Continue reading the full briefing.
Why it matters: GitHub Advisory Database codeigniter4/framework participates in the path from source code to production. A weakness can inherit runner permissions, build secrets, trusted artifacts, or deployment access.
What to verify: Trace untrusted input through pull requests and jobs, review token scope, isolate runners, pin trusted dependencies, and rebuild affected artifacts after remediation.
Open the original source record
CVE-2026-63221: CodeIgniter: SQL injection in Query Builder deleteBatch() when used with where() conditions
### Impact A SQL injection vulnerability exists in the Query Builder's `deleteBatch()` method. When `deleteBatch()` is used together with `where()` conditions, the bound values from the `WHERE` clause are substituted directly into the generated SQL **with their escape flag ignored**, so they are never escaped or quoted. If an application passes user-controlled input to `where()` before calling `deleteBatch()`, that input is interpreted as SQL rather than as a value, allowing SQL injection. This affects only…
Why it matters: GitHub Advisory Database codeigniter4/framework participates in the path from source code to production. A weakness can inherit runner permissions, build secrets, trusted artifacts, or deployment access.
What to verify: Trace untrusted input through pull requests and jobs, review token scope, isolate runners, pin trusted dependencies, and rebuild affected artifacts after remediation.
Craft CMS: Passkey login accepts replayed WebAuthn assertions
Craft CMS passkey login accepts WebAuthn requestOptions from the unauthenticated login request body and does not persist the updated credential counter returned by the WebAuthn assertion validator. A captured passkey login request body can therefore be replayed because the old challenge is accepted again, and the stored credential counter remains stale. Craft CMS 5.10.3 and current `5.x` HEAD accept `PublicKeyCredentialRequestOptions` from the unauthenticated `users/login-with-passkey` request body and do not persist the updated `PublicKeyCredentialSource` returned/mutated by…
Why it matters: GitHub Advisory Database craftcms/cms participates in the path from source code to production. A weakness can inherit runner permissions, build secrets, trusted artifacts, or deployment access.
What to verify: Trace untrusted input through pull requests and jobs, review token scope, isolate runners, pin trusted dependencies, and rebuild affected artifacts after remediation.
CVE-2026-62836: Improper restriction of communication channel to intended endpoints in Azure SQL Managed…
Improper restriction of communication channel to intended endpoints in Azure SQL Managed Instance allows an unauthorized attacker to elevate privileges over a network.
Why it matters: CVE-2026-62836 can involve both provider-managed software and tenant-owned identity or exposure settings. Those responsibilities must be separated before the finding can be closed.
What to verify: Check affected accounts and regions, public endpoints, identity paths, workload images, provider status, and centralized audit logs that prove the repaired control is active.
CVE-2026-18556: N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability
Authentication bypass using an alternate path or channel vulnerability in N-able N-central allows Authentication Bypass. This issue affects N-central: through 2026.1.
Why it matters: N-able N-central concerns a trust decision rather than a cosmetic defect. If the affected path is reachable, an attacker may cross a role, tenant, or login boundary.
What to verify: Reproduce the expected access checks safely, identify exposed roles and tenants, invalidate risky sessions or tokens, patch the decision point, and retest denied cases.
Coverage by security desk
Exploited and critical vulnerabilities
- CVE-2026-8037: Progress LoadMaster Command Injection Vulnerability – CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-8037 Progress LoadMaster Command Injection Vulnerability This type of…
- CVE-2026-63077: JetBrains TeamCity Deserialization of Untrusted Data Vulnerability – CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-63077 JetBrains TeamCity Deserialization of Untrusted Data Vulnerability This…
- CVE-2026-18577: N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability – CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-18577 N-able N-central Authentication Bypass Using an Alternate Path…
Windows and Microsoft security
- ClamAV Vulnerabilities Affecting Cisco Products: August 2026 – Multiple vulnerabilities in ClamAV could allow a remote attacker to cause a denial of service (DoS) condition, interrupting scanning operations. For more information about these vulnerabilities, see the…
- Microsoft named a Leader in the KuppingerCole Leadership Compass for Cloud Native Application Protection Platforms (CNAPP) – Learn why KuppingerCole named Microsoft a Leader in its Leadership Compass: Cloud Native Application Protection Platforms report. The post Microsoft named a Leader in the KuppingerCole Leadership Compass…
Network, VPN, firewall, and edge security
- CVE-2026-62836: Improper restriction of communication channel to intended endpoints in Azure SQL Managed… – Improper restriction of communication channel to intended endpoints in Azure SQL Managed Instance allows an unauthorized attacker to elevate privileges over a network.
