Daily digest
Tuesday 18 August 2026
A heavy day: 458 new CVEs, well above the recent average of about 202. Severity skewed high: 70 critical and 197 high, 58% of the total. 16 arrived with exploitation evidence or public exploit code already attached. CISA added 4 CVEs to the Known Exploited Vulnerabilities catalog. oracle was the most-affected vendor with 68.
Added to CISA KEV
Confirmed exploitation in the wild — federal remediation deadlines attach to these.
CVE-2026-59310Critical· 9.8CISA KEVPoCvCenter directory-traversal vulnerability
VMware vCenter contains a directory traversal vulnerability in the Syslog server. A malicious actor with network access to vCenter may exploit this issue to execute arbitrary code.
CVE-2026-33824Critical· 9.8CISA KEVPoCDouble free in Windows IKE Extension allows an unauthorized attacker to execute code over a network.
Double free in Windows IKE Extension allows an unauthorized attacker to execute code over a network.
CVE-2026-55040Critical· 9.1CISA KEVPoCMicrosoft SharePoint Server Security Feature Bypass Vulnerability
Weak authentication in Microsoft Office SharePoint allows an unauthorized attacker to bypass a security feature over a network.
CVE-2026-65400Critical· 9.8CISA KEVPoCAn authentication issue was addressed with improved state management
An authentication issue was addressed with improved state management. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.7.9, macOS Sonoma 14.8.9, macOS Tahoe 26.6.1, macOS Tahoe 26.7. An attacker on the network may be able to…
New this day, ranked by depth score
The 12 that matter most of the 458 published.
CVE-2026-75627Critical· 9.8PoCBastillion fails to properly validate request URI paths in its controller dispatcher, allowing unauthenticated attackers to bypass authentication filters by prefixing requests with arbitrary path segments
Bastillion fails to properly validate request URI paths in its controller dispatcher, allowing unauthenticated attackers to bypass authentication filters by prefixing requests with arbitrary path segments. Attackers can access administra…
CVE-2026-74943Critical· 9.8PoC⚖ disputedUse-after-free in the Graphics: ImageLib component
Use-after-free in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.
CVE-2026-74936Critical· 9.8PoC⚖ disputedUse-after-free in the JavaScript: WebAssembly component
Use-after-free in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.
CVE-2021-43716Critical· 9.8PoCVerification Bypass vulnerability exists in EPSON 150075647YWWV110 EasyMP Network Updater Ver.1.20
Verification Bypass vulnerability exists in EPSON 150075647YWWV110 EasyMP Network Updater Ver.1.20. The Epson projector can be updated by encrypted firmware through USB.
CVE-2026-18963Critical· 9.1PoCA flaw was found in the reset-credentials flow of the keycloak-services component, which is the core engine for identity and access management in Red Hat Build of Keycloak
A flaw was found in the reset-credentials flow of the keycloak-services component, which is the core engine for identity and access management in Red Hat Build of Keycloak. The issue allows an unauthenticated attacker to force the passwo…
CVE-2026-75827High· 8.8PoCGrav before 2.0.15 contains an arbitrary file write vulnerability in the Blueprint dynamic-data bare-function validation that uses an incomplete denylist instead of a positive allowlist
Grav before 2.0.15 contains an arbitrary file write vulnerability in the Blueprint dynamic-data bare-function validation that uses an incomplete denylist instead of a positive allowlist. Attackers with page-edit or blueprint-config acces…
CVE-2026-24301High· 8.8PoCMicrosoft Copilot Information Disclosure Vulnerability
Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to disclose information over a network.
CVE-2026-75855High· 8.7PoCArcadeDB versions before 26.8.1 fail to sanitize database names in the POST /api/v1/server endpoint's create database and drop database commands, allowing authenticated root users to write and delete arbitrary files outside the configure…
ArcadeDB versions before 26.8.1 fail to sanitize database names in the POST /api/v1/server endpoint's create database and drop database commands, allowing authenticated root users to write and delete arbitrary files outside the configure…
CVE-2026-19501High· 8.8PoCCSV export functionality in Brainstorm Force SureForms version, <= 2.12.1, fails to neutralize spreadsheet formula characters in user-controlled form field names before generating CSV exports, which allows a remote attacker to execute sp…
CSV export functionality in Brainstorm Force SureForms version, <= 2.12.1, fails to neutralize spreadsheet formula characters in user-controlled form field names before generating CSV exports, which allows a remote attacker to execute sp…
CVE-2026-75898High· 8.5PoCRAGFlow before 0.26.3 contains a server-side request forgery vulnerability in the agent workflow "Invoke" component (agent/component/invoke.py)
RAGFlow before 0.26.3 contains a server-side request forgery vulnerability in the agent workflow "Invoke" component (agent/component/invoke.py). The component builds an outbound request URL from canvas configuration and runtime template …
CVE-2026-71059Critical· 9.9Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: Web Service API)
Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: Web Service API). Supported versions that are affected are 8.2.0.0.0 and 26.1.0.0.0. Easily exploitable vulnerability allows low privileged attacker with …
CVE-2026-70921Critical· 10.0Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security)
Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with …
Most-changed records
Existing CVEs whose severity, score, KEV or exploitation status moved.
- CVE-2026-65400An authentication issue was addressed with improved state managementkev, exploited81
- CVE-2019-10869Path Traversal and Unrestricted File Upload exists in the Ninja Forms plugin before 3.0.23 for WordPress (when the Uploads add-on is activated)epss58
- CVE-2026-14620webpack-dev-server versions 5.2.5 and earlier expose two internal developer endpoints, /webpack-dev-server/open-editor and /webpack-dev-server/invalidate, that perform state-changing actions on any GET request without verifying that the …exploit_available38
Most-affected vendors
By CVEs published in the period.