Bastion Codex – Weekly Defender Brief (2026-08-17)
This weekly defender brief summarizes vulnerability movement observed over the past 7 and 30 days.
The goal is simple: highlight signal that matters to frontline defenders — patch workload pressure, severity shifts, and KEV movement.
Bastion Codex – Weekly Defender Brief
Week of 2026-08-17
Executive Snapshot
- 3513 CVEs observed in the last 7 days
- 363 Critical
- 1404 High
- 4 KEV-listed vulnerabilities in last 30 days
Week-over-Week Movement
- Total CVEs: 537 (from 2976 to 3513, 18.0%)
- Critical: 98 (from 265 to 363, 37.0%)
- High: 410 (from 994 to 1404, 41.2%)
- Medium: 62 (from 794 to 856, 7.8%)
- Low: 4 (from 62 to 66, 6.5%)
- Unknown: -37 (from 861 to 824, -4.3%)
Defender Takeaways
- Elevated volume of Critical vulnerabilities this week. Prioritize external-facing asset review.
- Recently added KEV vulnerabilities detected. Review CISA remediation timelines.
- High severity volume suggests increased patch workload. Focus on internet-exposed services first.
Severity Breakdown (7 Days)
- Critical: 363
- High: 1404
- Medium: 856
- Low: 66
- Unknown: 824
Top Vendors (30 Days)
- Check Point: 1
- Cisco: 1
- Metabase: 1
- Microsoft: 1
Top Products (30 Days)
- Metabase: 1
- Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD): 1
- SmartConsole: 1
- Windows Ancillary Function Driver for WinSock: 1
Priority Watchlist (Top 10)
- CVE-2020-0796 | CVSS: 10.0 | KEV: True | A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol handles certain reque
- CVE-2021-22893 | CVSS: 10.0 | KEV: True | Pulse Connect Secure 9.0R3/9.1R1 and higher is vulnerable to an authentication bypass vulnerability exposed by the Windows File Share Browse
- CVE-2021-30116 | CVSS: 10.0 | KEV: True | Kaseya VSA before 9.5.7 allows credential disclosure, as exploited in the wild in July 2021. By default Kaseya VSA on premise offers a downl
- CVE-2021-44228 | CVSS: 10.0 | KEV: True | Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log mess
- CVE-2026-72898 | CVSS: 10.0 | KEV: True | Metabase allows a remote, unauthenticated attacker to inject arbitrary SQL via the ‘/reset_password’ database endpoint and gain administrato
- CVE-2025-20333 | CVSS: 9.9 | KEV: True | A vulnerability in the VPN web server of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat D
- CVE-2010-2861 | CVSS: 9.8 | KEV: True | Multiple directory traversal vulnerabilities in the administrator console in Adobe ColdFusion 9.0.1 and earlier allow remote attackers to re
- CVE-2012-0507 | CVSS: 9.8 | KEV: True | Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 2 and earlier, 6 Update 30 and earlier,
- CVE-2016-1019 | CVSS: 9.8 | KEV: True | Adobe Flash Player 21.0.0.197 and earlier allows remote attackers to cause a denial of service (application crash) or possibly execute arbit
- CVE-2017-11357 | CVSS: 9.8 | KEV: True | Progress Telerik UI for ASP.NET AJAX before R2 2017 SP2 does not properly restrict user input to RadAsyncUpload, which allows remote attacke
Generated via Bastion Codex pipeline at 2026-08-17T15:11:49.588067+00:00