{"date_iso":"2026-08-12","date_human":"Wednesday, August 12, 2026","generated_utc":"2026-08-12 14:22 UTC","read_minutes":6,"patch_tuesday":false,"top_stories":[{"title":"Microsoft\u2019s massive Patch Tuesday releases continue as AI reshapes bug discovery","link":"https://therecord.media/microsoft-massive-patch-tuesday-releases-continue-ai","reason":"Microsoft","category":"News","sources":["Bleeping Computer","CCCS Alerts & Advisories","Cisco Talos","Cyber Security News","Dark Reading","Infosecurity Magazine","Krebs On Security","Malwarebytes Labs","Rapid7 Blog","SANS Internet Storm Center","SecurityWeek","Tenable Blog","The Hacker News","The Record","The Register Security","Zero Day Initiative"],"coverage":16,"cve_ids":["CVE-2026-55040","CVE-2026-68820","CVE-2026-70329"],"summary":"This month\u2019s update features about five times the volume of patches Microsoft was shipping in a typical month before AI-assisted vulnerability discovery took hold.","source":"The Record","date_rel":"6m ago","thumbnail":"http://cms.therecord.media/uploads/Microsoft_Israel_f69980a35e.jpg","description":"","related":[{"title":"Hackers leverage new Microsoft SharePoint exploit in attacks","link":"https://www.bleepingcomputer.com/news/microsoft/hackers-leverage-new-microsoft-sharepoint-exploit-in-attacks/","source":"Bleeping Computer","date_rel":"19m ago"},{"title":"CISA gives federal agencies two weeks to patch Microsoft bug exploited in DPRK campaign","link":"https://therecord.media/cisa-gives-federal-agencies-two-weeks-to-patch-dprk-microsoft-bug","source":"The Record","date_rel":"38m ago"},{"title":"New Microsoft Defender 'ShieldBreak' zero-day grants SYSTEM privileges","link":"https://www.bleepingcomputer.com/news/security/new-microsoft-defender-shieldbreak-zero-day-grants-system-privileges/","source":"Bleeping Computer","date_rel":"2h ago"},{"title":"Microsoft Fixes 400 Flaws on August Patch Tuesday","link":"https://www.infosecurity-magazine.com/news/microsoft-fixes-400-flaws-august/","source":"Infosecurity Magazine","date_rel":"4h ago"},{"title":"ShieldBreak Zero-Day PoC Claims Microsoft Defender Patch Bypass With SYSTEM Access","link":"https://thehackernews.com/2026/08/shieldbreak-zero-day-poc-claims.html","source":"The Hacker News","date_rel":"6h ago"},{"title":"Microsoft SharePoint Server Vulnerability Allows Attackers to Inject and Execute Malicious Code Remotely","link":"https://cybersecuritynews.com/microsoft-sharepoint-server-vulnerability/","source":"Cyber Security News","date_rel":"7h ago"}]},{"title":"Nightmare-Eclipse Drops ShieldBreak Windows Defender 0-day Vulnerability","link":"https://cybersecuritynews.com/nightmare-eclipse-drops-shieldbreak-0-day/","reason":"Windows","category":"News","sources":["Cyber Security News","Fortinet PSIRT","Microsoft Security","SecurityWeek","The Hacker News"],"coverage":5,"cve_ids":["CVE-2026-50472","CVE-2026-54984","CVE-2026-56174"],"summary":"The prolific and controversial security researcher known as Nightmare-Eclipse (also tracked under the alias Chaotic Eclipse) has released a ninth Windows zero-day exploit called ShieldBreak, and this time the target is\u2026","source":"Cyber Security News","date_rel":"2h ago","thumbnail":"https://cybersecuritynews.com/wp-content/uploads/2026/08/Nightmare-Eclipse-Drops-ShieldBreak-0-Day.webp","description":"The prolific and controversial security researcher known as Nightmare-Eclipse (also tracked under the alias Chaotic Eclipse) has released a ninth Windows zero-day exploit called ShieldBreak, and this time the target is Microsoft\u2019s own fix. ShieldBreak demonstrates a complete bypass of the patch Microsoft shipped for RoguePlanet, the Windows Defender elevation-of-privilege flaw tracked as CVE-2026-50656 , proving that the underlying weakness in the Microsoft Malware Protection Engine was never fully closed. RoguePlanet