Government-confirmed exploitation, corroborated by ENISA EUVD, with exploitation probability now past 80%. Act now — don’t wait for more evidence.
Week of August 11, 2026
Your CVE score is data. The change is the signal.
The week's movers, every Tuesday. No noise, just what changed.
Exploitation probability spikes overnight. Public exploits land. CVEs cross into confirmed in-the-wild use. That movement, the change, is what ESIP scores and surfaces.
Silence is not clearance: a CVE that didn't move isn't a safe one, just one nothing has happened to this week. When something does move, that change is the exposure signal.
Government-confirmed exploitation, corroborated by ENISA EUVD, with exploitation probability now past 80%. Act now — don’t wait for more evidence.
An authentication bypass in N-able, now government-confirmed as exploited and corroborated by ENISA EUVD. Confirmed at critical severity — act now.
Unauthenticated code injection in IBM Langflow, confirmed exploited with probability climbing fast. High velocity — treat as immediate.
PHP code injection in OpenCATS, now with a public Metasploit module. Active and escalating — review against your asset inventory.
An authentication bypass in Ghost CMS, now weaponized with a Metasploit module. Active and escalating — review against your inventory.
An injection flaw in Ghost CMS, paired with CVE-2026-22594 in one public exploit chain. Active and escalating — review against your inventory.
Updated every Tuesday. Subscribe to get it by email.