{
 "counts": {
  "critical": 8,
  "kev": 3,
  "mover": 8,
  "news": 1
 },
 "date": "2026-08-11",
 "generated_at": "2026-08-12T00:47:26+00:00",
 "items": [
  {
   "entities": {
    "actor_ids": [],
    "cve_ids": [
     "CVE-2026-20316"
    ],
    "vendor": "cisco"
   },
   "headline": "Added to CISA KEV: Cisco Secure Firewall Management Center Use of Hard-coded Password (CVE-2026-20316)",
   "id": "43e4b7e6e03d2ab4",
   "kind": "kev",
   "severity": {
    "break_glass": true,
    "kev": true,
    "risk": 75
   },
   "todos": [
    {
     "done_hint": "Done when no unpatched instances remain (or a compensating mitigation is deployed and recorded).",
     "id": "43e4b7e6e03d2ab4-verify-patch",
     "refs": [
      "/cve/CVE-2026-20316.html",
      "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
     ],
     "text": "Verify exposure to CVE-2026-20316 (Cisco Secure Firewall Management Center (FMC)) and apply the vendor patch or mitigation \u2014 CISA confirms active exploitation."
    },
    {
     "done_hint": "Done when a detection rule or telemetry source is verified to cover this CVE's exploitation path.",
     "id": "43e4b7e6e03d2ab4-confirm-detection",
     "refs": [
      "/cve/CVE-2026-20316.html",
      "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
     ],
     "text": "Confirm detection coverage for exploitation of CVE-2026-20316 (EDR/IDS rules, relevant log sources)."
    }
   ]
  },
  {
   "entities": {
    "actor_ids": [],
    "cve_ids": [
     "CVE-2025-68686"
    ],
    "vendor": "fortinet"
   },
   "headline": "Added to CISA KEV: Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor (CVE-2025-68686)",
   "id": "a930b83734fe0468",
   "kind": "kev",
   "severity": {
    "break_glass": true,
    "kev": true,
    "risk": 75
   },
   "todos": [
    {
     "done_hint": "Done when no unpatched instances remain (or a compensating mitigation is deployed and recorded).",
     "id": "a930b83734fe0468-verify-patch",
     "refs": [
      "/cve/CVE-2025-68686.html",
      "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
     ],
     "text": "Verify exposure to CVE-2025-68686 (Fortinet FortiOS) and apply the vendor patch or mitigation \u2014 CISA confirms active exploitation."
    },
    {
     "done_hint": "Done when a detection rule or telemetry source is verified to cover this CVE's exploitation path.",
     "id": "a930b83734fe0468-confirm-detection",
     "refs": [
      "/cve/CVE-2025-68686.html",
      "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
     ],
     "text": "Confirm detection coverage for exploitation of CVE-2025-68686 (EDR/IDS rules, relevant log sources)."
    }
   ]
  },
  {
   "entities": {
    "actor_ids": [],
    "cve_ids": [
     "CVE-2026-16812"
    ],
    "vendor": "arista"
   },
   "headline": "Added to CISA KEV: Arista VeloCloud Orchestrator On-Prem OS Command Injection (CVE-2026-16812)",
   "id": "798be85c4627e5a2",
   "kind": "kev",
   "severity": {
    "break_glass": true,
    "kev": true,
    "risk": 100
   },
   "todos": [
    {
     "done_hint": "Done when no unpatched instances remain (or a compensating mitigation is deployed and recorded).",
     "id": "798be85c4627e5a2-verify-patch",
     "refs": [
      "/cve/CVE-2026-16812.html",
      "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
     ],
     "text": "Verify exposure to CVE-2026-16812 (Arista VeloCloud Orchestrator) and apply the vendor patch or mitigation \u2014 CISA confirms active exploitation."
    },
    {
     "done_hint": "Done when a detection rule or telemetry source is verified to cover this CVE's exploitation path.",
     "id": "798be85c4627e5a2-confirm-detection",
     "refs": [
      "/cve/CVE-2026-16812.html",
      "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
     ],
     "text": "Confirm detection coverage for exploitation of CVE-2026-16812 (EDR/IDS rules, relevant log sources)."
    }
   ]
  },
  {
   "entities": {
    "actor_ids": [],
    "cve_ids": [
     "CVE-2026-8037"
    ],
    "vendor": "progress"
   },
   "headline": "Exploitation predicted: CVE-2026-8037 \u2014 EPSS 0.99, up from 0.85 a week ago",
   "id": "191059b216b8090c",
   "kind": "mover",
   "severity": {
    "break_glass": true,
    "kev": true,
    "risk": 94
   },
   "todos": [
    {
     "done_hint": "Done when affected assets are identified and a patch or mitigation is scheduled.",
     "id": "191059b216b8090c-assess",
     "refs": [
      "/cve/CVE-2026-8037.html"
     ],
     "text": "Assess exposure to CVE-2026-8037 \u2014 exploitation probability is climbing (EPSS 0.99, up from 0.85 a week ago)."
