NoteUpdated 1d ago · 2174 words

CVE Triage Daily — August 26, 2026

CVEs published 2026-08-26 (UTC). 396 published · 6 newly known-exploited · 19 patch today · 141 this week · 45 unrated.

A heavy day at the top. CISA added six vulnerabilities to the Known Exploited Vulnerabilities catalog — the most in a single day this month — and one of them, a Citrix NetScaler memory-overflow, carries a federal remediation deadline three days out.

Patch today — actively exploited

These six are not predictions. CISA has observed them being used against real targets, which is why each takes the full 40-point exploitation component regardless of how it scores elsewhere.

All six carry the same CISA required action: apply mitigations per vendor instructions in accordance with BOD 26-04 "Prioritizing Security Updates Based on Risk" and CISA's Forensics Triage Requirements; follow BOD 26-04 cloud guidance or discontinue use where mitigations are unavailable.

CVE-2026-8452 — NetScaler — ADC (+1 more) · 96/100

A memory-overflow in NetScaler ADC and NetScaler Gateway causing unpredictable behaviour and denial of service when the appliance is configured as a Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy). This is the day's top score and the reason is structural: it is network-reachable with no privileges and no user interaction, on an appliance class that sits at the network perimeter.

Field Value
Added to KEV 2026-08-26
CISA due date 2026-08-29
Ransomware campaign use Unknown
CVSS 8.8 HIGH (CVSS 4.0, CNA-assigned)
EPSS 0.01606 (74.1st percentile)
Stack Network edge & appliances

Score: exploitation 40 + severity 26.4 + exposure 20 + reach 10 − penalties 0 = 96

Link: https://nvd.nist.gov/vuln/detail/CVE-2026-8452

CVE-2019-1068 — Microsoft — Microsoft SQL Server 2014 SP2 32-bit (GDR) (+9 more) · 92/100

Remote code execution in Microsoft SQL Server via incorrect handling of internal functions. A 2019 CVE, newly listed — the ten affected product entries span several SQL Server versions and service packs. Its EPSS percentile is the highest of the six at 98.9, meaning it is modelled as more likely to be exploited than 98.9% of all scored CVEs.

Field Value
Added to KEV 2026-08-26
CISA due date 2026-08-29
Ransomware campaign use Unknown
CVSS 8.8 HIGH (CVSS 3.1, NVD analyst)
EPSS 0.52845 (98.9th percentile)
Stack Windows & Microsoft

Score: exploitation 40 + severity 26.4 + exposure 17 + reach 9 − penalties 0 = 92

Link: https://nvd.nist.gov/vuln/detail/CVE-2019-1068

CVE-2021-23758 — AjaxPro.2 · 92/100

Deserialization of untrusted data in all versions of the ajaxpro.2 package: arbitrary .NET classes can be deserialized, which is abusable for remote code execution. Unauthenticated, network-reachable, no user interaction, and a 9.8 CRITICAL from an NVD analyst.

Field Value
Added to KEV 2026-08-26
CISA due date 2026-09-09
Ransomware campaign use Unknown
CVSS 9.8 CRITICAL (CVSS 3.1, NVD analyst)
EPSS 0.83633 (99.7th percentile)
Stack Everything else

Score: exploitation 40 + severity 29.4 + exposure 20 + reach 3 − penalties 0 = 92

Link: https://nvd.nist.gov/vuln/detail/CVE-2021-23758

CVE-2022-0995 — kernel · 78/100

An out-of-bounds write in the Linux kernel's watch_queue event notification subsystem, allowing a local user to overwrite kernel state and escalate privileges. Local-only, which is why exposure scores 7 rather than 20 — but it is being used, and it is the kernel.

