CVE Triage Daily — August 26, 2026
CVEs published 2026-08-26 (UTC). 396 published · 6 newly known-exploited · 19 patch today · 141 this week · 45 unrated.
A heavy day at the top. CISA added six vulnerabilities to the Known Exploited Vulnerabilities catalog — the most in a single day this month — and one of them, a Citrix NetScaler memory-overflow, carries a federal remediation deadline three days out.
Patch today — actively exploited
These six are not predictions. CISA has observed them being used against real targets, which is why each takes the full 40-point exploitation component regardless of how it scores elsewhere.
All six carry the same CISA required action: apply mitigations per vendor instructions in accordance with BOD 26-04 "Prioritizing Security Updates Based on Risk" and CISA's Forensics Triage Requirements; follow BOD 26-04 cloud guidance or discontinue use where mitigations are unavailable.
CVE-2026-8452 — NetScaler — ADC (+1 more) · 96/100
A memory-overflow in NetScaler ADC and NetScaler Gateway causing unpredictable behaviour and denial of service when the appliance is configured as a Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy). This is the day's top score and the reason is structural: it is network-reachable with no privileges and no user interaction, on an appliance class that sits at the network perimeter.
| Field | Value |
|---|---|
| Added to KEV | 2026-08-26 |
| CISA due date | 2026-08-29 |
| Ransomware campaign use | Unknown |
| CVSS | 8.8 HIGH (CVSS 4.0, CNA-assigned) |
| EPSS | 0.01606 (74.1st percentile) |
| Stack | Network edge & appliances |
Score: exploitation 40 + severity 26.4 + exposure 20 + reach 10 − penalties 0 = 96
Link: https://nvd.nist.gov/vuln/detail/CVE-2026-8452
CVE-2019-1068 — Microsoft — Microsoft SQL Server 2014 SP2 32-bit (GDR) (+9 more) · 92/100
Remote code execution in Microsoft SQL Server via incorrect handling of internal functions. A 2019 CVE, newly listed — the ten affected product entries span several SQL Server versions and service packs. Its EPSS percentile is the highest of the six at 98.9, meaning it is modelled as more likely to be exploited than 98.9% of all scored CVEs.
| Field | Value |
|---|---|
| Added to KEV | 2026-08-26 |
| CISA due date | 2026-08-29 |
| Ransomware campaign use | Unknown |
| CVSS | 8.8 HIGH (CVSS 3.1, NVD analyst) |
| EPSS | 0.52845 (98.9th percentile) |
| Stack | Windows & Microsoft |
Score: exploitation 40 + severity 26.4 + exposure 17 + reach 9 − penalties 0 = 92
Link: https://nvd.nist.gov/vuln/detail/CVE-2019-1068
CVE-2021-23758 — AjaxPro.2 · 92/100
Deserialization of untrusted data in all versions of the ajaxpro.2 package: arbitrary .NET classes can be deserialized, which is abusable for remote code execution. Unauthenticated, network-reachable, no user interaction, and a 9.8 CRITICAL from an NVD analyst.
| Field | Value |
|---|---|
| Added to KEV | 2026-08-26 |
| CISA due date | 2026-09-09 |
| Ransomware campaign use | Unknown |
| CVSS | 9.8 CRITICAL (CVSS 3.1, NVD analyst) |
| EPSS | 0.83633 (99.7th percentile) |
| Stack | Everything else |
Score: exploitation 40 + severity 29.4 + exposure 20 + reach 3 − penalties 0 = 92
Link: https://nvd.nist.gov/vuln/detail/CVE-2021-23758
CVE-2022-0995 — kernel · 78/100
An out-of-bounds write in the Linux kernel's watch_queue event notification subsystem, allowing a local user to overwrite kernel state and escalate privileges. Local-only, which is why exposure scores 7 rather than 20 — but it is being used, and it is the kernel.
| Field | Value |
|---|---|
| Added to KEV | 2026-08-26 |
| CISA due date | 2026-09-09 |
| Ransomware campaign use | Unknown |
| CVSS | 7.8 HIGH (CVSS 3.1, NVD analyst) |
| EPSS | 0.09518 (95.1st percentile) |
| Stack | Linux & mobile OS |
Score: exploitation 40 + severity 23.4 + exposure 7 + reach 8 − penalties 0 = 78
Link: https://nvd.nist.gov/vuln/detail/CVE-2022-0995
CVE-2015-5287 — Red Hat — Automatic Bug Reporting Tool · 73/100
A symlink attack on a predictably-named file in the abrt-hook-ccpp helper (ABRT before 2.7.1) allows local privilege escalation. Eleven years old and newly listed as exploited.
