Back to Blog

The most hyped CVEs of August 2026: what made noise, what's being exploited

Eamon Carroll
Eamon Carroll
Marketing Coordinator

Key Points

cvemon is our free vulnerability intelligence platform that tracks trending vulnerabilities with a hype score and adds Insights from our security team. Here's what trended in August, what's being exploited, and where the two diverged.

TL;DR

  • The loudest CVE of the month was CVE-2026-82329 in JFrog Artifactory, with a peak hype score of 62 on 31 August. Days later, CISA added it to the Known Exploited Vulnerabilities catalog (KEV).
  • Our security team flagged xss2shell (CVE-2026-64638) as one to watch: a pre-auth XSS on the WordPress login screen, exploitable by any unauthenticated attacker, with a working proof of concept already out.
  • Another 31 CVEs picked up a KEV entry this month, but didn't trend on social, including Windows IKE, SharePoint, vCenter, NetScaler, Zimbra, and PaperCut.
  • Microsoft's Entra ID bug (CVE-2026-69836) was published as a CVSS 10.0 exploited in the wild, then corrected: it wasn't exploited, and Microsoft had already mitigated it on their infrastructure.

CVE-2026-64638: WordPress core, a login-screen XSS that can reach the server (xss2shell)

What is xss2shell?

xss2shell is the nickname for CVE-2026-64638, a pre-authentication reflected XSS on the WordPress login screen that, under the right conditions, escalates to PHP code execution on the server.

What happened

xss2shell was disclosed on 7 August by the team at pwn.ai and rated high at CVSS 8.9. Every version of WordPress is listed as affected, with the fix backported as far back as 4.7, and a working proof of concept was available from the start.

Intruder's verdict

Underhyped - cvemon hype score: 0

xss2shell is a serious vulnerability affecting all supported WordPress versions. It can be exploited by any unauthenticated attacker, and a working proof of concept is available. However, to achieve remote code execution an attacker must trick a WordPress admin into opening a malicious link as part of a social engineering attack. This vulnerability is patched in WordPress 7.0.3 (released 6 August, 2026). We expected more hype on this one, but perhaps with wp2shell just behind us, it’s not impactful enough to get lots of attention.

Read more

Full activity history and live status on cvemon.

CVE-2026-82329: JFrog Artifactory, unauthenticated admin on a default install

What is CVE-2026-82329?

CVE-2026-82329 is an authentication weakness in JFrog Artifactory that, under its default configuration, lets an unauthenticated attacker with network access obtain administrative privileges. It has a critical CVSS score of 9.8, with no user interaction required.

What happened

JFrog disclosed and patched CVE-2026-82329 on 28 August. CISA added it to KEV on 2 September.

Intruder's verdict

Hype warranted - cvemon hype score: 62

Artifactory sits in the middle of a lot of build pipelines, so admin access there carries more risk than the CVSS score alone reflects.

Read more

Full activity history and live status on cvemon.

More CISA KEV additions from August 2026

The rest of August's KEV additions didn't trend, but all are confirmed exploited. 

  • Windows IKE service extensions (CVE-2026-33824): unauthenticated RCE via crafted UDP packets.
  • Microsoft SharePoint Server (CVE-2026-55040): unauthenticated JWT bypass, chainable to RCE.
  • VMware vCenter (CVE-2026-59310): unauthenticated path traversal to code execution.
  • Citrix NetScaler ADC and Gateway (CVE-2026-8452): pre-auth memory overflow, listed as denial of service.
  • Zimbra Collaboration (CVE-2026-73570): unauthenticated OS command injection via SMTP.
  • Oracle HTTP Server and WebLogic proxy plug-in (CVE-2026-21962): unauthenticated access to proxy-reachable data, CVSS 10.0.
  • PaperCut NG/MF (CVE-2026-81578, CVE-2026-82078): access-control bypass plus unsafe class loading, chained into pre-auth RCE.

Another 23 CVEs hit KEV in August (TrueConf Server, Metabase, JetBrains TeamCity, IBM Langflow, Gitea, Progress LoadMaster, Cisco ASA/FTD, N-able N-central, Apple macOS, and more), six of them backfilled from 2015-2023 after Cisco Talos reported on UAT-10147 targeting long-unpatched servers. The full month is on cvemon.

Loud in August, but not worth the hype

Microsoft's Entra ID deserialization bug (CVE-2026-69836) is a CVSS 10.0 unauthenticated RCE that trended to a hype score of 30 on 24 August, but Microsoft had already mitigated it on its own infrastructure and later corrected the advisory: it wasn't exploited in the wild.

RoguePlanet (CVE-2026-50656) re-trended to 30 after a patch bypass was published, but it's a local Defender elevation of privilege. LG SmartShare (CVE-2026-15929) hit 60 for an SQL injection in a consumer DLNA server on Windows 10 and earlier.

Keep up with what's trending on cvemon

Get our free

Ultimate Guide to Vulnerability Scanning

Learn everything you need to get started with vulnerability scanning and how to get the most out of your chosen product with our free PDF guide.