Week 33, 2026 — Aug 10 – Aug 16, 2026
Everything the 24 aggregated CERT, PSIRT and vulnerability-database feeds published in this ISO week, condensed: what was added to the CISA KEV catalog, which advisories matter most and which products were hit. Daily detail lives in the daily briefings.
Added to the CISA KEV catalog
- criticalCVE-2026-68820added 2026-08-11 · CVSS 7 · public exploit code
- criticalCVE-2026-20349added 2026-08-11 · CVSS 8.6
- criticalCVE-2026-72898added 2026-08-11 · CVSS 10 · public exploit code
Notable advisories
[NEW] [high] JetBrains TeamCity: Vulnerability allows code execution
CVE-2026-72898: Metabase SQL Injection Vulnerability
CVE-2026-68820: Microsoft Windows Ancillary Function Driver for WinSock Use-After-Free Vulnerability
CVE-2026-20349: Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) Heap Inspection Vulnerability
#StopRansomware: Gunra Ransomware
CVE-2026-68820: Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
[UPDATE] [high] http/2 implementations: Vulnerability allows denial of service
AL26-018 - Vulnerability affecting Cisco ASA and Secure Firewall Threat Defense Software Remote Access SSL VPN - CVE-2026-20349
[NEW] [high] Cisco ASA (Adaptive Security Appliance) and Secure Firewall Threat Defense: Vulnerability enables denial of service
[UPDATE] [high] Oracle Communications: Multiple vulnerabilities
[UPDATE] [high] Oracle Communications: Multiple vulnerabilities
Most-affected products
Volume by source
Other weeks
Don't wait a week. The daily briefing lands in your inbox every morning after 06:00 UTC — subscribe free, or watch specific products for instant advisory alerts.