    }
   ]
  },
  {
   "entities": {
    "actor_ids": [],
    "cve_ids": [
     "CVE-2025-5961"
    ],
    "vendor": "wpvivid"
   },
   "headline": "Exploitation predicted: CVE-2025-5961 \u2014 EPSS 0.51, up from 0.49 a week ago",
   "id": "6ee68d420bc29493",
   "kind": "mover",
   "severity": {
    "break_glass": false,
    "kev": false,
    "risk": 75
   },
   "todos": [
    {
     "done_hint": "Done when affected assets are identified and a patch or mitigation is scheduled.",
     "id": "6ee68d420bc29493-assess",
     "refs": [
      "/cve/CVE-2025-5961.html"
     ],
     "text": "Assess exposure to CVE-2025-5961 \u2014 exploitation probability is climbing (EPSS 0.51, up from 0.49 a week ago)."
    }
   ]
  },
  {
   "entities": {
    "actor_ids": [],
    "cve_ids": [
     "CVE-2023-39475"
    ],
    "vendor": "inductiveautomation"
   },
   "headline": "Exploitation predicted: CVE-2023-39475 \u2014 EPSS 0.64, up from 0.62 a week ago",
   "id": "422060ef16996fed",
   "kind": "mover",
   "severity": {
    "break_glass": true,
    "kev": false,
    "risk": 97
   },
   "todos": [
    {
     "done_hint": "Done when affected assets are identified and a patch or mitigation is scheduled.",
     "id": "422060ef16996fed-assess",
     "refs": [
      "/cve/CVE-2023-39475.html"
     ],
     "text": "Assess exposure to CVE-2023-39475 \u2014 exploitation probability is climbing (EPSS 0.64, up from 0.62 a week ago)."
    }
   ]
  },
  {
   "entities": {
    "actor_ids": [],
    "cve_ids": [
     "CVE-2013-3307"
    ],
    "vendor": null
   },
   "headline": "Exploitation predicted: CVE-2013-3307 \u2014 EPSS 0.53, up from 0.53 a week ago",
   "id": "dca0a1e359dd01fe",
   "kind": "mover",
   "severity": {
    "break_glass": false,
    "kev": false,
    "risk": 82
   },
   "todos": [
    {
     "done_hint": "Done when affected assets are identified and a patch or mitigation is scheduled.",
     "id": "dca0a1e359dd01fe-assess",
     "refs": [
      "/cve/CVE-2013-3307.html"
     ],
     "text": "Assess exposure to CVE-2013-3307 \u2014 exploitation probability is climbing (EPSS 0.53, up from 0.53 a week ago)."
    }
   ]
  },
  {
   "entities": {
    "actor_ids": [],
    "cve_ids": [
     "CVE-2022-34169"
    ],
    "vendor": "apache"
   },
   "headline": "Exploitation predicted: CVE-2022-34169 \u2014 EPSS 0.81, up from 0.81 a week ago",
   "id": "7d7c79cf8ee5df96",
   "kind": "mover",
   "severity": {
    "break_glass": false,
    "kev": false,
    "risk": 84
   },
   "todos": [
    {
     "done_hint": "Done when affected assets are identified and a patch or mitigation is scheduled.",
     "id": "7d7c79cf8ee5df96-assess",
     "refs": [
      "/cve/CVE-2022-34169.html"
     ],
     "text": "Assess exposure to CVE-2022-34169 \u2014 exploitation probability is climbing (EPSS 0.81, up from 0.81 a week ago)."
    }
   ]
  },
  {
   "entities": {
    "actor_ids": [],
    "cve_ids": [
     "CVE-2022-42904"
    ],
    "vendor": "zohocorp"
   },
   "headline": "Exploitation predicted: CVE-2022-42904 \u2014 EPSS 0.83, up from 0.83 a week ago",
   "id": "8cc8602ba1614cda",
   "kind": "mover",
   "severity": {
    "break_glass": false,
    "kev": false,
    "risk": 80
   },
   "todos": [
    {
     "done_hint": "Done when affected assets are identified and a patch or mitigation is scheduled.",
     "id": "8cc8602ba1614cda-assess",
     "refs": [
      "/cve/CVE-2022-42904.html"
     ],
     "text": "Assess exposure to CVE-2022-42904 \u2014 exploitation probability is climbing (EPSS 0.83, up from 0.83 a week ago)."
