CVE Tools

Security news, decoded.

74 stories in the last 7 days, naming 204 CVEs; 59 of those CVEs are in CISA KEV.

RSS feed

The wire

Page 12 of 36 · newest first · times in UTC

Friday, Aug 142 stories

  1. watchTowr Labs
    You’re Back In The Room (Citrix NetScaler Pre-Auth RCE CVE-2026-8452(?))

    watchTowr Labs has published a proof-of-concept exploit for a pre-authentication remote code execution vulnerability in Citrix NetScaler ADC and NetScaler Gateway, identified as CVE-2026-8452. The flaw is a heap overflow triggered during the canonicalization of SAML signature data, specifically when processing an overly large PrefixList element within the SignedInfo block. Successful exploitation allows attackers to gain root-level code execution on affected appliances, which are widely used for enterprise remote access. Citrix addressed the issue in recent security bulletins; administrators must update NetScaler ADC and Gateway to version 14.1-72.61 or 13.1-63.18 immediately.

    PoC publicCitrix NetScaler ADC
  2. SecurityWeek
    AmnesiaStealer macOS Malware Steals Data, Controls Browser Sessions

    Researchers have identified active exploitation of a new Rust-based macOS information stealer called AmnesiaStealer, which is distributed through malicious ClickFix campaigns involving counterfeit GitHub download pages. The malware utilizes a three-stage infection chain that includes leveraging the TCC bypass vulnerability CVE-2020-9771 to harvest sensitive data from Chromium-based browsers and Apple Notes. Notably, the tool allows attackers to establish live, interactive control over victim browser sessions via a headless module, distinguishing it from other similar macOS threats.

    Reported exploitedmacOS

Thursday, Aug 1315 stories

  1. Dark Reading
    Global Threat Campaign Hits Critical VMware vCenter Flaw

    A suspected advanced persistent threat actor has launched a global campaign exploiting CVE-2026–59310, a critical directory traversal vulnerability in VMware vCenter with a CVSS score of 9.8. German security firm QUIRSO reported observing active exploitation beginning on August 3, just days after Broadcom and VMware disclosed the flaw on July 29. The attack targets allow remote code execution in virtual environments, affecting infrastructure across 47 countries including the US, France, Iran, and Turkey. Notably, attackers establish post-exploitation persistence using the reversessh tool, meaning that simply applying the patch may not remove existing backdoors from compromised systems. Organizations are advised to conduct forensic investigations and isolate management interfaces to prevent continued command-and-control access.

    Reported exploitedVMware vCenter
  2. The Hacker News
    GeoServer Zero-Day Targeted in Active Exploitation Attempts, Can Lead to RCE

    WatchTowr has confirmed active exploitation attempts against a critical SQL injection vulnerability in GeoServer, which allows for remote code execution when specific PostGIS configurations are used. Although the flaw was initially reported without a CVE identifier, the vendor has since issued patches in versions 3.0.1, 2.28.5, and 2.27.6, assigning the issue the identifier GHSA-mqjf-5f49-2fjh with a CVSS score of 9.8. The vulnerability stems from improper escaping in the jsonArrayContains function within the GeoTools library, enabling attackers to inject malicious SQL commands. This represents a regression of previously fixed issues, specifically CVE-2023-25158. Organizations are strongly advised to upgrade to the latest patched versions immediately to mitigate the risk of system compromise.

    Reported exploitedGeoServer
  3. The Hacker News
    ThreatsDay: GhostJacking AI Attacks, EtherHiding ClickFix, Cursor CLI Flaw + 17 More Stories

    This weekly security roundup highlights a new AI attack vector called GhostJacking, which manipulates autonomous agents into executing arbitrary code and exfiltrating data via poisoned logs. Additionally, a pre-trust code execution flaw in the Cursor CLI coding agent has been resolved following responsible disclosure. The bulletin also covers active in-the-wild exploitation by threat actor UNC6671 using the Work Panel platform for large-scale voice phishing campaigns against identity providers. Other notable updates include blockchain-based C2 obfuscation techniques like EtherHiding, industrial ransomware trends, and various supply chain compromises across cloud and software ecosystems.

