● Daily security briefing
Tuesday, August 25, 2026
August 25 saw heavy advisory activity with 181 CERT/PSIRT advisories and 3,013 CVEs published, headlined by Gitea code injection vulnerability (CVE-2026-60004) added to CISA's KEV catalog. Multiple critical vulnerabilities dominated the landscape, including four CVSS 10.0 flaws in Adobe Campaign Classic and TOTOLINK routers, alongside critical NVIDIA OpenShell sandbox escape issues and Chainlit command injection allowing unauthenticated remote code execution. Beyond the newly cataloged Gitea issue, notable exploited vulnerabilities affecting Linux kernels, Oracle Fusion Middleware, and industrial systems like the Bendix EC80 Brake ECU were highlighted across CERT-Bund and CISA advisories, indicating sustained exploitation activity across enterprise and critical infrastructure targets.
19 critical3 high1 medium1 unknownacross the day’s notable advisories and CVEs
Added to the KEV catalog
Exploitation observed in the wild — remediate first.
Notable advisories
Critical/high or exploited items from national CERTs and vendor PSIRTs.
- mediumexploitedcert-bund[UPDATE] [medium] Linux Kernel: Multiple vulnerabilities allow Denial of Service
- highexploitedcisaCISA Adds One Known Exploited Vulnerability to Catalog
- highexploitedcert-bund[UPDATE] [high] Linux Kernel: Multiple vulnerabilities
- criticalexploitedcert-bund[UPDATE] [critical] Oracle Fusion Middleware: Multiple Vulnerabilities
- unknownexploitedcccsGitea security advisory (AV26-845)
- criticalcisaPayRange API
- criticalcisaZoneminder
- criticalcisaBendix EC80 Brake ECU
- criticalcisaA Tale of Two SOCs: Insights From Two Red Team Assessments
- criticalcisaEbyte NE2-D11
- highcert-bund[NEW] [high] Contao: Multiple Vulnerabilities
- criticalcisaSiemens SIMATIC IoT2050 Advanced
Notable CVEs
Highest-severity CVEs published this day from the NVD and GitHub Advisory firehose — the sharpest items behind the day’s numbers.
- criticalCVE-2026-76197CVSS 10Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could result in arbitra
- criticalCVE-2026-79911CVSS 10A security vulnerability has been detected in TOTOLINK N600R 4.3.0cu.7647_B20210106. The affected element is the function setSystemConfig of the file /cgi-bin/cstecgi.cgi of the co
- criticalCVE-2026-76195CVSS 10Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could result in arbitra
- criticalCVE-2026-76193CVSS 10Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in arbitrary code execution in the context of the current user. An
- criticalCVE-2026-65083CVSS 9.9NVIDIA OpenShell for Linux contains a vulnerability in its sandbox provisioning API, where an attacker could cause an incomplete list of disallowed inputs. A successful exploit of
- criticalCVE-2026-65093CVSS 9.9NVIDIA OpenShell for Linux contains a vulnerability where an attacker could cause a sandbox escape. A successful exploit of this vulnerability might lead to code execution, escalat
- criticalCVE-2026-45018CVSS 9.8GHSA-w3fx-mc44-mf6j: Chainlit has command injection via MCP stdio transport that allows unauthenticated remote code execution
- criticalCVE-2026-45018CVSS 9.8Chainlit is a Python framework for building production-ready conversational AI applications. From 2.4.0rc0 until 2.12.0, Chainlit deployments with features.mcp.enabled set to true
- criticalCVE-2026-80104CVSS 9.8DB-GPT builds the destination path for an uploaded skill from the multipart filename without constraining it to the upload directory. skill_upload in packages/dbgpt-app/src/dbgpt_a
- criticalCVE-2026-79787CVSS 9.8Alluxio's S3 REST proxy fails to verify AWS Signature Version 4 signatures in its default configuration, allowing unauthenticated attackers to spoof user identity. Attackers can ex
- criticalCVE-2026-80138CVSS 9.8ClipBucket V5's web installer fails to properly validate or escape the php_cli_filepath parameter before passing it to shell execution. Unauthenticated attackers can submit a craft
- criticalCVE-2026-79675CVSS 9.8NLTK before 3.10.3 fails to validate JVM options passed through the per-call options parameter in the java() function, allowing attackers to inject dangerous JVM flags. Attackers c
Where the day’s advisories came from
Curated CERT and PSIRT sources — these add up to the 181 above.