● Daily security briefing
Friday, August 21, 2026
CSIRT teams face a significant advisory load today with 188 CERT/PSIRT advisories and 3,716 CVEs published. The day's most critical threat is CVE-2026-73570, a Zimbra Collaboration Suite OS command injection vulnerability added to CISA's Known Exploited Vulnerabilities catalog, with active exploitation already confirmed in the wild. Multiple critical vulnerabilities were disclosed across infrastructure software including several CVSS 10.0 remote code execution flaws in Xinference and Azure SQL Database, plus five critical Incus container manager vulnerabilities (CVSS 9.9) affecting versions prior to 7.3.0. Additional notable advisories include updates to Linux Kernel vulnerabilities enabling denial of service attacks, new vulnerabilities in Apache CloudStack and PTC Windchill/FlexPLM, and a Cisco Crosswork Security Hardening release addressing multiple issues.
13 critical8 high1 medium2 unknownacross the day’s notable advisories and CVEs
Added to the KEV catalog
Exploitation observed in the wild — remediate first.
Notable advisories
Critical/high or exploited items from national CERTs and vendor PSIRTs.
- unknownexploitedcccsZimbra security advisory (AV26-816) – Update 1
- highexploitedcisaCISA Adds One Known Exploited Vulnerability to Catalog
- mediumexploitedcert-bund[UPDATE] [medium] Linux Kernel: Multiple vulnerabilities allow Denial of Service
- unknownexploitedcert-fr-avisMultiple vulnerabilities in IBM products (August 21, 2026)
- highexploitedcert-bund[UPDATE] [high] Linux Kernel: Multiple vulnerabilities
- highcert-bund[NEW] [high] Apache CloudStack: Multiple vulnerabilities
- highcert-bund[NEW] [high] PTC Windchill and FlexPLM: Multiple vulnerabilities
- criticalcisco-psirtCisco Crosswork Security Hardening Release: August 2026
- highcert-bund[UPDATE] [high] Linux Kernel: Multiple vulnerabilities
- highcert-bund[NEW] [high] Linux Kernel: Multiple vulnerabilities
- highcert-bund[NEW] [high] Tor: Multiple vulnerabilities
- highcert-bund[NEW] [high] Red Hat Enterprise Linux (mrtg, kbd, urwid): Multiple vulnerabilities
Notable CVEs
Highest-severity CVEs published this day from the NVD and GitHub Advisory firehose — the sharpest items behind the day’s numbers.
- criticalCVE-2026-61539CVSS 10GHSA-x2rj-828p-hx9m: Xinference vulnerable to remote code execution via unsafe `eval()` in Llama3 tool-call parsing
- criticalCVE-2026-61539CVSS 10Xinference is an inference API for running open-source, speech, and multimodal models. In 2.5.0 and earlier, Xinference passes attacker-influenced Llama3 tool-call output to eval()
- criticalCVE-2026-69502CVSS 10Server-side request forgery (ssrf) in Azure SQL Database allows an unauthorized attacker to elevate privileges over a network.
- criticalCVE-2026-62940CVSS 9.9Incus is a system container and virtual machine manager. Prior to version 7.3.0, when migrating an instance to another cluster member, user-supplied configuration overrides (includ
- criticalCVE-2026-63343CVSS 9.9Incus is a system container and virtual machine manager. Prior to version 7.3.0, a malicious image containing a `metadata.yaml` symlink pointing to an arbitrary host path allows an
- criticalCVE-2026-63125CVSS 9.9Incus is a system container and virtual machine manager. Prior to version 7.3.0, an unprivileged, project-confined Incus user (a non-admin TLS/RBAC identity with `can_create_images
- criticalCVE-2026-62867CVSS 9.9Incus is a system container and virtual machine manager. Prior to version 7.3.0, improper validation of user-provided `block.create_options` in storage volume configuration leads t
- criticalCVE-2026-48769CVSS 9.9Incus is a system container and virtual machine manager. Prior to version 7.2.0, an arbitrary file write exists in the Incus client when a malicious image server returns a crafted
- criticalCVE-2026-62941CVSS 9.9Incus is a system container and virtual machine manager. Prior to version 7.3.0, when copying an instance across projects, the project restriction check (`AllowInstanceCreation`) r
- criticalCVE-2026-77810CVSS 9.9In the Neptune connector, a user with access to Neptune through Athena Federated Query could gain access to properties in the Lambda supplying the compute for the connector. To rem
- criticalCVE-2026-62283CVSS 9.9Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. Nezha versions 1.14.13 through 1.14.14 and 2.0.0 through 2.0.9 do not bind stream id
- criticalCVE-2026-48755CVSS 9.9Incus is a system container and virtual machine manager. Prior to version 7.1.0, improper validation of user-provided backup compression algorithm leads to argument injection in th
Where the day’s advisories came from
Curated CERT and PSIRT sources — these add up to the 188 above.