Weekly Security Roundup: August 03 to August 16, 2026

Weekly security briefing from Sherlock Forensics covering August 03 to August 16, 2026. 38 vulnerabilities analyzed: 29 critical (CVSS 9.0+) and 9 high. Grouped by vendor with patching priorities.

The Week in Security

Other had 29 vulnerabilities this week including Goanywhere Managed File Transfer Deserialization of Untrusted Data (CVSS 10.0 CRITICAL) (CVSS 10.0). Microsoft got hit with a CVSS 10.0 for Netweaver Security (CVSS 10.0 CRITICAL). Mozilla Firefox had 3 vulnerabilities this week including Firefox Security (CVSS 9.8 CRITICAL) (CVSS 9.8).

We tracked 38 vulnerabilities this week. 29 scored 9.0 or above. If you only have time for one thing today, scroll to "What To Do This Week" at the bottom.

Other Had a Rough Week

29 vulnerabilities across Other products this week. The worst: CVE-2025-10035 (CVSS 10.0) lets attackers run code on your systems. Patch now if you run Other.

  • CVE-2025-10035: Goanywhere Managed File Transfer Deserialization of Untrusted Data (CVSS 10.0 CRITICAL) (CVSS 10.0)
  • CVE-2024-51378: Cyberpanel OS Command Injection (CVSS 10.0 CRITICAL) (CVSS 10.0)
  • CVE-2024-51378: Cyberpanel OS Command Injection (CVSS 10.0 CRITICAL) (CVSS 10.0)
  • CVE-2024-51378: Cyberpanel OS Command Injection (CVSS 10.0 CRITICAL) (CVSS 10.0)
  • CVE-2024-42467: Openhab Web Interface Security (CVSS 10.0 CRITICAL) (CVSS 10.0)
  • CVE-2024-42467: Openhab Web Interface Security (CVSS 10.0 CRITICAL) (CVSS 10.0)
  • CVE-2025-62718: Axios Security (CVSS 9.9 CRITICAL) (CVSS 9.9)
  • CVE-2025-62718: Axios Security (CVSS 9.9 CRITICAL) (CVSS 9.9)
  • CVE-2025-62718: Axios Security (CVSS 9.9 CRITICAL) (CVSS 9.9)
  • CVE-2026-49875: Cxf Security (CVSS 9.8 CRITICAL) (CVSS 9.8)
  • CVE-2026-14537: Mcp Toolbox For Databases Security (CVSS 9.8 CRITICAL) (CVSS 9.8)
  • CVE-2026-14537: Mcp Toolbox For Databases Security (CVSS 9.8 CRITICAL) (CVSS 9.8)
  • CVE-2026-12569: Flexplm Deserialization of Untrusted Data (CVSS 9.8 CRITICAL) (CVSS 9.8)
  • CVE-2024-55956: Harmony Security (CVSS 9.8 CRITICAL) (CVSS 9.8)
  • CVE-2024-50623: Harmony Security (CVSS 9.8 CRITICAL) (CVSS 9.8)
  • CVE-2024-21762: Fortiproxy Security (CVSS 9.8 CRITICAL) (CVSS 9.8)
  • CVE-2024-21762: Fortiproxy Security (CVSS 9.8 CRITICAL) (CVSS 9.8)
  • CVE-2024-21762: Fortiproxy Security (CVSS 9.8 CRITICAL) (CVSS 9.8)
  • CVE-2026-8037: Connection Manager For Objectscale Security (CVSS 9.6 CRITICAL) (CVSS 9.6)
  • CVE-2026-8037: Connection Manager For Objectscale Security (CVSS 9.6 CRITICAL) (CVSS 9.6)
  • CVE-2024-24919: Quantum Spark Firmware Security (CVSS 8.6 HIGH) (CVSS 8.6)
  • CVE-2024-24919: Quantum Spark Firmware Security (CVSS 8.6 HIGH) (CVSS 8.6)
  • CVE-2024-24919: Quantum Spark Firmware Security (CVSS 8.6 HIGH) (CVSS 8.6)
  • CVE-2025-22225: Esxi Security (CVSS 8.2 HIGH) (CVSS 8.2)
  • CVE-2025-22225: Esxi Security (CVSS 8.2 HIGH) (CVSS 8.2)
  • CVE-2025-22225: Esxi Security (CVSS 8.2 HIGH) (CVSS 8.2)
  • CVE-2024-1086: H300S Firmware Security (CVSS 7.8 HIGH) (CVSS 7.8)
  • CVE-2024-1086: H300S Firmware Security (CVSS 7.8 HIGH) (CVSS 7.8)
  • CVE-2024-11667: Zld Path Traversal (CVSS 7.5 HIGH) (CVSS 7.5)

Microsoft Hit With CVSS 10.0

CVE-2025-31324 scores a 10.0. Microsoft lets attackers run code on your systems.

Mozilla Firefox: 3 Critical Flaws at Once

3 vulnerabilities across Mozilla Firefox products this week. The worst: CVE-2024-9680 (CVSS 9.8) lets attackers run code on your systems. Patch now if you run Mozilla Firefox.

Linux Kernel: 5 Critical Flaws at Once

5 vulnerabilities across Linux Kernel products this week. The worst: CVE-2025-38209 (CVSS 9.8) lets attackers run code on your systems. Patch now if you run Linux Kernel.

By the Numbers

Total CVEs analyzed38
Critical (9.0+)29
High (7.0-8.9)9
Remote code execution38
Authentication bypass0
Cross-site scripting0
SQL injection0

What To Do This Week

One action item per vendor. Start at the top and work down.

  1. Other: Update immediately. 20 critical-severity issues patched this week.
  2. Microsoft: Update immediately. 1 critical-severity issues patched this week.
  3. Mozilla Firefox: Update immediately. 3 critical-severity issues patched this week.
  4. Linux Kernel: Update immediately. 5 critical-severity issues patched this week.