Friday, August 7, 2026

Today's Security Snapshot

Critical vulnerabilities, curated daily for security professionals

Today's Security Brief

Yesterday's disclosures were dominated by unauthenticated flaws in WordPress commercial plugins and two high-severity Google Chrome vulnerabilities, alongside data platform and AI tooling components including DataLinkDC Dinky and FlowiseAI Flowise. The set totals 52 CVEs: 20 critical (CVSS 9.0+), down 68% from the prior day's 63, and 32 high-priority (CVSS 7.0-8.9), down 61% from 83. Notable entries include CVE-2026-14812 (CVSS 10) in Premium SEO, CVE-2026-11976 (CVSS 10) in MonsterInsights Pro, CVE-2026-67622 (CVSS 9.9) in FlowiseAI Flowise, and CVE-2026-17726 and CVE-2026-17727 (CVSS 9.6) in Google Chrome. Attack patterns skew toward unauthenticated remote code execution and access control failures in web application plugins and appointment booking software, with five vulnerabilities carrying confirmed active exploitation across N-able N-central, Apache Tomcat, IBM Langflow OSS, and JetBrains TeamCity. Patch availability across the set is currently recorded at 0%, so teams should verify vendor advisories directly and apply compensating controls where fixes have not yet shipped.

  • WordPress commercial plugins account for the largest share of critical disclosures, including CVE-2026-14812 (CVSS 10, Premium SEO), CVE-2026-11976 (CVSS 10, MonsterInsights Pro), and CVE-2026-17032 (CVSS 9.8) affecting three Supsystic Pro products
  • 20 critical CVEs (CVSS 9.0+), a 68% decrease from the prior day's 63
  • 32 high-priority CVEs (CVSS 7.0-8.9), a 61% decrease from the prior day's 83
  • Unauthenticated remote code execution and access control bypass dominate, affecting DataLinkDC Dinky (CVE-2026-70558, CVSS 9.8), FlowiseAI Flowise (CVE-2026-67622, CVSS 9.9), and appointment booking software from themetechmount and open-reception
  • Google Chrome carries two CVSS 9.6 issues (CVE-2026-17726, CVE-2026-17727) that reach users through routine browsing
  • Five vulnerabilities show confirmed active exploitation, spanning N-able N-central (CVE-2026-18577, CVE-2026-18556), Apache Tomcat (CVE-2026-34486), IBM Langflow OSS (CVE-2026-9198), and JetBrains TeamCity (CVE-2026-63077)

Immediate action: Prioritize the actively exploited platforms first: N-able N-central, Apache Tomcat, IBM Langflow OSS, and JetBrains TeamCity, all of which are commonly internet-facing management or build systems. Next, audit WordPress installations for the affected Premium SEO, MonsterInsights Pro, Supsystic Pro, and TrueBooker plugins, and update Chrome to the current stable channel. Patch availability is recorded at 0% for this set, so confirm fix status directly with each vendor and restrict external access to affected services until updates are confirmed.

How to read this brief

CVSS score (e.g. 9.1) — severity from 0–10. Red marks critical (9+), orange high (7–8.9).

Exploitability — how hard the flaw is to attack, read from the CVSS vector:

  • Network / Adjacent / Local / Physical — how close an attacker must get. Network means reachable over the internet.
  • No / Low / High privileges — the access they need first. No privileges means no login required.
  • No interaction / User interaction — whether a victim has to do something (open a file, click a link). No interaction means fully automatable.

The lower the bar on all three, the easier to exploit at scale — “Network · No privileges · No interaction” is the worst case: hit from anywhere, no credentials, no victim action.

Actively exploited — confirmed under attack in the wild (CISA’s Known Exploited Vulnerabilities catalog). Prioritize these regardless of score.

EPSS · Nth percentile — FIRST.org’s estimated chance a flaw is exploited within 30 days. We flag it only in the top 10% — a statistical signal it’s unusually likely to be targeted, separate from whether attacks are confirmed.

💡 Tip: Swipe CVE cards left to ⭐ star, right to ❌ remove

Section Navigation