was originally disclosed as a race condition in mpengine.dll, the core\u2026","related":[{"title":"Fresh Windows Zero-Day Exploited in North Korean Cyberattacks","link":"https://www.securityweek.com/fresh-windows-zero-day-exploited-in-north-korean-cyberattacks/","source":"SecurityWeek","date_rel":"3h ago"},{"title":"Heap overflow in kernel driver due to missing size validation","link":"https://fortiguard.fortinet.com/psirt/FG-IR-26-156","source":"Fortinet PSIRT","date_rel":"5h ago"},{"title":"CVE-2026-50472 Windows LUA File Virtualization Filter Driver Elevation of Privilege Vulnerability","link":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50472","source":"Microsoft Security","date_rel":"22h ago"},{"title":"CVE-2026-56174 Windows Narrator Braille Elevation of Privilege Vulnerability","link":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-56174","source":"Microsoft Security","date_rel":"22h ago"},{"title":"CVE-2026-54984 Windows Imaging Component Remote Code Execution Vulnerability","link":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-54984","source":"Microsoft Security","date_rel":"22h ago"},{"title":"Researchers Turn USB Auto-Install Into a Full SYSTEM Takeover on Windows 11","link":"https://thehackernews.com/2026/08/researchers-turn-usb-auto-install-into.html","source":"The Hacker News","date_rel":"11 Aug"}]},{"title":"Kimwolf v7 Android Botnet Makes HTTP/2 DDoS Traffic Look Like Legitimate Browsing","link":"https://thehackernews.com/2026/08/kimwolf-v7-android-botnet-makes-http2.html","reason":"Android","category":"News","sources":["Bleeping Computer","CISA Alerts & Advisories","CyberScoop","Palo Alto Unit 42","The Hacker News"],"coverage":5,"cve_ids":[],"summary":"Cybersecurity researchers have discovered a new version of the Kimwolf/AISURU Android and Internet of Things (IoT) botnet that comes with significant improvements to improve its operational resilience and conduct\u2026","source":"The Hacker News","date_rel":"17h ago","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEieGDZmdQhY70KqvppH4w5wMVhbs804WeageCN1UXtRK4KpFkYWNk-wkTeTv9CUSNGYQMsaZ04XYWimXsIQmfl0uYSFgNJe7uBbXsg1xPw-cukXwJY3O3TAHUpWiiYmleWgDpu4PLMRfjgIQtOxb6Wq2yFjvqyb6lpoCOcOyWOpZoURLpddzyGkmc8soRHe/s1600/android-botnet.jpg","description":"Cybersecurity researchers have discovered a new version of the Kimwolf/AISURU Android and Internet of Things (IoT) botnet that comes with significant improvements to improve its operational resilience and conduct distributed denial-of-service (DDoS) attacks. The new version, tracked as Kimwolf v7, was discovered by Palo Alto Networks Unit 42 in February 2026. \"Kimwolf v7 adds an HTTP/2-based","related":[{"title":"Google says Chrome cuts 7 billion unwanted Android notifications a day to fight abuse","link":"https://www.bleepingcomputer.com/news/security/google-says-chrome-cuts-7-billion-unwanted-android-notifications-a-day-to-fight-abuse/","source":"Bleeping Computer","date_rel":"11h ago"},{"title":"Kimwolf botnet rebuilt to survive takedowns, researchers say","link":"https://cyberscoop.com/kimwolf-botnet-palo-alto-unit-42-android-tv-boxes/","source":"CyberScoop","date_rel":"12h ago"},{"title":"Mira Hormone Monitor, Mira Android App","link":"https://www.cisa.gov/news-events/ics-medical-advisories/icsma-26-223-01","source":"CISA Alerts & Advisories","date_rel":"11 Aug"},{"title":"Kimwolf v7: An Evolution of the Kimwolf Botnet","link":"https://unit42.paloaltonetworks.com/kimwolf-v7-botnet-malware/","source":"Palo Alto Unit 42","date_rel":"11 Aug"}]},{"title":"CAV3RN Uses Google Apps Script as C2 Relay to Hide Malware Traffic Behind Google Infrastructure","link":"https://cybersecuritynews.com/cav3rn-uses-google-apps-script/","reason":"Google","category":"News","sources":["CCCS Alerts & Advisories","Cyber Security News","Kaspersky