● Daily security briefing
Tuesday, August 18, 2026
Tuesday saw significant advisory activity with 56 CERT/PSIRT releases and 1,229 CVEs published, including four vulnerabilities added to CISA's Known Exploited Vulnerabilities catalog: CVE-2026-33824 affecting Microsoft IKE services, CVE-2026-59310 in Broadcom VMware vCenter, CVE-2026-55040 in Microsoft SharePoint, and CVE-2026-65400 in Apple macOS. Multiple critical CVSS 10.0 vulnerabilities were disclosed across Oracle Hyperion products, Firefox, WordPress plugins, and network devices, with particular attention needed for CVE-2026-73343 (unauthenticated RCE in WP Compress) and CVE-2026-75874 (Firefox sandbox escape). Notable advisories include Microsoft's August monthly rollup, updates for VMware and Apple, and critical warnings for Siemens Simcenter Nastran and CISA Malcolm, alongside ongoing Linux kernel vulnerability disclosures.
16 critical5 high3 unknownacross the day’s notable advisories and CVEs
Added to the KEV catalog
Exploitation observed in the wild — remediate first.
- exploitedCVE-2026-33824CVE-2026-33824: Microsoft Internet Key Exchange (IKE) Service Extensions Double Free Vulnerability
- exploitedCVE-2026-59310CVE-2026-59310: Broadcom VMware vCenter Path Traversal Vulnerability
- exploitedCVE-2026-55040CVE-2026-55040: Microsoft SharePoint Weak Authentication Vulnerability
- exploitedCVE-2026-65400CVE-2026-65400: Apple macOS Improper Authentication Vulnerability
Notable advisories
Critical/high or exploited items from national CERTs and vendor PSIRTs.
- unknownexploitedcccsApple security advisory (AV26-823) – Update 1
- unknownexploitedcccsVMware security advisory (AV26-763) – Update 1
- unknownexploitedcccsMicrosoft security advisory – August 2026 monthly rollup (AV26-804) – Update 1
- highexploitedcisaCISA Adds Four Known Exploited Vulnerabilities to Catalog
- highcert-bund[NEW] [high] Linux Kernel: Multiple vulnerabilities
- criticalcisaSiemens Simcenter Nastran
- criticalcisaCISA Malcolm
- highcert-bund[UPDATE] [high] Linux Kernel: Multiple Vulnerabilities
- criticalcert-bund[NEW] [high] Linux Kernel: Multiple vulnerabilities
- highcert-bund[UPDATE] [high] Linux Kernel: Multiple vulnerabilities
- highcert-bund[NEW] [high] Linux Kernel: Multiple Vulnerabilities Enable Unspecified Attack
- criticalcccsGitLab security advisory (AV26-827)
Notable CVEs
Highest-severity CVEs published this day from the NVD and GitHub Advisory firehose — the sharpest items behind the day’s numbers.
- criticalCVE-2026-75874CVSS 10Sandbox escape in the Remote Settings Client component. This vulnerability was fixed in Firefox 154 and Thunderbird 154.
- criticalCVE-2026-70921CVSS 10Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploi
- criticalCVE-2026-55107CVSS 10GHSA-7pwq-q9jf-539h: kobako Sandbox Escape: guest eval reaches host RCE via method_missing → public_send (any bound Service)
- criticalCVE-2026-73343CVSS 10Unauthenticated Remote Code Execution (RCE) in WP Compress < 7.20.01 versions.
- criticalCVE-2026-70880CVSS 10Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security). The supported version that is affected is 11.2.25.0
- criticalCVE-2026-75784CVSS 10A vulnerability was detected in TRENDnet TEW-WLC100 1v2.07b01. Affected by this issue is the function FUN_0040da4c of the file /usr/nginx/sbin/nginx of the component HTTP Header Ha
- criticalCVE-2026-61241CVSS 10Vulnerability in the Oracle Internet Directory product of Oracle Fusion Middleware (component: OID LDAP Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.
- criticalCVE-2026-61317CVSS 9.9Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager). Supported versions that are affected are 22.3-26.6. Easily explo
- criticalCVE-2026-62452CVSS 9.9Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager). Supported versions that are affected are 22.3-26.6. Easily explo
- criticalCVE-2026-61248CVSS 9.9Vulnerability in the Oracle Internet Directory product of Oracle Fusion Middleware (component: OID LDAP Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.
- criticalCVE-2026-62512CVSS 9.9Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager). Supported versions that are affected are 22.3-26.6. Easily explo
- criticalCVE-2026-71059CVSS 9.9Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: Web Service API). Supported versions that are affected are 8.2.0.0.0 and 26.1.0.0.0. Easily explo
Highest exploitation probability
EPSS (FIRST.org) estimated probability of exploitation within 30 days, among CVEs published this day.
Where the day’s advisories came from
Curated CERT and PSIRT sources — these add up to the 56 above.