Friday, August 14, 2026 Archive

Archived Security Snapshot

Critical vulnerabilities, curated daily for security professionals

Archived Security Brief

WordPress plugin and authentication components dominate the day's disclosures, with authentication bypass and remote code execution flaws in WPManageNinja Fluent Forms Pro, miniOrange Headless Single Sign On, and rtCamp Log in with Google, joined by infrastructure issues in Budibase Server and OpenWrt LuCI. The set disclosed yesterday includes 32 critical CVEs (up 3 percent from the prior day) and 80 high-priority CVEs (up 90 percent), a marked widening of the high-severity tier. CVE-2026-72851 in Budibase Server carries a CVSS of 10, CVE-2026-72841 in OpenWrt LuCI scores 9.9, and CVE-2026-73649 in the shepherdwind velocity.js library scores 9.8, giving attackers server-side execution paths in widely deployed management and templating components. Three vulnerabilities have confirmed active exploitation: Cisco Secure Firewall ASA and FTD (CVE-2026-20349), Metabase (CVE-2026-72898), and the Microsoft Windows Ancillary Function Driver for WinSock (CVE-2026-68820), spanning perimeter, analytics, and endpoint layers. Patch data is unavailable for the tracked set (0 percent confirmed), so teams should verify fix availability directly with vendors and prioritize internet-facing WordPress installs, Budibase instances, and edge network devices.

  • WordPress plugin ecosystem carries the largest share of critical flaws, including Fluent Forms Pro (CVE-2026-73532), Ninja Tables Pro (CVE-2026-73533), Wishlist Member (CVE-2026-12949), and WooCommerce Customer Email Verification (CVE-2026-14182), all at CVSS 9.8
  • 32 critical CVEs (CVSS 9.0+), up 3 percent from the prior day's 31
  • 80 high-priority CVEs (CVSS 7.0 to 8.9), up 90 percent from the prior day's 42
  • Remote code execution and authentication bypass are the dominant patterns, affecting Budibase Server (CVE-2026-72851, CVSS 10), OpenWrt LuCI (CVE-2026-72841, CVSS 9.9), and miniOrange Headless Single Sign On (CVE-2026-28149)
  • Patch availability is unconfirmed at 0 percent across the tracked set, including the Budibase, OpenWrt, and SMEWebify WebErpMesv2 (CVE-2026-49827) issues
  • Three CVEs are under active exploitation, covering Cisco Secure Firewall ASA and FTD, Metabase, and the Windows Ancillary Function Driver for WinSock

Immediate action: Prioritize Cisco Secure Firewall ASA and FTD, Metabase, and Windows systems for immediate patching given confirmed exploitation, then move to internet-facing WordPress sites running Fluent Forms Pro, Ninja Tables Pro, miniOrange SSO, or Wishlist Member, followed by Budibase Server and OpenWrt LuCI deployments. Fix availability is not confirmed for the tracked critical issues, so check vendor advisories directly and apply mitigations such as restricting administrative interfaces and disabling affected plugins where updates are not yet published.

How to read this brief

CVSS score (e.g. 9.1) — severity from 0–10. Red marks critical (9+), orange high (7–8.9).

Exploitability — how hard the flaw is to attack, read from the CVSS vector:

  • Network / Adjacent / Local / Physical — how close an attacker must get. Network means reachable over the internet.
  • No / Low / High privileges — the access they need first. No privileges means no login required.
  • No interaction / User interaction — whether a victim has to do something (open a file, click a link). No interaction means fully automatable.

The lower the bar on all three, the easier to exploit at scale — “Network · No privileges · No interaction” is the worst case: hit from anywhere, no credentials, no victim action.

Actively exploited — confirmed under attack in the wild (CISA’s Known Exploited Vulnerabilities catalog). Prioritize these regardless of score.

EPSS · Nth percentile — FIRST.org’s estimated chance a flaw is exploited within 30 days. We flag it only in the top 10% — a statistical signal it’s unusually likely to be targeted, separate from whether attacks are confirmed.

💡 Tip: Swipe CVE cards left to ⭐ star, right to ❌ remove

Section Navigation