● Daily security briefing
Sunday, August 23, 2026
August 23rd saw moderate advisory activity with 82 CVEs published and three CERT/PSIRT advisories, though no new KEV additions were recorded. A Zimbra Collaboration Suite vulnerability tracked as NCSC-2026-0324 was flagged as exploited, warranting attention from affected organizations. Critical severity dominated the day's notable CVEs, including multiple privilege escalation and sanitization bypass issues: CVE-2026-78155 in StackGres operator (CVSS 9.9), CVE-2026-78050 in Comfast CF-N1-S (CVSS 9.9), and three critical HTML sanitization flaws in justhtml versions below 1.16.0 (CVSS 9.8 each). WordPress plugin vulnerabilities also ranked high, with object injection in PPWP (CVSS 8.8) and authorization bypass in Security Hardener (CVSS 8.8), plus a GitLab authentication issue affecting multiple versions (CVSS 8.5).
5 critical7 high1 unknownacross the day’s notable advisories and CVEs
Notable advisories
Critical/high or exploited items from national CERTs and vendor PSIRTs.
- unknownexploitedncsc-nlNCSC-2026-0324 [1.00] [M/H] Vulnerability fixed in Zimbra Collaboration Suite
Notable CVEs
Highest-severity CVEs published this day from the NVD and GitHub Advisory firehose — the sharpest items behind the day’s numbers.
- criticalCVE-2026-78155CVSS 9.9privilege escalation in StackGres operator allows a low-privilege tenant who owns a database to gain administrator privileges
- criticalCVE-2026-78050CVSS 9.9A vulnerability was found in Comfast CF-N1-S 2.6.0.1. The affected element is the function sub_41AD7C of the file /cgi-bin/mbox-config?method=SET§ion=ntp_timezone of the compon
- criticalCVE-2026-8445CVSS 9.8justhtml versions <= 1.11.0 (fixed in 1.12.0) do not sufficiently escape HTML-significant characters (angle brackets) in text nodes when converting a parsed document to Markdown vi
- criticalCVE-2026-7808CVSS 9.8justhtml before 1.16.0 contains multiple HTML sanitization bypass issues that can allow active/dangerous content (e.g., script or style) to survive sanitization, potentially leadin
- criticalCVE-2026-5388CVSS 9.8justhtml before 1.15.0 contains multiple security issues in URL sanitization helpers (clean_url_value/clean_url_in_js_string), HTML serialization, Markdown passthrough (html_passth
- highCVE-2026-0551CVSS 8.8The PPWP – Password Protect Pages plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.9.18 via deserialization of untrusted input fro
- highCVE-2026-16149CVSS 8.8The Security Hardener plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 2.4.4. The vulnerability exists because the plugin's user-en
- highCVE-2026-10053CVSS 8.5GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.8 before 19.0.6, 19.1 before 19.1.4, and 19.2 before 19.2.2 that under certain conditions could have a
- highCVE-2026-78136CVSS 7.8chirpmyradio CHIRP before 39178db allows eval injection via crafted CSV data. This occurs in _clean_tmode in drivers/kenwood_itm.py.
- highCVE-2026-9769CVSS 7.5justhtml through 1.9.1 (fixed in 1.10.0) is vulnerable to uncontrolled recursion leading to denial of service. During JustHTML() construction, TreeBuilder.finish() unconditionally
- highCVE-2026-4671CVSS 7.5justhtml before 1.18.0 contains multiple low-severity denial-of-service issues in CSS selector handling and linkification. Applications that evaluate attacker-controlled selector s
- highCVE-2026-78141CVSS 7.4A vulnerability has been found in Tenda CH22 1.0.0.1. This affects the function formexeCommand of the file /goform/exeCommand. The manipulation of the argument cmdinput leads to co
Where the day’s advisories came from
Curated CERT and PSIRT sources — these add up to the 3 above.