<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"><channel><title>Cyber Resilience — Vulnerabilities News</title><link>https://security-resilience.ai/vulnerabilities/</link><description>Ranked vulnerabilities security news with our own read on each story — what it is, how confident we are, and what it means for you.</description><lastBuildDate>Sun, 23 Aug 2026 02:27:13 +0000</lastBuildDate><item><title>KEV: CVE-2026-0770 — Langflow Langflow (Langflow Inclusion of Functionality from Untrusted Control Sphere Vulnerability)</title><link>https://security-resilience.ai/news/story/sr-1cd21886308f.html</link><guid isPermaLink="true">https://security-resilience.ai/news/story/sr-1cd21886308f.html</guid><category>confirmed</category><pubDate>Sun, 23 Aug 2026 02:27:13 +0000</pubDate><description>CISA adds CVE-2026-0770 to KEV: unauthenticated remote code execution in Langflow, exploitation confirmed. Langflow instances get spun up for AI experiments and forgotten — whether you're an enterprise lab or a two-person shop, find yours, get it off the open internet, patch.</description></item><item><title>KEV: CVE-2026-72898 — Metabase Metabase (Metabase SQL Injection Vulnerability)</title><link>https://security-resilience.ai/news/story/sr-46c34dcdddec.html</link><guid isPermaLink="true">https://security-resilience.ai/news/story/sr-46c34dcdddec.html</guid><category>confirmed</category><pubDate>Sun, 23 Aug 2026 02:27:13 +0000</pubDate><description>CISA added CVE-2026-72898 to KEV: unauthenticated SQL injection in Metabase that yields admin access, credential theft, and data exfil. Patch immediately if you run Metabase yourself.</description></item><item><title>KEV: CVE-2025-68686 — Fortinet FortiOS (Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability)</title><link>https://security-resilience.ai/news/story/sr-1e730c30c2b8.html</link><guid isPermaLink="true">https://security-resilience.ai/news/story/sr-1e730c30c2b8.html</guid><category>confirmed</category><pubDate>Sun, 23 Aug 2026 02:27:13 +0000</pubDate><description>CISA added CVE-2025-68686 to KEV. It lets a remote unauthenticated attacker bypass a prior FortiOS symbolic-link patch via crafted HTTP requests, but only after filesystem-level compromise via another flaw. Patch if you run FortiOS yourself.</description></item><item><title>Patch bundle: July 2026 Security Updates — 1164 CVEs, 3 exploited</title><link>https://security-resilience.ai/news/story/sr-da751a93d0a8.html</link><guid isPermaLink="true">https://security-resilience.ai/news/story/sr-da751a93d0a8.html</guid><category>confirmed</category><pubDate>Sun, 23 Aug 2026 02:27:13 +0000</pubDate><description>Microsoft's July 2026 bundle fixes 1164 CVEs including 3 already exploited in the wild (SharePoint CVE-2026-58644, two others). Patch those three out-of-band this week; the rest on your normal cycle. Lean-IT shops without SharePoint can largely ignore it; enterprises running on-prem SharePoint must treat the KEV trio as urgent.</description></item><item><title>KEV: CVE-2026-20316 — Cisco Secure Firewall Management Center (FMC) (Cisco Secure Firewall Management Center Use of Hard-coded Password Vulnerability)</title><link>https://security-resilience.ai/news/story/sr-ce0e7ef98629.html</link><guid isPermaLink="true">https://security-resilience.ai/news/story/sr-ce0e7ef98629.html</guid><category>confirmed</category><pubDate>Sun, 23 Aug 2026 02:27:13 +0000</pubDate><description>CISA added CVE-2026-20316 to KEV: hard-coded password in Cisco Secure FMC, exploited as a zero-day. Patch if you run FMC (enterprises, MSPs); most smaller shops don't deploy it and can skip this.</description></item><item><title>KEV: CVE-2026-16812 — Arista VeloCloud Orchestrator (Arista VeloCloud Orchestrator On-Prem OS Command Injection Vulnerability)</title><link>https://security-resilience.ai/news/story/sr-78bd02e91239.html</link><guid isPermaLink="true">https://security-resilience.ai/news/story/sr-78bd02e91239.html</guid><category>confirmed</category><pubDate>Sun, 23 Aug 2026 02:27:13 +0000</pubDate><description>CISA added CVE-2026-16812 to KEV: unauthenticated OS command injection in on-prem Arista VeloCloud Orchestrator, actively exploited. Patch VCO now if you self-host it; managed/cloud SD-WAN tenants can skip this one.</description></item><item><title>Tenable security advisory (AV26-724)</title><link>https://security-resilience.ai/news/story/sr-2caf5d5031f1.html</link><guid isPermaLink="true">https://security-resilience.ai/news/story/sr-2caf5d5031f1.html</guid><category>confirmed</category><pubDate>Sun, 23 Aug 2026 02:27:13 +0000</pubDate><description>Tenable released a patch for critical vulnerabilities in Security Center 6.6.0–6.8.0. Update now if you self-host it (some enterprises); most smaller teams use the hosted Tenable.io or Vulnerability Management and can ignore this one.