Bastion Codex – Weekly Defender Brief (2026-08-24)
This weekly defender brief summarizes vulnerability movement observed over the past 7 and 30 days.
The goal is simple: highlight signal that matters to frontline defenders — patch workload pressure, severity shifts, and KEV movement.
Bastion Codex – Weekly Defender Brief
Week of 2026-08-24
Executive Snapshot
- 3484 CVEs observed in the last 7 days
- 445 Critical
- 1359 High
- 7 KEV-listed vulnerabilities in last 30 days
Week-over-Week Movement
- Total CVEs: -29 (from 3513 to 3484, -0.8%)
- Critical: 82 (from 363 to 445, 22.6%)
- High: -45 (from 1404 to 1359, -3.2%)
- Medium: 29 (from 856 to 885, 3.4%)
- Low: 36 (from 66 to 102, 54.5%)
- Unknown: -131 (from 824 to 693, -15.9%)
Defender Takeaways
- Elevated volume of Critical vulnerabilities this week. Prioritize external-facing asset review.
- Recently added KEV vulnerabilities detected. Review CISA remediation timelines.
- High severity volume suggests increased patch workload. Focus on internet-exposed services first.
Severity Breakdown (7 Days)
- Critical: 445
- High: 1359
- Medium: 885
- Low: 102
- Unknown: 693
Top Vendors (30 Days)
- TrueConf: 2
- Apple: 1
- Broadcom: 1
- MLflow: 1
- Microsoft: 1
- Synacor: 1
Top Products (30 Days)
- Server: 2
- MLflow: 1
- VMware vCenter: 1
- Windows Ancillary Function Driver for WinSock: 1
- Zimbra Collaboration Suite (ZCS): 1
- macOS: 1
Priority Watchlist (Top 10)
- CVE-2026-33824 | CVSS: 9.8 | KEV: True | Double free in Windows IKE Extension allows an unauthorized attacker to execute code over a network.
- CVE-2026-9198 | CVSS: 9.8 | KEV: True | IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to chain /api/v1/auto_login (mints SUPERUSER tokens to any network ca
- CVE-2026-59310 | CVSS: 9.8 | KEV: True | VMware vCenter contains a directory traversal vulnerability in the Syslog server. A malicious actor with network access to vCenter may explo
- CVE-2026-65400 | CVSS: 9.8 | KEV: True | An authentication issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.9, macOS Sonoma 14.8.9, macO
- CVE-2026-72529 | CVSS: 9.8 | KEV: True | A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to 5.3.9, 5.4.X to 5.4.9, 5.5.X t
- CVE-2022-26486 | CVSS: 9.6 | KEV: True | An unexpected message in the WebGPU IPC framework could lead to a use-after-free and exploitable sandbox escape. We have had reports of atta
- CVE-2026-64849 | CVSS: 9.3 | KEV: True | MLflow is an open source AI engineering platform for agents, large language models, and machine learning models. Prior to 3.15.0, the unauth
- CVE-2021-26855 | CVSS: 9.1 | KEV: True | Microsoft Exchange Server Remote Code Execution Vulnerability
- CVE-2026-55040 | CVSS: 9.1 | KEV: True | Weak authentication in Microsoft Office SharePoint allows an unauthorized attacker to bypass a security feature over a network.
- CVE-2026-72530 | CVSS: 9.0 | KEV: True | A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to 5.3.9, 5.4.X to 5.4.9, 5.5.X t
Generated via Bastion Codex pipeline at 2026-08-24T19:46:58.470755+00:00