Week 34, 2026 — Aug 17 – Aug 23, 2026
Everything the 24 aggregated CERT, PSIRT and vulnerability-database feeds published in this ISO week, condensed: what was added to the CISA KEV catalog, which advisories matter most and which products were hit. Daily detail lives in the daily briefings.
Added to the CISA KEV catalog
- criticalCVE-2026-73570added 2026-08-21 · CVSS 8.9 · public exploit code
- criticalCVE-2026-72530added 2026-08-20 · CVSS 9 · public exploit code
- criticalCVE-2026-72529added 2026-08-20 · CVSS 9.8
- criticalCVE-2026-64849added 2026-08-19 · CVSS 9.3 · public exploit code
- criticalCVE-2026-55040added 2026-08-18 · CVSS 9.1 · public exploit code
- criticalCVE-2026-33824added 2026-08-18 · public exploit code
- criticalCVE-2026-59310added 2026-08-18 · CVSS 9.8 · public exploit code
- criticalCVE-2026-65400added 2026-08-18 · CVSS 7.1 · public exploit code
- criticalCVE-2025-62593added 2026-08-17 · public exploit code
Notable advisories
CISA Adds Two Known Exploited Vulnerabilities to Catalog
CVE-2026-72529: TrueConf Server Missing Authentication for Critical Function Vulnerability
CVE-2026-72530: TrueConf Server Code Injection Vulnerability
CVE-2026-64849: MLflow Server-Side Request Forgery Vulnerability
CVE-2026-65400: Apple macOS Improper Authentication Vulnerability
CVE-2026-55040: Microsoft SharePoint Weak Authentication Vulnerability
CVE-2026-59310: Broadcom VMware vCenter Path Traversal Vulnerability
CVE-2026-33824: Microsoft Internet Key Exchange (IKE) Service Extensions Double Free Vulnerability
CVE-2025-62593: Ray-Project Ray Code Injection Vulnerability
CISA Adds One Known Exploited Vulnerability to Catalog
[NEW] [high] MLflow: Vulnerability enables bypassing security measures
Most-affected products
Volume by source
Other weeks
Don't wait a week. The daily briefing lands in your inbox every morning after 06:00 UTC — subscribe free, or watch specific products for instant advisory alerts.