Bastion Codex – Weekly Defender Brief (2026-08-11)


This weekly defender brief summarizes vulnerability movement observed over the past 7 and 30 days.

The goal is simple: highlight signal that matters to frontline defenders — patch workload pressure, severity shifts, and KEV movement.


Bastion Codex – Weekly Defender Brief

Week of 2026-08-11

Executive Snapshot

  • 2976 CVEs observed in the last 7 days
  • 265 Critical
  • 994 High
  • 8 KEV-listed vulnerabilities in last 30 days

Week-over-Week Movement

  • Total CVEs: 192 (from 2784 to 2976, 6.9%)
  • Critical: -155 (from 420 to 265, -36.9%)
  • High: -72 (from 1066 to 994, -6.8%)
  • Medium: 33 (from 761 to 794, 4.3%)
  • Low: -42 (from 104 to 62, -40.4%)
  • Unknown: 428 (from 433 to 861, 98.8%)

Defender Takeaways

  • Elevated volume of Critical vulnerabilities this week. Prioritize external-facing asset review.
  • Recently added KEV vulnerabilities detected. Review CISA remediation timelines.
  • High severity volume suggests increased patch workload. Focus on internet-exposed services first.

Severity Breakdown (7 Days)

  • Critical: 265
  • High: 994
  • Medium: 794
  • Low: 62
  • Unknown: 861

Top Vendors (30 Days)

  • N-able: 2
  • Check Point: 1
  • Cisco: 1
  • IBM: 1
  • JetBrains: 1
  • Metabase: 1
  • Microsoft: 1

Top Products (30 Days)

  • N-central: 2
  • Langflow: 1
  • Metabase: 1
  • Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD): 1
  • SmartConsole: 1
  • TeamCity: 1
  • Windows Ancillary Function Driver for WinSock: 1

Priority Watchlist (Top 10)

  • CVE-2021-22205 | CVSS: 10.0 | KEV: True | An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validating image files that
  • CVE-2021-44228 | CVSS: 10.0 | KEV: True | Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log mess
  • CVE-2024-51378 | CVSS: 10.0 | KEV: True | getresetstatus in dns/views.py and ftp/views.py in CyberPanel (aka Cyber Panel) before 1c0c6cb allows remote attackers to bypass authenticat
  • CVE-2024-51567 | CVSS: 10.0 | KEV: True | upgrademysqlstatus in databases/views.py in CyberPanel (aka Cyber Panel) before 5b08cd6 allows remote attackers to bypass authentication and
  • CVE-2025-31324 | CVSS: 10.0 | KEV: True | SAP NetWeaver Visual Composer Metadata Uploader is not protected with a proper authorization, allowing unauthenticated agent to upload poten
  • CVE-2025-10035 | CVSS: 10.0 | KEV: True | A deserialization vulnerability in the License Servlet of Fortra’s GoAnywhere MFT allows an actor with a validly forged license response sig
  • CVE-2025-55182 | CVSS: 10.0 | KEV: True | A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 inclu
  • CVE-2026-72898 | CVSS: 10.0 | KEV: True | Metabase allows a remote, unauthenticated attacker to inject arbitrary SQL via the ‘/reset_password’ database endpoint and gain administrato
  • CVE-2025-20333 | CVSS: 9.9 | KEV: True | A vulnerability in the VPN web server of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat D
  • CVE-2012-1710 | CVSS: 9.8 | KEV: True | Unspecified vulnerability in the Oracle WebCenter Forms Recognition component in Oracle Fusion Middleware 10.1.3.5 allows remote attackers t

Generated via Bastion Codex pipeline at 2026-08-11T22:34:50.949656+00:00