Bastion Codex – Weekly Defender Brief (2026-08-17)


This weekly defender brief summarizes vulnerability movement observed over the past 7 and 30 days.

The goal is simple: highlight signal that matters to frontline defenders — patch workload pressure, severity shifts, and KEV movement.


Bastion Codex – Weekly Defender Brief

Week of 2026-08-17

Executive Snapshot

  • 3513 CVEs observed in the last 7 days
  • 363 Critical
  • 1404 High
  • 4 KEV-listed vulnerabilities in last 30 days

Week-over-Week Movement

  • Total CVEs: 537 (from 2976 to 3513, 18.0%)
  • Critical: 98 (from 265 to 363, 37.0%)
  • High: 410 (from 994 to 1404, 41.2%)
  • Medium: 62 (from 794 to 856, 7.8%)
  • Low: 4 (from 62 to 66, 6.5%)
  • Unknown: -37 (from 861 to 824, -4.3%)

Defender Takeaways

  • Elevated volume of Critical vulnerabilities this week. Prioritize external-facing asset review.
  • Recently added KEV vulnerabilities detected. Review CISA remediation timelines.
  • High severity volume suggests increased patch workload. Focus on internet-exposed services first.

Severity Breakdown (7 Days)

  • Critical: 363
  • High: 1404
  • Medium: 856
  • Low: 66
  • Unknown: 824

Top Vendors (30 Days)

  • Check Point: 1
  • Cisco: 1
  • Metabase: 1
  • Microsoft: 1

Top Products (30 Days)

  • Metabase: 1
  • Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD): 1
  • SmartConsole: 1
  • Windows Ancillary Function Driver for WinSock: 1

Priority Watchlist (Top 10)

  • CVE-2020-0796 | CVSS: 10.0 | KEV: True | A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol handles certain reque
  • CVE-2021-22893 | CVSS: 10.0 | KEV: True | Pulse Connect Secure 9.0R3/9.1R1 and higher is vulnerable to an authentication bypass vulnerability exposed by the Windows File Share Browse
  • CVE-2021-30116 | CVSS: 10.0 | KEV: True | Kaseya VSA before 9.5.7 allows credential disclosure, as exploited in the wild in July 2021. By default Kaseya VSA on premise offers a downl
  • CVE-2021-44228 | CVSS: 10.0 | KEV: True | Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log mess
  • CVE-2026-72898 | CVSS: 10.0 | KEV: True | Metabase allows a remote, unauthenticated attacker to inject arbitrary SQL via the ‘/reset_password’ database endpoint and gain administrato
  • CVE-2025-20333 | CVSS: 9.9 | KEV: True | A vulnerability in the VPN web server of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat D
  • CVE-2010-2861 | CVSS: 9.8 | KEV: True | Multiple directory traversal vulnerabilities in the administrator console in Adobe ColdFusion 9.0.1 and earlier allow remote attackers to re
  • CVE-2012-0507 | CVSS: 9.8 | KEV: True | Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 2 and earlier, 6 Update 30 and earlier,
  • CVE-2016-1019 | CVSS: 9.8 | KEV: True | Adobe Flash Player 21.0.0.197 and earlier allows remote attackers to cause a denial of service (application crash) or possibly execute arbit
  • CVE-2017-11357 | CVSS: 9.8 | KEV: True | Progress Telerik UI for ASP.NET AJAX before R2 2017 SP2 does not properly restrict user input to RadAsyncUpload, which allows remote attacke

Generated via Bastion Codex pipeline at 2026-08-17T15:11:49.588067+00:00