Skip to content
feed: live
>_0dayNews
$ briefings

Briefings

Periodic SITREPs that compress the week's vulnerability and exploit news into a single readable digest, sourced throughout.

20
editions
129
items covered
13
critical flags
~/briefings/2026-08-10 --latest
Latest edition·August 10, 2026

Aug 3–10: Four KEV Additions, Metabase CVSS 10

Four CISA KEV additions this week. Metabase CVSS 10 patched under active exploitation. WordPress triple chain, 10 MCP CVEs, breaches at Levi Strauss and Valve.

2c5m
KEV0-DAYOT/ICSAI/MCP
  • Metabase patched its CVSS 10.0 unauthenticated SQL injection zero-day today — active exploitation confirmed since August 8. No CVE assigned yet. Update immediately.
  • Four KEV additions this week: CVE-2026-18577 (N-able N-central, Aug 3), CVE-2026-34486 (Apache Tomcat, Aug 4), CVE-2026-9198 (Langflow, CVSS 9.8 unauth RCE), CVE-2026-8037 (Kemp LoadMaster, 792 attempts).
  • WordPress triple chain CVE-2026-18468/18469/18470 enables unauthenticated admin takeover in Login & Register Forms plugin before 4.0.2. Update now.
  • Ten MCP server CVEs hit NVD on August 9 — all SSRF or path traversal, ten distinct open-source implementations, most maintainers silent.
Read full briefing →
$ archive

Archive begins June 29, 2026.