Monday, August 3, 2026

Today's Security Snapshot

Critical vulnerabilities, curated daily for security professionals

Today's Security Brief

Bouncy Castle's BC-JAVA cryptographic library accounts for four of the day's critical entries, alongside a 9.6-rated flaw in FreeRDP that affects remote desktop deployments across Linux and embedded platforms. The brief covers 16 critical CVEs, down 30 percent from the prior day's 23, and 55 high-priority CVEs, up 28 percent from 43. Notable critical items include CVE-2026-68579 (FreeRDP, CVSS 9.6), CVE-2026-58062 and CVE-2026-59638 (Legion of the Bouncy Castle BC-JAVA, CVSS 9.3 each), and a cluster of Mozilla Firefox memory safety issues at CVSS 9.1 including CVE-2026-16364 and CVE-2026-16370. Attack patterns skew toward remote code execution in client-side and protocol handling code, with browser, RDP client, and WordPress plugin components carrying the bulk of the risk, plus two actively exploited network security appliance flaws in Cisco Secure Firewall Management Center and Fortinet FortiOS. Patch availability data was not published for any of the 71 CVEs at collection time, so teams should treat vendor advisories as the authoritative source for fix status and prioritize inventory checks over patch deployment assumptions.

  • Four critical Bouncy Castle BC-JAVA flaws (CVSS 9.3) affect Java applications relying on the library for TLS, certificate handling, and cryptographic operations
  • 16 critical CVEs, down 30 percent from 23 the prior day
  • 55 high-priority CVEs, up 28 percent from 43 the prior day
  • Remote code execution dominates the critical set: CVE-2026-68579 in FreeRDP (CVSS 9.6) and four Mozilla Firefox issues at CVSS 9.1
  • Patch availability reported at 0 percent across all 71 CVEs, affecting Bouncy Castle, FreeRDP, Firefox, and WordPress plugin deployments
  • Two CVEs have confirmed active exploitation: CVE-2026-20316 in Cisco Secure Firewall Management Center and CVE-2025-68686 in Fortinet FortiOS, both CVSS 9.5

Immediate action: Prioritize the two actively exploited appliance flaws first: audit Cisco Secure Firewall Management Center and Fortinet FortiOS instances for the affected versions and apply vendor fixes or mitigations promptly. Next, inventory Java applications bundling Bouncy Castle, FreeRDP clients and gateways, and Firefox deployments, since these carry the highest-rated non-exploited issues. No patch availability was recorded for this batch, so check vendor advisories directly to confirm whether fixed builds have shipped before scheduling remediation windows.

How to read this brief

CVSS score (e.g. 9.1) — severity from 0–10. Red marks critical (9+), orange high (7–8.9).

Exploitability — how hard the flaw is to attack, read from the CVSS vector:

  • Network / Adjacent / Local / Physical — how close an attacker must get. Network means reachable over the internet.
  • No / Low / High privileges — the access they need first. No privileges means no login required.
  • No interaction / User interaction — whether a victim has to do something (open a file, click a link). No interaction means fully automatable.

The lower the bar on all three, the easier to exploit at scale — “Network · No privileges · No interaction” is the worst case: hit from anywhere, no credentials, no victim action.

Actively exploited — confirmed under attack in the wild (CISA’s Known Exploited Vulnerabilities catalog). Prioritize these regardless of score.

EPSS · Nth percentile — FIRST.org’s estimated chance a flaw is exploited within 30 days. We flag it only in the top 10% — a statistical signal it’s unusually likely to be targeted, separate from whether attacks are confirmed.

💡 Tip: Swipe CVE cards left to ⭐ star, right to ❌ remove

Section Navigation