    }
   ]
  },
  {
   "entities": {
    "actor_ids": [],
    "cve_ids": [
     "CVE-2023-27293"
    ],
    "vendor": "opencats"
   },
   "headline": "Exploitation predicted: CVE-2023-27293 \u2014 EPSS 0.57, up from 0.57 a week ago",
   "id": "f84fb0b893be3b34",
   "kind": "mover",
   "severity": {
    "break_glass": false,
    "kev": false,
    "risk": 70
   },
   "todos": [
    {
     "done_hint": "Done when affected assets are identified and a patch or mitigation is scheduled.",
     "id": "f84fb0b893be3b34-assess",
     "refs": [
      "/cve/CVE-2023-27293.html"
     ],
     "text": "Assess exposure to CVE-2023-27293 \u2014 exploitation probability is climbing (EPSS 0.57, up from 0.57 a week ago)."
    }
   ]
  },
  {
   "entities": {
    "actor_ids": [],
    "cve_ids": [
     "CVE-2023-51448"
    ],
    "vendor": "cacti"
   },
   "headline": "Exploitation predicted: CVE-2023-51448 \u2014 EPSS 0.67, up from 0.67 a week ago",
   "id": "88497dd4f6a710dd",
   "kind": "mover",
   "severity": {
    "break_glass": true,
    "kev": false,
    "risk": 90
   },
   "todos": [
    {
     "done_hint": "Done when affected assets are identified and a patch or mitigation is scheduled.",
     "id": "88497dd4f6a710dd-assess",
     "refs": [
      "/cve/CVE-2023-51448.html"
     ],
     "text": "Assess exposure to CVE-2023-51448 \u2014 exploitation probability is climbing (EPSS 0.67, up from 0.67 a week ago)."
    }
   ]
  },
  {
   "entities": {
    "actor_ids": [],
    "cve_ids": [
     "CVE-2026-61511"
    ],
    "vendor": null
   },
   "headline": "New critical: CVE-2026-61511 (CVSS 9.8, public PoC) \u2014 vBulletin 5.x through 5.7.5 and 6.x through 6.2.1 contains an eval injection vulnerability in the\u2026",
   "id": "762065f8dab83742",
   "kind": "critical",
   "severity": {
    "break_glass": false,
    "kev": false,
    "risk": 76
   },
   "todos": [
    {
     "done_hint": "Done when asset inventory is checked and any affected systems are flagged for patching.",
     "id": "762065f8dab83742-inventory",
     "refs": [
      "/cve/CVE-2026-61511.html"
     ],
     "text": "Check inventory for software affected by CVE-2026-61511 (CVSS 9.8, public PoC) published this week."
    }
   ]
  },
  {
   "entities": {
    "actor_ids": [],
    "cve_ids": [
     "CVE-2026-67208"
    ],
    "vendor": null
   },
   "headline": "New critical: CVE-2026-67208 (CVSS 9.8, public PoC) \u2014 Juggle through 1.6.0 contains a remote code execution vulnerability that allows unauthenticated remote\u2026",
   "id": "d2742282e139f9e9",
   "kind": "critical",
   "severity": {
    "break_glass": false,
    "kev": false,
    "risk": 75
   },
   "todos": [
    {
     "done_hint": "Done when asset inventory is checked and any affected systems are flagged for patching.",
     "id": "d2742282e139f9e9-inventory",
     "refs": [
      "/cve/CVE-2026-67208.html"
     ],
     "text": "Check inventory for software affected by CVE-2026-67208 (CVSS 9.8, public PoC) published this week."
    }
   ]
  },
  {
   "entities": {
    "actor_ids": [],
    "cve_ids": [
     "CVE-2026-41939"
    ],
    "vendor": null
   },
   "headline": "New critical: CVE-2026-41939 (CVSS 9.8, public PoC) \u2014 Care Everywhere Gateway 14.3.10 contains a hard-coded credentials vulnerability in the bundled WildFly\u2026",
   "id": "e8c0cb694e3a4c79",
   "kind": "critical",
   "severity": {
    "break_glass": false,
    "kev": false,
    "risk": 74
   },
   "todos": [
    {
     "done_hint": "Done when asset inventory is checked and any affected systems are flagged for patching.",
     "id": "e8c0cb694e3a4c79-inventory",
     "refs": [
      "/cve/CVE-2026-41939.html"
     ],
     "text": "Check inventory for software affected by CVE-2026-41939 (CVSS 9.8, public PoC) published this week."
    }
   ]
  },
  {
   "entities": {
    "actor_ids": [],
    "cve_ids": [
     "CVE-2026-66012"
    ],
    "vendor": null
   },
   "headline": "New critical: CVE-2026-66012 (CVSS 10.0, public PoC) \u2014 SiYuan before v3.7.2 contains a missing authorization vulnerability in the POST /mcp kernel endpoint, which\u2026",
   "id": "8ae91644f0992e4e",
   "kind": "critical",
   "severity": {
    "break_glass": false,
    "kev": false,
    "risk": 74
   },
   "todos": [
    {
     "done_hint": "Done when asset inventory is checked and any affected systems are flagged for patching.",
     "id": "8ae91644f0992e4e-inventory",
     "refs": [
      "/cve/CVE-2026-66012.html"
     ],
     "text": "Check inventory for software affected by CVE-2026-66012 (CVSS 10.0, public PoC) published this week."