Securelist"],"coverage":3,"cve_ids":[],"summary":"CAV3RN is a modular espionage framework that is becoming harder to see on a network. Its newest communication component hides remote-control traffic behind Google Apps Script, a service many organizations use\u2026","source":"Cyber Security News","date_rel":"2h ago","thumbnail":"https://cybersecuritynews.com/wp-content/uploads/2026/08/CAV3RN-Uses-Google-Apps-Script-as-C2-Relay-to-Hide-Malware-Traffic-Behind-Google-Infrastructure.webp","description":"CAV3RN is a modular espionage framework that is becoming harder to see on a network. Its newest communication component hides remote-control traffic behind Google Apps Script, a service many organizations use legitimately. That design can make a harmful connection look less unusual at first glance. The framework has been used against targets in Israel and has continued to gain new components. Researchers have not described the initial infection route in this update, but once installed, its modules can exchange messages, collect software details, receive tasks, and update parts of the toolkit\u2026","related":[{"title":"Google security advisory (AV26-806)","link":"https://cyber.gc.ca/en/alerts-advisories/google-security-advisory-av26-806","source":"CCCS Alerts & Advisories","date_rel":"10m ago"},{"title":"Google-themed Credential Phishing Attempt Delivered Through a Fake \u2018New Audio MSG\u2019 Email","link":"https://cybersecuritynews.com/google-themed-credential-phishing/","source":"Cyber Security News","date_rel":"4h ago"},{"title":"Project CAV3RN continues: Google Apps Script as C2 relay and DNS-based C2 channel selection","link":"https://securelist.com/project-cav3rn-continues/120991/","source":"Kaspersky Securelist","date_rel":"11 Aug"}]},{"title":"Top 10 Best Business VPN Solutions in 2026","link":"https://cybersecuritynews.com/best-business-vpn-solutions/","reason":"Cisco","category":"News","sources":["CCCS Alerts & Advisories","Cyber Security News","Zero Day Initiative"],"coverage":3,"cve_ids":[],"summary":"The best business VPN solutions in 2026 are increasingly the ones that aren\u2019t traditional VPNs at all. Twingate and Tailscale lead for modern least-privilege remote access, Cisco Secure Client (AnyConnect) and Palo Alto\u2026","source":"Cyber Security News","date_rel":"4h ago","thumbnail":"https://cybersecuritynews.com/wp-content/uploads/2026/08/Best-Business-VPN-Solutions.webp","description":"The best business VPN solutions in 2026 are increasingly the ones that aren\u2019t traditional VPNs at all. Twingate and Tailscale lead for modern least-privilege remote access, Cisco Secure Client (AnyConnect) and Palo Alto GlobalProtect remain the enterprise incumbents, and NordLayer offers the most approachable published pricing for small teams. A business VPN encrypts remote connections into your corporate network but because traditional VPN appliances have become a primary target for attackers, modern organizations are shifting toward Zero Trust architecture principles to restrict access by\u2026","related":[{"title":"ZDI-26-533: Cisco Secure Firewall Management Center login.cgi Authentication Bypass Vulnerability","link":"http://www.zerodayinitiative.com/advisories/ZDI-26-533/","source":"Zero Day Initiative","date_rel":"11 Aug"},{"title":"Cisco security advisory (AV26-794)","link":"https://cyber.gc.ca/en/alerts-advisories/cisco-security-advisory-av26-794","source":"CCCS Alerts & Advisories","date_rel":"10 Aug"}]},{"title":"Shipping 10\u201350\u00d7 More Code? Watch This Webinar on Securing AI-Speed Development","link":"https://thehackernews.com/2026/08/shipping-1050-more-code-watch-this.html","reason":"Teams","category":"News","sources":["CyberScoop","Microsoft Security","Microsoft Security Blog","The Hacker News"],"coverage":4,"cve_ids":["CVE-2026-65768"],"summary":"AI is helping development teams produce