Weekly digest
Week 34, 2026 (17–23 Aug)
A busier-than-usual week with 1,319 new CVEs (recent average about 843). Severity skewed high: 188 critical and 483 high, 51% of the total. 66 arrived with exploitation evidence or public exploit code already attached. CISA added 7 CVEs to the Known Exploited Vulnerabilities catalog. 2 CVEs saw exploit probability (EPSS) jump by ten points or more. oracle was the most-affected vendor with 68.
Added to CISA KEV
Confirmed exploitation in the wild — federal remediation deadlines attach to these.
CVE-2026-59310Critical· 9.8CISA KEVPoCvCenter directory-traversal vulnerability
VMware vCenter contains a directory traversal vulnerability in the Syslog server. A malicious actor with network access to vCenter may exploit this issue to execute arbitrary code.
CVE-2026-33824Critical· 9.8CISA KEVPoCDouble free in Windows IKE Extension allows an unauthorized attacker to execute code over a network.
Double free in Windows IKE Extension allows an unauthorized attacker to execute code over a network.
CVE-2026-55040Critical· 9.1CISA KEVPoCMicrosoft SharePoint Server Security Feature Bypass Vulnerability
Weak authentication in Microsoft Office SharePoint allows an unauthorized attacker to bypass a security feature over a network.
CVE-2026-65400Critical· 9.8CISA KEVPoCAn authentication issue was addressed with improved state management
An authentication issue was addressed with improved state management. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.7.9, macOS Sonoma 14.8.9, macOS Tahoe 26.6.1, macOS Tahoe 26.7. An attacker on the network may be able to…
CVE-2025-62593CriticalCISA KEVPoCRay is an AI compute engine
Ray is an AI compute engine. Prior to version 2.52.0, developers working with Ray as a development tool can be exploited via a critical RCE vulnerability exploitable via Firefox and Safari. This vulnerability is due to an insufficient gu…
CVE-2026-73570High· 8.9CISA KEVPoCA remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp package is installed and SNMP notifications are enabled
A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp package is installed and SNMP notifications are enabled. Due to improper sanitization of untrusted input during SNMP …
CVE-2026-64849High· 8.5CISA KEVPoCmlflow: MLflow: Unauthenticated full-read SSRF in webhook delivery: _validate_webhook_url bypassed via unvalidated HTTP redirects (and DNS …
A flaw was found in MLflow. An unauthenticated remote attacker can exploit a Server-Side Request Forgery (SSRF) vulnerability by sending a specially crafted request to the webhook test endpoint. This occurs because the system validates onl…
Rising exploit probability
Largest EPSS increases inside the period (≥ 10 points).
- CVE-2026-20896Critical· 9.8Gitea Docker image versions up to and including 1.26.2 use REVERSE_PROXY_TRUSTED_PROXIES=* by default, allowing any source IP to impersonate a user when reverse-proxy authentication headers such as X-WEBAUTH-USER are enabled.32% → 62%
- CVE-2026-33824Critical· 9.8Double free in Windows IKE Extension allows an unauthorized attacker to execute code over a network.56% → 78%
New this week, ranked by depth score
The 12 that matter most of the 1319 published.
CVE-2026-19490Critical· 9.8CISA KEVPoCVulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: from 14.1 through 73.32 and from 13.1 through 63.21; Gateway: from 14.1 through 73.32 and from 13.1 through 63.21.
Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: from 14.1 through 73.32 and from 13.1 through 63.21; Gateway: from 14.1 through 73.32 and from 13.1 through 63.21.
