Welcome to the latest CVE WATCHTOWER briefing. Our team compiled this weekly threat intelligence report to highlight active cyber risks. Between August 10 and August 16, 2026, security researchers logged a staggering 3,976 new vulnerabilities. Consequently, security teams must deploy active vulnerability updates immediately to defend enterprise perimeters. Attackers continue to weaponize critical administrative flaws across multiple platforms. Therefore, defenders must prioritize patching internet-facing systems without delay.
Actively Exploited Threats in CISA KEV
The Cybersecurity and Infrastructure Security Agency (CISA) added three urgent vulnerabilities to its catalog. In addition, threat actors are weaponizing critical infrastructure software worldwide.
The most dangerous flaw involves a critical SQL injection in Metabase (CVE-2026-72898). Specifically, unauthenticated attackers can exploit the password reset endpoint to seize complete administrator control. Furthermore, Cisco Secure Firewall appliances suffer from an SSL VPN denial-of-service weakness (CVE-2026-20349). Attackers can remotely crash firewall gateways using crafted HTTP requests. Meanwhile, local adversaries exploit a Windows WinSock driver flaw (CVE-2026-68820) to elevate privileges.
Actively Exploited Vulnerabilities Overview
| CVE Identifier | Affected Product | CVSS Score | Vulnerability Overview |
| CVE-2026-72898 | Metabase | 10.0 |
Unauthenticated SQL injection via
/reset_password enabling full takeover. |
| CVE-2026-20349 | Cisco ASA & FTD Software | 8.6 |
Remote HTTP request exploit causing unexpected firewall reboots and DoS.
|
| CVE-2026-68820 | Windows WinSock Driver | 7.0 |
Use-after-free bug in
afd.sys allowing local privilege escalation. |
| CVE-2026-59309 | VMware vCenter Server | 9.8 |
Unauthenticated Directory Service bypass leading to complete system access.
|
Catastrophic Cloud and Endpoint Risks
Beyond known active exploits, our weekly threat intelligence report identified severe cloud vulnerabilities. For example, Microsoft Teams contains an authorization flaw that allows unauthorized privilege escalation (CVE-2026-65667). Similarly, Azure SQL Database harbors an improper authentication bug carrying a maximum 10.0 CVSS score (CVE-2026-56162).
Moreover, multiple WordPress plugins suffer from critical administrative bypasses. The Pods plugin (CVE-2026-19598) and Frontend Admin (CVE-2026-18432) allow unauthenticated attackers to hijack administrative accounts. Additionally, network hardware from D-Link and Edimax exposes unauthenticated command injection flaws.
Strategic Mitigation Guidelines
Organizations must act swiftly on this weekly threat intelligence report to mitigate exposure. First, patch all Metabase instances and Cisco firewall appliances immediately. Second, apply Microsoft’s security updates across Windows endpoints and Azure cloud environments. Finally, audit all edge routers and third-party WordPress extensions for unauthorized changes. Continuous monitoring remains essential to stay ahead of sophisticated threat actors.
Support Our Threat Intelligence
If you find our CVE report and cybersecurity news helpful, consider supporting our work.