Sunday, August 2, 2026

Today's Security Snapshot

Critical vulnerabilities, curated daily for security professionals

Today's Security Brief

Yesterday's disclosures centered on widely deployed client and server software, with FreeRDP, ArcadeData ArcadeDB, and Mozilla Firefox accounting for the highest-severity entries. The set includes 23 critical CVEs (CVSS 9.0+), down 4% from the prior day, and 43 high-priority CVEs, down 44%. CVE-2026-66402 (CVSS 9.8) and CVE-2026-67305 (CVSS 9.4) affect FreeRDP, the RDP client library embedded in numerous remote access tools, while CVE-2026-67340, CVE-2026-67341, and CVE-2026-67342 (all CVSS 9.8) hit ArcadeDB, and CVE-2026-16379 and CVE-2026-16377 (both CVSS 9.8) affect Firefox. WordPress and Joomla extensions make up a further cluster, including CVE-2026-8457 in WooCommerce Social Login and CVE-2026-65431 in the Regular Labs GeoIP extension, both authentication and access control weaknesses in internet-facing sites. Three CVEs have confirmed active exploitation in network edge products from Arista, Cisco, and Fortinet, and no patch availability was recorded for the disclosed set, so confirm fixed versions directly with vendor advisories before scheduling remediation.

  • FreeRDP carries two of the day's highest-severity issues, CVE-2026-66402 (CVSS 9.8) and CVE-2026-67305 (CVSS 9.4), affecting any product that bundles the library for remote desktop connectivity
  • 23 critical CVEs (CVSS 9.0+) disclosed, a 4% decrease from the prior day's 24
  • 43 high-priority CVEs (CVSS 7.0-8.9) disclosed, a 44% decrease from the prior day's 77
  • Remote code execution and authentication bypass dominate the critical tier: three ArcadeDB flaws at CVSS 9.8 (CVE-2026-67340, CVE-2026-67341, CVE-2026-67342), two Firefox flaws at CVSS 9.8, and login bypass in WooCommerce Social Login (CVE-2026-8457) and Single Sign On For TNG (CVE-2026-15964)
  • Patch availability is recorded at 0% for this set, meaning fixed versions were not captured at disclosure time for FreeRDP, ArcadeDB, Firefox, or the affected WordPress and Joomla extensions
  • Three CVEs show active exploitation in the wild: CVE-2026-16812 in Arista VeloCloud Orchestrator On-Prem, CVE-2026-20316 in Cisco Secure Firewall Management Center, and CVE-2025-68686 in Fortinet FortiOS, all CVSS 9.5

Immediate action: Prioritize the network edge appliances under active exploitation first: Arista VeloCloud Orchestrator On-Prem, Cisco Secure Firewall Management Center, and Fortinet FortiOS. Next, inventory systems bundling FreeRDP, internet-reachable ArcadeDB instances, and Firefox deployments, then update WordPress and Joomla sites running WooCommerce Social Login, Single Sign On For TNG, or the Regular Labs GeoIP extension. No patch data was recorded for these disclosures, so check vendor advisories for fixed builds and apply access restrictions or network segmentation where a fix is not yet published.

How to read this brief

CVSS score (e.g. 9.1) — severity from 0–10. Red marks critical (9+), orange high (7–8.9).

Exploitability — how hard the flaw is to attack, read from the CVSS vector:

  • Network / Adjacent / Local / Physical — how close an attacker must get. Network means reachable over the internet.
  • No / Low / High privileges — the access they need first. No privileges means no login required.
  • No interaction / User interaction — whether a victim has to do something (open a file, click a link). No interaction means fully automatable.

The lower the bar on all three, the easier to exploit at scale — “Network · No privileges · No interaction” is the worst case: hit from anywhere, no credentials, no victim action.

Actively exploited — confirmed under attack in the wild (CISA’s Known Exploited Vulnerabilities catalog). Prioritize these regardless of score.

EPSS · Nth percentile — FIRST.org’s estimated chance a flaw is exploited within 30 days. We flag it only in the top 10% — a statistical signal it’s unusually likely to be targeted, separate from whether attacks are confirmed.

💡 Tip: Swipe CVE cards left to ⭐ star, right to ❌ remove

Section Navigation