CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

● Daily security briefing

Monday, August 31, 2026

August 31st saw significant CSIRT activity with 186 CERT/PSIRT advisories and 2,867 CVEs published. CISA added two PaperCut vulnerabilities to the Known Exploited Vulnerabilities catalog: CVE-2026-81578 (missing authentication for critical function) and CVE-2026-82078 (unsafe reflection), both already being exploited in the wild. Beyond PaperCut, the day was dominated by critical CVSS 10.0 vulnerabilities across multiple vendors including three Tenda router flaws (CVE-2026-82693, 82694, 82695), WordPress plugin issues (CVE-2026-82970 in WP Legal Pages and CVE-2026-82971 in QVidium Opera11), unauthenticated file upload in Hash Form (CVE-2026-81780), and configuration vulnerabilities in Dokploy (CVE-2026-82954 at CVSS 9.9). Additional updates covered Linux kernel issues, PHP, and Keycloak vulnerabilities, indicating a busy day with broad exposure across infrastructure and application layers.

Last updated 23:53 UTC

CERT / PSIRT advisories
186
CVEs published
2867
Added to KEV
2
Known exploited
5

13 critical8 high1 medium2 unknownacross the day’s notable advisories and CVEs

Added to the KEV catalog

Exploitation observed in the wild — remediate first.

Notable advisories

Critical/high or exploited items from national CERTs and vendor PSIRTs.

Notable CVEs

Highest-severity CVEs published this day from the NVD and GitHub Advisory firehose — the sharpest items behind the day’s numbers.

Where the day’s advisories came from

Curated CERT and PSIRT sources — these add up to the 186 above.

plus 370 CVE records from the NVD/GHSA firehose — not counted above

Get this briefing by email. One free message every morning after 06:00 UTC — same data, zero noise, one-click unsubscribe. Subscribe. Tracking specific products instead? Watch them from any product page and get alerted only when they ship a new advisory.