The CVE WATCHTOWER logged 2,077 new vulnerabilities between July 27 and August 2, 2026. This CVE weekly roundup breaks down the numbers, flags what is under active attack, and highlights the entries that matter most to defenders.
Week at a glance
Of the 2,077 new entries, 273 earned a Critical rating and 624 scored High. Another 771 landed at Medium, 68 at Low, and 341 remain unscored. A total of 14 CVEs hit the maximum CVSS 10.0, including four Apache Traffic Server bugs, an Azure Cosmos DB code-execution flaw (CVE-2026-66803), and an Adobe Campaign Classic authorization bypass (CVE-2026-48449).
Google’s ecosystem led the vendor count with 389 entries. WordPress plugins followed at 289, then HP at 103, Apache at 79, and IBM at 68.
Exploited vulnerabilities
CISA added three entries to its Known Exploited Vulnerabilities catalog this week. Combined with one supply-chain backdoor flagged as actively exploited, defenders face four confirmed threats. The table below lists every exploited vulnerability from this CVE weekly roundup.
| CVE ID | Product | CVSS | Severity | Key detail |
|---|---|---|---|---|
| CVE-2026-16812 | VMware VeloCloud Orchestrator | 10.0 | Critical | Remote access to privileged internal functions; confirmed in the wild (CISA KEV) |
| CVE-2026-18072 | WordPress ARVE Plugin v10.8.7 | 9.8 | Critical | Hardcoded backdoor grants unauthenticated admin access; likely supply-chain compromise |
| CVE-2025-68686 | Fortinet FortiOS | 5.9 | Medium | Bypasses the symlink persistence patch; requires prior filesystem compromise (CISA KEV) |
| CVE-2026-20316 | Cisco Secure FMC | 5.3 | Medium | Static credentials expose sensitive data; can chain with other FMC flaws (CISA KEV) |
Standout entries
VeloCloud Orchestrator — CVSS 10.0
CVE-2026-16812 tops the list. The flaw gives a remote attacker access to internal-only functions on on-premises VeloCloud Orchestrator instances. VMware confirmed active exploitation and noted that hosted and dedicated deployments already received a patch before the public notice.
WordPress ARVE plugin — supply-chain backdoor
An attacker gained commit access to the Advanced Responsive Video Embedder plugin and planted a hardcoded SHA-256 token. Anyone who knows the token can log in as an administrator with no password. Version 10.8.7 is the only affected release. Site owners should remove or downgrade the plugin immediately.
Apache Traffic Server — four CVSS 10.0 bugs
Apache published fixes for request-smuggling, input-validation, and certificate-generation flaws in Traffic Server. All four rate CVSS 10.0 and affect versions from 9.2.0 onward. Upgrading to the patched release is the only fix.
Recommended actions
Patch every CISA KEV entry on the priority list above. Review WordPress plugin versions, especially ARVE, and remove any release that matches the compromised v10.8.7. Upgrade Apache Traffic Server if you run version 9.2.x or later. Finally, check Azure Cosmos DB and Adobe Campaign Classic configurations against the new advisories.
Support Our Threat Intelligence
If you find our CVE report and cybersecurity news helpful, consider supporting our work.