Skip to content
Cyber Times

Independent threat intelligence for security leaders.

Go back

CISO Intelligence Update — Monday, 24 August 2026

🛡️ Cyber Times — CISO Intelligence Update

Monday, 24 August 2026 · Coverage: 23 Aug 2026 08:00 IST → 24 Aug 2026 08:00 IST

The high-confidence sweep produced 17 publishable records. This edition presents 7 source-linked updates across 1 security domains; 7 are marked for priority review.

🛡️ Vulnerabilities Worth Attention

CVE-2026-78167 — A weakness has been identified in EFM ipTIME T16000M 14.20.2

CRITICAL — NVD CVSS 9.3 (critical). A weakness has been identified in EFM ipTIME T16000M 14.20.2. The impacted element is the function httpcon_check_session_url of the component Session Validation Handler. This manipulation causes improper authentication. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this…

Defender action: Confirm affected versions in the asset inventory, review the vendor advisory, and prioritize remediation by exposure.

Validation: primary source · Published: 24 Aug 2026 07:47 IST Sources: NVD

CVE-2026-78207 — exceljs-hardened before 5.0.0 contains a prototype pollution vulnerability in the deepMerge helper that fails to reject proto, constructor, or prototype keys…

CRITICAL — NVD CVSS 9.3 (critical). exceljs-hardened before 5.0.0 contains a prototype pollution vulnerability in the deepMerge helper that fails to reject proto, constructor, or prototype keys when merging note objects. Attackers can assign parsed JSON with a malicious proto property to cell notes, modifying Object.prototype and affecting all plain objects created in the process.

Defender action: Confirm affected versions in the asset inventory, review the vendor advisory, and prioritize remediation by exposure.

Validation: primary source · Published: 24 Aug 2026 06:46 IST Sources: NVD

CVE-2026-78155 — privilege escalation in StackGres operator allows a low-privilege tenant who owns a database to gain administrator privileges

CRITICAL — NVD CVSS 9.9 (critical). privilege escalation in StackGres operator allows a low-privilege tenant who owns a database to gain administrator privileges

Defender action: Confirm affected versions in the asset inventory, review the vendor advisory, and prioritize remediation by exposure.

Validation: primary source · Published: 23 Aug 2026 15:46 IST Sources: NVD

CVE-2026-8445 — justhtml versions are preserved, so untrusted input that is safe in to_html() — including entity-decoded text (e.g

CRITICAL — NVD CVSS 9.3 (critical). justhtml versions are preserved, so untrusted input that is safe in to_html() — including entity-decoded text (e.g. ) or text from RCDATA/RAWTEXT-parsed elements like , , , and — can be emitted as raw HTML in the Markdown output, enabling a sanitizer bypass and potential cross-site scripting when that output is rendered.

Defender action: Confirm affected versions in the asset inventory, review the vendor advisory, and prioritize remediation by exposure.

Validation: primary source · Published: 23 Aug 2026 19:46 IST Sources: NVD

CVE-2026-7808 — justhtml before 1.16.0 contains multiple HTML sanitization bypass issues that can allow active/dangerous content (e.g., script or style) to survive sanitization…

CRITICAL — NVD CVSS 9.3 (critical). justhtml before 1.16.0 contains multiple HTML sanitization bypass issues that can allow active/dangerous content (e.g., script or style) to survive sanitization, potentially leading to cross-site scripting. The issues primarily affect advanced usage rather than the default JustHTML(…, sanitize=True) path for ordinary parsed HTML: mutating or reusing sanitization policy objects (including…

Defender action: Confirm affected versions in the asset inventory, review the vendor advisory, and prioritize remediation by exposure.

Validation: primary source · Published: 23 Aug 2026 19:46 IST Sources: NVD

CVE-2026-5388 — justhtml before 1.15.0 contains multiple security issues in URL sanitization helpers (clean_url_value/clean_url_in_js_string), HTML serialization, Markdown…

CRITICAL — NVD CVSS 9.3 (critical). justhtml before 1.15.0 contains multiple security issues in URL sanitization helpers (clean_url_value/clean_url_in_js_string), HTML serialization, Markdown passthrough (html_passthrough=True), and several custom sanitization-policy edge cases. Depending on configuration, an attacker can bypass sanitization to inject active HTML and JavaScript — for example via encoded javascript: URLs…

Defender action: Confirm affected versions in the asset inventory, review the vendor advisory, and prioritize remediation by exposure.

Validation: primary source · Published: 23 Aug 2026 19:46 IST Sources: NVD

CVE-2026-78168 — A security vulnerability has been detected in EFM ipTIME T24000M up to 14.20.0

HIGH — NVD CVSS 8.9 (high). A security vulnerability has been detected in EFM ipTIME T24000M up to 14.20.0. This affects the function httpcon_check_session_url of the component Session Validation Handler. Such manipulation leads to improper authentication. The attack can be executed remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond…

Defender action: Confirm affected versions in the asset inventory, review the vendor advisory, and prioritize remediation by exposure.

Validation: primary source · Published: 24 Aug 2026 07:47 IST Sources: NVD

💡 Defensive Priority

Open the linked primary or corroborating evidence before changing production systems. Confirm asset exposure, use vendor guidance for remediation, and retain the source links with the operational change record.


Collection: 2,273 records inspected · 70 passed collection filters · 17 passed the high-confidence evidence gate · 27/28 source endpoints available. Automated intelligence is a triage aid; verify exposure and remediation against the linked primary advisory.


Topics in this briefing

Share this post on:

Previous Post
CISO Intelligence Update — Tuesday, 25 August 2026
Next Post
Cyber Times Brief — Wednesday, 01-04-2026