● Daily security briefing
Monday, August 24, 2026
CSIRT teams should prioritize CVE-2026-21962, an Oracle HTTP Server and Oracle WebLogic Server proxy plug-in improper access control vulnerability added to the KEV catalog today. Activity was notably heavy with 4,153 CVEs published and 206 CERT/PSIRT advisories issued, including critical Oracle and Red Hat patches and multiple Linux kernel updates spanning DoS and code execution flaws. Several critical vulnerabilities demand immediate attention: CVE-2026-78167 (EFM ipTIME router, CVSS 10.0), CVE-2026-78169 (UTT HiPER gateway, CVSS 9.9), CVE-2026-66897 (LXD container escape, CVSS 9.9), and multiple WordPress and DrayTek router flaws rated 9.8-9.9 affecting authentication and privilege escalation. Notable exploited vulnerabilities include issues in Metabase, Zimbra, and 389-ds-base that warrant rapid assessment across enterprise environments.
13 critical8 high1 medium2 unknownacross the day’s notable advisories and CVEs
Added to the KEV catalog
Exploitation observed in the wild — remediate first.
Notable advisories
Critical/high or exploited items from national CERTs and vendor PSIRTs.
- unknownexploitedcert-fr-avisMultiple vulnerabilities in Metabase (August 24, 2026)
- highexploitedcisaCISA Adds One Known Exploited Vulnerability to Catalog
- mediumexploitedcert-bund[UPDATE] [medium] Linux Kernel: Multiple vulnerabilities allow Denial of Service
- criticalexploitedcccsOracle security advisory – January 2026 quarterly rollup (AV26-042) – Update 2
- unknownexploitedhkcertZimbra Multiple Vulnerabilities
- highexploitedcert-bund[UPDATE] [high] Linux Kernel: Multiple vulnerabilities
- highcert-bund[NEW] [high] Red Hat Enterprise Linux (389-ds-base): Multiple vulnerabilities allow code execution and DoS
- highcert-bund[UPDATE] [high] Linux Kernel: Multiple Vulnerabilities
- highcert-bund[NEW] [high] Red Hat Enterprise Linux (nodejs:24): Multiple vulnerabilities
- highcert-bund[UPDATE] [high] Linux Kernel: Multiple Vulnerabilities
- highcert-bund[UPDATE] [high] Linux Kernel: Multiple Vulnerabilities
- highcert-bund[NEW] [high] util-linux: Multiple vulnerabilities
Notable CVEs
Highest-severity CVEs published this day from the NVD and GitHub Advisory firehose — the sharpest items behind the day’s numbers.
- criticalCVE-2026-78167CVSS 10A weakness has been identified in EFM ipTIME T16000M 14.20.2. The impacted element is the function httpcon_check_session_url of the component Session Validation Handler. This manip
- criticalCVE-2026-78169CVSS 9.9A vulnerability was detected in UTT HiPER 1250GW up to 3.2.7-210907-180535. This impacts the function strcpy of the file /goform/aspRemoteApConfTempSend of the component HTTP Reque
- criticalCVE-2026-66897CVSS 9.9A path traversal vulnerability in LXD's instance template processing allows an attacker with container edit permissions, or any user launching a crafted image, to overwrite arbitra
- criticalCVE-2026-32559CVSS 9.9Subscriber Arbitrary File Upload in UltimateAI <= 3.1.0 versions.
- criticalCVE-2026-78262CVSS 9.8Unauthenticated PHP Object Injection in WP Project Manager <= 4.0.6 versions.
- criticalCVE-2026-78267CVSS 9.8Unauthenticated Privilege Escalation in TranslatePress <= 3.3.2 versions.
- criticalCVE-2026-66650CVSS 9.8Unauthenticated PHP Object Injection in FreightCo <= 1.1.15 versions.
- criticalCVE-2026-71921CVSS 9.8Multiple DrayTek VigorSwitch models contain a pre-authentication command injection vulnerability in the setget.cgi interface. The vulnerability is caused by insufficient filtering
- criticalCVE-2026-78265CVSS 9.8Unauthenticated PHP Object Injection in The Events Calendar <= 6.17.2 versions.
- criticalCVE-2026-71914CVSS 9.8Multiple DrayTek VigorAP models contain a command injection vulnerability in the dray_apm component. The vulnerability is caused by insufficient validation of UDP message content a
- criticalCVE-2026-77915CVSS 9.8rConfig 8.0.0 before 8.2.13 contains an authentication bypass vulnerability that allows unauthenticated attackers to self-register accounts with full Administrator privileges due t
- criticalCVE-2026-32563CVSS 9.8Subscriber PHP Object Injection in ACPT (Pro) - Custom Post Types Plugin for WordPress <= 2.0.63 versions.
Highest exploitation probability
EPSS (FIRST.org) estimated probability of exploitation within 30 days, among CVEs published this day.
Where the day’s advisories came from
Curated CERT and PSIRT sources — these add up to the 206 above.