    Reported exploitedUNC6671
  4. BleepingComputer
    Microsoft patches LegacyHive Windows zero-day vulnerability

    Microsoft has addressed a zero-day vulnerability in the Windows User Profile Service, tracked as CVE-2026-62832, through its August Patch Tuesday updates. The flaw, dubbed "LegacyHive" by researcher Nightmare Eclipse, involves improper link resolution that permits local attackers to escalate privileges to administrator level. Although a proof-of-concept exploit was made public shortly after the July security release, it requires specific local credentials for successful exploitation. Analysts have confirmed that the exploit can modify registry hives to grant automatic code execution upon admin login, and unofficial mitigations were previously provided by ACROS Security for recent Windows versions.

    PoC publicWindows User Profile Service
  5. BleepingComputer
    Critical VMware vCenter RCE flaw exploited for reverse SSH access

    An active exploitation campaign is targeting a critical directory traversal vulnerability, CVE-2026-59310, within the VMware vCenter Syslog Server to deploy a reverse SSH tool for persistence and remote access. Disclosed by Broadcom on July 29, the flaw enables unauthenticated attackers with network access to execute arbitrary code, impacting numerous organizations across 47 countries. To remediate the risk, administrators should immediately apply the emergency updates for VMware vCenter releases 9.1.0.0300, 9.0.2.0100, or 8.0 U3k/U2f, as no other workarounds are currently available.

    Reported exploitedVMware vCenter
  6. The Hacker News
    New PATCHCORD Backdoor Targets Afghan Telecom and Indian Critical Infrastructure

    Acronis TRU revealed an active campaign by APT36 (Transparent Tribe) targeting Afghan telecommunications providers and critical infrastructure in India. The operation deploys two previously undocumented backdoors, PATCHCORD and SHEETCORD, using lures that impersonate the state-owned Afghan Telecom (AFTEL) and India's National Informatics Center (NIC). These implants establish persistence via browser shortcut hijacking and utilize unconventional C2 channels, including Google Sheets and GitHub Gists, while a staging server exposed open-source frameworks and the exploit for CVE-2024-6387.

    Reported exploitedPATCHCORD
  7. SecurityWeek
    Adobe Commerce Bug Targeted Immediately After Disclosure

    Adobe has released a security update to address CVE-2026-71362, a critical authorization flaw affecting Adobe Commerce and Magento Open Source that was rapidly targeted following its public disclosure. With a CVSS score of 9.1, this vulnerability allows unauthenticated remote attackers to hijack customer sessions and access private data by switching account identities. Although Adobe reported no prior in-the-wild exploitation before the advisory, security firm Sansec confirmed they intercepted initial exploitation attempts shortly after the bug was made public. The fix modifies how customer identity is handled in sessions and applies to all versions up to and including the July 2026 patches.

    PatchAdobe Commerce
  8. The Hacker News
    AmnesiaStealer Hijacks Chromium Sessions to Give Attackers Live Browser Control on macOS

    Jamf Threat Labs identified a new Rust-based macOS information stealer named AmnesiaStealer that combines credential harvesting with the ability to remotely operate Chromium-based browsers such as Google Chrome and Microsoft Edge. Distributed through fraudulent GitHub download pages using ClickFix techniques, the malware extracts system passwords, Keychain data, and browser sessions to exfiltrate sensitive user information. Distinctively, it utilizes the Chrome DevTools Protocol to launch headless browsers, allowing operators to manipulate tabs, input keystrokes, and navigate sites in real-time while spoofing fingerprinting checks. The tool leverages patched vulnerabilities like CVE-2020-9771 to access protected data on older macOS versions, establishing persistence through disguised system services. While no specific threat actor attribution was provided, the combination of automated data theft and interactive session hijacking represents a significant escalation in macOS malware capabilities.

    ResearchmacOS
  9. Help Net Security
    Attackers exploit critical SharePoint flaw after PoC goes public (CVE-2026-55040)

    Threat actors have begun actively exploiting a critical vulnerability in Microsoft SharePoint, identified as CVE-2026-55040, following the public release of proof-of-concept code by Rapid7. This flaw enables remote unauthenticated attackers to bypass authentication mechanisms by manipulating the JWT token validation process, potentially allowing them to access sensitive files or modify data. While Microsoft had previously issued a fix during its July 2026 Patch Tuesday cycle, recent intelligence indicates that adversaries are now leveraging the available exploits against honeypots and live systems.