| Field | Value |
|---|---|
| Added to KEV | 2026-08-26 |
| CISA due date | 2026-09-09 |
| Ransomware campaign use | Unknown |
| CVSS | 7.8 HIGH (CVSS 3.1, NVD analyst) |
| EPSS | 0.04962 (91.5th percentile) |
| Stack | Everything else |
Score: exploitation 40 + severity 23.4 + exposure 7 + reach 3 − penalties 0 = 73
Link: https://nvd.nist.gov/vuln/detail/CVE-2015-5287
CVE-2015-3246 — Red Hat — Libuser · 68/100
libuser (before 0.56.13-8, and 0.60 before 0.60-7), as used by the userhelper program in the usermode package, writes /etc/passwd directly, which local users can abuse via a race condition to leave the file in an inconsistent state. The lowest severity of the six at 5.1 MEDIUM — and it still lands at 68 purely because it is being exploited.
| Field | Value |
|---|---|
| Added to KEV | 2026-08-26 |
| CISA due date | 2026-09-09 |
| Ransomware campaign use | Unknown |
| CVSS | 5.1 MEDIUM (CVSS 3.1, CNA-assigned) |
| EPSS | 0.08799 (94.8th percentile) |
| Stack | Everything else |
Score: exploitation 40 + severity 15.3 + exposure 10 + reach 3 − penalties 0 = 68
Link: https://nvd.nist.gov/vuln/detail/CVE-2015-3246
Patch today — high score, not yet known exploited
19 CVEs scored 70 or above today. The table below shows those that survived the per-CNA cap (see the note under "What was left out").
| # | CVE | Product | Stack | Score | CVSS | EPSS pct |
|---|---|---|---|---|---|---|
| 1 | CVE-2026-19042 | TeamViewer — Full Client (+1 more) | Linux & mobile OS | 74 | 8.8 HIGH | 0.793 |
| 2 | CVE-2026-77537 | Ubiquiti Inc — UniFi Protect Application | Everything else | 71 | 10 CRITICAL | 0.585 |
| 3 | CVE-2026-77554 | Ubiquiti Inc — UniFi Talk Application | Everything else | 71 | 10 CRITICAL | 0.600 |
| 4 | CVE-2026-74737 | Linux | Linux & mobile OS | 71 | 9.8 CRITICAL | 0.442 |
| 5 | CVE-2026-19632 | cozmoslabs — TranslatePress | Web CMS & plugins | 70 | 9.8 CRITICAL | 0.535 |
| 6 | CVE-2026-74743 | Linux | Linux & mobile OS | 70 | 9.8 CRITICAL | 0.419 |
| 7 | CVE-2026-74744 | Linux | Linux & mobile OS | 70 | 9.8 CRITICAL | 0.419 |
| 8 | CVE-2026-77552 | Ubiquiti Inc — UniFi Enterprise Audio/Video Bridge | Everything else | 70 | 9.8 CRITICAL | 0.569 |
Every severity rating in this table is CNA-assigned — the vendor that reported the flaw also rated it. No NVD analyst has reviewed any of them yet.
CVE-2026-19042 — TeamViewer Full Client and Host for Linux, before 15.81.5. Command injection allowing a remote attacker to execute arbitrary commands in the context of the current user. It leads the non-KEV rows on exploitation probability rather than severity: at the 79.3rd EPSS percentile it is the most likely-to-be-exploited thing published today that CISA has not yet listed. Exposure is 16 rather than 20 because it requires user interaction (AV:N / PR:N / UI:R).
Score: exploitation 23.8 + severity 26.4 + exposure 16 + reach 8 − penalties 0 = 74
CVE-2026-77537 — Ubiquiti UniFi Protect Application. Improper input validation reachable by anyone with network access, leading to command injection on the host device. A perfect 10.0 CRITICAL and a full 20 on exposure — network, no privileges, no interaction. It scores below the TeamViewer flaw only because EPSS models it as less likely to be attacked in the next 30 days.
