(TLP CLEAR) Weekly Vulnerabilities to Prioritize – August 13, 2026
Created: Thursday, August 13, 2026 - 14:31
Categories: Cybersecurity, Security Preparedness
The below vulnerabilities have been identified by WaterISAC analysts as important for water and wastewater utilities to prioritize in their vulnerability management efforts. WaterISAC shares critical vulnerabilities that affect widely used products and may be under active exploitation. WaterISAC draws additional awareness in alerts and advisories when vulnerabilities are confirmed to be impacting, or have a high likelihood of impacting, water and wastewater utilities. Members are encouraged to regularly review these vulnerabilities, many of which are often included in CISA’s Known Exploited Vulnerabilities (KEV) Catalog.
Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software Vulnerability
See WaterISAC’s recent notification regarding this vulnerability
Progress LoadMaster Command Injection Vulnerability
CVSS v3.1: 9.6
CVEs: CVE-2026-8037
Description: OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an un-authenticated attacker to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in multiple command endpoints. CISA added this vulnerabilities to its Known Exploited Vulnerability Catalog.
Source: https://community.progress.com/s/article/LoadMaster-Critical-Security-Bulletin-June-2026-CVE-2026-8037-CVE-2026-33691
Microsoft Windows Ancillary Function Driver for WinSock Use-After-Free Vulnerability
CVSS v3.1: 7.0
CVEs: CVE-2026-68820
Description: Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. CISA added this vulnerabilities to its Known Exploited Vulnerability Catalog.
Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68820
Metabase SQL Injection Vulnerability
CVSS v4.0: 10.0
CVEs: CVE-2026-72898
Description: Metabase allows a remote, unauthenticated attacker to inject arbitrary SQL via the ‘/reset_password’ database endpoint and gain administrator access to the connected Metabase instance. CISA added this vulnerabilities to its Known Exploited Vulnerability Catalog.
Source: https://www.metabase.com/blog/security-update
Grafana MCP Server Vulnerability
CVSS v3.1: 9.1
CVEs: CVE-2026-19516
Description: A caller-supplied X-Grafana-URL request header controls the destination of mcp-grafana’s outbound requests, and the grafana_api_request tool lets the caller also choose the HTTP method, path, and body. Because the destination is not restricted to the configured Grafana instance, a caller can direct requests at internal, loopback, and link-local network services (including metadata endpoints) and read the responses, resulting in server-side request forgery. The fix for CVE-2026-15583 prevented the configured service-account token from being sent to unintended destinations but did not restrict the destinations themselves.
Source: https://grafana.com/security/security-advisories/cve-2026-19516
