Saturday, August 15, 2026 Archive

Archived Security Snapshot

Critical vulnerabilities, curated daily for security professionals

Archived Security Brief

Saturday's disclosures center on unauthenticated remote code execution and access-control failures in open-source platforms and WordPress plugins, including MindsDB Minds Platform (CVE-2026-73678, CVSS 10) and the SiYuan note-taking application (CVE-2026-72811, CVSS 10). The brief covers 24 critical CVEs, down 25% from the prior day, and 52 high-priority CVEs, down 35%. Notable entries include CVE-2026-19626 (CVSS 9.9) in Tenable Security Center, CVE-2026-48528 (CVSS 9.8) in NCEAS Metacat, and CVE-2026-15826 (CVSS 9.8) in the cozmoslabs User Profile Builder plugin. WordPress ecosystem components account for a large share of the critical set, with authentication bypass and privilege escalation flaws in User Session Synchronizer, TrueBooker, and MStore API exposing site takeover paths. Three CVEs have confirmed active exploitation, affecting Cisco Secure Firewall ASA/FTD, Metabase, and the Windows Ancillary Function Driver for WinSock. Vendor patch data was not resolved for this set (0% confirmed availability), so verify fixed versions directly against vendor advisories before scheduling remediation.

  • MindsDB Minds Platform (CVE-2026-73678) and SiYuan (CVE-2026-72811) both carry CVSS 10 scores, indicating unauthenticated compromise of the affected service
  • 24 critical CVEs (CVSS 9.0+), a 25% decrease from the prior day's 32
  • 52 high-priority CVEs (CVSS 7.0-8.9), a 35% decrease from the prior day's 80
  • Authentication bypass and privilege escalation dominate the WordPress plugin disclosures: User Profile Builder, User Session Synchronizer, TrueBooker, and MStore API
  • Patch availability is unconfirmed across the set (0%); confirm fixed versions in vendor advisories for Tenable Security Center, MindsDB, and NCEAS Metacat
  • Three CVEs show confirmed active exploitation: Cisco Secure Firewall ASA/FTD (CVE-2026-20349), Metabase (CVE-2026-72898), and Windows AFD for WinSock (CVE-2026-68820)

Immediate action: Prioritize the actively exploited issues first: Cisco Secure Firewall ASA/FTD, Metabase, and the Windows Ancillary Function Driver for WinSock, then move to internet-facing WordPress installations running User Profile Builder, User Session Synchronizer, TrueBooker, or MStore API. Patch status is unconfirmed for this data set, so check each vendor advisory for a fixed version and apply the vendor's mitigation or access restriction where no patch exists. Tenable Security Center (CVE-2026-19626, CVSS 9.9) and any exposed MindsDB or SiYuan instances should be reviewed in the same pass given their administrative reach.

How to read this brief

CVSS score (e.g. 9.1) — severity from 0–10. Red marks critical (9+), orange high (7–8.9).

Exploitability — how hard the flaw is to attack, read from the CVSS vector:

  • Network / Adjacent / Local / Physical — how close an attacker must get. Network means reachable over the internet.
  • No / Low / High privileges — the access they need first. No privileges means no login required.
  • No interaction / User interaction — whether a victim has to do something (open a file, click a link). No interaction means fully automatable.

The lower the bar on all three, the easier to exploit at scale — “Network · No privileges · No interaction” is the worst case: hit from anywhere, no credentials, no victim action.

Actively exploited — confirmed under attack in the wild (CISA’s Known Exploited Vulnerabilities catalog). Prioritize these regardless of score.

EPSS · Nth percentile — FIRST.org’s estimated chance a flaw is exploited within 30 days. We flag it only in the top 10% — a statistical signal it’s unusually likely to be targeted, separate from whether attacks are confirmed.

💡 Tip: Swipe CVE cards left to ⭐ star, right to ❌ remove

Section Navigation