Critical CVEs (3 of 3) — August 12, 2026

metal grunge, powerful belting vocals, lush orchestral arrangement, laid-back and groovy, frenetic breakneck tempo, clean reverb-soaked guitar leads · 5:26

Listen on 93

Lyrics

[Verse 1]
August twelfth, twenty twenty-six, four threats on the board
IBM and Keycloak, every sysadmin on guard
First up CVE-2026-10025, mark it eight point two
QRadar parsing XML, an attacker slips right through
Versions seven point six and seven point five in that range
The parseXmlPayload function is what the exploit deranges
XML External Entity — XXE is the name
Injecting rogue document references, exfiltrating the frame

[Chorus]
Four CVEs catalogued, CVSS scores don't lie
Critical infrastructure under a methodical eye
Patch the server, audit the config, no time to defer
Lacunose defenses — gaps in coverage — that's what they prefer
Patch now or bleed later, the arithmetic is clear
Four vulnerabilities dropping, August of the year

[Verse 2]
CVE-2026-16442, Keycloak's SAML broker cracked
Seven point four on the scale, identity federation attacked
IdP-initiated Single Sign-On endpoint fails to verify
Forged assertions slipping through, authentication's alibi
Federation links your users across domains and apps
One broken handshake in the chain and authorization collapses

[Chorus]
Four CVEs catalogued, CVSS scores don't lie
Critical infrastructure under a methodical eye
Patch the server, audit the config, no time to defer
Lacunose defenses — gaps in coverage — that's what they prefer
Patch now or bleed later, the arithmetic is clear
Four vulnerabilities dropping, August of the year

[Verse 3]
CVE-2026-8400, WebSphere scores eight point one
Application Server eight point five and nine point zero, not done
Liberty Continuous Delivery caught in the same snare
The ORB component inside IBM's Java layer
A malicious actor manipulates the object request broker
Remote code execution potential — no casual poker
Eight point one means critical, don't shelve it for a sprint
The JVM's trust model cracking at the weakest glint

[Bridge]
Now CVE-2026-17617 closes out the set
Eight point five is the highest score, most dangerous yet
IBM Application Gateway Operator, versions twenty-two through June
Server-Side Request Forgery when URLs aren't vetted by the system's immune
Custom resource definitions pointing inward at private topology
Attackers bounce requests off your own server's epistemology —
That rare word means the framework of what the system thinks it knows
Weaponize its own assumptions, redirect internal flows

[Chorus]
Four CVEs catalogued, CVSS scores don't lie
Critical infrastructure under a methodical eye
Patch the server, audit the config, no time to defer
Lacunose defenses — gaps in coverage — that's what they prefer
Patch now or bleed later, the arithmetic is clear
Four vulnerabilities dropping, August of the year

[Outro]
QRadar, Keycloak, WebSphere, Gateway Operator — four targets named
NVD confirmed, CVSS scored, nobody here gets to play unclaimed
Check your versions, cross-reference, apply every vendor fix
August twelfth twenty twenty-six — the clock already ticks

← Critical CVEs (2 of 3) — August 12, 2026 | IT Security News — August 12, 2026 →