- SonicWall Global VPN Client (GVC) Out-of-bounds kernel memory read vulnerability – SonicWall Global VPN Client version 4.10.8.1108 and earlier is vulnerable to an out-of-bounds kernel memory read in the SWIPsec.sys driver, which could allow a local attacker to cause…
Web applications, APIs, and WordPress
- CVE-2026-9198: IBM Langflow Code Injection Vulnerability – CISA has added three new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-9198 IBM Langflow Code Injection Vulnerability CVE-2026-18556 N-able N-central…
- CVE-2026-63223: CodeIgniter: Uploaded file extension validation bypass in `is_image` and `mime_in` rules – ### Impact This is an unsafe file upload validation vulnerability that can lead to remote code execution in vulnerable application configurations. Applications are impacted when they: – validate…
- CVE-2026-63221: CodeIgniter: SQL injection in Query Builder deleteBatch() when used with where() conditions – ### Impact A SQL injection vulnerability exists in the Query Builder's `deleteBatch()` method. When `deleteBatch()` is used together with `where()` conditions, the bound values from the `WHERE` clause…
DevOps and software supply chain
- CVE-2026-71851: crypto-js: Insufficient Entropy in Cryptographic Secret Generation via Vulnerable CryptoJS Dependency Chain – ### Summary `CryptoJS.lib.WordArray.random()` in affected versions is not a cryptographically secure random number generator. Nominal requests for 128 or 256 bits of entropy produce effective search spaces of…
- CVE-2026-63223: CodeIgniter: Uploaded file extension validation bypass in `is_image` and `mime_in` rules – ### Impact This is an unsafe file upload validation vulnerability that can lead to remote code execution in vulnerable application configurations. Applications are impacted when they: – validate…
- CVE-2026-63221: CodeIgniter: SQL injection in Query Builder deleteBatch() when used with where() conditions – ### Impact A SQL injection vulnerability exists in the Query Builder's `deleteBatch()` method. When `deleteBatch()` is used together with `where()` conditions, the bound values from the `WHERE` clause…
AI and agent security
- CVE-2026-9198: IBM Langflow Code Injection Vulnerability – CISA has added three new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-9198 IBM Langflow Code Injection Vulnerability CVE-2026-18556 N-able N-central…
- Responding to the next frontier of critical cyber capabilities – OpenAI is sharing preliminary cybersecurity evaluations for Astra and the steps we’re taking to strengthen safeguards and security controls.
Cloud and identity controls
- CVE-2026-62836: Improper restriction of communication channel to intended endpoints in Azure SQL Managed… – Improper restriction of communication channel to intended endpoints in Azure SQL Managed Instance allows an unauthorized attacker to elevate privileges over a network.
- Microsoft named a Leader in the KuppingerCole Leadership Compass for Cloud Native Application Protection Platforms (CNAPP) – Learn why KuppingerCole named Microsoft a Leader in its Leadership Compass: Cloud Native Application Protection Platforms report. The post Microsoft named a Leader in the KuppingerCole Leadership Compass…
Priority actions for today
- Confirm exposure: match CVEs and vendor advisories to exact products, versions, internet reachability, and business-critical roles.
- Move exploited items first: patch, isolate, or disable affected paths for confirmed known-exploited technology before routine CVSS-only work.
- Preserve evidence: review authentication, process, endpoint, network, and management-plane telemetry before rebooting or replacing an affected system.
- Validate remediation: prove that the fixed version is running, required restarts are complete, controls still report healthy, and exceptions have owners and deadlines.
Primary sources and references
- CISA Known Exploited Vulnerabilities: CVE-2026-8037: Progress LoadMaster Command Injection Vulnerability
- CISA Cybersecurity Advisories: CVE-2026-8037: Progress LoadMaster Command Injection Vulnerability
- CISA Known Exploited Vulnerabilities: CVE-2026-63077: JetBrains TeamCity Deserialization of Untrusted Data Vulnerability
- CISA Cybersecurity Advisories: CVE-2026-63077: JetBrains TeamCity Deserialization of Untrusted Data Vulnerability
- CISA Known Exploited Vulnerabilities: CVE-2026-18577: N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability
- NIST National Vulnerability Database: CVE-2026-18577: An incomplete patch for CVE-2026-18556 allows for authentication bypass and account takeover…
- CISA Cybersecurity Advisories: CISA Adds One Known Exploited Vulnerability to Catalog
- CISA Known Exploited Vulnerabilities: CVE-2026-9198: IBM Langflow Code Injection Vulnerability
- CISA Cybersecurity Advisories: CVE-2026-9198: IBM Langflow Code Injection Vulnerability
- GitHub Advisory Database: CVE-2026-71851: crypto-js: Insufficient Entropy in Cryptographic Secret Generation via Vulnerable CryptoJS Dependency Chain
- GitHub Advisory Database: CVE-2026-63223: CodeIgniter: Uploaded file extension validation bypass in `is_image` and `mime_in` rules
- GitHub Advisory Database: CVE-2026-63221: CodeIgniter: SQL injection in Query Builder deleteBatch() when used with where() conditions
- GitHub Advisory Database: Craft CMS: Passkey login accepts replayed WebAuthn assertions
- NIST National Vulnerability Database: CVE-2026-62836: Improper restriction of communication channel to intended endpoints in Azure SQL Managed…
- CISA Known Exploited Vulnerabilities: CVE-2026-18556: N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability
- NIST National Vulnerability Database: CVE-2026-18556: Authentication bypass using an alternate path or channel vulnerability in N-able N-central…
- SonicWall PSIRT: SonicWall Global VPN Client (GVC) Out-of-bounds kernel memory read vulnerability
- Cisco Security Advisories: ClamAV Vulnerabilities Affecting Cisco Products: August 2026
- WordPress Security Releases: WordPress 7.0.3 release
- Microsoft Security Blog: Microsoft named a Leader in the KuppingerCole Leadership Compass for Cloud Native Application Protection Platforms (CNAPP)
- GitHub Security Blog: How we took malware advisories beyond npm
- OpenAI News: Responding to the next frontier of critical cyber capabilities
Need to add context to this briefing?
Send corrections, security tips, source updates, or collaboration notes through the contact page so the editorial team can review them properly.


