VulnSea

Daily digest

Tuesday 11 August 2026

A heavy day: 620 new CVEs, well above the recent average of about 136. Severity skewed high: 26 critical and 361 high, 62% of the total. 15 arrived with exploitation evidence or public exploit code already attached. CISA added 2 CVEs to the Known Exploited Vulnerabilities catalog. Microsoft was the most-affected vendor with 403.

620
New CVEs
26
Critical
2
KEV additions
1
Records changed

Added to CISA KEV

Confirmed exploitation in the wild — federal remediation deadlines attach to these.

New this day, ranked by depth score

The 12 that matter most of the 620 published.

CVE-2026-20349High· 8.6CISA KEV0dayPoC
1mo ago

A vulnerability in the Remote Access SSL VPN service for Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause th…

A vulnerability in the Remote Access SSL VPN service for Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause th…

Abyssalcisco · adaptive_security_appliance_softwareEPSS 2.2%via NVD
CVE-2026-71362Critical· 9.1PoC
1mo ago

Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation

Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain elevated access to sensitive resources. Exploitation of this issue do…

Abyssaladobe · commerceEPSS 25%via NVD
CVE-2026-46670Critical· 9.8PoC
1mo ago

YesWiki is a wiki system written in PHP

YesWiki is a wiki system written in PHP. Prior to version 4.6.4, an unauthenticated SQL injection in the Bazar form-import path (`FormManager::create()`) allows any unauthenticated visitor of a default YesWiki install to inject arbitrar…

AbyssalEPSS 1.9%via NVD
CVE-2026-68820High· 7.0CISA KEV0dayPoC
1mo ago

Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability

Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

AbyssalMicrosoft · Windows 10 Version 1607EPSS 6.2%via CVEORG
CVE-2026-48046Critical· 9.3PoC
1mo ago

Streambert is a cross-platform Electron Desktop App to stream and download video content

Streambert is a cross-platform Electron Desktop App to stream and download video content. Versions prior to 2.5.0 contain an unvalidated auto-updater URL vulnerability that allows a compromised renderer process to make the main process d…

Abyssaltruelockmc · streambertEPSS 0.35%via NVD
CVE-2026-49179High· 8.8PoC
1mo ago

Improper neutralization of special elements used in a command ('command injection') in Windows Active Directory allows an unauthorized attacker to execute code over a network.

Improper neutralization of special elements used in a command ('command injection') in Windows Active Directory allows an unauthorized attacker to execute code over a network.

Midnightmicrosoft · windows_10_1607EPSS 0.83%via NVD
CVE-2026-63520High· 8.1PoC
1mo ago

Microsoft SharePoint Server Remote Code Execution Vulnerability

Improper input validation in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.

MidnightMicrosoft · Microsoft SharePoint Enterprise Server 2016EPSS 2.9%via CVEORG
CVE-2026-66804High· 7.8PoC
1mo ago

Microsoft Windows Cross Device Service Elevation of Privilege Vulnerability

Improper access control in Windows Cross Device Service allows an authorized attacker to elevate privileges locally.

MidnightMicrosoft · Windows 10 Version 22H2EPSS 5.3%via CVEORG
CVE-2026-62911High· 8.0PoC
1mo ago

Microsoft Exchange Server Elevation of Privilege Vulnerability

Authentication bypass by capture-replay in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.

MidnightMicrosoft · Microsoft Exchange Server 2016 Cumulative Update 23EPSS 1.3%via CVEORG
CVE-2026-73072High· 7.8PoC
1mo ago

Vim is an open source, command line text editor

Vim is an open source, command line text editor. Prior to 9.2.0846, set_sofo() in src/spellfile.c reuses sl_sal_first[] without resetting values left by set_sal_first(), so a crafted spell file containing an SN_SAL section before an SN_S…

MidnightRed Hat · Red Hat Enterprise Linux AppStream (v. 10)EPSS 0.13%via NVD
CVE-2026-62737High· 7.8PoC
1mo ago

Windows Kernel Elevation of Privilege Vulnerability

Untrusted pointer dereference in Windows Kernel allows an authorized attacker to elevate privileges locally.

MidnightMicrosoft · Windows 11 Version 24H2EPSS 2.8%via CVEORG
CVE-2026-62735High· 7.8PoC
1mo ago

Windows HTTP.sys Elevation of Privilege Vulnerability

Heap-based buffer overflow in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.

MidnightMicrosoft · Windows 10 Version 1607EPSS 0.48%via CVEORG

Most-changed records

Existing CVEs whose severity, score, KEV or exploitation status moved.

  • CVE-2021-31196Microsoft Exchange Server Remote Code Execution Vulnerability75

Most-affected vendors

By CVEs published in the period.