InfoSecNexus briefing

Live Cybersecurity Brief for August 18, 2026: Active Threats, CVEs, and Vendor Advisories

Cybersecurity analyst monitoring a holographic shield and threat map

A continuously updated operational brief built from current government, vulnerability-database, open-source, and vendor security advisories.

As of August 18, 2026 3:15 pm IST, this edition tracks 16 prioritized developments, including 1 known-exploited entries, 9 critical records, and 0 high-severity records. Treat the list as a starting point: final urgency depends on deployed versions, exposure, privilege, and available compensating controls.

Executive security snapshot

The highest-value work is to connect each advisory to a real asset and an accountable owner. Known exploitation and direct vendor warnings move ahead of ordinary backlog scoring, while newly disclosed records still require version and reachability checks before a response team declares exposure.

Top developments for August 18, 2026

CVE-2025-62593: Ray-Project Ray Code Injection Vulnerability

CISA Cybersecurity Advisories | August 17, 2026 5:30 pm IST | Known Exploited

Ray-Project Ray contains a code injection vulnerability that could allow remote code execution. Developers using Ray as a development tool may be exposed to this vulnerability exploitable through Firefox and Safari.

Why it matters: Ray-Project Ray may let attacker-controlled input cross into an interpreter or executable path, which can turn a reachable application feature into data access or code execution.

What to verify: Confirm the vulnerable route and authentication state, deploy the fixed release, review suspicious parameters and child processes, and test authorization boundaries after patching.

Open the original source record

CVE-2026-15748: The Forminator Forms plugin for WordPress is vulnerable to Arbitrary File Upload…

NIST National Vulnerability Database | August 18, 2026 11:46 am IST | CRITICAL | CVSS 9.8

The Forminator Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.56.1 via the handle_file_upload function. This is due to insufficient file type validation in handle_file_upload, where the dangerous-extension blocklist performs exact-key matching that is bypassed by pipe-alternative MIME type keys, combined with a public submission handler that trusts attacker-controlled upload field configuration injected via a forged Select field value. This makes it possible for unauthenticated attackers…

Why it matters: The Forminator Forms plugin for WordPress is vulnerable to Arbitrary File Upload… may sit directly on a public website, so a vulnerable core, plugin, or theme can turn a routine content system into an initial-access path.

What to verify: Record the exact WordPress core and extension versions, confirm whether the affected feature is enabled, review administrator accounts, and inspect web requests before and after the update.

Open the original source record

CVE-2026-75094: A flaw has been found in COMFAST CF-N1-S 2.6.0.1. This impacts the…

NIST National Vulnerability Database | August 18, 2026 7:47 am IST | CRITICAL | CVSS 9.1

A flaw has been found in COMFAST CF-N1-S 2.6.0.1. This impacts the function sub_44B438 of the file /cgi-bin/mbox-config?method=SET&section=ptest_ssid of the component CGI Interface. This manipulation of the argument ssid causes os command injection. Remote exploitation of the attack is possible. The exploit has been published and may be used.

Why it matters: A flaw has been found in COMFAST CF-N1-S 2.6.0.1. This impacts the… belongs in an exploit-led queue only after the affected product is matched to a reachable asset and accountable owner.

What to verify: Separate confirmed applicability from broad advisory language, assign the remediation decision, and keep any exception visible with an expiry date.

Open the original source record

CVE-2026-75110: MemOS is a memory operating system for LLMs and AI agents. In…

NIST National Vulnerability Database | August 18, 2026 2:46 am IST | CRITICAL | CVSS 9.8

MemOS is a memory operating system for LLMs and AI agents. In deployments where authentication is enabled (AUTH_ENABLED=true) but the undocumented, defaultless INTERNAL_SERVICE_SECRET environment variable is unset, the is_internal_request() check in src/memos/api/middleware/auth.py fails open: os.getenv("INTERNAL_SERVICE_SECRET") returns None and a request omitting the X-Internal-Service header also yields None, so the comparison None == None evaluates true. The request is then treated as a trusted internal principal and granted scopes: ["all"]. As a result, an unauthenticated remote…

Why it matters: MemOS is a memory operating system for LLMs and AI agents. In… should be evaluated as part of the complete model, agent, data, connector, and tool-permission system.

What to verify: Confirm the affected version and reachable component, preserve useful telemetry, apply the publisher guidance, and record the evidence used to close the item.

Open the original source record

CVE-2026-75106: OpnForm derives editable-submission secrets from sequential row identifiers using Hashids with an…

NIST National Vulnerability Database | August 18, 2026 2:46 am IST | CRITICAL | CVSS 9.3

OpnForm derives editable-submission secrets from sequential row identifiers using Hashids with an empty default salt, allowing unauthenticated attackers to compute hashes for any submission. Attackers can read other respondents' full submission data through the submission-fetch endpoint or overwrite submissions by supplying predicted hashes to the answer endpoint.

Why it matters: OpnForm derives editable-submission secrets from sequential row identifiers using Hashids with an… belongs in an exploit-led queue only after the affected product is matched to a reachable asset and accountable owner.

What to verify: Start with asset ownership and exposure, compare the fixed release with the deployed build, and validate both security behavior and service health afterward.

Open the original source record

CVE-2026-66795: A flaw was found in the managedcluster-import-controller. The Certificate Signing Request (CSR)…

NIST National Vulnerability Database | August 18, 2026 2:46 am IST | CRITICAL | CVSS 9.1

Continue reading the full briefing.

Corrections and tips

Need to add context to this briefing?

Send corrections, security tips, source updates, or collaboration notes through the contact page so the editorial team can review them properly.

Contact InfoSecNexus