Exposure Signal Digest

What moved
this week

Week of August 11, 2026

By Jonathan Risto

Your CVE score is data. The change is the signal.

Get the digest in your inbox.

The week's movers, every Tuesday. No noise, just what changed.


Why this digest exists

Most CVEs never move.
We watch the ones that do.

Exploitation probability spikes overnight. Public exploits land. CVEs cross into confirmed in-the-wild use. That movement, the change, is what ESIP scores and surfaces.

Silence is not clearance: a CVE that didn't move isn't a safe one, just one nothing has happened to this week. When something does move, that change is the exposure signal.

6
Escalating this week
5
New KEV additions
4
Newly weaponized

What moved this week

The movers.

Mover #1 · Confirmed · likelihood surging
Apache Tomcat
CriticalConfirmedVerified
Weakness: CWE-311 Missing Encryption of Sensitive Data; CWE-807 Reliance on Untrusted Inputs in a Security Decision
What changed this week
EPSS exploitation probability surged from 0.43 to 0.81 on a government-confirmed flaw.
Why it matters

Government-confirmed exploitation, corroborated by ENISA EUVD, with exploitation probability now past 80%. Act now — don’t wait for more evidence.

Mover #2 · EUVD-confirmed exploitation
N-able (authentication bypass)
CriticalConfirmedVerified
Weakness: CWE-288 Authentication Bypass Using an Alternate Path or Channel
What changed this week
ENISA EUVD confirmed exploitation on August 5; the signal crossed into Confirmed.
Why it matters

An authentication bypass in N-able, now government-confirmed as exploited and corroborated by ENISA EUVD. Confirmed at critical severity — act now.

Mover #3 · Confirmed, escalating fast
IBM Langflow
CriticalConfirmedVerified
Weakness: CWE-94 Improper Control of Generation of Code ('Code Injection')
What changed this week
EPSS exploitation probability climbed sharply (0.02 → 0.17), with evidence accumulating fast.
Why it matters

Unauthenticated code injection in IBM Langflow, confirmed exploited with probability climbing fast. High velocity — treat as immediate.

Mover #4 · Newly weaponized
OpenCATS
HighActiveHigh
Weakness: CWE-94 Improper Control of Generation of Code ('Code Injection')
What changed this week
A Metasploit module landed (opencats_installer_rce).
Why it matters

PHP code injection in OpenCATS, now with a public Metasploit module. Active and escalating — review against your asset inventory.

Mover #5 · Newly weaponized
Ghost CMS (auth bypass)
HighActiveHigh
Weakness: CWE-287 Improper Authentication
What changed this week
A Metasploit module landed (ghostcms_auth_rce).
Why it matters

An authentication bypass in Ghost CMS, now weaponized with a Metasploit module. Active and escalating — review against your inventory.

Mover #6 · Newly weaponized
Ghost CMS (injection)
HighActiveHigh
Weakness: CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
What changed this week
Weaponized by the same Metasploit chain (ghostcms_auth_rce) as CVE-2026-22594.
Why it matters

An injection flaw in Ghost CMS, paired with CVE-2026-22594 in one public exploit chain. Active and escalating — review against your inventory.


New confirmed exploitation

Newly confirmed exploited this week.

OS command injection RCE
Aug 7
JetBrains TeamCity (unauthenticated)
Aug 5
Apache Tomcat (missing encryption)
Aug 4
N-able (authentication bypass)
Aug 4
IBM Langflow (code injection)
Aug 4

Newly weaponized

New public exploits this week.

Orkes Conductor (unauthenticated)
Aug 11
Ghost CMS (Metasploit)
Aug 7
Ghost CMS (Metasploit)
Aug 7
OpenCATS (Metasploit)
Aug 5

The week in numbers

Stop patching by static score.

1,667
Active Critical signals
32
Active High signals
6
Escalating this week
5
New KEV additions
4
New weaponized exploits

Updated every Tuesday. Subscribe to get it by email.

Look up any CVE Get a free API key →