CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

● Daily security briefing

Sunday, August 23, 2026

August 23rd saw moderate advisory activity with 82 CVEs published and three CERT/PSIRT advisories, though no new KEV additions were recorded. A Zimbra Collaboration Suite vulnerability tracked as NCSC-2026-0324 was flagged as exploited, warranting attention from affected organizations. Critical severity dominated the day's notable CVEs, including multiple privilege escalation and sanitization bypass issues: CVE-2026-78155 in StackGres operator (CVSS 9.9), CVE-2026-78050 in Comfast CF-N1-S (CVSS 9.9), and three critical HTML sanitization flaws in justhtml versions below 1.16.0 (CVSS 9.8 each). WordPress plugin vulnerabilities also ranked high, with object injection in PPWP (CVSS 8.8) and authorization bypass in Security Hardener (CVSS 8.8), plus a GitLab authentication issue affecting multiple versions (CVSS 8.5).

Last updated 03:20 UTC

CERT / PSIRT advisories
3
CVEs published
82
Added to KEV
0
Known exploited
1

5 critical7 high1 unknownacross the day’s notable advisories and CVEs

Notable advisories

Critical/high or exploited items from national CERTs and vendor PSIRTs.

Notable CVEs

Highest-severity CVEs published this day from the NVD and GitHub Advisory firehose — the sharpest items behind the day’s numbers.

Where the day’s advisories came from

Curated CERT and PSIRT sources — these add up to the 3 above.

plus 46 CVE records from the NVD/GHSA firehose — not counted above

Get this briefing by email. One free message every morning after 06:00 UTC — same data, zero noise, one-click unsubscribe. Subscribe. Tracking specific products instead? Watch them from any product page and get alerted only when they ship a new advisory.