Patch Tuesday
August 2026
On the second Tuesday of each month Microsoft, Adobe, SAP, Siemens and Schneider Electric publish in bulk; Oracle on the third Tuesday of January, April, July and October. Records published that day, from our own database, sorted by action score: KEV and mature exploits first.
How it is computed: CNA stamp + publication date (two-day window, UTC). No claim of a one-to-one match with the vendor bulletin; out-of-band updates land on other days.
470 records · 3 KEV
Affecting your stack
This month's records that match the products and versions in your stack.
Sign in to see the ones matching your stack; records and notifications are free. →
Microsoft · August 11
400 · 2 KEV · 9 critical| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
66This week | CVE-2026-65660Weaponized | Microsoft SharePoint Server Remote Code Execution Vulnerabilitymicrosoft · sharepoint server · CWE-94 | High8.8 | KEV | 2.1% | Aug 11, 2026 |
58Plan | CVE-2026-68820Weaponized | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerabilitymicrosoft · windows 10 1607 · CWE-416 | High7.0 | KEV | 0.3% | Aug 11, 2026 |
39Monitor | CVE-2026-59124No exploit | Microsoft High Performance Computing (HPC) Pack Remote Code Execution Vulnerabilitymicrosoft · windows app · CWE-502 | Critical9.8 | — | 1.5% | Aug 11, 2026 |
39Monitor | CVE-2026-62815No exploit | Microsoft QUIC Remote Code Execution Vulnerabilitymicrosoft · windows 11 23h2 · CWE-416 | Critical9.8 | — | 1.0% | Aug 11, 2026 |
39Monitor | CVE-2026-62878Proof of concept | Windows DNS Server Remote Code Execution Vulnerabilitymicrosoft · windows 10 1607 · CWE-121 | Critical9.8 | — | 1.0% | Aug 11, 2026 |
39Monitor | CVE-2026-62893No exploit | Windows Deployment Services TFTP Server Remote Code Execution Vulnerabilitymicrosoft · windows 10 1607 · CWE-416 | Critical9.8 | — | 1.0% | Aug 11, 2026 |
39Monitor | CVE-2026-65768No exploit | Microsoft Teams Remote Code Execution Vulnerabilitymicrosoft · teams · CWE-22 | Critical9.8 | — | 0.9% | Aug 11, 2026 |
39Monitor | CVE-2026-65791No exploit | Windows iSCSI Target Service Remote Code Execution Vulnerabilitymicrosoft · windows 10 1607 · CWE-122 | Critical9.8 | — | 1.0% | Aug 11, 2026 |
38Monitor | CVE-2026-57104No exploit | Azure Storage Explorer Elevation of Privilege Vulnerabilitymicrosoft · azure storage explorer · CWE-79 | Critical9.6 | — | 0.9% | Aug 11, 2026 |
37Monitor | CVE-2026-50516No exploit | Microsoft Azure Kubernetes Service Elevation of Privilege Vulnerabilitymicrosoft · azure kubernetes service · CWE-306 | Critical9.4 | — | 0.8% | Aug 11, 2026 |
37Monitor | CVE-2026-70306No exploit | Microsoft Office SharePoint Spoofing Vulnerabilitymicrosoft · sharepoint server · CWE-79 | Critical9.3 | — | 1.0% | Aug 11, 2026 |
36Monitor | CVE-2026-63514No exploit | Microsoft SharePoint Server Remote Code Execution Vulnerabilitymicrosoft · sharepoint server · CWE-502 | High8.8 | — | 2.0% | Aug 11, 2026 |
- CVE-2026-6566066This week
Microsoft SharePoint Server Remote Code Execution Vulnerability
HighCVSS 8.8KEVWeaponizedEPSS 2%microsoft · sharepoint serverAug 11, 2026
- CVE-2026-6882058Plan
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
HighCVSS 7.0KEVWeaponizedEPSS 0%microsoft · windows 10 1607Aug 11, 2026
- CVE-2026-5912439Monitor
Microsoft High Performance Computing (HPC) Pack Remote Code Execution Vulnerability
CriticalCVSS 9.8No exploitEPSS 2%microsoft · windows appAug 11, 2026
- CVE-2026-6281539Monitor
Microsoft QUIC Remote Code Execution Vulnerability
CriticalCVSS 9.8No exploitEPSS 1%microsoft · windows 11 23h2Aug 11, 2026
- CVE-2026-6287839Monitor
Windows DNS Server Remote Code Execution Vulnerability
CriticalCVSS 9.8Proof of conceptEPSS 1%microsoft · windows 10 1607Aug 11, 2026
