CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

● Daily security briefing

Tuesday, August 25, 2026

August 25 saw heavy advisory activity with 181 CERT/PSIRT advisories and 3,013 CVEs published, headlined by Gitea code injection vulnerability (CVE-2026-60004) added to CISA's KEV catalog. Multiple critical vulnerabilities dominated the landscape, including four CVSS 10.0 flaws in Adobe Campaign Classic and TOTOLINK routers, alongside critical NVIDIA OpenShell sandbox escape issues and Chainlit command injection allowing unauthenticated remote code execution. Beyond the newly cataloged Gitea issue, notable exploited vulnerabilities affecting Linux kernels, Oracle Fusion Middleware, and industrial systems like the Bendix EC80 Brake ECU were highlighted across CERT-Bund and CISA advisories, indicating sustained exploitation activity across enterprise and critical infrastructure targets.

Last updated 03:20 UTC

CERT / PSIRT advisories
181
CVEs published
3013
Added to KEV
1
Known exploited
5

19 critical3 high1 medium1 unknownacross the day’s notable advisories and CVEs

Added to the KEV catalog

Exploitation observed in the wild — remediate first.

Notable advisories

Critical/high or exploited items from national CERTs and vendor PSIRTs.

Notable CVEs

Highest-severity CVEs published this day from the NVD and GitHub Advisory firehose — the sharpest items behind the day’s numbers.

Where the day’s advisories came from

Curated CERT and PSIRT sources — these add up to the 181 above.

plus 819 CVE records from the NVD/GHSA firehose — not counted above

Get this briefing by email. One free message every morning after 06:00 UTC — same data, zero noise, one-click unsubscribe. Subscribe. Tracking specific products instead? Watch them from any product page and get alerted only when they ship a new advisory.