Saturday, August 29, 2026 Archive

Archived Security Snapshot

Critical vulnerabilities, curated daily for security professionals

Archived Security Brief

Enterprise content and print management platforms drove the day's most severe disclosures, with CVE-2026-55634 in Pimcore (CVSS 9.9) and CVE-2026-82078 in PaperCut MF/NG (CVSS 9.4) exposing widely deployed business systems to remote compromise. Yesterday's disclosures produced 42 critical CVEs, up 56% from the prior day's 27, alongside 66 high-priority issues, down 14% from 77. Mission-critical and telecom infrastructure also featured prominently: CVE-2026-55565 and CVE-2026-55559 affect the Yamcs mission control platform (CVSS 9.9 and 9.8), CVE-2026-55068 affects the free5gc 5G core (CVSS 9.3), and CVE-2026-66906 affects Apache Camel (CVSS 9.1). Linux kernel flaws CVE-2026-80630 and CVE-2026-80612 (both CVSS 9.8) extend the exposure to Linux fleets broadly, while 11 CVEs including Oracle WebLogic Server Proxy Plug-in, Gitea, and NetScaler ADC and Gateway carry confirmed active exploitation. Vendor patch data was unavailable for these entries at publication, so teams should verify fixed versions directly with vendor advisories and prioritize internet-facing systems first.

  • Pimcore CVE-2026-55634 (CVSS 9.9) and PaperCut MF/NG CVE-2026-82078 (CVSS 9.4) expose widely deployed enterprise content and print management systems
  • 42 critical CVEs (CVSS 9.0+) disclosed, a 56% increase over the prior day's 27
  • 66 high-priority CVEs (CVSS 7.0-8.9), a 14% decrease from the prior day's 77
  • Remote code execution and authentication bypass patterns dominate, affecting Yamcs mission control (CVE-2026-55565, CVE-2026-55559), free5gc 5G core (CVE-2026-55068), and Apache Camel (CVE-2026-66906)
  • Patch availability recorded at 0% in the collected data, including for the two Linux kernel criticals CVE-2026-80630 and CVE-2026-80612 (both CVSS 9.8)
  • 11 CVEs have confirmed active exploitation, spanning Oracle WebLogic Server Proxy Plug-in, Gitea, NetScaler ADC and Gateway, and JFrog Artifactory

Immediate action: Prioritize internet-facing Oracle WebLogic, NetScaler ADC and Gateway, Gitea, and JFrog Artifactory instances given confirmed exploitation, then address Pimcore, PaperCut MF/NG, Apache Camel, and Linux kernel systems carrying CVSS 9.0+ issues. Patch availability is recorded at 0% in the collected data, so confirm fixed versions and interim mitigations directly against vendor advisories rather than assuming no fix exists. Where no patch is confirmed, restrict network exposure of the affected services and increase monitoring on the actively exploited products.

How to read this brief

CVSS score (e.g. 9.1) — severity from 0–10. Red marks critical (9+), orange high (7–8.9).

Exploitability — how hard the flaw is to attack, read from the CVSS vector:

  • Network / Adjacent / Local / Physical — how close an attacker must get. Network means reachable over the internet.
  • No / Low / High privileges — the access they need first. No privileges means no login required.
  • No interaction / User interaction — whether a victim has to do something (open a file, click a link). No interaction means fully automatable.

The lower the bar on all three, the easier to exploit at scale — “Network · No privileges · No interaction” is the worst case: hit from anywhere, no credentials, no victim action.

Actively exploited — confirmed under attack in the wild (CISA’s Known Exploited Vulnerabilities catalog). Prioritize these regardless of score.

EPSS · Nth percentile — FIRST.org’s estimated chance a flaw is exploited within 30 days. We flag it only in the top 10% — a statistical signal it’s unusually likely to be targeted, separate from whether attacks are confirmed.

💡 Tip: Swipe CVE cards left to ⭐ star, right to ❌ remove

Section Navigation