CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

● Daily security briefing

Saturday, August 22, 2026

August 22 saw moderate advisory activity with 242 CVEs published but no CERT/PSIRT advisories or KEV additions. The most critical findings include CVE-2026-77946 affecting TRENDnet TEW-821DAP routers (CVSS 10.0), followed by two WordPress plugins with critical remote code injection and SSRF vulnerabilities: WS Form LITE (CVE-2026-4703) and Mailgun for WordPress (CVE-2026-78003). Additional high-severity issues were identified in the WPeMatico RSS plugin, NLTK's AllowlistUnpickler, AVideo, SiYuan note-taking software, and hashcat, spanning authentication bypass, RCE, arbitrary file deletion, and command injection vectors. Organizations should prioritize patching the WordPress plugins and TRENDnet firmware given their critical severity scores and likely exposure in typical enterprise environments.

Last updated 03:17 UTC

CERT / PSIRT advisories
0
CVEs published
242
Added to KEV
0
Known exploited
0

3 critical9 highacross the day’s notable advisories and CVEs

Notable CVEs

Highest-severity CVEs published this day from the NVD and GitHub Advisory firehose — the sharpest items behind the day’s numbers.

Get this briefing by email. One free message every morning after 06:00 UTC — same data, zero noise, one-click unsubscribe. Subscribe. Tracking specific products instead? Watch them from any product page and get alerted only when they ship a new advisory.