● Daily security briefing
Saturday, August 22, 2026
August 22 saw moderate advisory activity with 242 CVEs published but no CERT/PSIRT advisories or KEV additions. The most critical findings include CVE-2026-77946 affecting TRENDnet TEW-821DAP routers (CVSS 10.0), followed by two WordPress plugins with critical remote code injection and SSRF vulnerabilities: WS Form LITE (CVE-2026-4703) and Mailgun for WordPress (CVE-2026-78003). Additional high-severity issues were identified in the WPeMatico RSS plugin, NLTK's AllowlistUnpickler, AVideo, SiYuan note-taking software, and hashcat, spanning authentication bypass, RCE, arbitrary file deletion, and command injection vectors. Organizations should prioritize patching the WordPress plugins and TRENDnet firmware given their critical severity scores and likely exposure in typical enterprise environments.
3 critical9 highacross the day’s notable advisories and CVEs
Notable CVEs
Highest-severity CVEs published this day from the NVD and GitHub Advisory firehose — the sharpest items behind the day’s numbers.
- criticalCVE-2026-77946CVSS 10A vulnerability was determined in TRENDnet TEW-821DAP 2.2.01b05. Affected by this vulnerability is the function uci_safe_get of the file /cgi-bin/apply_time.cgi of the component NT
- criticalCVE-2026-4703CVSS 9.8The WS Form LITE – Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.10.80 via deserialization of
- criticalCVE-2026-78003CVSS 9.8The Mailgun for WordPress plugin for WordPress is vulnerable to Server-Side Request Forgery (SSRF) via path traversal in versions up to and including 2.2.0. This is due to insuffic
- highCVE-2026-19883CVSS 8.8The WPeMatico RSS Feed Fetcher plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on th
- highCVE-2026-71513CVSS 8.8NLTK before 3.10.3 contains a remote code execution vulnerability in AllowlistUnpickler that validates only the pickle module string and not the global name, allowing attackers to
- highCVE-2026-59808CVSS 8.8AVideo through commit 9c39d8c8 contains an authentication bypass vulnerability where deduplicateByEncoderQueueId() returns video_id_hash credentials for any video by encoder_queue_
- highCVE-2026-60084CVSS 8.7SiYuan versions before v3.7.4 contain an arbitrary file deletion vulnerability in the /api/search/removeTemplate endpoint that accepts an unvalidated path parameter passed directly
- highCVE-2026-68766CVSS 7.8hashcat fails to restrict command-line options when parsing restore files, allowing attackers to inject output-redirecting options like --outfile and --potfile-path. Attackers can
- highCVE-2026-57998CVSS 7.8better-npm-audit through 3.11.0, and the 4.0.0-rc.2 prerelease, builds its npm audit command by interpolating the user-supplied --registry option into a command string in src/handl
- highCVE-2026-62384CVSS 7.5NLTK versions before 3.10.2 contain a symlink-based sandbox bypass in FramenetCorpusReader that allows attackers to read arbitrary XML files outside the corpus root. Attackers can
- highCVE-2026-2996CVSS 7.5The Advanced Product Fields (Product Addons) for WooCommerce plugin for WordPress is vulnerable to Improper Input Validation in all versions up to, and including, 1.6.21. This is d
- highCVE-2026-66393CVSS 7.5NLTK versions before 3.9.4 contain an unbounded recursion vulnerability in JSONTaggedDecoder.decode_obj() that allows attackers to cause denial of service by supplying deeply neste