Friday, August 21, 2026 Archive

Archived Security Snapshot

Critical vulnerabilities, curated daily for security professionals

Archived Security Brief

A large batch of IBM AIX and PowerVM VIOS vulnerabilities dominates yesterday's disclosures, joined by high-severity issues in Google Chrome, VMware Cloud Foundation, and SPIP. The day brought 26 critical CVEs (down 13% from 30) and 56 high-priority CVEs (down 8% from 61), for 82 total. Notable entries include CVE-2026-18835 (CVSS 9.9) in IBM AIX and PowerVM VIOS, CVE-2026-17924 (CVSS 9.6) in Google Chrome, and CVE-2026-77647 (CVSS 9.8) in SPIP. Remote code execution and privilege escalation against enterprise Unix, virtualization, and collaboration platforms are the recurring patterns, with 8 CVEs carrying confirmed active exploitation including Microsoft SharePoint, VMware vCenter, and Apple macOS. Patch availability is reported at 0% in this data set, so teams should track vendor advisories directly and apply mitigations or access restrictions while fixes are confirmed.

  • IBM AIX and PowerVM VIOS account for the majority of the day's critical entries, led by CVE-2026-18835 at CVSS 9.9
  • 26 critical CVEs (CVSS 9.0+), down 13% from 30 the prior day
  • 56 high-priority CVEs (CVSS 7.0-8.9), down 8% from 61 the prior day
  • Remote code execution and privilege escalation dominate, spanning Google Chrome (CVE-2026-17924), SPIP (CVE-2026-77647), and VMware Cloud Foundation and vCenter (CVE-2026-59310)
  • Patch availability is 0% in this data set, affecting enterprise Unix (AIX, VIOS), virtualization (VMware), and ML tooling (Ray, MLflow)
  • 8 CVEs have confirmed active exploitation, including Microsoft Windows, Microsoft SharePoint, Apple macOS, and TrueConf Server

Immediate action: Prioritize IBM AIX and PowerVM VIOS estates given the volume of CVSS 9.8+ entries, then Google Chrome, VMware Cloud Foundation and vCenter, and Microsoft SharePoint where exploitation is already confirmed. Patch data shows 0% availability for these critical issues, so check vendor advisories for interim fixes and apply network restrictions, credential rotation, or exposure reduction on internet-facing instances until updates land.

How to read this brief

CVSS score (e.g. 9.1) — severity from 0–10. Red marks critical (9+), orange high (7–8.9).

Exploitability — how hard the flaw is to attack, read from the CVSS vector:

  • Network / Adjacent / Local / Physical — how close an attacker must get. Network means reachable over the internet.
  • No / Low / High privileges — the access they need first. No privileges means no login required.
  • No interaction / User interaction — whether a victim has to do something (open a file, click a link). No interaction means fully automatable.

The lower the bar on all three, the easier to exploit at scale — “Network · No privileges · No interaction” is the worst case: hit from anywhere, no credentials, no victim action.

Actively exploited — confirmed under attack in the wild (CISA’s Known Exploited Vulnerabilities catalog). Prioritize these regardless of score.

EPSS · Nth percentile — FIRST.org’s estimated chance a flaw is exploited within 30 days. We flag it only in the top 10% — a statistical signal it’s unusually likely to be targeted, separate from whether attacks are confirmed.

💡 Tip: Swipe CVE cards left to ⭐ star, right to ❌ remove

Section Navigation