-19977CVSS 10A vulnerability was detected in EFM ipTIME A3004T 14.19.0. The affected element is the function httpcon_check_session_url of the component Session Validation. Performing a manipula
- criticalCVE-2026-74843CVSS 10A vulnerability was determined in Wavlink WN531P3 and WN535M1 V250922. Affected by this vulnerability is the function strcpy of the file /etc/lighttpd/www/cgi-bin/export_pingortrac
- criticalCVSS 10GHSA-m5w8-4gq2-6f8x: vm2: NodeVM `builtin: ['*']` exposes `os` and `dns` — process-wide observability reads AND writes that hijack the host (sibling class of GHSA-9g8x-92q2-p28f)
- criticalCVE-2026-47686CVSS 9.9GHSA-m283-3h24-438v: VM2 has Missing Error.cause Sanitization that Enables Sandbox Escape to RCE
- criticalCVE-2026-66792CVSS 9.9A flaw was found in the multicloud-operators-subscription component. This vulnerability allows a user on a managed cluster to escalate their privileges by creating a Subscription w
- criticalCVE-2026-65974CVSS 9.9ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.111.0 and 16.22.0, limited authenticated users can cross a permission boundary in Frappe safe execu
- criticalCVE-2026-47686CVSS 9.9vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.6, handleException() in lib/setup-sandbox.js sanitizes SuppressedError.error, SuppressedError.suppressed, and AggregateE
- criticalCVE-2026-47698CVSS 9.8GHSA-cfcw-xp6x-25gj: vm2: Sandbox Breakout Using Dangerous Host Proto Mutators
- criticalCVE-2026-47698CVSS 9.8vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.6, lib/bridge.js and lib/setup-sandbox.js fail to block stacked indirection through Function.prototype.call around dange
- criticalCVE-2026-50768CVSS 9.8File Upload vulnerability in T-Systems International GmbH ImageMaster Version: 9.14.2.8.1 allows a remote attacker to execute arbitrary code via the add attachments feature in the
- criticalCVE-2026-75110CVSS 9.8MemOS is a memory operating system for LLMs and AI agents. In deployments where authentication is enabled (AUTH_ENABLED=true) but the undocumented, defaultless INTERNAL_SERVICE_SEC
- criticalCVE-2026-74901CVSS 9.8openssl_encrypt versions before 1.4.0 contain an authentication bypass vulnerability in pqc.py where AES-GCM decryption failures trigger fallback to unauthenticated AES-CTR mode. A
Highest exploitation probability
EPSS (FIRST.org) estimated probability of exploitation within 30 days, among CVEs published this day.
Where the day’s advisories came from
Curated CERT and PSIRT sources — these add up to the 209 above.