far more code, far faster. But security teams still have to review vulnerabilities, manage dependencies, prioritize fixes, and control risk at human speed. When software output\u2026","source":"The Hacker News","date_rel":"10 Aug","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhy3fcUJacnxspYO1ssk2-ESCQ9QYb5BBCB0-3Jk8UyWQFmKZxt8RCeYemwUlJ08y_hnkyVm4LaAq6a_oyz5BPmpuwkmephJ0K7iy6cFvPjAe-b3pQ4Q28jh3KzNqLhZ6qtecuG9jenDpeVsjpUrG9ZBEwe2WStxgh6RiOwhI_rlsxYelFv2BD31o9rhd8/s1600/chain-webinar.jpg","description":"AI is helping development teams produce far more code, far faster. But security teams still have to review vulnerabilities, manage dependencies, prioritize fixes, and control risk at human speed. When software output jumps 10 to 50 times, the problem is no longer just finding vulnerabilities. It is keeping security from becoming the bottleneck, or worse, losing control of what gets shipped.","related":[{"title":"CVE-2026-65768 Microsoft Teams Remote Code Execution Vulnerability","link":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65768","source":"Microsoft Security","date_rel":"22h ago"},{"title":"Microsoft named a Leader in the 2026 IDC MarketScape for MDR/MXDR for the Enterprise","link":"https://www.microsoft.com/en-us/security/blog/2026/08/10/microsoft-named-a-leader-in-the-2026-idc-marketscape-for-mdr-mxdr-for-the-enterprise/","source":"Microsoft Security Blog","date_rel":"10 Aug"},{"title":"Why transparent AI agents matter more than you think","link":"https://cyberscoop.com/transparent-ai-agent-security-op-ed/","source":"CyberScoop","date_rel":"10 Aug"}]},{"title":"Cisco ASA and FTD Flaw Exploited in the Wild Can Trigger Remote DoS","link":"https://thehackernews.com/2026/08/cisco-asa-and-ftd-flaw-exploited-in.html","reason":"Asa","category":"News","sources":["Bleeping Computer","Cisco Security Advisories","The Hacker News"],"coverage":3,"cve_ids":[],"summary":"Cisco has warned that a new vulnerability impacting Secure Firewall Adaptive Security Appliance (ASA) Software and Secure Firewall Threat Defense (FTD) Software has been exploited in the wild. The high-severity flaw\u2026","source":"The Hacker News","date_rel":"6h ago","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgRIn51DQNDe2IfVEJzqiWXY9k8QyRhulSTcOh67As0Pj7Da1DCB5Lu1RBhjI55Y7_TF9PW9F9HOBn6moaPRNrpl0G_OGeMbC9z5BMfdOqtF6sHpd5tJLvQqnvlCd77R-4oCYiDVfFlUtRe4mp7W8cFDCHmJ8kz4TueVL06-jbGzpVdWasZF02YRwYyrZJc/s1600/cisco-powerhouse.jpg","description":"Cisco has warned that a new vulnerability impacting Secure Firewall Adaptive Security Appliance (ASA) Software and Secure Firewall Threat Defense (FTD) Software has been exploited in the wild. The high-severity flaw, tracked as CVE-2026-20349 (CVSS score: 8.6), is a case of insufficient error checking when processing HTTP requests that could allow an unauthenticated, remote attacker to trigger","related":[{"title":"Cisco warns of ASA and FTD VPN flaw exploited to crash devices","link":"https://www.bleepingcomputer.com/news/security/cisco-warns-of-asa-and-ftd-vpn-flaw-exploited-to-crash-devices/","source":"Bleeping Computer","date_rel":"16h ago"},{"title":"Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software Remote Access SSL VPN Denial of Service Vulnerability","link":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-vpn-dos-dzv4mQFF?