Wednesday, August 5, 2026 Archive

Archived Security Snapshot

Critical vulnerabilities, curated daily for security professionals

Archived Security Brief

Content management and web application platforms account for most of yesterday's critical disclosures, led by three unauthenticated flaws in MaxSite CMS and a remote code execution issue in Pluck CMS. The day brought 26 critical CVEs, down 41 percent from the prior day's 44, alongside 74 high-priority vulnerabilities, essentially flat against 75. Notable entries include CVE-2026-70553, CVE-2026-70554, and CVE-2026-70552 (MaxSite CMS, CVSS 9.8), CVE-2026-63455 in HPE EdgeConnect SD-WAN Orchestrator (CVSS 9.8), and CVE-2026-43682 affecting Apple macOS (CVSS 9.8). Enterprise infrastructure also features, with four vulnerabilities under active exploitation in N-able N-central, Apache Tomcat, and IBM Langflow OSS. Patch data is unavailable for the full set at disclosure time, so treat vendor advisories as the authoritative source and prioritize internet-facing CMS and management platforms.

  • MaxSite CMS carries three CVSS 9.8 vulnerabilities (CVE-2026-70552, CVE-2026-70553, CVE-2026-70554), the heaviest single-product concentration of the day
  • 26 critical CVEs (CVSS 9.0+), down 41 percent from 44 the prior day
  • 74 high-priority CVEs (CVSS 7.0-8.9), down 1 percent from 75
  • Remote code execution and authentication bypass dominate, affecting Pluck CMS (CVE-2026-70376, CVSS 9.6), HPE EdgeConnect SD-WAN Orchestrator (CVE-2026-63455), and Apple macOS (CVE-2026-43682)
  • Patch availability is reported at 0 percent across the disclosed set, so confirm fixed versions directly with vendors before scheduling remediation
  • Four vulnerabilities show confirmed active exploitation: N-able N-central (CVE-2026-18577, CVE-2026-18556), Apache Tomcat (CVE-2026-34486), and IBM Langflow OSS (CVE-2026-9198), all CVSS 9.5

Immediate action: Prioritize N-able N-central, Apache Tomcat, and IBM Langflow OSS instances given confirmed exploitation, then move to internet-facing MaxSite CMS and Pluck CMS deployments and HPE EdgeConnect SD-WAN Orchestrator. Patch availability was not confirmed at disclosure, so check each vendor advisory for a fixed release and apply access restrictions or WAF rules where no update exists yet.

How to read this brief

CVSS score (e.g. 9.1) — severity from 0–10. Red marks critical (9+), orange high (7–8.9).

Exploitability — how hard the flaw is to attack, read from the CVSS vector:

  • Network / Adjacent / Local / Physical — how close an attacker must get. Network means reachable over the internet.
  • No / Low / High privileges — the access they need first. No privileges means no login required.
  • No interaction / User interaction — whether a victim has to do something (open a file, click a link). No interaction means fully automatable.

The lower the bar on all three, the easier to exploit at scale — “Network · No privileges · No interaction” is the worst case: hit from anywhere, no credentials, no victim action.

Actively exploited — confirmed under attack in the wild (CISA’s Known Exploited Vulnerabilities catalog). Prioritize these regardless of score.

EPSS · Nth percentile — FIRST.org’s estimated chance a flaw is exploited within 30 days. We flag it only in the top 10% — a statistical signal it’s unusually likely to be targeted, separate from whether attacks are confirmed.

💡 Tip: Swipe CVE cards left to ⭐ star, right to ❌ remove

Section Navigation