August 9, 2026 weekly
- N-able N-central — CVE-2026-18556 / CVE-2026-18577 — god-mode auth bypass, ransomware in play, on KEV, two patches to reach 2026.3.1.10. Horizon3 · Under Active Exploitation
- Oracle WebLogic — CVE-2026-60206 — CVSS 9.9 SAML auth bypass, public PoC. PoC · Under Active Exploitation
- N-able ships a third N-central hotfix or an advisory revision for CVE-2026-18556/18577 within 3 weeks, as the Cloudflare Tunnel persistence angle forces scope expansion beyond the auth bypass itself. · Wild Speculation