Skip to content
Weekly Signal
Demonstration intelligence Updated 18:42 UTC

Daily operational briefing

What changed?

The evidence that changed vulnerability priority today, distilled into the decisions that matter.

Briefing date 17 August 2026 UTC reporting window

Today’s movement

2 New CISA KEV
7 Major EPSS movers
3 Newly exploited
3 Perimeter alerts
4 Key advisories

Analyst summary

Edge infrastructure remains the clearest priority. Two vulnerabilities gained authoritative exploitation evidence, while several high-CVSS desktop issues remain low signal.

Prioritised by evidence

What I’d look at first

Open Threat Radar
Priority1
CVE-2026-12345Fortinet · FortiOS

Active exploitation and KEV inclusion now combine with very high EPSS on an internet-facing edge product.

Confirm exposure, patch now and review appliance activity.
Signal94+12 today
Priority2
CVE-2026-23108Microsoft · Exchange Server

A public exploit and KEV inclusion materially increase the likelihood of targeting.

Patch exposed servers and run compromise checks.
Signal93+9 today
Priority3
CVE-2026-18472Cisco · Secure Firewall

EPSS is rising and a proof of concept is public, but exploitation is not yet confirmed.

Validate affected versions and internet exposure today.
Signal47+8 today

Evidence changes

Change feed

New KEVSignal 82 → 94
CVE-2026-12345

FortiOS command injection

Added to the demonstration KEV set after exploitation evidence was reported.

New KEVSignal 80 → 89
CVE-2026-23108

Exchange Server remote code execution

Public exploit availability and KEV status changed the remediation window.

EPSS mover+22.3 points
CVE-2026-18472

Cisco Secure Firewall memory corruption

EPSS increased from 52.1% to 74.4% in the fictional data set.

Exposure watchSignal unchanged
CVE-2026-29811

Ivanti Connect Secure access-control bypass

No confirmed exploitation, but the product remains attractive and commonly exposed.

Vendor intelligence

Significant advisories

FortinetFortiOS security updatePatch available · Immediate
MicrosoftExchange Server security updatePatch available · Immediate
CiscoSecure Firewall software advisoryFixed releases listed · Accelerated
AdobeAcrobat security bulletinUpdate available · Routine

Context over severity

What I wouldn’t overreact to

CVE-2026-31704

Adobe Acrobat memory safety flaw

CVSS 9.8, but EPSS remains 0.4% with no exploitation evidence. Keep it in the normal patch cycle.

CVE-2026-34019

Local privilege escalation

Requires authenticated local access and has no public exploit or credible activity.

CVE-2026-35287

Development dependency denial of service

Limited production exposure and no meaningful movement in exploitation probability.

Demonstration dataThis briefing uses fictional records to demonstrate the product experience. It must not be treated as current vulnerability or threat advice.