</description></item><item><title>Two new high severity WordPress vulnerabilities, patch immediately!</title><link>https://security-resilience.ai/news/story/sr-9ab4fec5233a.html</link><guid isPermaLink="true">https://security-resilience.ai/news/story/sr-9ab4fec5233a.html</guid><category>confirmed</category><pubDate>Sun, 23 Aug 2026 02:27:13 +0000</pubDate><description>WordPress 7.0.2 patches CVE-2026-60137 (SQL injection) and CVE-2026-63030 (REST API RCE) — both already under active exploitation per SecurityWeek and CCCS. If you run WordPress, update now; this is a huge share of lean-IT sites.</description></item><item><title>Patch bundle: Oracle Oracle Critical Security Patch Update Advisory - August 2026 — 1040 CVEs, 151 critical</title><link>https://security-resilience.ai/news/story/sr-e71eb3844fec.html</link><guid isPermaLink="true">https://security-resilience.ai/news/story/sr-e71eb3844fec.html</guid><category>corroborated</category><pubDate>Sun, 23 Aug 2026 02:27:13 +0000</pubDate><description>Oracle's August 2026 Critical Patch Update fixes 1040 CVEs, 151 Critical. No exploited-in-the-wild bugs listed, so patch on your normal cycle.</description></item><item><title>CISA orders feds to patch actively exploited TrueConf Server flaws</title><link>https://security-resilience.ai/news/story/sr-44ac4aece75f.html</link><guid isPermaLink="true">https://security-resilience.ai/news/story/sr-44ac4aece75f.html</guid><category>claimed</category><pubDate>Sun, 23 Aug 2026 02:27:13 +0000</pubDate><description>CISA added two TrueConf Server CVEs to KEV, confirming active exploitation in versions before 5.3.9, 5.4.9 and 5.5.5. Patch immediately if you run it yourself.</description></item><item><title>Critical Microsoft Entra ID vulnerability exploited in the wild (CVE-2026-69836)</title><link>https://security-resilience.ai/news/story/sr-ca4e2e5f1524.html</link><guid isPermaLink="true">https://security-resilience.ai/news/story/sr-ca4e2e5f1524.html</guid><category>claimed</category><pubDate>Sun, 23 Aug 2026 02:27:13 +0000</pubDate><description>A critical RCE (CVE-2026-69836, CVSS 10.0) in Entra ID that is already being exploited in the wild. A"Cloud vulnerability already patched by Microsoft - no action required on your part.</description></item><item><title>GitLab CVE-2026-19478 Comes Under Active Exploitation Within Days of Disclosure</title><link>https://security-resilience.ai/news/story/sr-e239a4afd659.html</link><guid isPermaLink="true">https://security-resilience.ai/news/story/sr-e239a4afd659.html</guid><category>claimed</category><pubDate>Sun, 23 Aug 2026 02:27:13 +0000</pubDate><description>watchTowr reports CVE-2026-19478 (CVSS 9.4) in GitLab under active exploitation within hours of disclosure: unauthenticated code injection letting attackers modify or delete public projects. Patch immediately if you self-host; hosted users are unaffected.</description></item><item><title>Critical Zimbra RCE flaw now actively exploited in attacks</title><link>https://security-resilience.ai/news/story/sr-0d2298a52b6c.html</link><guid isPermaLink="true">https://security-resilience.ai/news/story/sr-0d2298a52b6c.html</guid><category>claimed</category><pubDate>Sun, 23 Aug 2026 02:27:13 +0000</pubDate><description>CERT Polska reports active exploitation of a critical RCE in Zimbra Collaboration. Claimed but unconfirmed by any filing or second source; treat as unverified for now and review the advisory if you run Zimbra.</description></item><item><title>Critical RCE flaw in Windows IKE Extension now actively exploited</title><link>https://security-resilience.ai/news/story/sr-585cf6b5bac0.html</link><guid isPermaLink="true">https://security-resilience.ai/news/story/sr-585cf6b5bac0.html</guid><category>claimed</category><pubDate>Sun, 23 Aug 2026 02:27:13 +0000</pubDate><description>CISA added CVE-2025-33053 to its KEV catalog: this Windows IKE Extension RCE is confirmed exploited in the wild. Patch it now.</description></item><item><title>CISA gives feds 3 days to fix actively exploited Ray RCE bug</title><link>https://security-resilience.ai/news/story/sr-2dda05daa9d7.html</link><guid isPermaLink="true">https://security-resilience.ai/news/story/sr-2dda05daa9d7.html</guid><category>claimed</category><pubDate>Sun, 23 Aug 2026 02:27:13 +0000</pubDate><description>CISA added this browser-triggerable RCE in Ray to its KEV catalog, which means active exploitation is confirmed, not alleged. If you run Ray for ML workloads, patch now; if you don't, this one doesn't touch you.