Protecting 75,000+ users across Europe
Learn more →
Protecting 75,000+ users across Europe
Learn more →
Close icon to dismiss modals, popups and notifications
← back to regulation postsAugust - Top 5 vulnerabilities
Threat Intelligence
September 5, 2026

August - Top 5 vulnerabilities

Vulnerability Intelligence

The CISA Known Exploited Vulnerabilities (KEV) catalog added 31 new entries in August 2026, up from 26 in July and 22 in June, continuing an unbroken month-over-month acceleration. Several August additions were older, previously known CVEs (some dating back to 2015, 2019, and 2021) newly confirmed under active exploitation, a reminder that legacy, unpatched systems remain just as attractive to adversaries as fresh zero-days.

Below, we detail the top 5 critical vulnerabilities that demand immediate patching priority in August, ranked by CVSS severity and EPSS (Exploit Prediction Scoring System) probability of near-term exploitation.

1. Progress LoadMaster

CVE:  CVE-2026-8037 | Severity: Critical (CVSS 9.8) | EPSS: 99.6% | Exploitation Status: Actively exploited, CISA remediation deadline August 10, 2026

An unauthenticated OS command injection flaw in Progress LoadMaster, and the related ECS Connections Manager, ObjectScale Connection Manager, and MOVEit WAF products built on the same platform, lets a remote attacker execute arbitrary commands on the appliance through unsanitized input on multiple command endpoints.

LoadMaster is a load balancer and application delivery controller, typically deployed at the edge of the network with visibility into a large share of application traffic. With an EPSS score above 99%, near total certainty of exploitation, this is the highest priority patch on this list: CISA gave organizations only three days to remediate after adding it to the KEV catalog.

2. Gitea

CVE:  CVE-2026-60004 | Severity: Critical (CVSS 9.8, CNA) | EPSS: 86.8% | Exploitation Status: Actively exploited

Gitea versions 1.17 through 1.27.0 are vulnerable to remote code execution through the diffpatch API: an attacker with repository write access can send a crafted patch to plant an executable Git hook and run shell commands as the Gitea service account.

Self-hosted Git platforms like Gitea are an increasingly common alternative to GitHub or GitLab for internal source control. This vulnerability had not yet received an official NVD severity assessment at the time of writing, only the CNA/MITRE score of 9.8 is published, a reminder that CISA KEV inclusion, not NVD scoring, should drive patch urgency.

3. JetBrains TeamCity

CVE:  CVE-2026-63077 | Severity: Critical (CVSS 9.8) | EPSS: 86.5% | Exploitation Status: Actively exploited

A deserialization-of-untrusted-data flaw in the TeamCity agent polling protocol allows unauthenticated remote code execution against TeamCity servers older than 2025.11.7, or in the 2026.1 through 2026.1.2 range.

CI/CD servers like TeamCity sit at the center of the software supply chain, with access to source code, build artifacts, and deployment credentials. A compromised build server can be used to poison software releases downstream, making this one of the more consequential entries on this month's list despite its narrower deployment footprint.

4. AjaxPro.2 (Ajax.NET Professional)

CVE:  CVE-2021-23758 | Severity: Critical (CVSS 9.8) | EPSS: 83.6% | Exploitation Status: Actively exploited, five-year-old CVE newly weaponized

Every version of the AjaxPro.2 (Ajax.NET Professional) library up to 21.10.30.1 deserializes untrusted .NET classes, allowing remote code execution. The library is end of life and no longer maintained.

Originally disclosed in 2021, this CVE's appearance in August's KEV additions is a reminder that end-of-life components buried inside legacy .NET applications do not stop being exploitable just because nobody is patching them anymore. Any application still bundling AjaxPro.2 should be treated as a priority for replacement, not just mitigation.

5. Metabase

CVE:  CVE-2026-72898 | Severity: Critical (CVSS 10.0) | EPSS: 82.3% | Exploitation Status: Actively exploited

An unauthenticated attacker can inject arbitrary SQL through Metabase's /reset_password endpoint, escalating to full administrator access on the connected Metabase instance and, from there, to the credentials and data of every database Metabase is connected to.

Business intelligence platforms like Metabase are often connected directly to production databases, making this vulnerability's maximum CVSS score of 10.0 well earned: a successful attack does not just compromise Metabase, it compromises everything Metabase can see.

Key Takeaways

Old CVEs are new again: August's KEV additions included vulnerabilities from 2015, 2019, and 2021 newly confirmed as actively exploited, alongside 2026-disclosed flaws; patch management needs to cover the full historical stack, not just recent releases.

Software supply chain infrastructure is a growing target: Gitea and JetBrains TeamCity, both developer tooling platforms with access to source code and build pipelines, both made this month's top 5.

EPSS scores above 80% across four of five entries: continuing the pattern from July, most of August's top vulnerabilities carry EPSS scores well above 80%, indicating broad, ongoing mass exploitation rather than isolated attacks.

References
# CVE Vendor / Product NVD Link
1 CVE-2026-8037 Progress LoadMaster https://nvd.nist.gov/vuln/detail/CVE-2026-8037
2 CVE-2026-60004 Gitea https://nvd.nist.gov/vuln/detail/CVE-2026-60004
3 CVE-2026-63077 JetBrains TeamCity https://nvd.nist.gov/vuln/detail/CVE-2026-63077
4 CVE-2021-23758 AjaxPro.2 (Ajax.NET Professional) https://nvd.nist.gov/vuln/detail/CVE-2021-23758
5 CVE-2026-72898 Metabase https://nvd.nist.gov/vuln/detail/CVE-2026-72898

You can also check the vendor's official security advisory or the CISA KEV catalog directly for exploitation status

Arrow left navigation icon
See More

See more. Stay ahead.

VOC Services
Keep reading

More resources about Threat Intelligence

Cyber threats evolve fast. Our experts share the latest thinking on cybersecurity trends, regulatory changes and operational best practices — so your organization stays one step ahead.

Threat Intelligence
September 5, 2026

July - Top 5 vulnerabilities

Vulnerability Intelligence

Threat Intelligence
August 17, 2026

The Minnesota water stations attacks: lessons learned from the field

Published: August 5, 2026 | Stéphane Rabette | Reading Time: ~7 minutes