● Daily security briefing
Monday, August 31, 2026
August 31st saw significant CSIRT activity with 186 CERT/PSIRT advisories and 2,867 CVEs published. CISA added two PaperCut vulnerabilities to the Known Exploited Vulnerabilities catalog: CVE-2026-81578 (missing authentication for critical function) and CVE-2026-82078 (unsafe reflection), both already being exploited in the wild. Beyond PaperCut, the day was dominated by critical CVSS 10.0 vulnerabilities across multiple vendors including three Tenda router flaws (CVE-2026-82693, 82694, 82695), WordPress plugin issues (CVE-2026-82970 in WP Legal Pages and CVE-2026-82971 in QVidium Opera11), unauthenticated file upload in Hash Form (CVE-2026-81780), and configuration vulnerabilities in Dokploy (CVE-2026-82954 at CVSS 9.9). Additional updates covered Linux kernel issues, PHP, and Keycloak vulnerabilities, indicating a busy day with broad exposure across infrastructure and application layers.
13 critical8 high1 medium2 unknownacross the day’s notable advisories and CVEs
Added to the KEV catalog
Exploitation observed in the wild — remediate first.
Notable advisories
Critical/high or exploited items from national CERTs and vendor PSIRTs.
- unknownexploitedhkcertPaperCut Multiple Vulnerabilities
- criticalexploitedcisaCISA Adds Two Known Exploited Vulnerabilities to Catalog
- highexploitedcert-bund[UPDATE] [high] Linux Kernel: Multiple vulnerabilities
- unknownexploitedcccsPaperCut security advisory (AV26-858) – Update 2
- mediumexploitedcert-bund[NEW] [medium] Linux Kernel: Multiple vulnerabilities
- highcert-bund[UPDATE] [high] Linux Kernel: Multiple vulnerabilities
- highcert-bund[UPDATE] [high] PHP: Multiple Vulnerabilities
- highcert-bund[UPDATE] [high] Keycloak: Multiple vulnerabilities
- highcert-bund[NEW] [high] Gitea: Multiple vulnerabilities allow execution of arbitrary code
- highcert-bund[NEW] [high] MongoDB BI Connector and ODBC Driver: Multiple vulnerabilities
- highcert-bund[NEW] [high] Apache Wicket: Multiple vulnerabilities
- highcert-bund[NEW] [high] Microsoft Edge: Multiple vulnerabilities
Notable CVEs
Highest-severity CVEs published this day from the NVD and GitHub Advisory firehose — the sharpest items behind the day’s numbers.
- criticalCVE-2026-82694CVSS 10A vulnerability was identified in Tenda AC1206 15.03.06.23. This issue affects the function R7WebsSecurityHandler of the file /goform/ate of the component Web UI. The manipulation
- criticalCVE-2026-82695CVSS 10A security flaw has been discovered in Tenda AC18 15.03.05.19. Impacted is an unknown function of the file /goform/telnet of the component Telnet Handler. The manipulation results
- criticalCVE-2026-82693CVSS 10A vulnerability was determined in Tenda AC1206 15.03.06.23. This vulnerability affects the function TendaTelnet of the file /goform/telnet of the component Web UI. Executing a mani
- criticalCVE-2026-81779CVSS 10Improper Validation of Specified Quantity in Input vulnerability in Silk Themes Newspapers X allows Malicious Software Implanted. This issue affects Newspapers X: from 1.0.46 thro
- criticalCVE-2026-82970CVSS 10Unrestricted Upload of File with Dangerous Type vulnerability in WP Legal Pages WP Cookie Notice for GDPR, CCPA & ePrivacy Consent allows Using Malicious Files. This issue affects
- criticalCVE-2026-81780CVSS 10Unauthenticated Arbitrary File Upload in Hash Form <= 1.4.2 versions.
- criticalCVE-2026-82971CVSS 10A vulnerability was determined in QVidium Opera11 3.3.2a26-Ax4x-opera11. This affects an unknown part of the file /cgi-bin/net_tr.cgi of the component CGI Script. This manipulation
- criticalCVE-2026-82954CVSS 9.9A vulnerability was detected in Dokploy up to 0.29.7. This issue affects the function writeTraefikConfigInPath of the file packages/server/src/utils/traefik/application.ts of the c
- criticalCVE-2026-82692CVSS 9.9A vulnerability was found in D-Link DNS-340L and DNS-345 up to 20260717. This affects an unknown part of the file /cgi-bin/iscsi_mgr.cgi. Performing a manipulation of the argument
- criticalCVE-2026-79748CVSS 9.9MCPHub is a unified hub for centrally managing and dynamically orchestrating multiple MCP servers/APIs into separate endpoints with flexible routing strategies. Prior to version 0.
- criticalCVE-2026-83524CVSS 9.9A security vulnerability has been detected in RedPort Optimizer wXa-203, Optimizer wXa-213 and Optimizer wXa-223 up to 20260704. This impacts the function exec of the file /xgatev1
- criticalCVE-2026-82689CVSS 9.9A vulnerability was detected in D-Link DNS-320L, DNS-327L, DNS-340L and DNS-345 up to 20260717. Affected is an unknown function of the file /cgi-bin/isomount_mgr.cgi of the compone
Where the day’s advisories came from
Curated CERT and PSIRT sources — these add up to the 186 above.