    Reported exploitedMicrosoft SharePoint
  10. SecurityWeek
    WordPress 7.0.4 Patches Remote Code Execution Vulnerability

    WordPress has released version 7.0.4 to address a high-severity remote code execution vulnerability identified as CVE-2026-65640. This defect, which carries a CVSS score of 8.8, permits attackers with Author-level or higher privileges to execute arbitrary code by uploading malicious Postscript files disguised as images. The issue specifically impacts installations utilizing Imagick and Ghostscript, where a mismatch between WordPress' reliance on file extensions and ImageMagick's content-based processing allows for unintended script execution. While the fix is included in version 7.0.4, maintainers have backported the patch to all supported branches extending back to version 4.7.

    PatchWordPress
  11. SecurityWeek
    Fortinet Patches Authentication Flaws in FortiWeb and FortiManager

    Fortinet has released updates addressing eight vulnerabilities across its network security portfolio, prioritizing high-severity authentication defects in FortiWeb and FortiManager. In FortiWeb, CVE-2026-26035 enables unauthenticated remote attackers to gain GUI/CLI access via random credentials when specific non-default wildcard administrator settings are active; this flaw is corrected in versions 8.0.3, 7.6.7, 7.4.12, and 7.2.13. Concurrently, CVE-2026-70468 allows remote impersonation of managed FortiGate devices within FortiManager under specific CLI configurations. The release also resolves a high-severity buffer overflow in FortiClient for Windows (CVE-2026-70465) and various lower-severity issues in FortiSIEM and FortiOS.

    PatchFortiWeb
  12. SecurityWeek
    Critical VMware vCenter Vulnerability in Attackers’ Crosshairs

    Broadcom addressed a critical remote code execution flaw in VMware vCenter, tracked as CVE-2026-59310, following its disclosure on July 29. Quirso reported that an advanced persistent threat actor is actively exploiting this directory traversal vulnerability to deploy reverse shells for persistent access. The campaign targets exposed systems across 47 countries, with initial compromises observed shortly after the security bulletin was published.

    Reported exploitedVMware vCenter
  13. SecurityWeek
    Nightmare Eclipse Drops Windows Zero-Day Exploit ‘ShieldBreak’

    Security researcher Nightmare Eclipse has published the proof-of-concept exploit 'ShieldBreak' for CVE-2026-50656, a vulnerability in Microsoft Defender that enables local privilege escalation to System level. The exploit affects recent versions of Windows 11 and Windows Server 2025, and researchers indicate it likely impacts Windows 10 systems as well. While described by the researcher as a bypass to the earlier RoguePlanet flaw, technical analysts note that ShieldBreak operates via Cloud Filter API hooks rather than the filesystem race condition used in its predecessor.

    PoC publicMicrosoft Defender
  14. Help Net Security
    Cisco fixes vulnerability exploited to DoS its firewalls (CVE-2026-20349)

    Cisco has confirmed that attackers are actively exploiting a high-severity vulnerability, CVE-2026-20349, to trigger denial-of-service conditions on its firewall appliances. The flaw affects the Remote Access SSL VPN service running on Cisco Secure Firewall Adaptive Security Appliance (ASA) and Cisco Secure Firewall Threat Defense (FTD) software, specifically when IKEv2, SSL VPN, or ZTNA features are enabled. An unauthenticated attacker can send a specially crafted HTTP request to force the device to reload unexpectedly, interrupting network operations. Cisco PSIRT detected the active exploitation in August 2026, and CISA has since added the issue to its Known Exploited Vulnerabilities catalog with a remediation deadline for US civilian federal agencies of August 14, 2026. To mitigate the risk, administrators should apply the recently released hot fixes for ASA versions 9.16 through 9.24 and FTD versions 7.0 through 7.7 and 10.0, as no workarounds are available.

    Reported exploitedCisco Secure Firewall ASA
  15. The Hacker News
    Attackers Exploit SharePoint Authentication Bypass After Public PoC Release

    Microsoft is actively addressing CVE-2026-55040, a critical authentication bypass in SharePoint that allows unauthenticated attackers to forge JWTs and impersonate administrators or site users. Following the release of a public proof-of-concept by Rapid7 this week, threat actors have begun exploiting the vulnerability, which was patched in Microsoft's July 2026 Patch Tuesday update. With a CVSS score of 9.1, the flaw stems from weak token validation logic that enables file disclosure and data modification without affecting system availability. Administrators should immediately apply the latest updates to prevent unauthorized access.