Field Value
Added to KEV 2026-08-26
CISA due date 2026-09-09
Ransomware campaign use Unknown
CVSS 7.8 HIGH (CVSS 3.1, NVD analyst)
EPSS 0.09518 (95.1st percentile)
Stack Linux & mobile OS

Score: exploitation 40 + severity 23.4 + exposure 7 + reach 8 − penalties 0 = 78

Link: https://nvd.nist.gov/vuln/detail/CVE-2022-0995

CVE-2015-5287 — Red Hat — Automatic Bug Reporting Tool · 73/100

A symlink attack on a predictably-named file in the abrt-hook-ccpp helper (ABRT before 2.7.1) allows local privilege escalation. Eleven years old and newly listed as exploited.

Field Value
Added to KEV 2026-08-26
CISA due date 2026-09-09
Ransomware campaign use Unknown
CVSS 7.8 HIGH (CVSS 3.1, NVD analyst)
EPSS 0.04962 (91.5th percentile)
Stack Everything else

Score: exploitation 40 + severity 23.4 + exposure 7 + reach 3 − penalties 0 = 73

Link: https://nvd.nist.gov/vuln/detail/CVE-2015-5287

CVE-2015-3246 — Red Hat — Libuser · 68/100

libuser (before 0.56.13-8, and 0.60 before 0.60-7), as used by the userhelper program in the usermode package, writes /etc/passwd directly, which local users can abuse via a race condition to leave the file in an inconsistent state. The lowest severity of the six at 5.1 MEDIUM — and it still lands at 68 purely because it is being exploited.

Field Value
Added to KEV 2026-08-26
CISA due date 2026-09-09
Ransomware campaign use Unknown
CVSS 5.1 MEDIUM (CVSS 3.1, CNA-assigned)
EPSS 0.08799 (94.8th percentile)
Stack Everything else

Score: exploitation 40 + severity 15.3 + exposure 10 + reach 3 − penalties 0 = 68

Link: https://nvd.nist.gov/vuln/detail/CVE-2015-3246

Patch today — high score, not yet known exploited

19 CVEs scored 70 or above today. The table below shows those that survived the per-CNA cap (see the note under "What was left out").

# CVE Product Stack Score CVSS EPSS pct
1 CVE-2026-19042 TeamViewer — Full Client (+1 more) Linux & mobile OS 74 8.8 HIGH 0.793
2 CVE-2026-77537 Ubiquiti Inc — UniFi Protect Application Everything else 71 10 CRITICAL 0.585
3 CVE-2026-77554 Ubiquiti Inc — UniFi Talk Application Everything else 71 10 CRITICAL 0.600
4 CVE-2026-74737 Linux Linux & mobile OS 71 9.8 CRITICAL 0.442
5 CVE-2026-19632 cozmoslabs — TranslatePress Web CMS & plugins 70 9.8 CRITICAL 0.535
6 CVE-2026-74743 Linux Linux & mobile OS 70 9.8 CRITICAL 0.419
7 CVE-2026-74744 Linux Linux & mobile OS 70 9.8 CRITICAL 0.419
8 CVE-2026-77552 Ubiquiti Inc — UniFi Enterprise Audio/Video Bridge Everything else 70 9.8 CRITICAL 0.569

Every severity rating in this table is CNA-assigned — the vendor that reported the flaw also rated it. No NVD analyst has reviewed any of them yet.

CVE-2026-19042 — TeamViewer Full Client and Host for Linux, before 15.81.5. Command injection allowing a remote attacker to execute arbitrary commands in the context of the current user. It leads the non-KEV rows on exploitation probability rather than severity: at the 79.3rd EPSS percentile it is the most likely-to-be-exploited thing published today that CISA has not yet listed. Exposure is 16 rather than 20 because it requires user interaction (AV:N / PR:N / UI:R).

Score: exploitation 23.8 + severity 26.4 + exposure 16 + reach 8 − penalties 0 = 74

CVE-2026-77537 — Ubiquiti UniFi Protect Application. Improper input validation reachable by anyone with network access, leading to command injection on the host device. A perfect 10.0 CRITICAL and a full 20 on exposure — network, no privileges, no interaction. It scores below the TeamViewer flaw only because EPSS models it as less likely to be attacked in the next 30 days.

