Weekly Security Roundup: August 10 to August 23, 2026

Weekly security briefing from Sherlock Forensics covering August 10 to August 23, 2026. 38 vulnerabilities analyzed: 33 critical (CVSS 9.0+) and 5 high. Grouped by vendor with patching priorities.

The Week in Security

Other had 38 vulnerabilities this week including Axios Security (CVSS 9.9 CRITICAL) (CVSS 9.9).

We tracked 38 vulnerabilities this week. 33 scored 9.0 or above. If you only have time for one thing today, scroll to "What To Do This Week" at the bottom.

Other Had a Rough Week

38 vulnerabilities across Other products this week. The worst: CVE-2025-62718 (CVSS 9.9) lets attackers run code on your systems. Patch now if you run Other.

  • CVE-2025-62718: Axios Security (CVSS 9.9 CRITICAL) (CVSS 9.9)
  • CVE-2025-62718: Axios Security (CVSS 9.9 CRITICAL) (CVSS 9.9)
  • CVE-2025-62718: Axios Security (CVSS 9.9 CRITICAL) (CVSS 9.9)
  • CVE-2025-62718: Axios Security (CVSS 9.9 CRITICAL) (CVSS 9.9)
  • CVE-2026-8985: Maxicharger Single Charger Firmware OS Command Injection (CVSS 9.8 CRITICAL) (CVSS 9.8)
  • CVE-2026-8985: Maxicharger Single Charger Firmware OS Command Injection (CVSS 9.8 CRITICAL) (CVSS 9.8)
  • CVE-2026-8985: Maxicharger Single Charger Firmware OS Command Injection (CVSS 9.8 CRITICAL) (CVSS 9.8)
  • CVE-2026-8984: Maxicharger Single Charger Firmware Code Injection (CVSS 9.8 CRITICAL) (CVSS 9.8)
  • CVE-2026-8984: Maxicharger Single Charger Firmware Code Injection (CVSS 9.8 CRITICAL) (CVSS 9.8)
  • CVE-2026-8984: Maxicharger Single Charger Firmware Code Injection (CVSS 9.8 CRITICAL) (CVSS 9.8)
  • CVE-2026-8983: Maxicharger Single Charger Firmware Security (CVSS 9.8 CRITICAL) (CVSS 9.8)
  • CVE-2026-8983: Maxicharger Single Charger Firmware Security (CVSS 9.8 CRITICAL) (CVSS 9.8)
  • CVE-2026-49875: Cxf Security (CVSS 9.8 CRITICAL) (CVSS 9.8)
  • CVE-2026-29167: Http Server Security (CVSS 9.8 CRITICAL) (CVSS 9.8)
  • CVE-2026-28780: Http Server Security (CVSS 9.8 CRITICAL) (CVSS 9.8)
  • CVE-2026-16232: Multi-Domain Security Management Security (CVSS 9.8 CRITICAL) (CVSS 9.8)
  • CVE-2026-16232: Multi-Domain Security Management Security (CVSS 9.8 CRITICAL) (CVSS 9.8)
  • CVE-2026-16232: Multi-Domain Security Management Security (CVSS 9.8 CRITICAL) (CVSS 9.8)
  • CVE-2026-14537: Mcp Toolbox For Databases Security (CVSS 9.8 CRITICAL) (CVSS 9.8)
  • CVE-2025-9242: Fireware Security (CVSS 9.8 CRITICAL) (CVSS 9.8)
  • CVE-2025-9242: Fireware Security (CVSS 9.8 CRITICAL) (CVSS 9.8)
  • CVE-2025-9242: Fireware Security (CVSS 9.8 CRITICAL) (CVSS 9.8)
  • CVE-2025-14733: Fireware Security (CVSS 9.8 CRITICAL) (CVSS 9.8)
  • CVE-2025-14733: Fireware Security (CVSS 9.8 CRITICAL) (CVSS 9.8)
  • CVE-2025-14733: Fireware Security (CVSS 9.8 CRITICAL) (CVSS 9.8)
  • CVE-2025-14733: Fireware Security (CVSS 9.8 CRITICAL) (CVSS 9.8)
  • CVE-2024-23692: Http File Server Code Injection (CVSS 9.8 CRITICAL) (CVSS 9.8)
  • CVE-2024-23692: Http File Server Code Injection (CVSS 9.8 CRITICAL) (CVSS 9.8)
  • CVE-2024-23692: Http File Server Code Injection (CVSS 9.8 CRITICAL) (CVSS 9.8)
  • CVE-2026-8037: Connection Manager For Objectscale Security (CVSS 9.6 CRITICAL) (CVSS 9.6)
  • CVE-2026-8037: Connection Manager For Objectscale Security (CVSS 9.6 CRITICAL) (CVSS 9.6)
  • CVE-2026-8037: Connection Manager For Objectscale Security (CVSS 9.6 CRITICAL) (CVSS 9.6)
  • CVE-2026-8037: Connection Manager For Objectscale Security (CVSS 9.6 CRITICAL) (CVSS 9.6)
  • CVE-2026-65767: Teams Security (CVSS 8.8 HIGH) (CVSS 8.8)
  • CVE-2026-24072: Http Server Security (CVSS 8.8 HIGH) (CVSS 8.8)
  • CVE-2025-71390: Surrealdb Security (CVSS 8.8 HIGH) (CVSS 8.8)
  • CVE-2025-71390: Surrealdb Security (CVSS 8.8 HIGH) (CVSS 8.8)
  • CVE-2024-1086: H300S Firmware Security (CVSS 7.8 HIGH) (CVSS 7.8)

By the Numbers

Total CVEs analyzed38
Critical (9.0+)33
High (7.0-8.9)5
Remote code execution38
Authentication bypass0
Cross-site scripting0
SQL injection0

What To Do This Week

One action item per vendor. Start at the top and work down.

  1. Other: Update immediately. 33 critical-severity issues patched this week.