[Verse 1] August twelfth, twenty twenty-six, four threats on the board IBM and Keycloak, every sysadmin on guard First up CVE-2026-10025, mark it eight point two QRadar parsing XML, an attacker slips right through Versions seven point six and seven point five in that range The parseXmlPayload function is what the exploit deranges XML External Entity — XXE is the name Injecting rogue document references, exfiltrating the frame [Chorus] Four CVEs catalogued, CVSS scores don't lie Critical infrastructure under a methodical eye Patch the server, audit the config, no time to defer Lacunose defenses — gaps in coverage — that's what they prefer Patch now or bleed later, the arithmetic is clear Four vulnerabilities dropping, August of the year [Verse 2] CVE-2026-16442, Keycloak's SAML broker cracked Seven point four on the scale, identity federation attacked IdP-initiated Single Sign-On endpoint fails to verify Forged assertions slipping through, authentication's alibi Federation links your users across domains and apps One broken handshake in the chain and authorization collapses [Chorus] Four CVEs catalogued, CVSS scores don't lie Critical infrastructure under a methodical eye Patch the server, audit the config, no time to defer Lacunose defenses — gaps in coverage — that's what they prefer Patch now or bleed later, the arithmetic is clear Four vulnerabilities dropping, August of the year [Verse 3] CVE-2026-8400, WebSphere scores eight point one Application Server eight point five and nine point zero, not done Liberty Continuous Delivery caught in the same snare The ORB component inside IBM's Java layer A malicious actor manipulates the object request broker Remote code execution potential — no casual poker Eight point one means critical, don't shelve it for a sprint The JVM's trust model cracking at the weakest glint [Bridge] Now CVE-2026-17617 closes out the set Eight point five is the highest score, most dangerous yet IBM Application Gateway Operator, versions twenty-two through June Server-Side Request Forgery when URLs aren't vetted by the system's immune Custom resource definitions pointing inward at private topology Attackers bounce requests off your own server's epistemology — That rare word means the framework of what the system thinks it knows Weaponize its own assumptions, redirect internal flows [Chorus] Four CVEs catalogued, CVSS scores don't lie Critical infrastructure under a methodical eye Patch the server, audit the config, no time to defer Lacunose defenses — gaps in coverage — that's what they prefer Patch now or bleed later, the arithmetic is clear Four vulnerabilities dropping, August of the year [Outro] QRadar, Keycloak, WebSphere, Gateway Operator — four targets named NVD confirmed, CVSS scored, nobody here gets to play unclaimed Check your versions, cross-reference, apply every vendor fix August twelfth twenty twenty-six — the clock already ticks
← Critical CVEs (2 of 3) — August 12, 2026 | IT Security News — August 12, 2026 →