    Reported exploitedMicrosoft SharePoint

Wednesday, Aug 1219 stories

  1. BleepingComputer
    Hackers exploit critical Adobe Commerce flaw to hijack customer accounts

    Attackers are actively exploiting a critical incorrect authorization vulnerability, CVE-2026-71362, in Adobe Commerce and Magento platforms to hijack customer accounts without requiring authentication or administrative privileges. Security firm Sansec confirmed that their WAF is already blocking these attempts, noting that the flaw allows attackers to switch a customer session to another account. This issue was part of a security update released alongside six other vulnerabilities, including high-severity XSS flaws like CVE-2026-48413 and CVE-2026-48414. Administrators should apply the isolated August 2026 patch files after ensuring they have installed the latest point release for their specific supported version.

    Reported exploitedAdobe Commerce
  2. The Hacker News
    Lazarus Exploits Windows Zero-Day to Gain SYSTEM Access and Deploy Backdoor

    Check Point Research has attributed the exploitation of CVE-2026-68820 to the Lazarus Group, a North Korean state-sponsored threat actor targeting defense and aerospace firms in France, Germany, Brazil, and India. This privilege escalation vulnerability in the Windows Ancillary Function Driver for WinSock (AFD.sys) allows attackers to gain SYSTEM-level control, enabling them to deploy the ForestTiger backdoor and evade detection via Smart App Control manipulation. The campaign, part of the ongoing 'Dream Job' operation, lures victims with fraudulent job offers to install trojanized PDF viewers or malicious DLLs. These payloads execute MISTPEN modules to harvest system information and trigger the AFD.sys exploit. Organizations should immediately apply the fixes released in Microsoft's August 2026 Patch Tuesday updates and monitor for suspicious activity associated with compromised web infrastructure.

    Reported exploitedWindows
  3. BleepingComputer
    Plug and Pwn attack uses fake USB devices for Windows SYSTEM access

    Security researchers have presented "Plug and Pwn" techniques at DEF CON 34 that exploit the Windows Plug and Play mechanism to achieve full SYSTEM privilege escalation. By emulating specific USB devices using hardware like FaceDancer, attackers can trick Windows into automatically installing signed vendor packages that contain exploitable weaknesses, bypassing User Account Control. The demonstrations include both physical zero-click scenarios involving Sierra Wireless and Sony FeliCa drivers, as well as a remote variant, termed "NoPlug & Pwn," that leverages RDP USB redirection to target virtual desktop environments. While mitigations such as disabling co-installers reduce risk, the underlying attack surface persists, highlighting the need for stricter device installation policies on sensitive Windows systems.

    PoC publicWindows
  4. BleepingComputer
    Lazarus hackers exploited Windows zero-day to target defense firms

    Microsoft disclosed that North Korea's Lazarus Group is actively exploiting a use-after-free vulnerability in the Windows Ancillary Function Driver for WinSock, identified as CVE-2026-68820. This zero-day flaw allows attackers to escalate local privileges to SYSTEM level on Windows 11 systems, specifically builds 26100 and 26200, through a race condition triggered by a crafted application. The exploitation is part of the "Operation Dream Job" campaign, which targets defense, aerospace, and aviation organizations in Europe and India via deceptive job offers. To maintain access, Lazarus updated its FudModule rootkit to leverage this privilege escalation and deployed a new PHP web shell named RelayShell on compromised Roundcube instances.

    Reported exploitedWindows
  5. SecurityWeek
    SharePoint Vulnerability Exploited Shortly After PoC Release

    Active exploitation has been observed for CVE-2026-55040, a weak authentication vulnerability in Microsoft SharePoint that was patched during July Patch Tuesday. The attacks began immediately following the publication of a proof-of-concept exploit by Rapid7, allowing unauthenticated remote attackers to bypass security controls and access sensitive data. This incident marks the fifth SharePoint flaw targeted this summer, prompting urgent patching recommendations from CISA.

    Reported exploitedSharePoint
  6. BleepingComputer
    Hackers leverage new Microsoft SharePoint exploit in attacks

    Cybercriminals have begun deploying a proof-of-concept exploit for the critical authentication bypass flaw tracked as CVE-2026-55040, which affects Microsoft SharePoint Server. Published by Rapid7, the code allows unauthorized users to impersonate valid identities within SharePoint environments by exploiting weaknesses in the JWT token validation process. Although Microsoft patched this vulnerability during the July 2026 Patch Tuesday cycle for SharePoint Enterprise Server 2016 and SharePoint Server 2019, threat intelligence firm Defused confirmed that attackers are actively using the tool against exposed systems.