Score: exploitation 17.5 + severity 30 + exposure 20 + reach 3 − penalties 0 = 71
CVE-2026-77554 — Ubiquiti UniFi Talk Application. The same defect class in a sibling application, filed the same day by the same CNA, with effectively the same profile.
Score: exploitation 18 + severity 30 + exposure 20 + reach 3 − penalties 0 = 71
Patch this week
141 CVEs scored between 50 and 69. The 25 that reached the ranked table:
| CVE | Product | Stack | Score | CVSS | EPSS pct |
|---|---|---|---|---|---|
| CVE-2026-70419 | Dell — Cloud Disaster Recovery | Everything else | 69 | 9.1 | 0.811 |
| CVE-2026-18080 | wedevs — ERP: HR, Accounting & CRM for WooCommerce | Web CMS & plugins | 68 | 9.8 | 0.494 |
| CVE-2026-18431 | themefusion — Avada (Fusion) Builder (+1 more) | Web CMS & plugins | 68 | 9.8 | 0.480 |
| CVE-2026-54569 | senaite — senaite.core | Everything else | 68 | 9.8 | 0.532 |
| CVE-2026-65956 | 1Panel-dev — KubePi | Containers & Kubernetes | 67 | 10 | 0.286 |
| CVE-2026-80235 | Thinking Software Technology — EFence | Everything else | 66 | 9.3 | 0.496 |
| CVE-2026-74770 | Dell — PowerProtect One | Everything else | 65 | 8.8 | 0.622 |
| CVE-2026-59683 | CalcProgrammer1 — OpenRGB | Everything else | 64 | 9.3 | 0.451 |
| CVE-2026-65641 | Veeam — One | Everything else | 64 | 9.3 | 0.434 |
| CVE-2026-68861 | Dell — PowerProtect One | Everything else | 64 | 8.8 | 0.597 |
| CVE-2026-80428 | ILIAS-eLearning e.V. — ILIAS | Everything else | 63 | 9.3 | 0.418 |
| CVE-2026-80349 | TarsCloud — TarsWeb | Everything else | 62 | 9.3 | 0.376 |
By stack
- Everything else — 232
- Linux & mobile OS — 97
- Web CMS & plugins — 41
- Java / JVM — 19
- Python — 6
- Containers & Kubernetes — 2
- Network edge & appliances — 2
- Windows & Microsoft — 2
- JavaScript / npm — 1
The urgent rows are concentrated in three places today. Network edge carried the single most serious item (the NetScaler KEV addition) despite only two CVEs landing there all day — a reminder that stack volume and stack risk are different measurements. Linux took four of the eight ranked patch-today rows plus a kernel KEV addition. Web CMS contributed one, a TranslatePress flaw rated 9.8.
What was left out
308 rows across 16 CNAs were held back from the ranked tables by the per-CNA cap, which admits at most three rows from any one reporting body so a single bulk advisory release cannot own the day. The largest were the Linux kernel CNA (89 rows), MITRE (47) and GitHub (45). KEV rows are never capped. The by-stack counts and the verdict counts above are computed over all 402 scored CVEs, not over the capped tables.
Unrated
45 CVEs were published today with no CVSS score from any source — not NVD, not the assigning CNA. They are unmeasured, not harmless, and none of them can be triaged until someone rates them.
How this is built. Sources: NVD CVE API 2.0 (nvd.nist.gov), CISA Known Exploited Vulnerabilities catalog, FIRST EPSS. Rejected CVE IDs are excluded upstream. Every CVE published on the day is scored, plus every vulnerability CISA added to the Known Exploited Vulnerabilities catalog that day — those are usually older CVEs and would be missing from a feed built only from the day's publications.
Score (0–100) = known exploitation (max 40; CISA KEV membership takes all of it, EPSS earns at most 30) + severity (max 30, from CVSS base) + exposure (max 20: network-reachable, no privileges, no user interaction) + blast radius (max 10, by stack), less penalties for end-of-life or disputed CVEs. "Patch today" is KEV membership or 70+; "this week" is 50+. A CVE with no CVSS from anyone is reported as unrated rather than scored as harmless.
At most 3 rows per reporting CNA appear in the ranked tables, so one vendor's bulk advisory release cannot crowd out the day; KEV rows are never capped. EPSS scores are from the 2026-08-27 model. KEV catalog 2026.08.27. Rubric cve-triage/v1. Not security advice.