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Secure%20Firewall%20Adaptive%20Security%20Appliance%20and%20Secure%20Firewall%20Threat%20Defense%20Software%20Remote%20Access%20SSL%20VPN%20Denial%20of%20Service%20Vulnerability%26vs_k=1","source":"Cisco Security Advisories","date_rel":"20h ago"}]},{"title":"Top 10 Best DDoS Protection Services in 2026","link":"https://cybersecuritynews.com/ddos-protection-tools/","reason":"Cloudflare","category":"News","sources":["Bleeping Computer","Cyber Security News","The Register Security"],"coverage":3,"cve_ids":[],"summary":"Cloudflare is the best DDoS protection service for most organizations in 2026, scoring highest in our evaluation on the combination of network capacity, always-on mitigation speed, and cost predictability it publicly\u2026","source":"Cyber Security News","date_rel":"5h ago","thumbnail":"https://cybersecuritynews.com/wp-content/uploads/2026/08/Best-DDoS-Protection-Services-.webp","description":"Cloudflare is the best DDoS protection service for most organizations in 2026, scoring highest in our evaluation on the combination of network capacity, always-on mitigation speed, and cost predictability it publicly absorbed a record 31.4 Tbps attack in Q4 2025 without metering customers for the privilege. Akamai Prolexic scores highest for enterprise scrubbing, and AWS Shield leads for AWS-native estates. DDoS protection services detect and filter denial-of-service traffic before it exhausts your bandwidth or servers. Here are the ten best, scored. The 2026 DDoS Protection Scorecard Each\u2026","related":[{"title":"Two wars and a World Cup lead to epic DDoS attacks on publishers","link":"https://www.theregister.com/security/2026/08/11/two-wars-and-a-world-cup-lead-to-epic-ddos-attacks-on-publishers/5286278","source":"The Register Security","date_rel":"21h ago"},{"title":"DDoS attacks over 1 Tbps surged fivefold in the second quarter","link":"https://www.bleepingcomputer.com/news/security/ddos-attacks-over-1-tbps-surged-fivefold-in-the-second-quarter/","source":"Bleeping Computer","date_rel":"23h ago"}]},{"title":"Ivanti EPM Update Patches Remotely Exploitable Flaws","link":"https://www.securityweek.com/ivanti-epm-update-patches-remotely-exploitable-flaws/","reason":"Ivanti","category":"News","sources":["CCCS Alerts & Advisories","SecurityWeek"],"coverage":2,"cve_ids":[],"summary":"The vulnerabilities could be exploited to leak credentials for external SQL connections or crash an agent service.","source":"SecurityWeek","date_rel":"4h ago","thumbnail":"","description":"","related":[{"title":"Ivanti security advisory (AV26-805)","link":"https://cyber.gc.ca/en/alerts-advisories/ivanti-security-advisory-av26-805","source":"CCCS Alerts & Advisories","date_rel":"16h ago"}]},{"title":"ClickFix Attack Abuses Signed IBM SPSS IDE to Deploy New CNCMachineRMS RAT","link":"https://cybersecuritynews.com/clickfix-attack-ibm-spss-ide/","reason":"Ibm","category":"News","sources":["CCCS Alerts & Advisories","Cyber Security News"],"coverage":2,"cve_ids":[],"summary":"ClickFix campaigns are once again turning an ordinary user action into the opening move of a serious intrusion. A newly documented chain uses a fake fix prompt to lead victims toward CNCMachineRMS, a previously\u2026","source":"Cyber Security News","date_rel":"4h ago","thumbnail":"https://cybersecuritynews.com/wp-content/uploads/2026/08/ClickFix-Attack-Abuses-Signed-IBM-SPSS-IDE-to-Deploy-New-CNCMachineRMS-RAT.webp","description":"ClickFix campaigns are once again turning an ordinary user action into the opening move of a serious intrusion. A newly documented chain uses a fake fix prompt to lead victims toward CNCMachineRMS, a previously undocumented remote access trojan that gives an attacker lasting control of a Windows device. The campaign stands out because it hides behind software that is both legitimate and signed. After the ClickFix lure, attackers launch IBM SPSS WinWrap Basic IDE and steer its scripting function toward malicious files, allowing the activity to blend in with trusted software rather than an\u2026","related":[{"title":"IBM security advisory (AV26-789)","link":"https://cyber.gc.ca/en/alerts-advisories/ibm-security-advisory-av26-789","source":"CCCS Alerts & Advisories","date_rel":"10 Aug"}]}],"worth_reading":[{"title":"Chrome adopts what may be the best protection yet against account