HebridesCyber
← back to Security Weekly

This Week in Small Business Security — 2026-08-31

31 August 2026·2 min read

This week: FulcrumSec claims Manchester Airports hack, theft of 86 GB of data, plus 0 sites scanned and what we found.

A roundup of what's actually happened in security over the past week — real incidents and newly disclosed vulnerabilities, not filler.

In the news

Newly published, high-severity CVEs

  • CVE-2026-66897 (CVSS 9.9, CRITICAL) — A path traversal vulnerability in LXD's instance template processing allows an attacker with container edit permissions, or any user launching a crafted image, to overwrite arbitrary files on the host system as root. Whe…
  • CVE-2026-28165 (CVSS 9.8, CRITICAL) — Unauthenticated Privilege Escalation in Digits <= 9.2 versions.
  • CVE-2026-32558 (CVSS 9.8, CRITICAL) — Unauthenticated Privilege Escalation in Affiliate Pro - Affiliate Program for WooCommerce & WordPress <= 8.9.1 versions.
  • CVE-2026-66587 (CVSS 9.8, CRITICAL) — Unauthenticated Local File Inclusion in WP Cafe Pro < 3.0.15 versions.

Source: NIST National Vulnerability Database.

This week in our own scan data

We ran 0 Security Score scans across our customers in the past 7 days.

No findings recorded this week.

Nothing stood out — most sites checked out clean.

If any of the above sounds familiar, the fix is usually quick: missing security headers and outdated front-end libraries are the two most common findings we see, and both are typically a same-day fix. Run a free Security Score scan to see where your own site stands.

This roundup is generated weekly from CISA's KEV catalog, NIST's NVD, a small set of established security news feeds, and Hebrides Cyber's own (anonymised) scan data. Set AZURE_OPENAI_ENDPOINT/KEY/DEPLOYMENT for a narrative AI write-up instead of this templated summary — see src/lib/newsletter.ts.

$ ./get-your-score

Get a free Security Score for your site

Automated TLS, headers, DNS, and exposure checks — results in under a minute.

Request a free scan