- CVE-2026-6289339Monitor
Windows Deployment Services TFTP Server Remote Code Execution Vulnerability
CriticalCVSS 9.8No exploitEPSS 1%microsoft · windows 10 1607Aug 11, 2026
- CVE-2026-6576839Monitor
Microsoft Teams Remote Code Execution Vulnerability
CriticalCVSS 9.8No exploitEPSS 1%microsoft · teamsAug 11, 2026
- CVE-2026-6579139Monitor
Windows iSCSI Target Service Remote Code Execution Vulnerability
CriticalCVSS 9.8No exploitEPSS 1%microsoft · windows 10 1607Aug 11, 2026
- CVE-2026-5710438Monitor
Azure Storage Explorer Elevation of Privilege Vulnerability
CriticalCVSS 9.6No exploitEPSS 1%microsoft · azure storage explorerAug 11, 2026
- CVE-2026-5051637Monitor
Microsoft Azure Kubernetes Service Elevation of Privilege Vulnerability
CriticalCVSS 9.4No exploitEPSS 1%microsoft · azure kubernetes serviceAug 11, 2026
- CVE-2026-7030637Monitor
Microsoft Office SharePoint Spoofing Vulnerability
CriticalCVSS 9.3No exploitEPSS 1%microsoft · sharepoint serverAug 11, 2026
- CVE-2026-6351436Monitor
Microsoft SharePoint Server Remote Code Execution Vulnerability
HighCVSS 8.8No exploitEPSS 2%microsoft · sharepoint serverAug 11, 2026
+388 moreAll records of the vendor
Adobe · August 11
52 · 1 KEV · 6 critical| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
92Now | CVE-2026-71362Weaponized | Adobe Commerce | Incorrect Authorization (CWE-863)adobe · commerce · CWE-863 | Critical9.1 | KEV | 87.5% | Aug 11, 2026 |
41Plan | CVE-2026-48362No exploit | ColdFusion | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') (CWE-78)adobe · coldfusion · CWE-78 | Critical10.0 | — | 3.5% | Aug 11, 2026 |
40Plan | CVE-2026-27302No exploit | Adobe Campaign Classic (ACC) | Incorrect Authorization (CWE-863)adobe · campaign · CWE-863 | Critical10.0 | — | 1.2% | Aug 11, 2026 |
40Plan | CVE-2026-71398No exploit | Adobe Campaign Classic (ACC) | Incorrect Authorization (CWE-863)adobe · campaign · CWE-863 | Critical10.0 | — | 1.2% | Aug 11, 2026 |
38Monitor | CVE-2026-71384No exploit | ColdFusion | Incorrect Authorization (CWE-863)adobe · coldfusion · CWE-863 | Critical9.6 | — | 0.5% | Aug 11, 2026 |
36Monitor | CVE-2026-48381No exploit | Adobe Campaign Classic (ACC) | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') (CWE-89)adobe · campaign · CWE-89 | Critical9.0 | — | 0.8% | Aug 11, 2026 |
35Monitor | CVE-2026-71386No exploit | ColdFusion | Cross-site Scripting (XSS) (CWE-79)adobe · coldfusion · CWE-79 | High8.8 | — | 0.6% | Aug 11, 2026 |
35Monitor | CVE-2026-71387No exploit | ColdFusion | Incorrect Authorization (CWE-863)adobe · coldfusion · CWE-863 | High8.8 | — | 0.5% | Aug 11, 2026 |
34Monitor | CVE-2026-21273No exploit | ColdFusion | Improper Input Validation (CWE-20)adobe · coldfusion · CWE-20 | High8.7 | — | 0.9% | Aug 11, 2026 |
34Monitor | CVE-2026-48397No exploit | Lightroom Classic | Deserialization of Untrusted Data (CWE-502)adobe · lightroom · CWE-502 | High8.6 | — | 1.0% | Aug 11, 2026 |
34Monitor | CVE-2026-48413No exploit | Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79)adobe · commerce · CWE-79 | High8.7 | — | 0.7% | Aug 11, 2026 |
34Monitor | CVE-2026-48414No exploit | Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79)adobe · commerce · CWE-79 | High8.7 | — | 0.3% | Aug 11, 2026 |
- CVE-2026-7136292Now
Adobe Commerce | Incorrect Authorization (CWE-863)
CriticalCVSS 9.1KEVWeaponizedEPSS 88%adobe · commerceAug 11, 2026
- CVE-2026-4836241Plan
ColdFusion | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') (CWE-78)
CriticalCVSS 10.0No exploitEPSS 4%adobe · coldfusionAug 11, 2026
- CVE-2026-2730240Plan
Adobe Campaign Classic (ACC) | Incorrect Authorization (CWE-863)
CriticalCVSS 10.0No exploitEPSS 1%adobe · campaignAug 11, 2026
- CVE-2026-7139840Plan
Adobe Campaign Classic (ACC) | Incorrect Authorization (CWE-863)
