🛡️ Cyber Times — CISO Intelligence Update
Monday, 24 August 2026 · Coverage: 23 Aug 2026 08:00 IST → 24 Aug 2026 08:00 IST
The high-confidence sweep produced 17 publishable records. This edition presents 7 source-linked updates across 1 security domains; 7 are marked for priority review.
🛡️ Vulnerabilities Worth Attention
CVE-2026-78167 — A weakness has been identified in EFM ipTIME T16000M 14.20.2
CRITICAL — NVD CVSS 9.3 (critical). A weakness has been identified in EFM ipTIME T16000M 14.20.2. The impacted element is the function httpcon_check_session_url of the component Session Validation Handler. This manipulation causes improper authentication. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this…
Defender action: Confirm affected versions in the asset inventory, review the vendor advisory, and prioritize remediation by exposure.
Validation: primary source · Published: 24 Aug 2026 07:47 IST Sources: NVD
CVE-2026-78207 — exceljs-hardened before 5.0.0 contains a prototype pollution vulnerability in the deepMerge helper that fails to reject proto, constructor, or prototype keys…
CRITICAL — NVD CVSS 9.3 (critical). exceljs-hardened before 5.0.0 contains a prototype pollution vulnerability in the deepMerge helper that fails to reject proto, constructor, or prototype keys when merging note objects. Attackers can assign parsed JSON with a malicious proto property to cell notes, modifying Object.prototype and affecting all plain objects created in the process.
Defender action: Confirm affected versions in the asset inventory, review the vendor advisory, and prioritize remediation by exposure.
Validation: primary source · Published: 24 Aug 2026 06:46 IST Sources: NVD
CVE-2026-78155 — privilege escalation in StackGres operator allows a low-privilege tenant who owns a database to gain administrator privileges
CRITICAL — NVD CVSS 9.9 (critical). privilege escalation in StackGres operator allows a low-privilege tenant who owns a database to gain administrator privileges
Defender action: Confirm affected versions in the asset inventory, review the vendor advisory, and prioritize remediation by exposure.
Validation: primary source · Published: 23 Aug 2026 15:46 IST Sources: NVD
CVE-2026-8445 — justhtml versions are preserved, so untrusted input that is safe in to_html() — including entity-decoded text (e.g
CRITICAL — NVD CVSS 9.3 (critical). justhtml versions are preserved, so untrusted input that is safe in to_html() — including entity-decoded text (e.g. ) or text from RCDATA/RAWTEXT-parsed elements like , , , and — can be emitted as raw HTML in the Markdown output, enabling a sanitizer bypass and potential cross-site scripting when that output is rendered.
Defender action: Confirm affected versions in the asset inventory, review the vendor advisory, and prioritize remediation by exposure.
Validation: primary source · Published: 23 Aug 2026 19:46 IST Sources: NVD
CVE-2026-7808 — justhtml before 1.16.0 contains multiple HTML sanitization bypass issues that can allow active/dangerous content (e.g., script or style) to survive sanitization…
CRITICAL — NVD CVSS 9.3 (critical). justhtml before 1.16.0 contains multiple HTML sanitization bypass issues that can allow active/dangerous content (e.g., script or style) to survive sanitization, potentially leading to cross-site scripting. The issues primarily affect advanced usage rather than the default JustHTML(…, sanitize=True) path for ordinary parsed HTML: mutating or reusing sanitization policy objects (including…
Defender action: Confirm affected versions in the asset inventory, review the vendor advisory, and prioritize remediation by exposure.
Validation: primary source · Published: 23 Aug 2026 19:46 IST Sources: NVD
CVE-2026-5388 — justhtml before 1.15.0 contains multiple security issues in URL sanitization helpers (clean_url_value/clean_url_in_js_string), HTML serialization, Markdown…
CRITICAL — NVD CVSS 9.3 (critical). justhtml before 1.15.0 contains multiple security issues in URL sanitization helpers (clean_url_value/clean_url_in_js_string), HTML serialization, Markdown passthrough (html_passthrough=True), and several custom sanitization-policy edge cases. Depending on configuration, an attacker can bypass sanitization to inject active HTML and JavaScript — for example via encoded javascript: URLs…
Defender action: Confirm affected versions in the asset inventory, review the vendor advisory, and prioritize remediation by exposure.
Validation: primary source · Published: 23 Aug 2026 19:46 IST Sources: NVD
CVE-2026-78168 — A security vulnerability has been detected in EFM ipTIME T24000M up to 14.20.0
HIGH — NVD CVSS 8.9 (high). A security vulnerability has been detected in EFM ipTIME T24000M up to 14.20.0. This affects the function httpcon_check_session_url of the component Session Validation Handler. Such manipulation leads to improper authentication. The attack can be executed remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond…
Defender action: Confirm affected versions in the asset inventory, review the vendor advisory, and prioritize remediation by exposure.
Validation: primary source · Published: 24 Aug 2026 07:47 IST Sources: NVD
💡 Defensive Priority
Open the linked primary or corroborating evidence before changing production systems. Confirm asset exposure, use vendor guidance for remediation, and retain the source links with the operational change record.
Collection: 2,273 records inspected · 70 passed collection filters · 17 passed the high-confidence evidence gate · 27/28 source endpoints available. Automated intelligence is a triage aid; verify exposure and remediation against the linked primary advisory.