● Daily security briefing
Wednesday, August 26, 2026
CISA added six known exploited vulnerabilities to its catalog on August 26, headlined by CVE-2019-1068 affecting Microsoft SQL Server and CVE-2021-23758 in Ajax.NET Professional, both showing elevated EPSS scores. The day saw substantial advisory activity with 193 CERT/PSIRT notices and 2,375 CVEs published, including critical issues in Vercel Next.js (code execution), Citrix NetScaler ADC and Gateway, and Ubiquiti products that warrant immediate attention. Several critical CVEs with perfect or near-perfect CVSS scores emerged, including CVE-2026-60004 in Gitea (remote code execution via diffpatch API) and multiple CVSS 10.0 vulnerabilities involving improper input validation and CRLF sequence neutralization affecting network-accessible systems. Organizations should prioritize patching the Citrix and Ubiquiti advisories marked as exploited, along with the Gitea and Next.js vulnerabilities given their code execution potential.
16 critical8 highacross the day’s notable advisories and CVEs
Added to the KEV catalog
Exploitation observed in the wild — remediate first.
- exploitedCVE-2019-1068CVE-2019-1068: Microsoft SQL Server Remote Code Execution Vulnerability
- exploitedCVE-2021-23758CVE-2021-23758: Ajax.NET Professional Deserialization of Untrusted Data Vulnerability
- exploitedCVE-2015-3246CVE-2015-3246: Red Hat Libuser Race Condition Vulnerability
- exploitedCVE-2015-5287CVE-2015-5287: Red Hat Automatic Bug Reporting Tool Privilege Escalation Vulnerability
- exploitedCVE-2022-0995CVE-2022-0995: Linux Kernel Out-of-Bounds Write Vulnerability
- exploitedCVE-2026-8452CVE-2026-8452: Citrix NetScaler ADC and NetScaler Gateway Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability
Notable advisories
Critical/high or exploited items from national CERTs and vendor PSIRTs.
- highexploitedcisaCISA Adds Six Known Exploited Vulnerabilities to Catalog
- highexploitedcert-bund[UPDATE] [high] Apache HTTP Server: Multiple vulnerabilities
- criticalexploitedcccsCitrix security advisory (AV26-645) – Update 3
- criticalcccsUbiquiti security advisory (AV26-850)
- highcert-bund[NEW] [high] FreeBSD Project FreeBSD OS: Multiple vulnerabilities
- highcert-bund[NEW] [high] DNN: Multiple vulnerabilities
- criticalcert-bund[NEW] [critical] Vercel Next.js: Multiple vulnerabilities allow code execution
- highcert-bund[NEW] [high] Ubiquiti UnifiOS: Multiple vulnerabilities
- highcert-bund[NEW] [high] GitLab: Multiple vulnerabilities
- highcert-bund[NEW] [high] Red Hat Enterprise Linux (plexus-utils): Vulnerability allows execution of arbitrary code with user privileges
- highcert-bund[UPDATE] [high] Jenkins Plugins: Multiple vulnerabilities
- criticalcisaCISA Vulnerability Review
Notable CVEs
Highest-severity CVEs published this day from the NVD and GitHub Advisory firehose — the sharpest items behind the day’s numbers.
- criticalexploitedCVE-2026-60004CVSS 9.8Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation.
- criticalCVE-2026-77537CVSS 10A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi Protect Application to execute a Command Injection on the host
- criticalCVE-2026-77554CVSS 10A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi Talk Application to execute a Command Injection on the host dev
- criticalCVE-2026-77550CVSS 10A malicious actor with access to the network could exploit an Improper Neutralization of CRLF Sequences vulnerability found in certain devices running UniFi OS to bypass authentica
- criticalCVE-2026-77534CVSS 9.9A malicious actor with access to the network and low privileges could exploit an Improper Access Control vulnerability found in certain devices running UniFi OS to escalate privile
- criticalCVE-2026-77536CVSS 9.9A malicious actor with access to the network and low privileges could exploit an Improper Access Control vulnerability found in certain devices running UniFi OS to escalate privile
- criticalCVE-2026-77546CVSS 9.9A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi Access Application to execute a Command Inje
- criticalCVE-2026-77553CVSS 9.9A malicious actor with access to the network and low privileges could exploit an Improper Access Control vulnerability found in UniFi Access Application to escalate privileges on t
- criticalCVE-2026-77548CVSS 9.9A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi Protect Application to execute a Command Inj
- criticalCVE-2026-77547CVSS 9.9A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi Access Application to execute a Command Inje
- criticalCVE-2026-77543CVSS 9.9A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi Access Application to execute a Command Inje
- criticalCVE-2026-77533CVSS 9.9A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi Protect Application to execute a Command Inj
Highest exploitation probability
EPSS (FIRST.org) estimated probability of exploitation within 30 days, among CVEs published this day.
Where the day’s advisories came from
Curated CERT and PSIRT sources — these add up to the 193 above.