Exposure Signal Digest

What moved
this week

Week of August 25, 2026

By Jonathan Risto

Your CVE score is data. The change is the signal.

Get the digest in your inbox.

The week's movers, every Tuesday. No noise, just what changed.


Why this digest exists

Most CVEs never move.
We watch the ones that do.

Exploitation probability spikes overnight. Public exploits land. CVEs cross into confirmed in-the-wild use. That movement, the change, is what ESIP scores and surfaces.

Silence is not clearance: a CVE that didn't move isn't a safe one, just one nothing has happened to this week. When something does move, that change is the exposure signal.

7
Escalating this week
10
New KEV additions
5
Newly weaponized

What moved this week

The movers.

Mover #1 · EUVD-confirmed exploitation
Windows IKE Extension
CriticalConfirmedVerified
Weakness: CWE-415 Double Free
What changed this week
Government-confirmed exploited, with EPSS probability holding high near 0.73.
Why it matters

A double-free RCE in the Windows IKE extension, government-confirmed as exploited and corroborated by ENISA EUVD. Confirmed at critical severity — act now, don’t wait for more evidence.

Mover #2 · Confirmed, escalating fast
VMware vCenter (Syslog)
CriticalConfirmedVerified
Weakness: CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
What changed this week
A public PoC landed on ExploitDB just a day ago.
Why it matters

A directory-traversal flaw in VMware vCenter’s Syslog server, confirmed exploited with a fresh public PoC. High velocity, changing daily — treat as immediate.

Mover #3 · EUVD-confirmed exploitation
Microsoft SharePoint
CriticalConfirmedVerified
Weakness: CWE-1390 Weak Authentication
What changed this week
ENISA EUVD confirmed exploitation on August 19; the signal crossed into Confirmed.
Why it matters

Weak authentication in Microsoft SharePoint, now government-confirmed as exploited and corroborated by ENISA EUVD. Confirmed at critical severity — act now.

Mover #4 · Confirmed, escalating fast
Metabase (SQL injection)
CriticalConfirmedVerified
Weakness: CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
What changed this week
Two weeks in, the public ExploitDB PoC keeps driving escalation.
Why it matters

Unauthenticated SQL injection in Metabase, confirmed exploited and still escalating at high velocity. Treat as immediate if you run it.

Mover #5 · Newly weaponized
D-Link DNS-series NAS
HighActiveHigh
Weakness: CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
What changed this week
A public PoC landed on ExploitDB (verylazytech/CVE-2024-10914).
Why it matters

OS command injection in D-Link DNS-series NAS devices, now with a public exploit. Active and escalating — review against your asset inventory.

Mover #6 · Newly weaponized
webpack-dev-server
HighActiveHigh
Weakness: CWE-352 Cross-Site Request Forgery (CSRF); CWE-749 Exposed Dangerous Method or Function
What changed this week
A weaponized exploit landed on ExploitDB (entry 52649).
Why it matters

Exposed developer endpoints and CSRF in webpack-dev-server, now weaponized on ExploitDB. Active and escalating — review against your inventory.

Mover #7 · Newly weaponized
PCMan FTP Server
HighActiveHigh
Weakness: CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow'); CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer
What changed this week
A weaponized exploit landed on ExploitDB (entry 52657).
Why it matters

A classic buffer overflow in PCMan FTP Server, now weaponized on ExploitDB. Active and escalating — review against your inventory.


New confirmed exploitation

Newly confirmed exploited this week.

Oracle HTTP Server / WebLogic Server
Aug 24
Zimbra Collaboration (remote code execution)
Aug 21
Microsoft Entra ID (deserialization)
Aug 21
Remote unauthenticated network access
Aug 20
Remote unauthenticated network access
Aug 20
MLflow AI engineering platform
Aug 19
Windows IKE Extension (double free)
Aug 18
VMware vCenter (path traversal)
Aug 18
Microsoft SharePoint (weak authentication)
Aug 18
Authentication bypass (state management)
Aug 18

Newly weaponized

New public exploits this week.

SPIP CMS (< 4.4.20, Metasploit)
Aug 24
Flowise (OS command injection, Metasploit)
Aug 21
PCMan FTP Server (ExploitDB)
Aug 19
D-Link DNS-series NAS (ExploitDB)
Aug 18
webpack-dev-server (≤ 5.2.5, ExploitDB)
Aug 18

The week in numbers

Stop patching by static score.

1,682
Active Critical signals
33
Active High signals
7
Escalating this week
10
New KEV additions
5
New weaponized exploits

Updated every Tuesday. Subscribe to get it by email.

Look up any CVE Get a free API key →