    Reported exploitedMicrosoft
  7. Help Net Security
    Lazarus hackers pair fake job offers with Windows zero-day exploit

    Check Point researchers have revealed that the North Korea-linked Lazarus Group is actively exploiting a previously unknown Windows vulnerability, designated as CVE-2026-68820, within its ongoing 'Operation Dream Job' campaign. The attack vector involves luring targets, primarily from the defense industry, with fraudulent recruitment offers for companies like Lockheed Martin. Upon downloading trojanized PDF files, victims are subjected to an infection chain that leverages the AFD.sys driver flaw to escalate privileges and deploy the FudModule rootkit. Microsoft addressed the critical local privilege escalation issue during its August 11 Patch Tuesday update. In addition to the zero-day, the campaign utilizes modified versions of SecurityPDF and Roundcube webmail servers to establish persistent command-and-control infrastructure.

    Reported exploitedWindows AFD.sys
  8. The Hacker News
    Adobe Patches Three CVSS 10.0 ColdFusion and Campaign Classic Flaws

    Adobe has distributed security updates for its ColdFusion, Commerce, and Campaign Classic platforms to resolve multiple high-severity vulnerabilities that could enable remote code execution and privilege escalation. Among the patched issues are three defects with a maximum CVSS score of 10.0: two incorrect authorization flaws in Campaign Classic (CVE-2026-71398 and CVE-2026-27302) and one operating system command injection vulnerability in ColdFusion (CVE-2026-48362). Additionally, an eval injection flaw in ColdFusion (CVE-2026-48273) and incorrect authorization weaknesses in both ColdFusion and Commerce are addressed. No active exploitation of these specific bugs has been observed, but Adobe rates the updates as Priority 1 due to the significant risk they pose. Administrators should apply the fixes immediately, ideally within 72 hours. For ColdFusion, users must upgrade to versions 2025.0.12 or 2023.0.23, while Campaign Classic on-premise and hybrid deployments need to be updated to ACC v7 7.4.4 build 9400; note that Adobe-hosted instances do not require manual intervention.

    PatchColdFusion
  9. BleepingComputer
    New Microsoft Defender 'ShieldBreak' zero-day grants SYSTEM privileges

    Researcher Nightmare Eclipse has published a proof-of-concept for "ShieldBreak," a Microsoft Defender vulnerability that allows privilege escalation to SYSTEM on fully patched Windows systems. This exploit functions as a bypass for the previously patched RoguePlanet flaw (CVE-2026-50656), effectively rendering the July security fix ineffective. The PoC has been verified to work with a high success rate on Windows 11 25H2, Windows 10, and Windows Server editions where Microsoft Defender is active.

    PoC publicMicrosoft Defender
  10. Help Net Security
    Microsoft patches 400+ vulnerabilities, one zero-day under attack (CVE-2026-68820)

    Microsoft released over 400 security fixes in its August 2026 update cycle, addressing active attacks on Windows via a use-after-free flaw identified as CVE-2026-68820. Check Point researchers confirmed that Lazarus Group actors are leveraging this bug to install kernel-mode rootkits as part of their 'Operation Dream Job' intrusion campaign. The release also resolved several previously disclosed issues, including a User Profile Service privilege escalation (CVE-2026-62832) and two other flaws with public proof-of-concept exploits. Notably, researcher "Nightmare Eclipse" has published a "ShieldBreak" tool that reportedly circumvents recent protections for the Microsoft Defender vulnerability CVE-2026-50656.

    Reported exploitedWindows
  11. The Hacker News
    Attackers Exploit VMware vCenter Vulnerability to Gain Persistent Remote Access

    Threat actors are actively exploiting CVE-2026-59310, a critical directory-traversal vulnerability in Broadcom’s VMware vCenter, to gain remote code execution capabilities. German security firm QUIRSO confirmed active attacks affecting at least 361 victim IPs across 47 countries, beginning five days after the official disclosure. Attackers established persistence by deploying malicious cron jobs using reversessh to connect back to their infrastructure, likely driven by an advanced persistent threat group.

