Sunday, August 9, 2026 Archive

Archived Security Snapshot

Critical vulnerabilities, curated daily for security professionals

Archived Security Brief

A cluster of CVSS 9.8 flaws in the MSI Radix AXE6600 wireless router accounts for most of the day's critical disclosures, with N-able N-central, Apache Tomcat, JetBrains TeamCity, and Progress LoadMaster adding confirmed exploitation in enterprise management and web infrastructure. The brief covers 82 CVEs disclosed yesterday: 27 critical (up 145% from 11) and 55 high priority (down 11% from 62). Named critical issues include CVE-2026-71991 and CVE-2026-71990 (MSI Radix AXE6600, CVSS 9.8) and CVE-2026-15210 (WordPress OTP Login With Phone Number, CVSS 9.1), while CVE-2026-18577 and CVE-2026-18556 (N-able N-central, CVSS 9.5) and CVE-2026-34486 (Apache Tomcat, CVSS 9.5) carry active exploitation. Remote code execution and authentication bypass in network edge devices, remote monitoring platforms, and application servers are the recurring patterns, exposing managed service providers, hosting environments, and WordPress operators. No vendor patches are confirmed available for this set at publication, so prioritize exposure reduction, access restriction, and monitoring while tracking advisories for fixes.

  • MSI Radix AXE6600 accounts for the bulk of today's CVSS 9.8 critical entries, including CVE-2026-71984 through CVE-2026-71993
  • 27 critical CVEs (CVSS 9.0+), a 145% increase from 11 the prior day
  • 55 high priority CVEs (CVSS 7.0-8.9), down 11% from 62 the prior day
  • Remote code execution and authentication bypass dominate, affecting N-able N-central, Apache Tomcat, JetBrains TeamCity, Progress LoadMaster, and IBM Langflow OSS
  • Patch availability is recorded at 0% for this set, leaving consumer routers and remote management platforms without confirmed vendor fixes
  • 6 CVEs have confirmed active exploitation, unchanged from the prior day, concentrated in remote management and build infrastructure

Immediate action: Prioritize internet-facing N-able N-central, Apache Tomcat, JetBrains TeamCity, and Progress LoadMaster instances, restricting management interfaces to trusted networks and reviewing authentication logs for unauthorized access. MSI Radix AXE6600 routers should have remote administration disabled until a firmware update is confirmed. With no patches recorded as available for these disclosures, rely on network segmentation, access controls, and detection until vendor advisories publish fixes.

How to read this brief

CVSS score (e.g. 9.1) — severity from 0–10. Red marks critical (9+), orange high (7–8.9).

Exploitability — how hard the flaw is to attack, read from the CVSS vector:

  • Network / Adjacent / Local / Physical — how close an attacker must get. Network means reachable over the internet.
  • No / Low / High privileges — the access they need first. No privileges means no login required.
  • No interaction / User interaction — whether a victim has to do something (open a file, click a link). No interaction means fully automatable.

The lower the bar on all three, the easier to exploit at scale — “Network · No privileges · No interaction” is the worst case: hit from anywhere, no credentials, no victim action.

Actively exploited — confirmed under attack in the wild (CISA’s Known Exploited Vulnerabilities catalog). Prioritize these regardless of score.

EPSS · Nth percentile — FIRST.org’s estimated chance a flaw is exploited within 30 days. We flag it only in the top 10% — a statistical signal it’s unusually likely to be targeted, separate from whether attacks are confirmed.

💡 Tip: Swipe CVE cards left to ⭐ star, right to ❌ remove

Section Navigation