Weekly digest
Week 33, 2026 (10–16 Aug)
A heavy week: 1,432 new CVEs, well above the recent average of about 759. Severity skewed high: 140 critical and 656 high, 56% of the total. 40 arrived with exploitation evidence or public exploit code already attached. CISA added 2 CVEs to the Known Exploited Vulnerabilities catalog. One CVE saw exploit probability (EPSS) jump by ten points or more. Microsoft was the most-affected vendor with 407.
Added to CISA KEV
Confirmed exploitation in the wild — federal remediation deadlines attach to these.
CVE-2026-20349High· 8.6CISA KEV0dayPoCA vulnerability in the Remote Access SSL VPN service for Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause th…
A vulnerability in the Remote Access SSL VPN service for Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause th…
CVE-2026-68820High· 7.0CISA KEV0dayPoCWindows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
Rising exploit probability
Largest EPSS increases inside the period (≥ 10 points).
- CVE-2026-58644Critical· 9.8Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.6.4% → 45%
New this week, ranked by depth score
The 12 that matter most of the 1432 published.
CVE-2026-73570High· 8.9CISA KEVPoCA remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp package is installed and SNMP notifications are enabled
A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp package is installed and SNMP notifications are enabled. Due to improper sanitization of untrusted input during SNMP …
CVE-2026-20349High· 8.6CISA KEV0dayPoCA vulnerability in the Remote Access SSL VPN service for Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause th…
A vulnerability in the Remote Access SSL VPN service for Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause th…
CVE-2026-42018High· 7.5CISA KEVPoCAnonymous user token generation exposure in JFrog Artifactory
JFrog Artifactory could return an internal anonymous-user token to an unauthenticated caller when anonymous access is disabled, potentially exposing sensitive resources.
CVE-2026-15826Critical· 9.8PoCThe User Profile Builder plugin for WordPress is vulnerable to Authentication Bypass via Type Confusion in versions up to, and including, 3.16.4
The User Profile Builder plugin for WordPress is vulnerable to Authentication Bypass via Type Confusion in versions up to, and including, 3.16.4. This is due to the wppb_log_in_user() function calling absint() on the return value of wp_i…
CVE-2026-71362Critical· 9.1PoCAdobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation
Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain elevated access to sensitive resources. Exploitation of this issue do…
CVE-2026-19598Critical· 9.8PoCThe Pods – Custom Content Types and Fields plugin for WordPress is vulnerable to Privilege Escalation via Authorization Bypass in all versions up to, and including, 3.3.9
The Pods – Custom Content Types and Fields plugin for WordPress is vulnerable to Privilege Escalation via Authorization Bypass in all versions up to, and including, 3.3.9. The vulnerability exists because the pods_admin AJAX router funne…
CVE-2026-49819Critical· 9.8PoCUpSnap is a wake on lan web app
UpSnap is a wake on lan web app. Versions 4.4.1 through 5.3.5 are vulnerable to a missing-authentication / privilege-escalation chain in `pb.HandlerInitSuperuser` (`backend/pb/handlers.go:249`), reachable as `POST /api/upsnap/init-superu…
CVE-2026-63297Critical· 9.9PoCAn authorization bypass vulnerability in LXD due to a timing flaw during configuration merging allows an authenticated attacker to bypass target project restrictions during cross-project instance copies
An authorization bypass vulnerability in LXD due to a timing flaw during configuration merging allows an authenticated attacker to bypass target project restrictions during cross-project instance copies. When copying an instance to a tar…
CVE-2026-46670Critical· 9.8PoCYesWiki is a wiki system written in PHP
YesWiki is a wiki system written in PHP. Prior to version 4.6.4, an unauthenticated SQL injection in the Bazar form-import path (`FormManager::create()`) allows any unauthenticated visitor of a default YesWiki install to inject arbitrar…
CVE-2026-68820High· 7.0CISA KEV0dayPoCWindows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
CVE-2026-73296Critical· 9.4PoCMicrosoft UFO open-source framework for intelligent automation across devices and platforms
Microsoft UFO open-source framework for intelligent automation across devices and platforms. Prior to 3.0.8, create_mobile_data_collection_server and create_mobile_action_server in ufo/client/mcp/http_servers/mobile_mcp_server.py exposed…
CVE-2026-48046Critical· 9.3PoCStreambert is a cross-platform Electron Desktop App to stream and download video content
Streambert is a cross-platform Electron Desktop App to stream and download video content. Versions prior to 2.5.0 contain an unvalidated auto-updater URL vulnerability that allows a compromised renderer process to make the main process d…
Most-changed records
Existing CVEs whose severity, score, KEV or exploitation status moved.
- CVE-2026-58644Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.epss91
- CVE-2021-31196Microsoft Exchange Server Remote Code Execution Vulnerabilityepss75
- CVE-2026-61447PraisonAI before 1.6.78 contains a remote code execution vulnerability in CodeAgent._execute_python() that executes LLM-generated Python code without AST validation, import restrictions, or sandbox enforcementexploit_available67
- CVE-2026-61459MCP Server Kubernetes before 3.9.0 contains an argument injection vulnerability in structured tools (kubectl_get, kubectl_describe, kubectl_delete) that allows attackers to bypass the assertNoDangerousFlags security check by supplying re…exploit_available66
- CVE-2026-61876LuCI versions fail to properly encode DHCPv6 lease hostnames before rendering in status tables, allowing adjacent network attackers to inject HTML markupexploit_available61
- CVE-2026-3576The Planyo Online Reservation System plugin for WordPress is vulnerable to Server-Side Request Forgery leading to Local File Inclusion in all versions up to, and including, 3.0exploit_available54
Most-affected vendors
By CVEs published in the period.