CriticalCVSS 10.0No exploitEPSS 1%adobe · campaignAug 11, 2026
- CVE-2026-7138438Monitor
ColdFusion | Incorrect Authorization (CWE-863)
CriticalCVSS 9.6No exploitEPSS 0%adobe · coldfusionAug 11, 2026
- CVE-2026-4838136Monitor
Adobe Campaign Classic (ACC) | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') (CWE-89)
CriticalCVSS 9.0No exploitEPSS 1%adobe · campaignAug 11, 2026
- CVE-2026-7138635Monitor
ColdFusion | Cross-site Scripting (XSS) (CWE-79)
HighCVSS 8.8No exploitEPSS 1%adobe · coldfusionAug 11, 2026
- CVE-2026-7138735Monitor
ColdFusion | Incorrect Authorization (CWE-863)
HighCVSS 8.8No exploitEPSS 1%adobe · coldfusionAug 11, 2026
- CVE-2026-2127334Monitor
ColdFusion | Improper Input Validation (CWE-20)
HighCVSS 8.7No exploitEPSS 1%adobe · coldfusionAug 11, 2026
- CVE-2026-4839734Monitor
Lightroom Classic | Deserialization of Untrusted Data (CWE-502)
HighCVSS 8.6No exploitEPSS 1%adobe · lightroomAug 11, 2026
- CVE-2026-4841334Monitor
Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79)
HighCVSS 8.7No exploitEPSS 1%adobe · commerceAug 11, 2026
- CVE-2026-4841434Monitor
Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79)
HighCVSS 8.7No exploitEPSS 0%adobe · commerceAug 11, 2026
+40 moreAll records of the vendor
SAP · August 11
1 · 0 KEV · 1 critical| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2026-58231Proof of concept | Improper Authorization in SAP Commerce Cloud (Data Hub Adapter)sap_se · sap commerce cloud (data hub adapter) · CWE-94 | Critical10.0 | — | 0.9% | Aug 11, 2026 |
- CVE-2026-5823140Plan
Improper Authorization in SAP Commerce Cloud (Data Hub Adapter)
CriticalCVSS 10.0Proof of conceptEPSS 1%sap_se · sap commerce cloud (data hub adapter)Aug 11, 2026
Siemens · August 11
17 · 0 KEV · 1 critical| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2026-58115No exploit | A vulnerability has been identified in SIMATIC IoT2050 Advanced (6ES7647-0BA00-1YA2) (All versions < V4.3.4.1 running Industrial OS with Nodsiemens · simatic iot2050 advanced · CWE-306 | Critical10.0 | — | 1.0% | Aug 11, 2026 |
34Monitor | CVE-2026-69109No exploit | A vulnerability has been identified in Siemens License Server (SLS) (All versions < V5.3).siemens · siemens license server (sls) · CWE-35 | High8.7 | — | 0.6% | Aug 11, 2026 |
33Monitor | CVE-2026-69108No exploit | A vulnerability has been identified in Siemens License Server (SLS) (All versions < V5.1).siemens · siemens license server (sls) · CWE-732 | High8.3 | — | 0.2% | Aug 11, 2026 |
29Monitor | CVE-2026-50058No exploit | A vulnerability has been identified in Solid Edge SE2025 (All versions < V225.0 Update 15), Solid Edge SE2026 (All versions < V226.0 Update siemens · solid edge se2025 · CWE-125 | High7.3 | — | 0.2% | Aug 11, 2026 |
29Monitor | CVE-2026-50059No exploit | A vulnerability has been identified in Solid Edge SE2025 (All versions < V225.0 Update 15), Solid Edge SE2026 (All versions < V226.0 Update siemens · solid edge se2025 · CWE-787 | High7.3 | — | 0.2% | Aug 11, 2026 |
29Monitor | CVE-2026-50060No exploit | A vulnerability has been identified in Solid Edge SE2025 (All versions < V225.0 Update 15), Solid Edge SE2026 (All versions < V226.0 Update siemens · solid edge se2025 · CWE-416 | High7.3 | — | 0.2% | Aug 11, 2026 |
29Monitor | CVE-2026-50061No exploit | A vulnerability has been identified in Solid Edge SE2025 (All versions < V225.0 Update 15), Solid Edge SE2026 (All versions < V226.0 Update siemens · solid edge se2025 · CWE-416 | High7.3 | — | 0.2% | Aug 11, 2026 |
29Monitor | CVE-2026-50062No exploit | A vulnerability has been identified in Solid Edge SE2025 (All versions < V225.0 Update 15), Solid Edge SE2026 (All versions < V226.0 Update siemens · solid edge se2025 · CWE-125 | High7.3 | — | 0.2% | Aug 11, 2026 |
