Wednesday, August 26, 2026 Archive

Archived Security Snapshot

Critical vulnerabilities, curated daily for security professionals

Archived Security Brief

Enterprise application platforms dominated yesterday's disclosures, with Adobe Campaign Classic, Apache Hive, and Oracle WebLogic all carrying remotely exploitable flaws that reach core business systems. The day recorded 35 critical CVEs (CVSS 9.0+) and 65 high-priority CVEs, down 35% and 32% respectively from the prior day. Adobe Campaign Classic drew two CVSS 10.0 issues (CVE-2026-76193 and CVE-2026-76195), while CVE-2026-77998 (CVSS 10.0) affects miniOrange SAML SSO for Joomla and CVE-2026-49845 (CVSS 9.8) affects Apache Hive. Remote code execution and authentication bypass dominate the pattern, with additional exposure across web publishing stacks (Avada Fusion Builder, ClipBucket) and developer tooling (Chainlit, nokogiri); six CVEs, including flaws in Zimbra Collaboration, Oracle WebLogic Server Proxy Plug-in, Gitea, and MLflow, have confirmed active exploitation. Patch availability data was not confirmed for any of the 100 CVEs at publication, so teams should verify vendor advisories directly rather than assume fixes are staged.

  • Adobe Campaign Classic carries two CVSS 10.0 vulnerabilities (CVE-2026-76193, CVE-2026-76195), the highest-severity items of the day
  • 35 critical CVEs (CVSS 9.0+), down 35% from 54 the prior day
  • 65 high-priority CVEs (CVSS 7.0-8.9), down 32% from 96 the prior day
  • Remote code execution and authentication bypass lead the attack patterns, affecting Apache Hive, Oracle WebLogic, miniOrange SAML SSO for Joomla, and Chainlit
  • Patch availability confirmed for 0% of the 100 CVEs at publication; verify advisories for Adobe, Apache, Oracle, and Google Chrome directly
  • Six CVEs show confirmed active exploitation, including Zimbra Collaboration, Gitea, MLflow, and TrueConf Server

Immediate action: Prioritize internet-facing Adobe Campaign Classic, Oracle WebLogic (including the Proxy Plug-in), Apache Hive, and Zimbra Collaboration deployments, followed by Joomla sites running miniOrange SAML SSO and WordPress installs using Avada Fusion Builder. Google Chrome should be updated to the current stable channel to address CVE-2026-78909 and CVE-2026-18015. No patch status was confirmed for these CVEs at publication, so check each vendor advisory for fixed versions and apply interim mitigations or access restrictions where updates are not yet available.

How to read this brief

CVSS score (e.g. 9.1) — severity from 0–10. Red marks critical (9+), orange high (7–8.9).

Exploitability — how hard the flaw is to attack, read from the CVSS vector:

  • Network / Adjacent / Local / Physical — how close an attacker must get. Network means reachable over the internet.
  • No / Low / High privileges — the access they need first. No privileges means no login required.
  • No interaction / User interaction — whether a victim has to do something (open a file, click a link). No interaction means fully automatable.

The lower the bar on all three, the easier to exploit at scale — “Network · No privileges · No interaction” is the worst case: hit from anywhere, no credentials, no victim action.

Actively exploited — confirmed under attack in the wild (CISA’s Known Exploited Vulnerabilities catalog). Prioritize these regardless of score.

EPSS · Nth percentile — FIRST.org’s estimated chance a flaw is exploited within 30 days. We flag it only in the top 10% — a statistical signal it’s unusually likely to be targeted, separate from whether attacks are confirmed.

💡 Tip: Swipe CVE cards left to ⭐ star, right to ❌ remove

Section Navigation