    Reported exploitedVMware vCenter
  12. SecurityWeek
    Fresh Windows Zero-Day Exploited in North Korean Cyberattacks

    Check Point has reported that North Korea's Lazarus Group is actively exploiting a newly patched Windows zero-day vulnerability to compromise systems within the global defense sector. The attacks leverage a use-after-free flaw in the Ancillary Function Driver for WinSock (afd.sys), identified as CVE-2026-68820, to achieve System-level privileges. Microsoft addressed this critical race condition during its August 2026 Patch Tuesday cycle, and CISA has since added the identifier to its Known Exploited Vulnerabilities catalog. The campaign, dubbed Operation Dream Job, utilizes social engineering tactics involving fake recruitment offers to deliver malware such as Mistpen and ForestTiger.

    Reported exploitedWindows AFD.sys
  13. SecurityWeek
    Ivanti EPM Update Patches Remotely Exploitable Flaws

    Ivanti has released security updates addressing four vulnerabilities affecting its Endpoint Manager and Neurons for MDM products. The Endpoint Manager update resolves three high-severity issues, including CVE-2026-18129 and CVE-2026-18125, which allow remote unauthenticated attackers to perform man-in-the-middle credential theft or crash agent services via out-of-bounds reads. Additionally, the patch corrects CVE-2026-18127, an input validation flaw that could permit unauthorized file control in S3 buckets used for session recordings. These fixes are available in Endpoint Manager version 2024 SU7, while the medium-severity command injection bug in Neurons for MDM was already addressed in version R124 without requiring customer action. Ivanti stated it is currently unaware of any active exploitation of these specific vulnerabilities.

    PatchEndpoint Manager
  14. The Hacker News
    Malicious LiteLLM Releases Tied to Trivy Hack May Have Exposed 2,100+ Organizations

    Threat intelligence firm CloudSEK has released a public dataset indicating that the recent TeamPCP (UNC6780) supply-chain campaign may have affected over 2,500 organizations via compromised releases of the LiteLLM AI gateway and Aqua Security's Trivy scanner. The incident, tracked as CVE-2026-33634, involved malicious versions 1.82.7 and 1.82.8 of LiteLLM hosted on PyPI from March 24 until quarantine, containing code that harvested cloud keys, SSH credentials, and Kubernetes tokens. The FBI has warned that stolen long-lived secrets remain a persistent risk, urging organizations to audit their environments for these specific package versions installed between 10:39 and 16:00 UTC on March 24. Affected entities should rotate all associated credentials and scan GitHub repositories for suspicious artifacts named tpcp-docs or docs-tpcp.

    Reported exploitedLiteLLM
  15. The Hacker News
    SAP Commerce Cloud Flaw Could Let Unauthenticated Attackers Execute Arbitrary Code

    SAP has distributed a patch for a critical vulnerability in its Commerce Cloud (Data Hub Adapter) that permits unauthenticated attackers to execute arbitrary code. Identified as CVE-2026-58231, the flaw carries a perfect CVSS score of 10.0 due to insufficient authorization checks and input validation, which can lead to full compromise of application confidentiality, integrity, and availability. The update also resolves three other severe issues, including CVE-2026-44772 and CVE-2026-44758 in Manufacturing Integration and Intelligence, and CVE-2026-34265 in Application Server ABAP for SAP NetWeaver. Security firm Onapsis advises organizations to apply the latest release immediately or configure IP Filter Sets to restrict access to vulnerable endpoints until updates are deployed.

    PatchSAP Commerce Cloud
  16. SecurityWeek
    SonicWall Patches Critical Vulnerabilities in Discontinued GMS Platform

    SonicWall has released patches for eight vulnerabilities affecting its Global Management System (GMS) and Email Security platforms, addressing critical remote code execution risks. Notably, CVE-2026-66147 (CVSS 9.4) and CVE-2026-66145 (CVSS 9.1) in GMS allow unauthenticated attackers to execute arbitrary code via command injection and zipslip vulnerabilities, respectively. While GMS was discontinued in October 2025, updates for versions 9.5.1 and earlier are available in release 9.5.2. Additionally, two high-severity code injection flaws in Email Security appliances were resolved in version 10.0.36.

    PatchGlobal Management System
  17. The Hacker News
    ShieldBreak Zero-Day PoC Claims Microsoft Defender Patch Bypass With SYSTEM Access

    Security researcher Chaotic Eclipse has published a proof-of-concept exploit named ShieldBreak that serves as a complete patch bypass for the previously addressed Microsoft Defender vulnerability CVE-2026-50656. The flaw allows attackers to achieve privilege escalation to SYSTEM level on Windows 11 25H2 and Windows Server 2025, rendering recent security updates ineffective. While CISA is simultaneously adding the actively exploited WinSock zero-day CVE-2026-68820 to its Known Exploited Vulnerabilities catalog, this new disclosure highlights lingering issues in the Defender malware protection engine.