CVE-2026-64849High· 8.5CISA KEVPoCmlflow: MLflow: Unauthenticated full-read SSRF in webhook delivery: _validate_webhook_url bypassed via unvalidated HTTP redirects (and DNS …
A flaw was found in MLflow. An unauthenticated remote attacker can exploit a Server-Side Request Forgery (SSRF) vulnerability by sending a specially crafted request to the webhook test endpoint. This occurs because the system validates onl…
CVE-2026-77806Critical· 9.8⚠ ExploitedPoCSPIP before 4.4.21 allows unauthenticated remote attackers to execute arbitrary code, as exploited in the wild in August 2026
SPIP before 4.4.21 allows unauthenticated remote attackers to execute arbitrary code, as exploited in the wild in August 2026. This is related to code injection via an X-Spip-Filtre HTTP request header that is mishandled by analyse_resul…
CVE-2026-77647Critical· 9.8⚠ ExploitedPoCSPIP before 4.4.20 allows unauthenticated remote attackers to execute arbitrary code, as exploited in the wild in August 2026
SPIP before 4.4.20 allows unauthenticated remote attackers to execute arbitrary code, as exploited in the wild in August 2026. This is related to incorrect identification of <?php blocks, and var_export's mishandling of certain cases suc…
CVE-2026-18294High· 7.80dayOriginLab Origin Viewer OGW File Parsing Memory Corruption Remote Code Execution Vulnerability
OriginLab Origin Viewer OGW File Parsing Memory Corruption Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of OriginLab Origin Viewer. User interaction i…
CVE-2026-18293High· 7.80dayOriginLab Origin Viewer OPJ File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
OriginLab Origin Viewer OPJ File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of OriginLab Origin Viewer. User interaction…
CVE-2026-69836Critical· 10.0PoCMicrosoft Entra ID Remote Code Execution Vulnerability
Deserialization of untrusted data in Microsoft Entra ID allows an unauthorized attacker to execute code over a network.
CVE-2026-76904Critical· 9.8PoCGeoTools is an open source Java library that provides tools for geospatial data
GeoTools is an open source Java library that provides tools for geospatial data. Starting in version 30.5 and prior to versions 33.6, 34.5, and 33.6, an SQL Injection Vulnerability is present when executing OGC Filters with PostGIS DataS…
CVE-2026-75627Critical· 9.8PoCBastillion fails to properly validate request URI paths in its controller dispatcher, allowing unauthenticated attackers to bypass authentication filters by prefixing requests with arbitrary path segments
Bastillion fails to properly validate request URI paths in its controller dispatcher, allowing unauthenticated attackers to bypass authentication filters by prefixing requests with arbitrary path segments. Attackers can access administra…
CVE-2026-74943Critical· 9.8PoC⚖ disputedUse-after-free in the Graphics: ImageLib component
Use-after-free in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.
CVE-2026-74936Critical· 9.8PoC⚖ disputedUse-after-free in the JavaScript: WebAssembly component
Use-after-free in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.
CVE-2021-43716Critical· 9.8PoCVerification Bypass vulnerability exists in EPSON 150075647YWWV110 EasyMP Network Updater Ver.1.20
Verification Bypass vulnerability exists in EPSON 150075647YWWV110 EasyMP Network Updater Ver.1.20. The Epson projector can be updated by encrypted firmware through USB.
Most-changed records
Existing CVEs whose severity, score, KEV or exploitation status moved.
- CVE-2026-64849mlflow: MLflow: Unauthenticated full-read SSRF in webhook delivery: _validate_webhook_url bypassed via unvalidated HTTP redirects (and DNS …kev, exploited, epss75
- CVE-2026-65400An authentication issue was addressed with improved state managementkev, exploited81
- CVE-2026-33824Double free in Windows IKE Extension allows an unauthorized attacker to execute code over a network.epss93
- CVE-2017-8046Malicious PATCH requests submitted to servers using Spring Data REST versions prior to 2.6.9 (Ingalls SR9), versions prior to 3.0.1 (Kay SR1) and Spring Boot versions prior to 1.5.9, 2.0 M6 can use specially crafted JSON data to run arbi…epss83
- CVE-2018-0101A vulnerability in the Secure Sockets Layer (SSL) VPN functionality of the Cisco Adaptive Security Appliance (ASA) Software could allow an unauthenticated, remote attacker to cause a reload of the affected system or to remotely execute c…epss82
- CVE-2026-0770Langflow affected by Remote Code Execution via validate_code() exec()epss79
- CVE-2026-20896Gitea Docker image versions up to and including 1.26.2 use REVERSE_PROXY_TRUSTED_PROXIES=* by default, allowing any source IP to impersonate a user when reverse-proxy authentication headers such as X-WEBAUTH-USER are enabled.epss66
- CVE-2020-1102A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application packageepss61
Most-affected vendors
By CVEs published in the period.