Monday, August 10, 2026 Archive

Archived Security Snapshot

Critical vulnerabilities, curated daily for security professionals

Archived Security Brief

Vulnerabilities disclosed yesterday center on enterprise management and application infrastructure, with N-able N-central, Apache Tomcat, JetBrains TeamCity, IBM Langflow OSS, and Progress LoadMaster all carrying CVSS 9.5 issues under confirmed exploitation. Volume dropped sharply against the prior day: 2 critical CVEs (down 93% from 27) and 38 high-priority CVEs (down 31% from 55), for 40 total. The two critical entries are CVE-2026-19348 (CVSS 9.8) in the Shenzhen Aitemi M300 Wi-Fi Repeater and CVE-2026-15360 (CVSS 9.1) in the Ajax Load More WordPress plugin. Remote code execution and authentication bypass against internet-reachable management planes, CI/CD servers, and web application stacks dominate the set, with consumer networking gear and WordPress extensions adding externally exposed attack surface. No patch data is currently confirmed for any of the 40 CVEs (0% availability), so verify fix status directly with each vendor and apply compensating controls where updates are not yet published.

  • N-able N-central, Apache Tomcat, JetBrains TeamCity, IBM Langflow OSS, and Progress LoadMaster each disclosed CVSS 9.5 vulnerabilities with confirmed exploitation activity
  • 2 critical CVEs (CVSS 9.0+), down 93% from 27 the prior day
  • 38 high-priority CVEs (CVSS 7.0-8.9), down 31% from 55 the prior day
  • Remote code execution and authentication bypass lead the attack patterns, affecting remote monitoring platforms, CI/CD infrastructure, load balancers, and WordPress plugins
  • Patch availability sits at 0% across the 40 disclosed CVEs, including the Shenzhen Aitemi M300 Wi-Fi Repeater (CVE-2026-19348, CVSS 9.8) and Ajax Load More (CVE-2026-15360, CVSS 9.1)
  • 5 CVEs are listed as actively exploited, concentrated in remote-management and build-server products

Immediate action: Prioritize internet-facing N-able N-central, Progress LoadMaster, JetBrains TeamCity, Apache Tomcat, and IBM Langflow OSS deployments, since these carry CVSS 9.5 flaws with active exploitation and typically sit at the network edge or inside build pipelines. Patch availability is unconfirmed for all 40 CVEs, so check each vendor advisory for released updates and, where none exist, restrict management interface exposure, enforce network segmentation, and monitor authentication logs for anomalies. WordPress sites running Ajax Load More and networks using Shenzhen Aitemi M300 repeaters should be inventoried and isolated from sensitive segments until fixes ship.

How to read this brief

CVSS score (e.g. 9.1) — severity from 0–10. Red marks critical (9+), orange high (7–8.9).

Exploitability — how hard the flaw is to attack, read from the CVSS vector:

  • Network / Adjacent / Local / Physical — how close an attacker must get. Network means reachable over the internet.
  • No / Low / High privileges — the access they need first. No privileges means no login required.
  • No interaction / User interaction — whether a victim has to do something (open a file, click a link). No interaction means fully automatable.

The lower the bar on all three, the easier to exploit at scale — “Network · No privileges · No interaction” is the worst case: hit from anywhere, no credentials, no victim action.

Actively exploited — confirmed under attack in the wild (CISA’s Known Exploited Vulnerabilities catalog). Prioritize these regardless of score.

EPSS · Nth percentile — FIRST.org’s estimated chance a flaw is exploited within 30 days. We flag it only in the top 10% — a statistical signal it’s unusually likely to be targeted, separate from whether attacks are confirmed.

💡 Tip: Swipe CVE cards left to ⭐ star, right to ❌ remove

Section Navigation