Thursday, August 20, 2026

Today's Security Snapshot

Critical vulnerabilities, curated daily for security professionals

Today's Security Brief

A cluster of Google Chrome flaws scoring CVSS 9.6 dominates the day's critical disclosures, alongside remote code execution issues in IBM AIX and a maximum-severity flaw in the W3 Total Cache WordPress plugin. Critical CVEs totaled 30, down 44% from the prior day's 54, while high-priority CVEs fell 40% to 61. CVE-2026-18051 (CVSS 10) affects W3 Total Cache, CVE-2026-16816 and CVE-2026-15068 (both CVSS 9.9) affect IBM AIX, and CVE-2026-64696 (CVSS 9.8) affects Apple macOS. Enterprise virtualization, collaboration, and machine learning stacks also feature: six CVEs carry confirmed exploitation, including issues in VMware Cloud Foundation, Microsoft SharePoint, Ray, and MLflow. No vendor patch data was recorded for these entries at publication, so verify fix availability directly with each vendor advisory before scheduling remediation.

  • Six Google Chrome CVEs at CVSS 9.6 and two IBM AIX flaws at CVSS 9.9 lead the day's critical disclosures
  • 30 critical CVEs (CVSS 9.0+), down 44% from 54 the prior day
  • 61 high-priority CVEs (CVSS 7.0-8.9), down 40% from 101 the prior day
  • Remote code execution and memory corruption patterns dominate, spanning browsers, Unix server platforms, and WordPress caching plugins
  • Patch availability recorded at 0% in this data set, affecting confirmation for Chrome, AIX, macOS, and VMware Cloud Foundation entries
  • Six CVEs show confirmed exploitation activity, including CVE-2026-59310 (VMware Cloud Foundation), CVE-2026-55040 (Microsoft SharePoint), and CVE-2026-64849 (MLflow)

Immediate action: Prioritize browser fleets running Google Chrome, IBM AIX servers, Apple macOS endpoints, and VMware Cloud Foundation or vCenter deployments, followed by Microsoft SharePoint and any exposed Ray or MLflow instances. Patch availability is unconfirmed in this data set, so check vendor advisories directly and apply documented mitigations or network restrictions where no fix is yet published.

How to read this brief

CVSS score (e.g. 9.1) — severity from 0–10. Red marks critical (9+), orange high (7–8.9).

Exploitability — how hard the flaw is to attack, read from the CVSS vector:

  • Network / Adjacent / Local / Physical — how close an attacker must get. Network means reachable over the internet.
  • No / Low / High privileges — the access they need first. No privileges means no login required.
  • No interaction / User interaction — whether a victim has to do something (open a file, click a link). No interaction means fully automatable.

The lower the bar on all three, the easier to exploit at scale — “Network · No privileges · No interaction” is the worst case: hit from anywhere, no credentials, no victim action.

Actively exploited — confirmed under attack in the wild (CISA’s Known Exploited Vulnerabilities catalog). Prioritize these regardless of score.

EPSS · Nth percentile — FIRST.org’s estimated chance a flaw is exploited within 30 days. We flag it only in the top 10% — a statistical signal it’s unusually likely to be targeted, separate from whether attacks are confirmed.

💡 Tip: Swipe CVE cards left to ⭐ star, right to ❌ remove

Section Navigation