takeovers","link":"https://arstechnica.com/security/2026/08/chrome-adopts-what-may-be-the-best-protection-yet-against-account-takeovers/","reason":"Chrome","category":"Media","sources":["Ars Technica Security","Malwarebytes Labs"],"coverage":2,"cve_ids":[],"summary":"Google\u2019s Chrome browser has added a new feature that could go a long way in preventing a form of account takeover that\u2019s grown increasingly common as users adopt two-factor authentication, passkeys, and similar\u2026","source":"Ars Technica Security","date_rel":"15h ago","thumbnail":"https://cdn.arstechnica.net/wp-content/uploads/2026/08/phishing-account-takeover-500x500.jpg","description":"Google\u2019s Chrome browser has added a new feature that could go a long way in preventing a form of account takeover that\u2019s grown increasingly common as users adopt two-factor authentication, passkeys, and similar protections. The new Chrome protection is known as device-bound session credentials (DBSCs). The measure stores a unique encryption key in a silicon-resident fortress that\u2019s built into the device running the browser. On Windows machines, this fortress is called a TPM, short for Trusted Platform Module. On macOS and iOS, it\u2019s known as a secure enclave. Other platforms have differing\u2026","related":[{"title":"Fake CCleaner installs GhostDesk Chrome spyware","link":"https://www.malwarebytes.com/blog/threat-intel/2026/08/fake-ccleaner-installs-ghostdesk-chrome-spyware","source":"Malwarebytes Labs","date_rel":"16h ago"}]},{"title":"CVE-2026-63520: Microsoft SharePoint Remote Code Execution (FIXED)","link":"https://www.rapid7.com/blog/post/etr-cve-2026-63520-microsoft-sharepoint-remote-code-execution-fixed","reason":"CVE-2026-63520","category":"Research","sources":["Microsoft Security","Rapid7 Blog"],"coverage":2,"cve_ids":["CVE-2026-63520"],"summary":"Overview Rapid7 Labs conducted a zero-day research project against Microsoft SharePoint, resulting in the discovery of two new vulnerabilities that, when chained together, achieve unauthenticated remote code execution\u2026","source":"Rapid7 Blog","date_rel":"23h ago","thumbnail":"https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt65a432ba319f4043/6846abddaf18306debe6cf4d/ETR.webp","description":"Overview Rapid7 Labs conducted a zero-day research project against Microsoft SharePoint, resulting in the discovery of two new vulnerabilities that, when chained together, achieve unauthenticated remote code execution (RCE) against a vulnerable SharePoint server. Today, both Rapid7 and Microsoft are disclosing the second vulnerability in this chain, the RCE vulnerability CVE-2026-63520. The first vulnerability in the chain, CVE-2026-55040, was disclosed by Rapid7 and Microsoft last month. Our full disclosure timeline for the exploit chain can be seen below in Figure 1. Figure 1: The road to\u2026","related":[{"title":"CVE-2026-63520 Microsoft SharePoint Server Remote Code Execution Vulnerability","link":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-63520","source":"Microsoft Security","date_rel":"22h ago"}]}],"kev_watch":[],"vuln_watch":[{"id":"CVE-2026-58231","vendor":"SAP","product":"SAP Commerce Cloud (Data Hub Adapter)","severity":"CRITICAL","score":10.0,"description":"SAP Commerce Cloud allows an unauthenticated\nattacker to abuse a default authentication client and submit specially crafted\ninput to certain functions lacking sufficient validation. Successful\nexploitation could enable arbitrary code execut\u2026","cwe":"CWE-94","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-58231"},{"id":"CVE-2026-58115","vendor":"Siemens","product":"SIMATIC IoT2050 Advanced","severity":"CRITICAL","score":10.0,"description":"A vulnerability has been identified in SIMATIC IoT2050 Advanced (6ES7647-0BA00-1YA2) (All versions < V4.3.4.1 running Industrial