Security Leader Briefing
Week ending 12 August 2026 — what changed, whether it affects you, and what to tell the board. Composed from live exploit-risk signal, the AI Hype Index, and our control mappings.
Last updated: 12 August 2026 00:47 UTC
Board talking points
The headline read, in plain language.
- 5 newly confirmed-exploited vulnerabilities entered CISA’s KEV catalog this week.
- Highest-exposure vendors this week: Cisco, Microsoft, Metabase, Progress.
- The AI Hype Index is 83/100 (down 2 pts) — overall CVE disclosure is on pace for a record year (~94,840 projected vs 49,972 in 2025). Volume is climbing to new highs, but still runs well below the most aggressive LLM-discovery forecasts: the AI-driven surge is real and accelerating, not yet the predicted flood.
- Control leverage concentrates in Information Input Validation (SI-10) — the mitigation most often cited against this week’s exploited CVEs.
This week’s material changes — exploited in the wild
New CISA KEV additions (last 7 days). Each carries the confirmed-exploitation rationale, affected technology, CISA’s required action, and a link to the evidence.
Likely to be exploited next
CVEs whose exploit probability (EPSS) is rising fast, plus fresh criticals with an exploit indicator. Not yet on KEV — watch or pre-emptively patch.
- 100 CVE-2026-34908 EPSS 85.2% · rising
- 99 CVE-2026-48939 EPSS 82.5% · rising
- 99 CVE-2025-11953 EPSS 94.0% · rising
- 89 CVE-2008-5764 EPSS 45.4% · rising
- 79 CVE-2008-5789 EPSS 45.0% · rising
- 70 CVE-2025-6197 EPSS 66.8% · rising
- 66 CVE-2026-12605 CVSS 9.6 · PoC In Eclipse GlassFish versions 8.0.x before 8.0.4, CSRF + SSRF in DownloadServlet…
AI risk signal
A record year for CVE volume — but is it the predicted AI-driven flood? AI Hype Index →
Two things are true at once. CVE disclosure is on pace for a record year — roughly 94,840 projected for 2026 versus 49,972 in all of 2025 — so overall vulnerability volume is climbing to new highs. Yet that surge still runs well below the most aggressive LLM-discovery forecasts, which is why the Hype Index reads high. The AI-driven acceleration is real; the predicted explosion has not (yet) landed. Sustain the patch program — no emergency AI-exposure action is indicated this week.
Control implications
The NIST 800-53 controls most often cited as mitigating this week’s exploited CVEs — where to focus verification effort.
- SI-10 Information Input Validation cited for 6 of this week’s CVEs
- SA-11 Developer Testing and Evaluation cited for 4 of this week’s CVEs
- SA-8 Security and Privacy Engineering Principles cited for 4 of this week’s CVEs
- AC-4 Information Flow Enforcement cited for 3 of this week’s CVEs
- AC-6 Least Privilege cited for 2 of this week’s CVEs
Recommended decisions
Concrete, imperative next steps.
- Patch or mitigate the 5 newly-KEV CVEs on your standard exploited-in-the-wild priority track.
- Verify SI-10, SA-11 are enforced on Cisco, Microsoft, Metabase systems.
- Brief leadership that CVE volume is on track for a record year but still short of the aggressive LLM-discovery forecasts — sustain the patch program; no emergency AI-exposure action this week.