</description></item><item><title>CISA Flags Actively Exploited Ray Flaw That Can Trigger Browser-Based RCE</title><link>https://security-resilience.ai/news/story/sr-224b010a263e.html</link><guid isPermaLink="true">https://security-resilience.ai/news/story/sr-224b010a263e.html</guid><category>claimed</category><pubDate>Sun, 23 Aug 2026 02:27:13 +0000</pubDate><description>CISA added this browser-triggerable RCE in Ray to its KEV catalog, which means active exploitation is confirmed, not alleged. If you run Ray for ML workloads, patch now; if you don't, this one doesn't touch you.</description></item><item><title>Critical Progress LoadMaster flaw now actively exploited in attacks</title><link>https://security-resilience.ai/news/story/sr-0d7360668a54.html</link><guid isPermaLink="true">https://security-resilience.ai/news/story/sr-0d7360668a54.html</guid><category>claimed</category><pubDate>Sun, 23 Aug 2026 02:27:13 +0000</pubDate><description>CISA added the Progress Kemp LoadMaster command injection (CVE-2024-8190) to KEV: actively exploited. Patch LoadMaster immediately if you run it yourself; most smaller teams use a cloud or MSP version and can ignore this one.</description></item><item><title>Just 1% of AI-Discovered Vulnerabilities Exploited in the Wild, Research Shows</title><link>https://security-resilience.ai/news/story/sr-3c310fa3780b.html</link><guid isPermaLink="true">https://security-resilience.ai/news/story/sr-3c310fa3780b.html</guid><category>claimed</category><pubDate>Sun, 23 Aug 2026 02:27:13 +0000</pubDate><description>VulnCheck's research finds only 1% of AI-discovered vulnerabilities see wild exploitation so far. That suggests AI currently helps defenders more than attackers.</description></item><item><title>CISA orders urgent action on actively exploited Langflow RCE flaw</title><link>https://security-resilience.ai/news/story/sr-8d450f1146e4.html</link><guid isPermaLink="true">https://security-resilience.ai/news/story/sr-8d450f1146e4.html</guid><category>claimed</category><pubDate>Sun, 23 Aug 2026 02:27:13 +0000</pubDate><description>CISA orders urgent action on actively exploited Langflow RCE flaw</description></item><item><title>CISA Urges Immediate Patching of Exploited SharePoint Vulnerabilities</title><link>https://security-resilience.ai/news/story/sr-979f1255058a.html</link><guid isPermaLink="true">https://security-resilience.ai/news/story/sr-979f1255058a.html</guid><category>corroborated</category><pubDate>Sun, 23 Aug 2026 02:27:13 +0000</pubDate><description>CISA is urging immediate patches for three SharePoint vulnerabilities under active exploitation, two of them used as zero-days. If you run SharePoint and it is reachable, treat this as urgent and apply the fixes now.</description></item><item><title>ServiceNow security advisory (AV26-693)</title><link>https://security-resilience.ai/news/story/sr-0db439100e8a.html</link><guid isPermaLink="true">https://security-resilience.ai/news/story/sr-0db439100e8a.html</guid><category>confirmed</category><pubDate>Sun, 23 Aug 2026 02:27:13 +0000</pubDate><description>ServiceNow AV26-693 fixes critical RCE (CVE-2026-6875) in Brazil, Australia, Zurich, and Yokohama releases. Defused reports active exploitation; update affected versions now.</description></item><item><title>Patch bundle: August 2026 Early Security Updates — 19 CVEs, 0 exploited</title><link>https://security-resilience.ai/news/story/sr-ec4c5e36b3f4.html</link><guid isPermaLink="true">https://security-resilience.ai/news/story/sr-ec4c5e36b3f4.html</guid><category>claimed</category><pubDate>Sun, 23 Aug 2026 02:27:13 +0000</pubDate><description>Microsoft's August 2026 Early Security Updates fix 19 CVEs, 12 Critical, none exploited in the wild. Patch on your normal cycle; nothing here requires out-of-band work this week.</description></item><item><title>8-K Item 1.05: Hewlett Packard Enterprise Co reports material cybersecurity incident</title><link>https://security-resilience.ai/news/story/sr-7ddda56e7619.html</link><guid isPermaLink="true">https://security-resilience.ai/news/story/sr-7ddda56e7619.html</guid><category>confirmed</category><pubDate>Sun, 23 Aug 2026 02:27:12 +0000</pubDate><description>HPE filed an 8-K Item 1.05 disclosing a material cybersecurity incident. A giant can absorb this. If one breach could sink your company, rehearse it now: tested backups and an offline IR plan. Customers should watch for HPE notices.</description></item></channel></rss>