OS with Node-RED installed). Affected devices do not enforce authentication on the Node-RED HTTP interface, all\u2026","cwe":"CWE-306","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-58115"},{"id":"CVE-2026-48056","vendor":"truelockmc","product":"streambert","severity":"CRITICAL","score":10.0,"description":"Streambert is a cross-platform Electron Desktop App to stream and download video content. Versions prior to 2.5.0  improperly validate executable paths supplied to the \u00a0run-download\u00a0 IPC handler, allowing a compromised renderer process to e\u2026","cwe":"CWE-20","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-48056"},{"id":"CVE-2026-17061","vendor":"Dassault Syst\u00e8mes","product":"SIMULIA Execution Engine","severity":"CRITICAL","score":10.0,"description":"A Deserialization of Untrusted Data vulnerability affecting SIMULIA Execution Engine from Release 2023 through Release 2026 could lead to an unauthenticated remote code execution.","cwe":"CWE-502","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-17061"},{"id":"CVE-2026-48362","vendor":"Adobe","product":"ColdFusion 2025","severity":"CRITICAL","score":10.0,"description":"ColdFusion is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploi\u2026","cwe":"CWE-78","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-48362"},{"id":"CVE-2026-27302","vendor":"Adobe","product":"Adobe Campaign Classic","severity":"CRITICAL","score":10.0,"description":"Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. E\u2026","cwe":"CWE-863","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-27302"},{"id":"CVE-2026-71398","vendor":"Adobe","product":"Adobe Campaign Classic","severity":"CRITICAL","score":10.0,"description":"Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. E\u2026","cwe":"CWE-863","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-71398"},{"id":"CVE-2026-45618","vendor":"harttle","product":"liquidjs","severity":"CRITICAL","score":10.0,"description":"LiquidJS is a Shopify/GitHub Pages compatible template engine. Prior to version 10.26.0, it is possible to execute arbitrary code with crafted templates. Version 10.26.0 patches the issue.","cwe":"CWE-94","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-45618"},{"id":"CVE-2026-72603","vendor":"wg-easy","product":"wg-easy","severity":"CRITICAL","score":9.9,"description":"An OS command injection vulnerability in wg-easy 15.3.0 allows users with the clients.create permission to execute arbitrary commands as root by injecting newline-delimited WireGuard PostUp directives into the client name field. The client \u2026","cwe":"CWE-78","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-72603"},{"id":"CVE-2026-48765","vendor":"baptisteArno","product":"typebot.io","severity":"CRITICAL","score":9.9,"description":"TypeBot is a chatbot builder tool. Versions prior to 3.17.0 allow a low-privilege read collaborator to extract a workspace OAuth `credentialsId` from a readable bot configuration and then overwrite that credential through `handleUpdateOAuth\u2026","cwe":"CWE-639","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-48765"}],"vendor_spikes":[{"vendor":"Microsoft","count":483,"critical_count":8},{"vendor":"Adobe","count":52,"critical_count":6},{"vendor":"WordPress","count":39,"critical_count":1},{"vendor":"Unknown","count":36,"critical_count":0},{"vendor":"Red Hat","count":31,"critical_count":3},{"vendor":"MongoDB","count":25,"critical_count":0},{"vendor":"Linux","count":20,"critical_count":0},{"vendor":"Siemens","count":17,"critical_count":1},{"vendor":"n8n-io","count":16,"critical_count":0},{"vendor":"baptisteArno","count":11,"critical_count":1}],"epss_risers":[],"developing_map":{"https://thehackernews.com/2026/08/shipping-1050-more-code-watch-this.html":3},"trending_count":20,"new_cve_count":983,"has_news_data":true,"has_cve_data":true}