VYPR
AI Brief2026-08-14· generated Aug 14, 2026

What you need to know today.

CISA adds numerous critical vulnerabilities to KEV, including RCE in Drupal, QNAP, and Oracle WebLogic, alongside Windows privilege escalation flaws.

Multiple critical vulnerabilities have been added to the CISA Known Exploited Vulnerabilities (KEV) catalog today, including a remote code execution flaw in Drupal (CVE-2018-7602) and a command injection vulnerability in QNAP QTS (CVE-2018-19949). The Drupal vulnerability, affecting versions 7.x and 8.x, allows attackers to compromise sites through various attack vectors. The QNAP flaw enables remote attackers to execute arbitrary commands, with patches available in QTS versions 4.4.2.1231 and 4.4.1.1201. Additionally, a critical deserialization vulnerability in JBoss Application Server (CVE-2017-12149), affecting Red Hat Enterprise Application Platform 5.2, has been added, potentially leading to remote code execution. ConnectWise ManagedITSync integration (CVE-2017-18362) is also on the KEV list due to unauthenticated remote commands allowing database access, with active exploitation noted in February 2019. Kaseya VSA RMM (CVE-2018-20753) faces similar scrutiny, with active exploitation in January 2018 for unprivileged remote attackers executing PowerShell payloads.

Quest KACE System Management Appliance (CVE-2018-11138) is now in the KEV catalog due to an anonymous user's ability to execute arbitrary commands via the '/common/download_agent_installer.php' script. Gigabyte's APP Center, AORUS GRAPHICS ENGINE, XTREME GAMING ENGINE, and OC GURU II are affected by several high-severity vulnerabilities (CVE-2018-19323, CVE-2018-19322, CVE-2018-19321, CVE-2018-19320). These flaws involve improper handling of Machine Specific Registers (MSRs), IO ports, physical memory, and ring0 memcpy-like functionality, allowing local attackers to escalate privileges or execute arbitrary code. Microsoft Windows is also impacted by multiple high-severity privilege escalation vulnerabilities in the Win32k component (CVE-2018-8453, CVE-2018-8120), stemming from improper memory object handling. A separate high-severity remote code execution vulnerability in the VBScript engine (CVE-2018-8174) has also been added to the KEV list.

A critical use-after-free vulnerability in Adobe Flash Player (CVE-2018-15982) versions prior to 31.0.0.153 and 31.0.0.108 allows for arbitrary code execution. This has been added to the KEV catalog. Also new to KEV is a critical vulnerability in Oracle WebLogic Server (CVE-2017-10271), affecting multiple versions including 10.3.6.0.0, 12.1.3.0.0, 12.2.1.1.0, and 12.2.1.2.0, which is described as an easily exploitable vulnerability. A critical path traversal vulnerability in WinRAR (CVE-2018-20250) affecting versions up to and including 5.61, due to filename manipulation in the ACE format, has been added to KEV, with reports of it fueling attacks on Ukraine. WordPress is affected by two critical vulnerabilities: an unauthenticated arbitrary code execution flaw in WP BASE Booking (CVE-2026-61962) up to version 6.3.0, and an unauthenticated remote code execution vulnerability in QA Analytics (CVE-2026-27544) up to version 5.2.0.0. Lastly, a critical unauthenticated arbitrary file upload vulnerability in the Jquery File Upload Project (CVE-2018-9206) up to version 9.22.0 has been added to the KEV catalog.

Synthesized by Vypr AI
KEV Catalog Swells With Critical RCE and Privilege Escalation Flaws · VYPR