    PoC publicMicrosoft Defender
  18. The Hacker News
    Cisco ASA and FTD Flaw Exploited in the Wild Can Trigger Remote DoS

    Cisco has disclosed that attackers are actively exploiting a high-severity vulnerability in its Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) software. Tracked as CVE-2026-20349, this flaw involves insufficient error handling during HTTP request processing, allowing unauthenticated remote attackers to force a device reload and cause a denial of service. The advisory notes that exploitation targets specific configurations such as IKEv2, SSL-VPN, or Zero Trust Network Access. Organizations using affected versions should immediately apply the relevant hotfixes or upgrade to fixed releases, as CISA has added the issue to its Known Exploited Vulnerabilities catalog with a remediation deadline of August 14, 2026.

    Reported exploitedSecure Firewall Adaptive Security Appliance
  19. SecurityWeek
    Cisco Patches Firewall Zero-Day Exploited for DoS Attacks

    Cisco has released emergency patches for a zero-day denial-of-service vulnerability affecting Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD). The flaw, identified as CVE-2026-20349, permits remote attackers without authentication to trigger an appliance reload by sending malformed HTTP requests to the Remote Access SSL VPN service. With CISA adding the issue to its Known Exploited Vulnerabilities catalog due to confirmed active attacks since August 2026, organizations are urged to install the available hotfixes immediately to prevent network disruptions.

    Reported exploitedSecure Firewall Adaptive Security Appliance

Tuesday, Aug 114 stories

  1. Cisco Talos
    Microsoft Patch Tuesday for August 2026 — Snort rules and prominent vulnerabilities

    Microsoft has issued its August 2026 security updates to address 421 vulnerabilities across Windows, SharePoint Server, Exchange Server, and Office, including 62 rated as critical. Notably, one flaw, CVE-2026-68820, a use-after-free error in the Windows Ancillary Function Driver for WinSock, is confirmed to be under active exploitation in the wild. The release also highlights high-severity remote code execution issues such as CVE-2026-62893 in Windows Deployment Services (CVSS 9.8) and CVE-2026-65665 in Microsoft SharePoint Server (CVSS 8.8). Cisco Talos has published updated Snort rules to detect exploitation attempts against several of these newly disclosed weaknesses.

    Reported exploitedWindows
  2. Qualys Security Blog
    Microsoft Patch Tuesday, August 2026 Security Update Review

    Microsoft has released its August 2026 security updates, addressing a total of 421 vulnerabilities across Windows, Azure, and Exchange Server. Among these are three zero-day flaws, with one specifically identified as being actively exploited in the wild. Organizations should prioritize applying these patches immediately to mitigate risks, particularly regarding the active exploitation and several critical remote code execution issues.

    Reported exploitedWindows
  3. Dark Reading
    Microsoft's Patch Tuesday Deluge Continues With August Updates

    Microsoft has released its August 2026 security updates, addressing a total of 421 unique vulnerabilities with particular emphasis on Windows, Office, and SharePoint Server. The update package includes the active exploitation of CVE-2026-68820, a zero-day elevation of privilege flaw in the WinSock driver that grants attackers full SYSTEM access without user interaction. Security researchers also flag CVE-2026-62832 as a high-risk candidate for imminent abuse when combined with the initial foothold provided by the zero-day. Additionally, the release contains several critical remote code execution issues, such as the wormable CVE-2026-62878 in Windows DNS Server and CVE-2026-62815 in the QUIC protocol, both rated CVSS 9.8. Organizations should prioritize applying these cumulative updates immediately to mitigate the risk of lateral movement and full system compromise.

    Reported exploitedWindows
  4. Krebs on Security
    Microsoft Plugs Nearly 400 Security Holes

    Microsoft released its August security updates, addressing 398 vulnerabilities across Windows and other supported software, with one flaw under active exploitation and two previously publicly disclosed issues. The critical vulnerability CVE-2026-68820 allows privilege escalation through a race condition in the afd.sys driver, while CVE-2026-62832 targets the User Profile Service. Users should apply these patches promptly to secure their systems against ongoing threats.

    Reported exploitedWindows

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store