Score: exploitation 17.5 + severity 30 + exposure 20 + reach 3 − penalties 0 = 71

CVE-2026-77554 — Ubiquiti UniFi Talk Application. The same defect class in a sibling application, filed the same day by the same CNA, with effectively the same profile.

Score: exploitation 18 + severity 30 + exposure 20 + reach 3 − penalties 0 = 71

Patch this week

141 CVEs scored between 50 and 69. The 25 that reached the ranked table:

CVE Product Stack Score CVSS EPSS pct
CVE-2026-70419 Dell — Cloud Disaster Recovery Everything else 69 9.1 0.811
CVE-2026-18080 wedevs — ERP: HR, Accounting & CRM for WooCommerce Web CMS & plugins 68 9.8 0.494
CVE-2026-18431 themefusion — Avada (Fusion) Builder (+1 more) Web CMS & plugins 68 9.8 0.480
CVE-2026-54569 senaite — senaite.core Everything else 68 9.8 0.532
CVE-2026-65956 1Panel-dev — KubePi Containers & Kubernetes 67 10 0.286
CVE-2026-80235 Thinking Software Technology — EFence Everything else 66 9.3 0.496
CVE-2026-74770 Dell — PowerProtect One Everything else 65 8.8 0.622
CVE-2026-59683 CalcProgrammer1 — OpenRGB Everything else 64 9.3 0.451
CVE-2026-65641 Veeam — One Everything else 64 9.3 0.434
CVE-2026-68861 Dell — PowerProtect One Everything else 64 8.8 0.597
CVE-2026-80428 ILIAS-eLearning e.V. — ILIAS Everything else 63 9.3 0.418
CVE-2026-80349 TarsCloud — TarsWeb Everything else 62 9.3 0.376

By stack

  • Everything else — 232
  • Linux & mobile OS — 97
  • Web CMS & plugins — 41
  • Java / JVM — 19
  • Python — 6
  • Containers & Kubernetes — 2
  • Network edge & appliances — 2
  • Windows & Microsoft — 2
  • JavaScript / npm — 1

The urgent rows are concentrated in three places today. Network edge carried the single most serious item (the NetScaler KEV addition) despite only two CVEs landing there all day — a reminder that stack volume and stack risk are different measurements. Linux took four of the eight ranked patch-today rows plus a kernel KEV addition. Web CMS contributed one, a TranslatePress flaw rated 9.8.

What was left out

308 rows across 16 CNAs were held back from the ranked tables by the per-CNA cap, which admits at most three rows from any one reporting body so a single bulk advisory release cannot own the day. The largest were the Linux kernel CNA (89 rows), MITRE (47) and GitHub (45). KEV rows are never capped. The by-stack counts and the verdict counts above are computed over all 402 scored CVEs, not over the capped tables.

Unrated

45 CVEs were published today with no CVSS score from any source — not NVD, not the assigning CNA. They are unmeasured, not harmless, and none of them can be triaged until someone rates them.


How this is built. Sources: NVD CVE API 2.0 (nvd.nist.gov), CISA Known Exploited Vulnerabilities catalog, FIRST EPSS. Rejected CVE IDs are excluded upstream. Every CVE published on the day is scored, plus every vulnerability CISA added to the Known Exploited Vulnerabilities catalog that day — those are usually older CVEs and would be missing from a feed built only from the day's publications.

Score (0–100) = known exploitation (max 40; CISA KEV membership takes all of it, EPSS earns at most 30) + severity (max 30, from CVSS base) + exposure (max 20: network-reachable, no privileges, no user interaction) + blast radius (max 10, by stack), less penalties for end-of-life or disputed CVEs. "Patch today" is KEV membership or 70+; "this week" is 50+. A CVE with no CVSS from anyone is reported as unrated rather than scored as harmless.

At most 3 rows per reporting CNA appear in the ranked tables, so one vendor's bulk advisory release cannot crowd out the day; KEV rows are never capped. EPSS scores are from the 2026-08-27 model. KEV catalog 2026.08.27. Rubric cve-triage/v1. Not security advice.