CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

● Daily security briefing

Thursday, August 20, 2026

Activity was heavy on August 20th with 3,360 CVEs published and 239 CERT/PSIRT advisories issued. Two TrueConf Server vulnerabilities were added to the Known Exploited Vulnerabilities catalog: CVE-2026-72530 (code injection) and CVE-2026-72529 (missing authentication), with a related security advisory already in circulation. Critical attention should go to multiple CVSS 10.0 Microsoft vulnerabilities affecting Azure Arc, Entra ID, Exchange Online, and Azure Managed Instance, alongside critical flaws in Azure SQL Database and Active Directory, all carrying active exploitation indicators. Notable advisories also covered Apache HTTP Server vulnerabilities, Linux kernel issues including Dirty Frag in Amazon Linux systems, and a new security measure bypass in MLflow, with ongoing tracking of Copy.fail variants in AWS environments.

Last updated 03:19 UTC

CERT / PSIRT advisories
239
CVEs published
3360
Added to KEV
2
Known exploited
8

14 critical5 high1 medium4 unknownacross the day’s notable advisories and CVEs

Added to the KEV catalog

Exploitation observed in the wild — remediate first.

Notable advisories

Critical/high or exploited items from national CERTs and vendor PSIRTs.

Notable CVEs

Highest-severity CVEs published this day from the NVD and GitHub Advisory firehose — the sharpest items behind the day’s numbers.

Where the day’s advisories came from

Curated CERT and PSIRT sources — these add up to the 239 above.

plus 551 CVE records from the NVD/GHSA firehose — not counted above

Get this briefing by email. One free message every morning after 06:00 UTC — same data, zero noise, one-click unsubscribe. Subscribe. Tracking specific products instead? Watch them from any product page and get alerted only when they ship a new advisory.