Tuesday, August 4, 2026

Today's Security Snapshot

Critical vulnerabilities, curated daily for security professionals

Today's Security Brief

Adobe Campaign Classic accounts for a large share of yesterday's critical disclosures, with five CVSS 9.8+ flaws including two rated 10.0, alongside three maximum-severity vulnerabilities in the SiYuan open-source note-taking platform. Critical CVEs rose to 44 from 16 the prior day (175%), while high-priority CVEs reached 75, up 36%. Notable entries include CVE-2026-48330 and CVE-2026-48331 (Adobe Campaign Classic, CVSS 10), CVE-2026-69085 and CVE-2026-69084 (siyuan-note SiYuan, CVSS 10), and CVE-2026-69240 in the Sequelize ORM at CVSS 9.8. Remote code execution and authentication bypass patterns dominate, spanning enterprise marketing platforms, healthcare software (CVE-2026-39932 in OpenEMR, CVSS 9.1), and widely used JavaScript libraries such as Baileys and Sequelize. Two vulnerabilities have confirmed active exploitation, in Cisco Secure Firewall Management Center (CVE-2026-20316, CVSS 9.5) and N-able N-central (CVE-2026-18577, CVSS 8.2); with patch availability recorded at 0% across the set, teams should verify vendor advisories directly and apply mitigations where fixes are pending.

  • Adobe Campaign Classic carries five critical CVEs, two at CVSS 10.0 (CVE-2026-48330, CVE-2026-48331), making it the most heavily affected enterprise product
  • 44 critical CVEs (CVSS 9.0+), up 175% from 16 the prior day
  • 75 high-priority CVEs (CVSS 7.0-8.9), up 36% from 55
  • Remote code execution and authentication bypass dominate, affecting SiYuan (three CVSS 10.0 flaws), OpenEMR healthcare software, and the Sequelize and Baileys JavaScript libraries
  • Patch availability is recorded at 0% for this data set, so confirm fixed versions directly with Adobe, Cisco, and open-source project advisories
  • Two CVEs show confirmed active exploitation: Cisco Secure Firewall Management Center (CVE-2026-20316) and N-able N-central (CVE-2026-18577)

Immediate action: Prioritize Cisco Secure Firewall Management Center and N-able N-central, both under active exploitation and often internet-reachable management planes, then move to Adobe Campaign Classic instances exposed to untrusted input. Patch data is unavailable for these entries, so check vendor advisories for fixed builds and apply access restrictions or network segmentation on SiYuan, OpenEMR, and Sequelize-based applications until versions are confirmed.

How to read this brief

CVSS score (e.g. 9.1) — severity from 0–10. Red marks critical (9+), orange high (7–8.9).

Exploitability — how hard the flaw is to attack, read from the CVSS vector:

  • Network / Adjacent / Local / Physical — how close an attacker must get. Network means reachable over the internet.
  • No / Low / High privileges — the access they need first. No privileges means no login required.
  • No interaction / User interaction — whether a victim has to do something (open a file, click a link). No interaction means fully automatable.

The lower the bar on all three, the easier to exploit at scale — “Network · No privileges · No interaction” is the worst case: hit from anywhere, no credentials, no victim action.

Actively exploited — confirmed under attack in the wild (CISA’s Known Exploited Vulnerabilities catalog). Prioritize these regardless of score.

EPSS · Nth percentile — FIRST.org’s estimated chance a flaw is exploited within 30 days. We flag it only in the top 10% — a statistical signal it’s unusually likely to be targeted, separate from whether attacks are confirmed.

💡 Tip: Swipe CVE cards left to ⭐ star, right to ❌ remove

Section Navigation