Security Vulnerabilities Is Surging: 2 - August 3 2026 Roundup

2 new Security Vulnerabilities CVEs were disclosed this week, led by CVE-2026-18588 at CVSS 9.8. Sherlock Forensics analyzes the trend, its impact on Incident Response environments and what organizations should do now. Security assessments from $1,500 CAD.

Security Vulnerabilities Dominates This Week's CVE Disclosures

2 of the 10 CVEs published this week involve Security Vulnerabilities. The highest severity is CVE-2026-18588 at CVSS 9.8. This is not a one-off. Security Vulnerabilities vulnerabilities have been climbing steadily through 2026 and the trend shows no sign of slowing.

Meanwhile, cybersecurity news outlets are reporting: "Chinese Threat Actor Uses Leaked DarkSword Kit to Deploy GHOSTBLADE on iOS" which reinforces the pattern we are seeing in the raw vulnerability data.

This Week's Highest-Severity CVEs
CVE ID CVSS Description
CVE-2026-185889.8A vulnerability has been found in Wavlink WL-NU516U1 708c073-mt7628. This affects the function fgets of the file nas.cgi. The manipulation of the argu
CVE-2026-185899.8A vulnerability was found in Wavlink WL-NU516U1 708c073-mt7628. This impacts the function change_password of the file nas.cgi. The manipulation of the
CVE-2026-653219.8PyAthena prior to 3.35.4 contains a sql injection vulnerability that allows unauthenticated attackers to inject arbitrary SQL by exploiting improper q

Why Incident Response Teams Should Pay Attention

Security Vulnerabilities vulnerabilities directly affect Incident Response environments. In our 20 years of testing, we consistently find that organizations assume their existing controls catch these issues. They rarely do. Automated scanners flag the obvious instances but miss the chained exploitation paths that turn a medium-severity Security Vulnerabilities finding into a critical data breach.

If your last penetration test was more than 6 months ago, the attack surface has changed. New endpoints, updated dependencies and configuration drift all introduce fresh exposure that did not exist at the time of your last assessment.

What to Do This Week

Review affected systems
Check whether your applications or infrastructure use components affected by CVE-2026-18588 and the other CVEs listed above. Patch where possible.
Test your controls
Verify that your WAF, EDR and monitoring tools actually detect Security Vulnerabilities exploitation attempts. Configuration alone is not evidence of protection.
Schedule a focused assessment
A targeted Incident Response security assessment validates whether your defenses hold against the specific attack patterns trending this week. Quick audits start at $1,500 CAD.