Wednesday, August 12, 2026

Today's Security Snapshot

Critical vulnerabilities, curated daily for security professionals

Today's Security Brief

Adobe and Microsoft account for the bulk of yesterday's high-impact disclosures, with maximum-severity flaws in Adobe Campaign Classic and ColdFusion 2025 alongside a cluster of CVSS 9.8 issues across Windows and Windows Server. The day produced 24 critical vulnerabilities (down 54% from 52) and 88 high-priority vulnerabilities (down 12% from 100). CVE-2026-27302 and CVE-2026-71398 in Adobe Campaign Classic and CVE-2026-48362 in Adobe ColdFusion 2025 all carry CVSS 10, while CVE-2026-62815, CVE-2026-62893, and CVE-2026-65791 affect Microsoft Windows at CVSS 9.8. Open-source web platforms are also represented through CVE-2026-46670 in YesWiki and CVE-2026-73211 in PeerTube, both scored 9.8. Four vulnerabilities have confirmed active exploitation, including CVE-2026-20349 in Cisco Secure Firewall ASA and FTD and CVE-2026-72898 in Metabase; patch data is not yet recorded for any of yesterday's entries, so treat vendor advisories as the authoritative source.

  • Adobe Campaign Classic (CVE-2026-27302, CVE-2026-71398) and ColdFusion 2025 (CVE-2026-48362) all scored CVSS 10, the highest-impact disclosures of the day
  • 24 critical vulnerabilities (CVSS 9.0+), down 54% from 52 the prior day
  • 88 high-priority vulnerabilities (CVSS 7.0 to 8.9), down 12% from 100 the prior day
  • Remote code execution dominates the critical tier, spanning Microsoft Windows and Windows Server, Adobe enterprise applications, and web platforms including YesWiki and PeerTube
  • Patch availability is recorded at 0% for this set, so remediation depends on checking vendor advisories directly for Adobe, Microsoft, Cisco, and Progress products
  • Four vulnerabilities show confirmed active exploitation: Progress LoadMaster, Cisco Secure Firewall ASA and FTD, Metabase, and the Windows Ancillary Function Driver for WinSock

Immediate action: Prioritize internet-facing Adobe Campaign Classic and ColdFusion 2025 servers along with Microsoft Windows and Windows Server systems carrying the CVSS 9.8 remote code execution flaws. Address the actively exploited issues in Progress LoadMaster, Cisco Secure Firewall ASA and FTD, Metabase, and the Windows Ancillary Function Driver for WinSock in the same pass, since these are being used against live targets. No patch status is recorded for this set, so confirm fixed versions against each vendor's advisory and apply mitigations where updates are not yet published.

How to read this brief

CVSS score (e.g. 9.1) — severity from 0–10. Red marks critical (9+), orange high (7–8.9).

Exploitability — how hard the flaw is to attack, read from the CVSS vector:

  • Network / Adjacent / Local / Physical — how close an attacker must get. Network means reachable over the internet.
  • No / Low / High privileges — the access they need first. No privileges means no login required.
  • No interaction / User interaction — whether a victim has to do something (open a file, click a link). No interaction means fully automatable.

The lower the bar on all three, the easier to exploit at scale — “Network · No privileges · No interaction” is the worst case: hit from anywhere, no credentials, no victim action.

Actively exploited — confirmed under attack in the wild (CISA’s Known Exploited Vulnerabilities catalog). Prioritize these regardless of score.

EPSS · Nth percentile — FIRST.org’s estimated chance a flaw is exploited within 30 days. We flag it only in the top 10% — a statistical signal it’s unusually likely to be targeted, separate from whether attacks are confirmed.

💡 Tip: Swipe CVE cards left to ⭐ star, right to ❌ remove

Section Navigation