● Daily security briefing
Thursday, August 20, 2026
Activity was heavy on August 20th with 3,360 CVEs published and 239 CERT/PSIRT advisories issued. Two TrueConf Server vulnerabilities were added to the Known Exploited Vulnerabilities catalog: CVE-2026-72530 (code injection) and CVE-2026-72529 (missing authentication), with a related security advisory already in circulation. Critical attention should go to multiple CVSS 10.0 Microsoft vulnerabilities affecting Azure Arc, Entra ID, Exchange Online, and Azure Managed Instance, alongside critical flaws in Azure SQL Database and Active Directory, all carrying active exploitation indicators. Notable advisories also covered Apache HTTP Server vulnerabilities, Linux kernel issues including Dirty Frag in Amazon Linux systems, and a new security measure bypass in MLflow, with ongoing tracking of Copy.fail variants in AWS environments.
14 critical5 high1 medium4 unknownacross the day’s notable advisories and CVEs
Added to the KEV catalog
Exploitation observed in the wild — remediate first.
Notable advisories
Critical/high or exploited items from national CERTs and vendor PSIRTs.
- unknownexploitedcccsTrueConf security advisory (AV26-835)
- unknownexploitedawsOngoing updates on Copy.fail and variants
- unknownexploitedawsDirty Frag and other issues in Amazon Linux kernels
- mediumexploitedcert-bund[UPDATE] [medium] Linux Kernel: Multiple vulnerabilities allow Denial of Service
- highexploitedcert-bund[UPDATE] [high] Apache HTTP Server: Multiple vulnerabilities
- unknownexploitedawsCVE-2026-31431
- criticalexploitedcisaCISA Adds Two Known Exploited Vulnerabilities to Catalog
- highexploitedcert-bund[NEW] [high] MLflow: Vulnerability enables bypassing security measures
- highcert-bund[NEW] [UNPATCHED] [high] Drupal Module: Multiple vulnerabilities enable unspecified attack
- criticalcisaJohnson Controls Simplex Incident Manager
- highcert-bund[UPDATE] [high] CyberPanel: Multiple vulnerabilities
- highcert-bund[NEW] [high] Hashicorp Vault Secrets Operator: Vulnerability enables privilege escalation
Notable CVEs
Highest-severity CVEs published this day from the NVD and GitHub Advisory firehose — the sharpest items behind the day’s numbers.
- criticalCVE-2026-65816CVSS 10Use of incorrectly-resolved name or reference in Azure Arc allows an unauthorized attacker to elevate privileges over a network.
- criticalCVE-2026-69836CVSS 10Deserialization of untrusted data in Microsoft Entra ID allows an unauthorized attacker to execute code over a network.
- criticalCVE-2026-65801CVSS 10Server-side request forgery (ssrf) in Microsoft Exchange Online allows an unauthorized attacker to elevate privileges over a network.
- criticalCVE-2026-69555CVSS 10Incorrect authorization in Azure Arc allows an unauthorized attacker to elevate privileges over a network.
- criticalCVE-2026-65770CVSS 10Improper neutralization of argument delimiters in a command ('argument injection') in Azure Managed Instance for Apache Cassandra allows an unauthorized attacker to execute code ov
- criticalCVE-2026-68789CVSS 9.9Improper neutralization of special elements used in an sql command ('sql injection') in Azure SQL Database allows an authorized attacker to elevate privileges over a network.
- criticalCVE-2026-69851CVSS 9.9Server-side request forgery (ssrf) in Azure Active Directory allows an authorized attacker to elevate privileges over a network.
- criticalCVE-2026-67567CVSS 9.9A flaw was found in the multicloud-operators-subscription component. This vulnerability allows a tenant, who has the ability to create HelmRelease custom resources (CRs), to bypass
- criticalCVE-2026-68782CVSS 9.9Improper neutralization of special elements used in an sql command ('sql injection') in Azure SQL Database allows an authorized attacker to elevate privileges over a network.
- criticalCVE-2026-63509CVSS 9.9Relative path traversal in Microsoft Fabric allows an authorized attacker to elevate privileges over a network.
- criticalCVE-2026-18835CVSS 9.9IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in a
- criticalCVE-2026-77148CVSS 9.9A vulnerability was found in Comfast CF-N1-S 2.6.0.1. This impacts the function sub_44B50C of the file /cgi-bin/mbox-config?method=SET§ion=ptest_channel of the component Web Ma
Where the day’s advisories came from
Curated CERT and PSIRT sources — these add up to the 239 above.