Week 35, 2026 — Aug 24 – Aug 30, 2026
Everything the 24 aggregated CERT, PSIRT and vulnerability-database feeds published in this ISO week so far, condensed: what was added to the CISA KEV catalog, which advisories matter most and which products were hit. Daily detail lives in the daily briefings.
Added to the CISA KEV catalog
- criticalCVE-2026-60004added 2026-08-25 · public exploit code
- criticalCVE-2026-21962added 2026-08-24 · public exploit code
Notable advisories
CVE-2026-60004: Gitea Code Injection Vulnerability
Oracle security advisory – January 2026 quarterly rollup (AV26-042) – Update 2
CVE-2026-21962: Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in Improper Access Control Vulnerability
CISA Adds One Known Exploited Vulnerability to Catalog
[UPDATE] [high] Linux Kernel: Multiple vulnerabilities
CISA Adds One Known Exploited Vulnerability to Catalog
[UPDATE] [medium] Linux Kernel: Multiple vulnerabilities allow Denial of Service
Gitea security advisory (AV26-845)
Zimbra Multiple Vulnerabilities
Multiple vulnerabilities in Metabase (August 24, 2026)
Bendix EC80 Brake ECU
Most-affected products
Volume by source
Other weeks
Don't wait a week. The daily briefing lands in your inbox every morning after 06:00 UTC — subscribe free, or watch specific products for instant advisory alerts.