Cyber Resilience

Security Leader Briefing

Week ending 12 August 2026 — what changed, whether it affects you, and what to tell the board. Composed from live exploit-risk signal, the AI Hype Index, and our control mappings.

Last updated: 12 August 2026 00:47 UTC

Board talking points

The headline read, in plain language.

  • 5 newly confirmed-exploited vulnerabilities entered CISA’s KEV catalog this week.
  • Highest-exposure vendors this week: Cisco, Microsoft, Metabase, Progress.
  • The AI Hype Index is 83/100 (down 2 pts) — overall CVE disclosure is on pace for a record year (~94,840 projected vs 49,972 in 2025). Volume is climbing to new highs, but still runs well below the most aggressive LLM-discovery forecasts: the AI-driven surge is real and accelerating, not yet the predicted flood.
  • Control leverage concentrates in Information Input Validation (SI-10) — the mitigation most often cited against this week’s exploited CVEs.

This week’s material changes — exploited in the wild

New CISA KEV additions (last 7 days). Each carries the confirmed-exploitation rationale, affected technology, CISA’s required action, and a link to the evidence.

CVE-2026-20349 · Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) Heap Inspection
So whatConfirmed exploited in the wild; CISA added it to KEV on 2026-08-11.
Affected technologyCisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD)
Recommended actionApply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see… by 2026-08-14
EvidenceCVE-2026-20349 · CISA KEV
CVE-2026-68820 · Microsoft Windows Ancillary Function Driver for WinSock Use-After-Free
So whatConfirmed exploited in the wild; CISA added it to KEV on 2026-08-11.
Affected technologyMicrosoft Windows Ancillary Function Driver for WinSock
Recommended actionApply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see… by 2026-08-25
EvidenceCVE-2026-68820 · CISA KEV
CVE-2026-72898 · Metabase SQL Injection
So whatConfirmed exploited in the wild; CISA added it to KEV on 2026-08-11.
Affected technologyMetabase Metabase
Recommended actionApply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see… by 2026-08-14
EvidenceCVE-2026-72898 · CISA KEV
CVE-2026-8037 · Progress LoadMaster Command Injection
So whatConfirmed exploited in the wild; CISA added it to KEV on 2026-08-07.
Affected technologyProgress LoadMaster
Recommended actionApply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see… by 2026-08-10
EvidenceCVE-2026-8037 · CISA KEV
CVE-2026-63077 · JetBrains TeamCity Deserialization of Untrusted Data
So whatConfirmed exploited in the wild; CISA added it to KEV on 2026-08-05.
Affected technologyJetBrains TeamCity
Recommended actionApply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see… by 2026-08-08
EvidenceCVE-2026-63077 · CISA KEV

Likely to be exploited next

CVEs whose exploit probability (EPSS) is rising fast, plus fresh criticals with an exploit indicator. Not yet on KEV — watch or pre-emptively patch.

EPSS movers
Fresh criticals

AI risk signal

A record year for CVE volume — but is it the predicted AI-driven flood? AI Hype Index →

83 / 100 · down 2 pts · 0 = predictions on track, 100 = pre-LLM baseline

Two things are true at once. CVE disclosure is on pace for a record year — roughly 94,840 projected for 2026 versus 49,972 in all of 2025 — so overall vulnerability volume is climbing to new highs. Yet that surge still runs well below the most aggressive LLM-discovery forecasts, which is why the Hype Index reads high. The AI-driven acceleration is real; the predicted explosion has not (yet) landed. Sustain the patch program — no emergency AI-exposure action is indicated this week.

Control implications

The NIST 800-53 controls most often cited as mitigating this week’s exploited CVEs — where to focus verification effort.

Recommended decisions

Concrete, imperative next steps.

  • Patch or mitigate the 5 newly-KEV CVEs on your standard exploited-in-the-wild priority track.
  • Verify SI-10, SA-11 are enforced on Cisco, Microsoft, Metabase systems.
  • Brief leadership that CVE volume is on track for a record year but still short of the aggressive LLM-discovery forecasts — sustain the patch program; no emergency AI-exposure action this week.