    }
   ]
  },
  {
   "entities": {
    "actor_ids": [],
    "cve_ids": [
     "CVE-2026-67191"
    ],
    "vendor": null
   },
   "headline": "New critical: CVE-2026-67191 (CVSS 9.8, public PoC) \u2014 Xlight FTP Server before 3.9.5 contains a pre-authentication heap buffer overflow vulnerability that allows\u2026",
   "id": "42add99560a6bd75",
   "kind": "critical",
   "severity": {
    "break_glass": false,
    "kev": false,
    "risk": 74
   },
   "todos": [
    {
     "done_hint": "Done when asset inventory is checked and any affected systems are flagged for patching.",
     "id": "42add99560a6bd75-inventory",
     "refs": [
      "/cve/CVE-2026-67191.html"
     ],
     "text": "Check inventory for software affected by CVE-2026-67191 (CVSS 9.8, public PoC) published this week."
    }
   ]
  },
  {
   "entities": {
    "actor_ids": [],
    "cve_ids": [
     "CVE-2026-60112"
    ],
    "vendor": null
   },
   "headline": "New critical: CVE-2026-60112 (CVSS 9.8, public PoC) \u2014 AMMOS Instrument Toolkit (AIT) GUI before 2.5.1 contains a missing authentication vulnerability that allows\u2026",
   "id": "c073b6f595b9a8ca",
   "kind": "critical",
   "severity": {
    "break_glass": false,
    "kev": false,
    "risk": 73
   },
   "todos": [
    {
     "done_hint": "Done when asset inventory is checked and any affected systems are flagged for patching.",
     "id": "c073b6f595b9a8ca-inventory",
     "refs": [
      "/cve/CVE-2026-60112.html"
     ],
     "text": "Check inventory for software affected by CVE-2026-60112 (CVSS 9.8, public PoC) published this week."
    }
   ]
  },
  {
   "entities": {
    "actor_ids": [],
    "cve_ids": [
     "CVE-2026-60113"
    ],
    "vendor": null
   },
   "headline": "New critical: CVE-2026-60113 (CVSS 9.8, public PoC) \u2014 AMMOS Instrument Toolkit (AIT) Deep Space Network (DSN) Interface before 2.2.2 contains a missing\u2026",
   "id": "b5b344cf3690dd80",
   "kind": "critical",
   "severity": {
    "break_glass": false,
    "kev": false,
    "risk": 73
   },
   "todos": [
    {
     "done_hint": "Done when asset inventory is checked and any affected systems are flagged for patching.",
     "id": "b5b344cf3690dd80-inventory",
     "refs": [
      "/cve/CVE-2026-60113.html"
     ],
     "text": "Check inventory for software affected by CVE-2026-60113 (CVSS 9.8, public PoC) published this week."
    }
   ]
  },
  {
   "entities": {
    "actor_ids": [],
    "cve_ids": [
     "CVE-2026-67594"
    ],
    "vendor": null
   },
   "headline": "New critical: CVE-2026-67594 (CVSS 9.8, public PoC) \u2014 Spikster through commit e1cdf8c contains a missing authentication vulnerability that allows unauthenticated\u2026",
   "id": "510407c089b3f7f4",
   "kind": "critical",
   "severity": {
    "break_glass": false,
    "kev": false,
    "risk": 73
   },
   "todos": [
    {
     "done_hint": "Done when asset inventory is checked and any affected systems are flagged for patching.",
     "id": "510407c089b3f7f4-inventory",
     "refs": [
      "/cve/CVE-2026-67594.html"
     ],
     "text": "Check inventory for software affected by CVE-2026-67594 (CVSS 9.8, public PoC) published this week."
    }
   ]
  },
  {
   "date": "2026-08-11",
   "entities": {
    "actor_ids": [],
    "cve_ids": [],
    "vendor": null
   },
   "headline": "Water sector example added to the NCSC\u2019s Secure connectivity principles",
   "id": "cdc4770984f7eeae",
   "kind": "news",
   "severity": {
    "break_glass": false,
    "kev": false,
    "risk": null
   },
   "source": "ncsc",
   "todos": [],
   "url": "https://www.ncsc.gov.uk/blogs/water-sector-example-added-to-the-ncscs-secure-connectivity-principles"
  }
 ],
 "summary_line": "3 new KEV entries, 8 rising, 8 fresh criticals, 1 news item."
}
