🛡️ Cyber Times — CISO Intelligence Update
Tuesday, 25 August 2026 · Coverage: 24 Aug 2026 08:00 IST → 25 Aug 2026 08:00 IST
The high-confidence sweep produced 31 publishable records. This edition presents 8 source-linked updates across 2 security domains; 8 are marked for priority review.
🔴 Critical Threats & Active Exploitation
CVE-2026-21962 added to CISA KEV — Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in
CRITICAL — Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in contain an improper access control vulnerability that can result in unauthorized creation, deletion or modification access to critical data as well as unauthorized access to critical data or complete access to all Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in accessible data. Required action: Apply mitigations per vendor instructions, follow…
Defender action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Validation: primary source · Published: 24 Aug 2026 05:30 IST Sources: CISA KEV
🛡️ Vulnerabilities Worth Attention
CVE-2025-36939 — Multiple vulnerabilities exist in OpenThread’s handling of MLE packets
CRITICAL — NVD CVSS 10.0 (critical). Multiple vulnerabilities exist in OpenThread’s handling of MLE packets. An authenticated attacker on the same Thread network could send specially crafted packets to cause a denial of service. These issues include triggerable assertion failures and a stack-based buffer overflow.
Defender action: Confirm affected versions in the asset inventory, review the vendor advisory, and prioritize remediation by exposure.
Validation: primary source · Published: 24 Aug 2026 22:47 IST Sources: NVD
CVE-2026-77995 — Joomla Extension - miniorange.com - Arbitrary account takeover in miniOrange OAuth Client < 3.2.0 - The manipulation of a cookie value allows actors to login as…
CRITICAL — NVD CVSS 10.0 (critical). Joomla Extension - miniorange.com - Arbitrary account takeover in miniOrange OAuth Client < 3.2.0 - The manipulation of a cookie value allows actors to login as arbitrary accounts, including admins.
Defender action: Confirm affected versions in the asset inventory, review the vendor advisory, and prioritize remediation by exposure.
Validation: primary source · Published: 24 Aug 2026 19:47 IST Sources: NVD
CVE-2026-32559 — Subscriber Arbitrary File Upload in UltimateAI <= 3.1.0 versions.
CRITICAL — NVD CVSS 9.9 (critical). Subscriber Arbitrary File Upload in UltimateAI <= 3.1.0 versions.
Defender action: Confirm affected versions in the asset inventory, review the vendor advisory, and prioritize remediation by exposure.
Validation: primary source · Published: 25 Aug 2026 03:46 IST Sources: NVD
CVE-2026-66897 — A path traversal vulnerability in LXD’s instance template processing allows an attacker with container edit permissions, or any user launching a crafted image…
CRITICAL — NVD CVSS 9.9 (critical). A path traversal vulnerability in LXD’s instance template processing allows an attacker with container edit permissions, or any user launching a crafted image, to overwrite arbitrary files on the host system as root. When processing target template paths specified in metadata.yaml, LXD validates the path against a confined os.Root directory handle but subsequently opens and creates the file…
Defender action: Confirm affected versions in the asset inventory, review the vendor advisory, and prioritize remediation by exposure.
Validation: primary source · Published: 24 Aug 2026 15:46 IST Sources: NVD
CVE-2026-78267 — Unauthenticated Privilege Escalation in TranslatePress <= 3.3.2 versions.
CRITICAL — NVD CVSS 9.8 (critical). Unauthenticated Privilege Escalation in TranslatePress <= 3.3.2 versions.
Defender action: Confirm affected versions in the asset inventory, review the vendor advisory, and prioritize remediation by exposure.
Validation: primary source · Published: 25 Aug 2026 03:47 IST Sources: NVD
CVE-2026-78265 — Unauthenticated PHP Object Injection in The Events Calendar <= 6.17.2 versions.
CRITICAL — NVD CVSS 9.8 (critical). Unauthenticated PHP Object Injection in The Events Calendar <= 6.17.2 versions.
Defender action: Confirm affected versions in the asset inventory, review the vendor advisory, and prioritize remediation by exposure.
Validation: primary source · Published: 25 Aug 2026 03:47 IST Sources: NVD
CVE-2026-78262 — Unauthenticated PHP Object Injection in WP Project Manager <= 4.0.6 versions.
CRITICAL — NVD CVSS 9.8 (critical). Unauthenticated PHP Object Injection in WP Project Manager <= 4.0.6 versions.
Defender action: Confirm affected versions in the asset inventory, review the vendor advisory, and prioritize remediation by exposure.
Validation: primary source · Published: 25 Aug 2026 03:47 IST Sources: NVD
💡 Defensive Priority
Open the linked primary or corroborating evidence before changing production systems. Confirm asset exposure, use vendor guidance for remediation, and retain the source links with the operational change record.
Collection: 2,630 records inspected · 136 passed collection filters · 31 passed the high-confidence evidence gate · 27/28 source endpoints available. Automated intelligence is a triage aid; verify exposure and remediation against the linked primary advisory.