CVE WATCHTOWER logged 2,488 new vulnerabilities between August 24 and August 30, 2026. This weekly CVE report breaks down that flood of disclosures. It also flags the 11 flaws that CISA confirmed as actively exploited. The numbers show a busy week for defenders across enterprise, cloud, and open-source software.
The Week in Numbers
The volume of new disclosures stayed high. Of the 2,488 fresh CVEs, 286 rated Critical and 795 rated High. Another 720 landed at Medium severity, while the rest were low, unscored, or pending analysis.
This weekly CVE report counted 18 flaws with the maximum CVSS score of 10.0. Many affected cloud-native and AI tooling, a pattern worth watching. Web application flaws also surged, driven by a large wave of WordPress plugin bugs.
Exploited Vulnerabilities Added to CISA KEV
CISA added 11 vulnerabilities to its Known Exploited Vulnerabilities catalog this week. Attackers are using each one in real attacks. Notably, the list mixes brand-new flaws with bugs that are a decade old, which shows that unpatched legacy systems remain a soft target. Federal agencies must patch these by their due dates, and every organization should do the same.
| CVE ID | Affected Product | CVSS | Type |
|---|---|---|---|
| CVE-2026-21962 | Oracle WebLogic Server Proxy Plug-in | 10.0 | Critical flaw |
| CVE-2026-60004 | Gitea (before 1.27.1) | 9.8 | Remote code execution |
| CVE-2023-49105 | ownCloud core | 9.8 | Auth bypass / file access |
| CVE-2019-1068 | Microsoft SQL Server | 8.8 | Remote code execution |
| CVE-2021-23758 | AjaxPro (ajaxpro.2 package) | 8.1 | Deserialization |
| CVE-2015-5287 | ABRT (abrt-hook-ccpp) | 7.8 | Privilege escalation |
| CVE-2022-0995 | Linux kernel watch_queue | 7.8 | Out-of-bounds write |
| CVE-2026-53362 | Linux kernel IPv6 | 7.8 | Memory flaw |
| CVE-2026-66384 | Docker cache path | 5.3 | Improper write |
| CVE-2015-3246 | libuser / userhelper | 5.1 | Privilege escalation |
| CVE-2026-8452 | NetScaler ADC and Gateway | N/A | Memory overflow / DoS |
The Oracle WebLogic proxy flaw, CVE-2026-21962, is the standout. It carries a perfect 10.0 score and sits in widely deployed middleware. The Gitea remote code execution bug is another priority for teams running self-hosted repositories.
Notable New Critical Flaws
Beyond the exploited set, several new Critical bugs deserve attention. ServiceNow patched three 10.0-rated issues, including a SQL injection and a code injection flaw. Cloud and AI projects also featured heavily, with maximum-severity bugs in Kubeflow Pipelines, KubePi, and several MCP server packages that exposed network interfaces by default.
Apache Tomcat drew scrutiny too. An authentication bypass in its DIGEST authenticator and an incomplete earlier fix both scored 9.8. WordPress site owners face the largest cleanup. Dozens of plugins and themes, from Tutor LMS to the Avada theme, shipped Critical authentication bypass, privilege escalation, and file write flaws.
What Defenders Should Do
Start with the exploited list. Prioritize the CISA KEV entries above, since attackers are already using them. Next, review your exposure to the 10.0-rated cloud and AI tooling flaws. Finally, audit WordPress installs and update every affected plugin. Regular attention to each weekly CVE report keeps patch backlogs from turning into breaches.
Never Miss a Critical CVE Again
Tracking 2,488 new CVEs by hand is not realistic. Our CVE email alert service does the watching for you. Pick the vendors you care about, and get an email the moment one of their flaws enters the CISA KEV catalog or crosses a high EPSS exploit-probability threshold. No noise, just the alerts that matter to your stack.
Start free with up to three vendors, or go Pro for unlimited vendors and coverage of every new CVE. Teams can add Slack and Microsoft Teams webhook delivery. Choose your plan below and get your first alert today.
- Unlimited vendors
- All new CVE alerts
- Custom EPSS threshold
- No ads on site
- Everything in Pro
- Slack / Teams webhook
- Team name in alerts
- CSV / JSON export
Support Our Threat Intelligence
Find our zero-day alerts and CVE reports helpful? Support our work today and unlock a 100% ad-free reading experience!