Bastion Codex – Weekly Defender Brief (2026-08-11)
This weekly defender brief summarizes vulnerability movement observed over the past 7 and 30 days.
The goal is simple: highlight signal that matters to frontline defenders — patch workload pressure, severity shifts, and KEV movement.
Bastion Codex – Weekly Defender Brief
Week of 2026-08-11
Executive Snapshot
- 2976 CVEs observed in the last 7 days
- 265 Critical
- 994 High
- 8 KEV-listed vulnerabilities in last 30 days
Week-over-Week Movement
- Total CVEs: 192 (from 2784 to 2976, 6.9%)
- Critical: -155 (from 420 to 265, -36.9%)
- High: -72 (from 1066 to 994, -6.8%)
- Medium: 33 (from 761 to 794, 4.3%)
- Low: -42 (from 104 to 62, -40.4%)
- Unknown: 428 (from 433 to 861, 98.8%)
Defender Takeaways
- Elevated volume of Critical vulnerabilities this week. Prioritize external-facing asset review.
- Recently added KEV vulnerabilities detected. Review CISA remediation timelines.
- High severity volume suggests increased patch workload. Focus on internet-exposed services first.
Severity Breakdown (7 Days)
- Critical: 265
- High: 994
- Medium: 794
- Low: 62
- Unknown: 861
Top Vendors (30 Days)
- N-able: 2
- Check Point: 1
- Cisco: 1
- IBM: 1
- JetBrains: 1
- Metabase: 1
- Microsoft: 1
Top Products (30 Days)
- N-central: 2
- Langflow: 1
- Metabase: 1
- Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD): 1
- SmartConsole: 1
- TeamCity: 1
- Windows Ancillary Function Driver for WinSock: 1
Priority Watchlist (Top 10)
- CVE-2021-22205 | CVSS: 10.0 | KEV: True | An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validating image files that
- CVE-2021-44228 | CVSS: 10.0 | KEV: True | Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log mess
- CVE-2024-51378 | CVSS: 10.0 | KEV: True | getresetstatus in dns/views.py and ftp/views.py in CyberPanel (aka Cyber Panel) before 1c0c6cb allows remote attackers to bypass authenticat
- CVE-2024-51567 | CVSS: 10.0 | KEV: True | upgrademysqlstatus in databases/views.py in CyberPanel (aka Cyber Panel) before 5b08cd6 allows remote attackers to bypass authentication and
- CVE-2025-31324 | CVSS: 10.0 | KEV: True | SAP NetWeaver Visual Composer Metadata Uploader is not protected with a proper authorization, allowing unauthenticated agent to upload poten
- CVE-2025-10035 | CVSS: 10.0 | KEV: True | A deserialization vulnerability in the License Servlet of Fortra’s GoAnywhere MFT allows an actor with a validly forged license response sig
- CVE-2025-55182 | CVSS: 10.0 | KEV: True | A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 inclu
- CVE-2026-72898 | CVSS: 10.0 | KEV: True | Metabase allows a remote, unauthenticated attacker to inject arbitrary SQL via the ‘/reset_password’ database endpoint and gain administrato
- CVE-2025-20333 | CVSS: 9.9 | KEV: True | A vulnerability in the VPN web server of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat D
- CVE-2012-1710 | CVSS: 9.8 | KEV: True | Unspecified vulnerability in the Oracle WebCenter Forms Recognition component in Oracle Fusion Middleware 10.1.3.5 allows remote attackers t
Generated via Bastion Codex pipeline at 2026-08-11T22:34:50.949656+00:00