Compiled from 52 monitored sources · 777 articles reviewed
Today’s Briefing
CVE-2026-8452 in Citrix NetScaler ADC and NetScaler Gateway now has a public proof-of-concept demonstrating remote code execution, according to NHS Digital reporting. CISA published two industrial control system advisories: CVE-2025-7639 in AVEVA Enterprise SCADA 2024 and 2025, a deserialisation flaw enabling code execution, and CVE-2026-19188 in Haiwell IoT Cloud HMI Gateway 3.40.1.12, an OS command injection exploitable with root privileges. Microsoft released its August 2026 update bundle covering 64 CVEs; the watchlist includes CVE-2026-68820, a use-after-free in the Windows Ancillary Function Driver for WinSock marked as exploited, alongside five critical-severity flaws in Windows components and SharePoint. Kaspersky and Cisco Talos both published actor research today, though neither directly affects patching priorities for UK defenders.
Top Stories
- CC-4832 - Proof-of-Concept Exploit Released for Citrix NetScaler ADC and NetScaler Gateway Vulnerability
- AVEVA Enterprise SCADA
- Haiwell IoT Cloud HMI Gateway
Full brief available to subscribers
The complete operator brief — action items with patch deadlines, the vulnerability appendix and named actor activity — goes out by email each morning. Subscribe free to receive it.