Friday, August 28, 2026 Archive

Archived Security Snapshot

Critical vulnerabilities, curated daily for security professionals

Archived Security Brief

Yesterday's disclosures center on two clusters: unauthenticated remote code execution in enterprise platforms (ServiceNow AI Platform, Redis, Bytedance UI-TARS-desktop) and a large batch of WordPress plugin vulnerabilities affecting Tutor LMS, Hash Form, Geo Controller, ACPT and the WPMU DEV Dashboard. Volume dropped sharply from the prior day: 27 critical CVEs (down 76% from 114) and 77 high-priority CVEs (down 46% from 143), for 104 total. CVE-2026-74820 (CVSS 10, ServiceNow AI Platform) and CVE-2026-81735 (CVSS 10, Bytedance UI-TARS-desktop) sit at the top of the list, alongside CVE-2026-81934 (CVSS 9.8) in Redis and CVE-2026-74232 (CVSS 9.8) spanning more than a dozen Zbtlink router models. The pattern is heavily weighted toward pre-authentication code execution and access-control failures in internet-facing components, which puts hosting providers, SaaS operators and small-business web estates in the primary blast radius. Patch data is unavailable for the current set (0% confirmed), so treat vendor advisories as the authoritative source and prioritize exposure reduction where fixes are not yet published; 11 CVEs carry confirmed active exploitation, including Oracle WebLogic Server Proxy Plug-in, Gitea, NetScaler ADC and Gateway, and JFrog Artifactory.

  • ServiceNow AI Platform (CVE-2026-74820) and Bytedance UI-TARS-desktop (CVE-2026-81735) both score CVSS 10, the day's highest-impact disclosures
  • 27 critical CVEs (CVSS 9.0+), down 76% from 114 the prior day
  • 77 high-priority CVEs (CVSS 7.0-8.9), down 46% from 143 the prior day
  • Unauthenticated RCE and access-control bypass dominate, spanning Redis (CVE-2026-81934), WordPress plugins (Tutor LMS, Hash Form, Geo Controller, ACPT, WPMU DEV Dashboard) and 15 Zbtlink router models (CVE-2026-74232)
  • Patch availability confirmed for 0% of this set; check vendor advisories directly for Redis, ServiceNow and the affected WordPress plugins before assuming a fix exists
  • 11 CVEs have confirmed active exploitation, including Oracle WebLogic Server Proxy Plug-in (CVE-2026-21962), Gitea (CVE-2026-60004), NetScaler ADC and Gateway (CVE-2026-8452) and JFrog Artifactory (CVE-2026-66384)

Immediate action: Prioritize internet-facing enterprise systems first: NetScaler ADC and Gateway, Oracle WebLogic, Gitea, JFrog Artifactory and ServiceNow AI Platform, followed by Redis instances reachable from untrusted networks and WordPress estates running Tutor LMS, Hash Form, Geo Controller, ACPT or the WPMU DEV Dashboard. No patch availability is confirmed for this set, so verify fix status against each vendor advisory rather than assuming updates exist. Where no fix is published, restrict network exposure, tighten authentication and monitor for exploitation of the actively targeted CVEs.

How to read this brief

CVSS score (e.g. 9.1) — severity from 0–10. Red marks critical (9+), orange high (7–8.9).

Exploitability — how hard the flaw is to attack, read from the CVSS vector:

  • Network / Adjacent / Local / Physical — how close an attacker must get. Network means reachable over the internet.
  • No / Low / High privileges — the access they need first. No privileges means no login required.
  • No interaction / User interaction — whether a victim has to do something (open a file, click a link). No interaction means fully automatable.

The lower the bar on all three, the easier to exploit at scale — “Network · No privileges · No interaction” is the worst case: hit from anywhere, no credentials, no victim action.

Actively exploited — confirmed under attack in the wild (CISA’s Known Exploited Vulnerabilities catalog). Prioritize these regardless of score.

EPSS · Nth percentile — FIRST.org’s estimated chance a flaw is exploited within 30 days. We flag it only in the top 10% — a statistical signal it’s unusually likely to be targeted, separate from whether attacks are confirmed.

💡 Tip: Swipe CVE cards left to ⭐ star, right to ❌ remove

Section Navigation