Skip to content
Cyber Times

Independent threat intelligence for security leaders.

Go back

CISO Intelligence Update — Monday, 31 August 2026

🛡️ Cyber Times — CISO Intelligence Update

Monday, 31 August 2026 · Coverage: 30 Aug 2026 08:00 IST → 31 Aug 2026 08:00 IST

The high-confidence sweep produced 28 publishable records. This edition presents 7 source-linked updates across 1 security domains; 7 are marked for priority review.

🛡️ Vulnerabilities Worth Attention

CVE-2026-77956 — Improper Control of Generation of Code (Code Injection) vulnerability in ash-project ash_ai allows a remote, unauthenticated client to execute arbitrary Elixir…

CRITICAL — NVD CVSS 10.0 (critical). Improper Control of Generation of Code (Code Injection) vulnerability in ash-project ash_ai allows a remote, unauthenticated client to execute arbitrary Elixir code. AshAi.Actions.Prompt evaluates prompt content through EEx.eval_string/2. The documented prompt: fn input, context -> … end form lets the prompt content be built from action arguments, so when a prompt action’s text…

Defender action: Confirm affected versions in the asset inventory, review the vendor advisory, and prioritize remediation by exposure.

Validation: primary source · Published: 31 Aug 2026 06:46 IST Sources: NVD

CVE-2026-15980 — The MyHome Core plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 4.4.5

CRITICAL — NVD CVSS 9.8 (critical). The MyHome Core plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 4.4.5. This is due to missing authorization in the send_link() AJAX handler and improper token validation in the activate() function. This makes it possible for unauthenticated attackers to generate an activation token for an unconfirmed user account and obtain a valid…

Defender action: Confirm affected versions in the asset inventory, review the vendor advisory, and prioritize remediation by exposure.

Validation: primary source · Published: 30 Aug 2026 10:46 IST Sources: NVD

CRITICAL — NVD CVSS 9.3 (critical). SiYuan before v3.8.1 fails to properly escape block name, alias, and memo fields in hint, backlink, and breadcrumb rendering functions. Attackers can set a block’s name to contain HTML/script tags that execute when another user views documents referencing or displaying that block.

Defender action: Confirm affected versions in the asset inventory, review the vendor advisory, and prioritize remediation by exposure.

Validation: primary source · Published: 30 Aug 2026 20:46 IST Sources: NVD

CVE-2026-82653 — SiYuan before v3.8.1 contains a stored cross-site scripting vulnerability in confirmDialog() where unescaped package names and notebook names are interpolated…

CRITICAL — NVD CVSS 9.3 (critical). SiYuan before v3.8.1 contains a stored cross-site scripting vulnerability in confirmDialog() where unescaped package names and notebook names are interpolated directly into innerHTML assignments. Attackers can submit malicious bazaar packages with HTML/script payloads in the name field that execute in users’ browsers when uninstalling packages or unlocking encrypted notebooks.

Defender action: Confirm affected versions in the asset inventory, review the vendor advisory, and prioritize remediation by exposure.

Validation: primary source · Published: 30 Aug 2026 20:46 IST Sources: NVD

CVE-2026-82542 — A weakness has been identified in Tenda HG10 300001138

CRITICAL — NVD CVSS 9.3 (critical). A weakness has been identified in Tenda HG10 300001138. Affected by this issue is the function formIPv6Routing of the file /boaform/admin/formIPv6Routing of the component Boa Web Server. This manipulation of the argument destNet causes buffer overflow. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used for attacks.

Defender action: Confirm affected versions in the asset inventory, review the vendor advisory, and prioritize remediation by exposure.

Validation: primary source · Published: 30 Aug 2026 18:46 IST Sources: NVD

CVE-2026-82645 — AVideo (current commit e01e41ecc and earlier) exposes stream credentials through the plugin/Live/view/Live_restreams/getLiveKey.json.php endpoint

CRITICAL — NVD CVSS 9.2 (critical). AVideo (current commit e01e41ecc and earlier) exposes stream credentials through the plugin/Live/view/Live_restreams/getLiveKey.json.php endpoint. Supplying a ‘token’ request parameter waives both the Live::canRestream() access gate and the restream ownership check, causing the endpoint to return any restream’s stream_key and stream_url (credentials for external platforms such as YouTube…

Defender action: Confirm affected versions in the asset inventory, review the vendor advisory, and prioritize remediation by exposure.

Validation: primary source · Published: 30 Aug 2026 20:46 IST Sources: NVD

HIGH — NVD CVSS 8.6 (high). A flaw has been found in D-Link DIR-825M 1.1.8. This impacts the function sub_41802C of the file /boafrm/formLtefotaUpgradeFibocom of the component LTE Module Firmware Upgrade. This manipulation of the argument fota_url causes stack-based buffer overflow. The attack is possible to be carried out remotely. The exploit has been published and may be used.

Defender action: Confirm affected versions in the asset inventory, review the vendor advisory, and prioritize remediation by exposure.

Validation: primary source · Published: 31 Aug 2026 05:46 IST Sources: NVD

💡 Defensive Priority

Open the linked primary or corroborating evidence before changing production systems. Confirm asset exposure, use vendor guidance for remediation, and retain the source links with the operational change record.


Collection: 570 records inspected · 81 passed collection filters · 28 passed the high-confidence evidence gate · 27/28 source endpoints available. Automated intelligence is a triage aid; verify exposure and remediation against the linked primary advisory.


Topics in this briefing

Share this post on:

Previous Post
CISO Intelligence Update — Tuesday, 01 September 2026
Next Post
CISO Intelligence Update — Sunday, 30 August 2026