Bastion Codex – Weekly Defender Brief (2026-08-24)


This weekly defender brief summarizes vulnerability movement observed over the past 7 and 30 days.

The goal is simple: highlight signal that matters to frontline defenders — patch workload pressure, severity shifts, and KEV movement.


Bastion Codex – Weekly Defender Brief

Week of 2026-08-24

Executive Snapshot

  • 3484 CVEs observed in the last 7 days
  • 445 Critical
  • 1359 High
  • 7 KEV-listed vulnerabilities in last 30 days

Week-over-Week Movement

  • Total CVEs: -29 (from 3513 to 3484, -0.8%)
  • Critical: 82 (from 363 to 445, 22.6%)
  • High: -45 (from 1404 to 1359, -3.2%)
  • Medium: 29 (from 856 to 885, 3.4%)
  • Low: 36 (from 66 to 102, 54.5%)
  • Unknown: -131 (from 824 to 693, -15.9%)

Defender Takeaways

  • Elevated volume of Critical vulnerabilities this week. Prioritize external-facing asset review.
  • Recently added KEV vulnerabilities detected. Review CISA remediation timelines.
  • High severity volume suggests increased patch workload. Focus on internet-exposed services first.

Severity Breakdown (7 Days)

  • Critical: 445
  • High: 1359
  • Medium: 885
  • Low: 102
  • Unknown: 693

Top Vendors (30 Days)

  • TrueConf: 2
  • Apple: 1
  • Broadcom: 1
  • MLflow: 1
  • Microsoft: 1
  • Synacor: 1

Top Products (30 Days)

  • Server: 2
  • MLflow: 1
  • VMware vCenter: 1
  • Windows Ancillary Function Driver for WinSock: 1
  • Zimbra Collaboration Suite (ZCS): 1
  • macOS: 1

Priority Watchlist (Top 10)

  • CVE-2026-33824 | CVSS: 9.8 | KEV: True | Double free in Windows IKE Extension allows an unauthorized attacker to execute code over a network.
  • CVE-2026-9198 | CVSS: 9.8 | KEV: True | IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to chain /api/v1/auto_login (mints SUPERUSER tokens to any network ca
  • CVE-2026-59310 | CVSS: 9.8 | KEV: True | VMware vCenter contains a directory traversal vulnerability in the Syslog server. A malicious actor with network access to vCenter may explo
  • CVE-2026-65400 | CVSS: 9.8 | KEV: True | An authentication issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.9, macOS Sonoma 14.8.9, macO
  • CVE-2026-72529 | CVSS: 9.8 | KEV: True | A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to 5.3.9, 5.4.X to 5.4.9, 5.5.X t
  • CVE-2022-26486 | CVSS: 9.6 | KEV: True | An unexpected message in the WebGPU IPC framework could lead to a use-after-free and exploitable sandbox escape. We have had reports of atta
  • CVE-2026-64849 | CVSS: 9.3 | KEV: True | MLflow is an open source AI engineering platform for agents, large language models, and machine learning models. Prior to 3.15.0, the unauth
  • CVE-2021-26855 | CVSS: 9.1 | KEV: True | Microsoft Exchange Server Remote Code Execution Vulnerability
  • CVE-2026-55040 | CVSS: 9.1 | KEV: True | Weak authentication in Microsoft Office SharePoint allows an unauthorized attacker to bypass a security feature over a network.
  • CVE-2026-72530 | CVSS: 9.0 | KEV: True | A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to 5.3.9, 5.4.X to 5.4.9, 5.5.X t

Generated via Bastion Codex pipeline at 2026-08-24T19:46:58.470755+00:00