29Monitor | CVE-2026-50063No exploit | A vulnerability has been identified in Solid Edge SE2025 (All versions < V225.0 Update 15), Solid Edge SE2026 (All versions < V226.0 Update siemens · solid edge se2025 · CWE-125 | High7.3 | — | 0.2% | Aug 11, 2026 |
29Monitor | CVE-2026-50064No exploit | A vulnerability has been identified in Solid Edge SE2025 (All versions < V225.0 Update 15), Solid Edge SE2026 (All versions < V226.0 Update siemens · solid edge se2025 · CWE-787 | High7.3 | — | 0.2% | Aug 11, 2026 |
29Monitor | CVE-2026-59086No exploit | A vulnerability has been identified in Simcenter Femap (All versions < V2606), Simcenter Nastran (All versions < V2606).siemens · simcenter femap · CWE-121 | High7.3 | — | 0.2% | Aug 11, 2026 |
29Monitor | CVE-2026-59700No exploit | A vulnerability has been identified in Simcenter Femap (All versions < V2606.0001).siemens · simcenter femap · CWE-125 | High7.3 | — | 0.2% | Aug 11, 2026 |
- CVE-2026-5811540Plan
A vulnerability has been identified in SIMATIC IoT2050 Advanced (6ES7647-0BA00-1YA2) (All versions < V4.3.4.1 running Industrial OS with Nod
CriticalCVSS 10.0No exploitEPSS 1%siemens · simatic iot2050 advancedAug 11, 2026
- CVE-2026-6910934Monitor
A vulnerability has been identified in Siemens License Server (SLS) (All versions < V5.3).
HighCVSS 8.7No exploitEPSS 1%siemens · siemens license server (sls)Aug 11, 2026
- CVE-2026-6910833Monitor
A vulnerability has been identified in Siemens License Server (SLS) (All versions < V5.1).
HighCVSS 8.3No exploitEPSS 0%siemens · siemens license server (sls)Aug 11, 2026
- CVE-2026-5005829Monitor
A vulnerability has been identified in Solid Edge SE2025 (All versions < V225.0 Update 15), Solid Edge SE2026 (All versions < V226.0 Update
HighCVSS 7.3No exploitEPSS 0%siemens · solid edge se2025Aug 11, 2026
- CVE-2026-5005929Monitor
A vulnerability has been identified in Solid Edge SE2025 (All versions < V225.0 Update 15), Solid Edge SE2026 (All versions < V226.0 Update
HighCVSS 7.3No exploitEPSS 0%siemens · solid edge se2025Aug 11, 2026
- CVE-2026-5006029Monitor
A vulnerability has been identified in Solid Edge SE2025 (All versions < V225.0 Update 15), Solid Edge SE2026 (All versions < V226.0 Update
HighCVSS 7.3No exploitEPSS 0%siemens · solid edge se2025Aug 11, 2026
- CVE-2026-5006129Monitor
A vulnerability has been identified in Solid Edge SE2025 (All versions < V225.0 Update 15), Solid Edge SE2026 (All versions < V226.0 Update
HighCVSS 7.3No exploitEPSS 0%siemens · solid edge se2025Aug 11, 2026
- CVE-2026-5006229Monitor
A vulnerability has been identified in Solid Edge SE2025 (All versions < V225.0 Update 15), Solid Edge SE2026 (All versions < V226.0 Update
HighCVSS 7.3No exploitEPSS 0%siemens · solid edge se2025Aug 11, 2026
- CVE-2026-5006329Monitor
A vulnerability has been identified in Solid Edge SE2025 (All versions < V225.0 Update 15), Solid Edge SE2026 (All versions < V226.0 Update
HighCVSS 7.3No exploitEPSS 0%siemens · solid edge se2025Aug 11, 2026
- CVE-2026-5006429Monitor
A vulnerability has been identified in Solid Edge SE2025 (All versions < V225.0 Update 15), Solid Edge SE2026 (All versions < V226.0 Update
HighCVSS 7.3No exploitEPSS 0%siemens · solid edge se2025Aug 11, 2026
- CVE-2026-5908629Monitor
A vulnerability has been identified in Simcenter Femap (All versions < V2606), Simcenter Nastran (All versions < V2606).
HighCVSS 7.3No exploitEPSS 0%siemens · simcenter femapAug 11, 2026
- CVE-2026-5970029Monitor
A vulnerability has been identified in Simcenter Femap (All versions < V2606.0001).
HighCVSS 7.3No exploitEPSS 0%siemens · simcenter femapAug 11, 2026
+5 moreAll records of the vendor
Schneider Electric · August 11
0 · 0 KEV · 0 criticalNo records in this window.