Thursday, August 13, 2026 Archive

Archived Security Snapshot

Critical vulnerabilities, curated daily for security professionals

Archived Security Brief

Yesterday's disclosures centered on unauthenticated remote code execution and authentication bypass flaws in WordPress commerce plugins, Joomla extensions, and enterprise infrastructure from Red Hat and Microsoft. The brief covers 31 critical CVEs (up 29% from the prior day) and 42 high-priority CVEs (down 52%), for 73 total. CVE-2026-15413 in Link Factory and CVE-2026-73299 in Microsoft Prompty both carry CVSS 10, while CVE-2026-73263 in prowler-cloud prowler and CVE-2026-72526 in Red Hat Advanced Cluster Management for Kubernetes score 9.9 and put cloud security tooling and container orchestration at risk. WordPress plugin flaws dominate the critical set, with CVE-2026-18391 (WooCommerce Subscriptions), CVE-2026-16051 (WPMU DEV wpmudev-updates), and CVE-2026-18366 (Events Manager) all at CVSS 9.8, exposing e-commerce and membership sites to pre-authentication compromise. Four CVEs have confirmed active exploitation, including Progress LoadMaster, Cisco Secure Firewall ASA and FTD, Metabase, and the Windows Ancillary Function Driver for WinSock. Vendor patch data was unavailable for this set at publication, so verify fixed versions directly with each vendor and prioritize internet-facing systems.

  • WordPress plugin ecosystem accounts for the largest share of critical disclosures, with WooCommerce Subscriptions, WPMU DEV wpmudev-updates, and Events Manager all at CVSS 9.8
  • 31 critical CVEs (CVSS 9.0+), up 29% from 24 the prior day
  • 42 high-priority CVEs (CVSS 7.0-8.9), down 52% from 88 the prior day
  • Unauthenticated RCE and authentication bypass dominate, affecting Link Factory (CVSS 10), Microsoft Prompty (CVSS 10), Red Hat Advanced Cluster Management for Kubernetes (CVSS 9.9), and the Joomla Sourcerer extension (CVSS 9.8)
  • Patch availability recorded at 0% for this batch, so affected WordPress, Joomla, Kubernetes management, and cloud security tooling deployments need vendor advisories checked directly
  • 4 CVEs are under confirmed active exploitation: Progress LoadMaster, Cisco Secure Firewall ASA and FTD, Metabase, and Windows Ancillary Function Driver for WinSock

Immediate action: Prioritize the actively exploited set first: Progress LoadMaster, Cisco Secure Firewall ASA and FTD, Metabase, and the Windows Ancillary Function Driver for WinSock, all internet-facing or privilege-escalation paths. Next, audit WordPress and Joomla installations for the affected plugins and extensions, and review Red Hat Advanced Cluster Management and prowler deployments. Patch availability is reported at 0% for this batch, so confirm fixed versions with each vendor and apply available mitigations or access restrictions in the interim.

How to read this brief

CVSS score (e.g. 9.1) — severity from 0–10. Red marks critical (9+), orange high (7–8.9).

Exploitability — how hard the flaw is to attack, read from the CVSS vector:

  • Network / Adjacent / Local / Physical — how close an attacker must get. Network means reachable over the internet.
  • No / Low / High privileges — the access they need first. No privileges means no login required.
  • No interaction / User interaction — whether a victim has to do something (open a file, click a link). No interaction means fully automatable.

The lower the bar on all three, the easier to exploit at scale — “Network · No privileges · No interaction” is the worst case: hit from anywhere, no credentials, no victim action.

Actively exploited — confirmed under attack in the wild (CISA’s Known Exploited Vulnerabilities catalog). Prioritize these regardless of score.

EPSS · Nth percentile — FIRST.org’s estimated chance a flaw is exploited within 30 days. We flag it only in the top 10% — a statistical signal it’s unusually likely to be targeted, separate from whether attacks are confirmed.

💡 Tip: Swipe CVE cards left to ⭐ star, right to ❌ remove

Section Navigation