CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

● Daily security briefing

Wednesday, August 26, 2026

CISA added six known exploited vulnerabilities to its catalog on August 26, headlined by CVE-2019-1068 affecting Microsoft SQL Server and CVE-2021-23758 in Ajax.NET Professional, both showing elevated EPSS scores. The day saw substantial advisory activity with 193 CERT/PSIRT notices and 2,375 CVEs published, including critical issues in Vercel Next.js (code execution), Citrix NetScaler ADC and Gateway, and Ubiquiti products that warrant immediate attention. Several critical CVEs with perfect or near-perfect CVSS scores emerged, including CVE-2026-60004 in Gitea (remote code execution via diffpatch API) and multiple CVSS 10.0 vulnerabilities involving improper input validation and CRLF sequence neutralization affecting network-accessible systems. Organizations should prioritize patching the Citrix and Ubiquiti advisories marked as exploited, along with the Gitea and Next.js vulnerabilities given their code execution potential.

Last updated 23:35 UTC

CERT / PSIRT advisories
193
CVEs published
2375
Added to KEV
6
Known exploited
4

16 critical8 highacross the day’s notable advisories and CVEs

Added to the KEV catalog

Exploitation observed in the wild — remediate first.

Notable advisories

Critical/high or exploited items from national CERTs and vendor PSIRTs.

Notable CVEs

Highest-severity CVEs published this day from the NVD and GitHub Advisory firehose — the sharpest items behind the day’s numbers.

Highest exploitation probability

EPSS (FIRST.org) estimated probability of exploitation within 30 days, among CVEs published this day.

Where the day’s advisories came from

Curated CERT and PSIRT sources — these add up to the 193 above.

plus 421 CVE records from the NVD/GHSA firehose — not counted above

Get this briefing by email. One free message every morning after 06:00 UTC — same data, zero noise, one-click unsubscribe. Subscribe. Tracking specific products instead? Watch them from any product page and get alerted only when they ship a new advisory.