The CVE record failed as an index of what to patch in both directions this week — two national CERTs withdrew advisories built on CVEs an LLM invented, while three exploited or CVSS-10 flaws had no CVE at all and one vendor issued one CVE per bug class
A prior weekly recorded that the two standard prioritisation feeds failed together — an exploited flaw absent from CISA's catalogue, and critical flaws with no patch to apply. This week the failure moved one layer down, to the identifier those feeds are keyed on. Six unrelated disclosures in 2026-W32 show the CVE record failing as an index of what to patch, and failing in both directions at once.
In the false-positive direction, two national authorities retracted published advisories. NCSC-NL revised advisory NCSC-2026-0268 on 3 August to state plainly that its SQLite CVE "is door een LLM gehallucineerd" (NCSC-NL, 2026-08-03), and BSI CERT-Bund retitled two SQLite advisories to "MELDUNG ZURÜCKGEZOGEN" (BSI CERT-Bund, 2026-08-03). The originating work is JFrog's reproduction audit, which found that of 55 advisories published through one GitHub account, "54 were completely fabricated, while one contained a real bug wrapped in unverified CVE metadata" — the SQLite entries naming functions absent from the claimed version, citing line numbers past end-of-file, and shipping proofs-of-concept that produce no crash (JFrog Security Research, 2026-07-30). JFrog's structural diagnosis is the part that outlives this batch: "because no step in today's system actually requires a proof-of-concept or bug reproduction, a plausible-sounding fake advisory can slide right through the pipeline and end up in GHSA, downstream databases, and enterprise scanners." Retraction propagated unevenly — GitHub's advisory database was still carrying one of the withdrawn records when this pipeline checked on 4 August.
In the false-negative direction, four flaws that a defender must act on carry no identifier to act on. Metabase disclosed that "Metabase Cloud was attacked by someone utilizing an unknown ('0-day') security vulnerability in versions 1.58 and above," an unauthenticated SQL injection yielding administrator access from which stored credentials for every connected database can be taken (Metabase, 2026-08-06). Two customers, the laptop maker Framework and the form builder Tally, have confirmed that data was taken from their instances on 3 August (BleepingComputer, 2026-08-07). No CVE was assigned, so a purely CVE-driven patch process never surfaces it at all. WALLIX published an authentication bypass in the Bastion REST API rated CVSS 4.0 base 10.0 that hands a remote unauthenticated caller full administrative control of the privileged-access appliance — its credential vault and session recordings included — under the vendor advisory reference WSA-2026-07-0001 rather than a CVE (WALLIX, 2026-07-20); CERT-FR relayed it to its constituency carrying the same absence of an identifier (CERT-FR, 2026-08-06). Traefik's three tenant-isolation advisories, one of which lets a Kubernetes namespace silently take over another's routes, state that no CVE identifiers were assigned (Traefik Labs, 2026-08-03), and Check Point's five workerd sandbox-escape findings were disclosed without CVEs (Check Point Research, 2026-08-06).
Two further cases break the assumption that one CVE describes one flaw with one fix. Cisco's August IOS XE hardening release grouped internally found bugs by weakness class and assigned one CVE per class, stating that "the CVSS score that is assigned to each CVE ID represents the maximum potential severity of the single most impactful underlying bug within that specific CWE category" (Cisco PSIRT, 2026-08-05) — so no individual flaw can be assessed and the only triage unit left is the release. At the other extreme, InfoGuard Labs published 22 CVEs against Tobit TeamDavid, a DACH-region collaboration suite the researchers put at roughly 12,000 publicly accessible instances, bounded at "Rollout 524" with no fixed release named; the researchers' own remediation guidance is "update to newest version, we don't exactly know which vulnerabilities are fixed and which are not," and they report that both they and the national cyber security centre coordinating the disclosure "had been ghosted by the manufacturer" (InfoGuard Labs, 2026-08-07).
This pipeline is not a bystander to the pattern and published two corrections of its own in the same week: a July weekly entry claimed that ten CVEs across four product classes were "every one KEV-listed" when two of them — the Progress ShareFile chain CVE-2026-2699 and CVE-2026-2701 — never were, and a 5 August entry told readers there was no vendor fix for the Thermo Fisher genetic-analyzer integrity flaw when its own cited advisory named patched versions for five product lines. Both errors were produced by treating a catalogue entry or an advisory summary as the fact rather than reading the record itself.
A broader audit of 55 advisories published by the same GitHub account revealed that 54 were completely fabricated, while one contained a real bug wrapped in unverified CVE metadata.
Because no step in today's system actually requires a proof-of-concept or bug reproduction, a plausible-sounding fake advisory can slide right through the pipeline and end up in GHSA, downstream databases, and enterprise scanners.
We recently identified that Metabase Cloud was attacked by someone utilizing an unknown (“0-day”) security vulnerability in versions 1.58 and above.
The CVSS score that is assigned to each CVE ID represents the maximum potential severity of the single most impactful underlying bug within that specific CWE category.
ATT&CK mapping
2 techniques mapped from the cited reporting · MITRE ATT&CK v19.2
Initial Access TA0001
T1190Exploit Public-Facing Application
Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.
T1195.002Supply Chain Compromise: Compromise Software Supply Chain
Adversaries may manipulate application software prior to receipt by a final consumer for the purpose of data or system compromise. Supply chain compromise of software can take place in a number of ways, including manipulation of the application source code, manipulation of the update/distribution mechanism for that software, or replacing compiled releases with a modified version.
Sources
AI-generated · no human review · this permalink is the shareable record for the finding · verify operationally critical claims against the linked primary source.