Cyber brief — 11 August 2026
3 new KEV entries, 8 rising, 8 fresh criticals, 1 news item.
The day's signal, decomposed into to-dos you can check off and export. Add your vendors to focus it — filters stay in your browser; actively-exploited items always show. Machine-readable: brief.json · RSS.
Last updated: 12 August 2026 00:47 UTC
Newly exploited — added to CISA KEV3 items
- 75Added to CISA KEV: Cisco Secure Firewall Management Center Use of Hard-coded Password (CVE-2026-20316)CISA KEVciscoshown despite your filter: actively exploited
- 75Added to CISA KEV: Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor (CVE-2025-68686)CISA KEVfortinetshown despite your filter: actively exploited
- 100Added to CISA KEV: Arista VeloCloud Orchestrator On-Prem OS Command Injection (CVE-2026-16812)CISA KEVaristashown despite your filter: actively exploited
Exploitation predicted — biggest EPSS movers8 items
- 94Exploitation predicted: CVE-2026-8037 — EPSS 0.99, up from 0.85 a week agoCISA KEVprogressshown despite your filter: actively exploited
- 75Exploitation predicted: CVE-2025-5961 — EPSS 0.51, up from 0.49 a week agowpvividshown despite your filter: actively exploited
- 97Exploitation predicted: CVE-2023-39475 — EPSS 0.64, up from 0.62 a week agoinductiveautomationshown despite your filter: actively exploited
- 82Exploitation predicted: CVE-2013-3307 — EPSS 0.53, up from 0.53 a week agoshown despite your filter: actively exploited
- 84Exploitation predicted: CVE-2022-34169 — EPSS 0.81, up from 0.81 a week agoapacheshown despite your filter: actively exploited
- 80Exploitation predicted: CVE-2022-42904 — EPSS 0.83, up from 0.83 a week agozohocorpshown despite your filter: actively exploited
- 70Exploitation predicted: CVE-2023-27293 — EPSS 0.57, up from 0.57 a week agoopencatsshown despite your filter: actively exploited
- 90Exploitation predicted: CVE-2023-51448 — EPSS 0.67, up from 0.67 a week agocactishown despite your filter: actively exploited
New & severe — fresh criticals8 items
- 76New critical: CVE-2026-61511 (CVSS 9.8, public PoC) — vBulletin 5.x through 5.7.5 and 6.x through 6.2.1 contains an eval injection vulnerability in the…shown despite your filter: actively exploited
- 75New critical: CVE-2026-67208 (CVSS 9.8, public PoC) — Juggle through 1.6.0 contains a remote code execution vulnerability that allows unauthenticated remote…shown despite your filter: actively exploited
- 74New critical: CVE-2026-41939 (CVSS 9.8, public PoC) — Care Everywhere Gateway 14.3.10 contains a hard-coded credentials vulnerability in the bundled WildFly…shown despite your filter: actively exploited
- 74New critical: CVE-2026-66012 (CVSS 10.0, public PoC) — SiYuan before v3.7.2 contains a missing authorization vulnerability in the POST /mcp kernel endpoint, which…shown despite your filter: actively exploited
- 74New critical: CVE-2026-67191 (CVSS 9.8, public PoC) — Xlight FTP Server before 3.9.5 contains a pre-authentication heap buffer overflow vulnerability that allows…shown despite your filter: actively exploited
- 73New critical: CVE-2026-60112 (CVSS 9.8, public PoC) — AMMOS Instrument Toolkit (AIT) GUI before 2.5.1 contains a missing authentication vulnerability that allows…shown despite your filter: actively exploited
- 73New critical: CVE-2026-60113 (CVSS 9.8, public PoC) — AMMOS Instrument Toolkit (AIT) Deep Space Network (DSN) Interface before 2.2.2 contains a missing…shown despite your filter: actively exploited
- 73New critical: CVE-2026-67594 (CVSS 9.8, public PoC) — Spikster through commit e1cdf8c contains a missing authentication vulnerability that allows unauthenticated…shown despite your filter: actively exploited
In the news1 item
- NCSCWater sector example added to the NCSC’s Secure connectivity principlesshown despite your filter: actively exploited