● Daily security briefing
Wednesday, August 19, 2026
CISA added CVE-2026-64849, an MLflow server-side request forgery vulnerability, to the Known Exploited Vulnerabilities catalog on August 19th, joining multiple other actively exploited threats across critical infrastructure and enterprise software. A critical vulnerability in Citrix NetScaler ADC and Gateway (2026-010) and active threats targeting Siemens S7 Series PLCs demand immediate attention, while eight different critical CVSS 10.0 vulnerabilities were published affecting Cisco products, WordPress plugins, and embedded devices. Notable advisories also included multiple high-severity vulnerabilities in Atlassian products, Oracle WebLogic, and Cisco BroadWorks requiring prompt patching. With 3,104 CVEs published and 210 CERT/PSIRT advisories issued, this represents a typical high-volume advisory day with several items requiring urgent prioritization in SOC queues.
17 critical5 high2 unknownacross the day’s notable advisories and CVEs
Added to the KEV catalog
Exploitation observed in the wild — remediate first.
Notable advisories
Critical/high or exploited items from national CERTs and vendor PSIRTs.
- highexploitedcisaCISA Adds One Known Exploited Vulnerability to Catalog
- unknownexploitedcccsMLflow security advisory (AV26-832)
- unknownexploitedcert-fr-avisMultiple vulnerabilities in Oracle Weblogic (August 19, 2026)
- highexploitedcert-bund[NEW] [high] Atlassian Products (Bamboo, Bitbucket, Confluence, Crucible, Fisheye, and Jira): Multiple vulnerabilities
- highcisco-psirtCisco BroadWorks Out-of-Band Blind XML External Entity Injection Vulnerability
- highcisco-psirtCisco Industrial Ethernet 1000 Series Switches Denial of Service Vulnerability
- criticalcert-eu2026-010: Critical Vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway
- criticalcisaDefending Against an Active Threat to Siemens S7 Series PLCs
- criticalcisco-psirtCisco Crosswork Security Hardening Release: August 2026
- highcert-bund[NEW] [high] Joomla: Multiple vulnerabilities
- criticalcisco-psirtCisco Secure Workload Software Security Hardening Release: August 2026
- criticalcisco-psirtCisco Advance Notification for Publication of August 19, 2026, Security Advisories
Notable CVEs
Highest-severity CVEs published this day from the NVD and GitHub Advisory firehose — the sharpest items behind the day’s numbers.
- criticalCVE-2026-76008CVSS 10A flaw has been found in Comfast CF-N1-S 2.6.0.1. This affects the function get_para_from_uri of the file /cgi-bin/mbox-config of the component URI Parameter Parsing. This manipula
- criticalCVE-2026-20358CVSS 10As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Crosswork engineering team has conducted a comprehensive internal security review. This r
- criticalCVE-2026-18051CVSS 10The W3 Total Cache WordPress plugin before 2.10.5 does not properly validate the request path it uses to build cache file names, allowing unauthenticated attackers to write a file
- criticalCVE-2026-20317CVSS 10As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Workload engineering team has conducted a comprehensive internal security review.
- criticalCVE-2026-20315CVSS 10As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Workload engineering team has conducted a comprehensive internal security review.
- criticalCVE-2026-22306CVSS 10Download of code without integrity check, inclusion of functionality from untrusted control sphere, and cleartext transmission of sensitive information vulnerability in Ozols Grup
- criticalCVE-2026-20357CVSS 10As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Crosswork engineering team has conducted a comprehensive internal security review. This r
- criticalCVE-2026-20030CVSS 10As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Crosswork engineering team has conducted a comprehensive internal security review. This r
- criticalCVE-2026-76589CVSS 9.9A vulnerability was found in TRENDnet TEW-755AP up to 20260702. Affected is the function FUN_401000 of the file /sbin/mycli. The manipulation of the argument ssid results in stack-
- criticalCVE-2026-20359CVSS 9.9As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Crosswork engineering team has conducted a comprehensive internal security review. This r
- criticalCVE-2026-70496CVSS 9.9A flaw was found in search-v2-operator. The operator's ClusterRole has permissions equivalent to a cluster administrator, allowing it to impersonate other entities, write Role-Base
- criticalCVE-2026-76590CVSS 9.9A vulnerability was identified in TRENDnet TEW-755AP up to 20260702. Affected by this issue is some unknown functionality of the file /cgi-bin/wan.cgi of the component ssi. Such ma
Highest exploitation probability
EPSS (FIRST.org) estimated probability of exploitation within 30 days, among CVEs published this day.
- 100%CVE-2023-22518
- 100%CVE-2023-22527
- 100%CVE-2023-46604
- 100%CVE-2022-1471
- 56%CVE-2022-23521
Where the day’s advisories came from
Curated CERT and PSIRT sources — these add up to the 210 above.