Sunday, August 16, 2026 Archive

Archived Security Snapshot

Critical vulnerabilities, curated daily for security professionals

Archived Security Brief

WordPress ecosystem plugins account for the bulk of yesterday's critical disclosures, with unauthenticated file upload and access control flaws reported in Pods, ProSolution WP Client, ARForms, Link Library, and RapiSafe. The day brought 28 critical CVEs (CVSS 9.0+), up 17% from the prior day's 24, and 79 high-priority CVEs, up 52% from 52. Notable entries include CVE-2026-19598 (CVSS 9.8) in sc0ttkclark Pods, CVE-2026-16098 (CVSS 9.8) in ProSolution WP Client, and CVE-2026-64695 (CVSS 9.8) in Apple macOS, alongside three critical issues in the SiYuan note-taking application (CVE-2026-73043, CVE-2026-73046, CVE-2026-73052). Remote code execution and authentication or authorization bypass are the recurring patterns, concentrated in web-facing content management and collaboration software. Patch data is not yet recorded for any of the 107 CVEs in this set, so teams should track vendor advisories directly; three CVEs affecting Cisco ASA/FTD, Metabase, and the Windows Ancillary Function Driver for WinSock have confirmed exploitation.

  • WordPress plugin ecosystem carries the highest volume of critical issues, including Pods (CVE-2026-19598, CVSS 9.8), ProSolution WP Client (CVE-2026-16098, CVSS 9.8), and ARForms (CVE-2024-13784, CVSS 9.8)
  • 28 critical CVEs (CVSS 9.0+), a 17% increase over the prior day's 24
  • 79 high-priority CVEs (CVSS 7.0-8.9), a 52% increase over the prior day's 52
  • Remote code execution and authentication bypass dominate, affecting content management plugins, the SiYuan knowledge base application, and Apple macOS (CVE-2026-64695, CVSS 9.8)
  • Patch availability is recorded at 0% across all 107 CVEs, so remediation depends on checking vendor advisories for Apple, Cisco, Microsoft, and individual plugin authors
  • Three CVEs have confirmed active exploitation: Cisco Secure Firewall ASA/FTD (CVE-2026-20349), Metabase (CVE-2026-72898), and Windows Ancillary Function Driver for WinSock (CVE-2026-68820), all CVSS 9.5

Immediate action: Prioritize the actively exploited issues in Cisco Secure Firewall ASA/FTD, Metabase, and the Windows Ancillary Function Driver for WinSock, then audit WordPress installations for Pods, ProSolution WP Client, ARForms, Link Library, and RapiSafe and update or disable affected plugins. Apple macOS systems should be checked against the latest security update for CVE-2026-64695. Patch status is unconfirmed for this set, so verify fix availability against each vendor's advisory before scheduling remediation windows.

How to read this brief

CVSS score (e.g. 9.1) — severity from 0–10. Red marks critical (9+), orange high (7–8.9).

Exploitability — how hard the flaw is to attack, read from the CVSS vector:

  • Network / Adjacent / Local / Physical — how close an attacker must get. Network means reachable over the internet.
  • No / Low / High privileges — the access they need first. No privileges means no login required.
  • No interaction / User interaction — whether a victim has to do something (open a file, click a link). No interaction means fully automatable.

The lower the bar on all three, the easier to exploit at scale — “Network · No privileges · No interaction” is the worst case: hit from anywhere, no credentials, no victim action.

Actively exploited — confirmed under attack in the wild (CISA’s Known Exploited Vulnerabilities catalog). Prioritize these regardless of score.

EPSS · Nth percentile — FIRST.org’s estimated chance a flaw is exploited within 30 days. We flag it only in the top 10% — a statistical signal it’s unusually likely to be targeted, separate from whether attacks are confirmed.

💡 Tip: Swipe CVE cards left to ⭐ star, right to ❌ remove

Section Navigation