Monday, August 17, 2026 Archive

Archived Security Snapshot

Critical vulnerabilities, curated daily for security professionals

Archived Security Brief

Consumer and small-office network hardware led yesterday's disclosures, with EFM ipTIME A3004T (CVE-2026-19977, CVSS 10) and two Edimax EW-7478APC flaws (CVE-2026-19961 and CVE-2026-19959, both CVSS 9.9) exposing internet-facing router and access point management to remote compromise. The day produced 10 critical CVEs, down 64% from the prior day's 28, alongside 104 high-priority CVEs, up 32% from 79. Server-side software also featured prominently: CVE-2026-15623 (CVSS 9.4) affects Google Cloud SecOps (Chronicle SOAR), while CVE-2026-73061 and CVE-2026-74790 both hit the scriban templating library, a dependency risk for .NET applications embedding user-supplied templates. Web application platforms account for much of the remaining volume, including Joomla's Phoca Cart extension (CVE-2026-74251, CVSS 9.3), WP Directory Kit (CVE-2026-18473, CVSS 9.1), and siyuan-note (CVE-2026-73056, CVSS 9.8), with remote code execution and authentication bypass the dominant patterns. Three CVEs have confirmed active exploitation, affecting Cisco Secure Firewall ASA/FTD, Metabase, and the Windows Ancillary Function Driver for WinSock. Patch availability is recorded at 0% in the collected data, so verify fix status directly with each vendor before scheduling remediation.

  • EFM ipTIME A3004T (CVE-2026-19977, CVSS 10) and Edimax EW-7478APC (CVE-2026-19961, CVE-2026-19959, CVSS 9.9) expose network edge devices to remote compromise
  • 10 critical CVEs (CVSS 9.0+), down 64% from 28 the prior day
  • 104 high-priority CVEs (CVSS 7.0-8.9), up 32% from 79 the prior day
  • Remote code execution and authentication bypass dominate, spanning scriban (CVE-2026-73061, CVE-2026-74790), siyuan-note (CVE-2026-73056), and Google Cloud SecOps (CVE-2026-15623)
  • Patch availability recorded at 0% across the collected set, including the Joomla Phoca Cart and WP Directory Kit web extensions
  • 3 CVEs with confirmed active exploitation: Cisco Secure Firewall ASA/FTD, Metabase, and Windows Ancillary Function Driver for WinSock

Immediate action: Prioritize the actively exploited issues first: Cisco Secure Firewall ASA/FTD (CVE-2026-20349), Metabase (CVE-2026-72898), and the Windows Ancillary Function Driver for WinSock (CVE-2026-68820). Next, inventory internet-exposed EFM ipTIME and Edimax devices, restrict their management interfaces to trusted networks, and audit .NET services and Joomla or WordPress sites for the affected scriban, Phoca Cart, and WP Directory Kit components. Patch availability is not confirmed for any of today's critical items, so check vendor advisories directly and apply network-level mitigations where fixes are not yet published.

How to read this brief

CVSS score (e.g. 9.1) — severity from 0–10. Red marks critical (9+), orange high (7–8.9).

Exploitability — how hard the flaw is to attack, read from the CVSS vector:

  • Network / Adjacent / Local / Physical — how close an attacker must get. Network means reachable over the internet.
  • No / Low / High privileges — the access they need first. No privileges means no login required.
  • No interaction / User interaction — whether a victim has to do something (open a file, click a link). No interaction means fully automatable.

The lower the bar on all three, the easier to exploit at scale — “Network · No privileges · No interaction” is the worst case: hit from anywhere, no credentials, no victim action.

Actively exploited — confirmed under attack in the wild (CISA’s Known Exploited Vulnerabilities catalog). Prioritize these regardless of score.

EPSS · Nth percentile — FIRST.org’s estimated chance a flaw is exploited within 30 days. We flag it only in the top 10% — a statistical signal it’s unusually likely to be targeted, separate from whether attacks are confirmed.

💡 Tip: Swipe CVE cards left to ⭐ star, right to ❌ remove

Section Navigation