A double-free RCE in the Windows IKE extension, government-confirmed as exploited and corroborated by ENISA EUVD. Confirmed at critical severity — act now, don’t wait for more evidence.
Week of August 25, 2026
Your CVE score is data. The change is the signal.
The week's movers, every Tuesday. No noise, just what changed.
Exploitation probability spikes overnight. Public exploits land. CVEs cross into confirmed in-the-wild use. That movement, the change, is what ESIP scores and surfaces.
Silence is not clearance: a CVE that didn't move isn't a safe one, just one nothing has happened to this week. When something does move, that change is the exposure signal.
A double-free RCE in the Windows IKE extension, government-confirmed as exploited and corroborated by ENISA EUVD. Confirmed at critical severity — act now, don’t wait for more evidence.
A directory-traversal flaw in VMware vCenter’s Syslog server, confirmed exploited with a fresh public PoC. High velocity, changing daily — treat as immediate.
Weak authentication in Microsoft SharePoint, now government-confirmed as exploited and corroborated by ENISA EUVD. Confirmed at critical severity — act now.
Unauthenticated SQL injection in Metabase, confirmed exploited and still escalating at high velocity. Treat as immediate if you run it.
OS command injection in D-Link DNS-series NAS devices, now with a public exploit. Active and escalating — review against your asset inventory.
Exposed developer endpoints and CSRF in webpack-dev-server, now weaponized on ExploitDB. Active and escalating — review against your inventory.
A classic buffer overflow in PCMan FTP Server, now weaponized on ExploitDB. Active and escalating — review against your inventory.
Updated every Tuesday. Subscribe to get it by email.