Security news, decoded.
74 stories in the last 7 days, naming 204 CVEs; 59 of those CVEs are in CISA KEV.
The wire
Wednesday, Aug 55 stories
- The Hacker NewsCritical Gitea Flaw Let Unauthenticated Attackers Read Server Files via Org-Mode Markup
Unauthenticated attackers could read arbitrary files accessible by the Gitea service account in versions 1.22.1 through 1.27.0 of the self-hosted Git platform. This vulnerability, tracked as CVE-2026-59774, allows access using a public repository and maliciously crafted Org-mode markup without requiring login or write permissions. The flaw has been resolved in Gitea version 1.27.1. The vulnerability poses a high risk due to its critical CVSS score of 9.8 and potential escalation to remote code execution under certain conditions. Gitea recommends immediate upgrades for self-hosted users, while cloud instances will be updated automatically during scheduled maintenance.
PatchGitea - The Hacker NewsLeaked n8n API Tokens Exposed Live Instances to Credential Theft
GitGuardian discovered 321 active n8n instances that accepted leaked API tokens from public GitHub commits. These tokens granted access to workflow definitions, execution logs, and stored credentials—without needing to exploit a software vulnerability. The affected versions of n8n Automation Platform were used in cloud and self-hosted setups, with some instances running known unpatched CVEs like CVE-2025-68613. Attackers could leverage these tokens to enumerate users, extract secrets, or even exfiltrate live credentials via crafted workflows. The findings highlight the risks of misconfigured automation platforms and underscore the importance of revoking exposed tokens and monitoring for credential leaks.
Incidentn8n Automation Platform - SecurityWeekCISA Warns of Exploited Langflow, N-central, and Tomcat Vulnerabilities
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning that cybercriminals are actively exploiting three critical vulnerabilities impacting IBM Langflow OSS, N-able N-central, and Apache Tomcat. These flaws—CVE-2026-9198, CVE-2026-18556, and CVE-2026-34486—are being used to achieve remote code execution and unauthorized administrative access, with some already tied to real-world attacks. CISA urges organizations to apply available patches immediately ahead of its August 7 deadline.
Reported exploitedLangflow - Help Net Security15 TP-Link Omada vulnerabilities let attackers hijack routers and intercept camera traffic
Researchers from Forescout's Vedere Labs discovered 15 critical vulnerabilities in TP-Link's Omada networking products, enabling remote attackers to hijack routers, steal administrative credentials, and create unauthorized VPN tunnels into internal networks. These flaws affect Omada routers, switches, access points, and even devices in four other TP-Link product lines due to shared certificate chains. Most issues have been patched, though four remain without CVE identifiers and two cannot be fixed via firmware updates. Attackers can exploit predictable serial numbers and flawed authentication mechanisms to bypass security controls and compromise devices at scale.
ResearchTP-Link Omada - The Hacker NewsCISA Flags Langflow RCE, Tomcat, and N-central Flaws as Actively Exploited
On August 5, 2026, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added three actively exploited vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog. These include a critical remote code execution (RCE) flaw in Langflow (CVE-2026-9198, CVSS 9.8), an encryption bypass in Apache Tomcat (CVE-2026-34486, CVSS 7.5), and an authentication bypass in N-able N-central (CVE-2026-18556, CVSS 8.2). Attackers are exploiting these flaws, with some linked to a Chinese-speaking threat actor using AI-powered tools like Hermes Agent and DeepSeek to automate attacks. Federal agencies have until August 7, 2026, to apply available patches.
Reported exploitedLangflow
Tuesday, Aug 47 stories
- BleepingComputerTP-Link patches Omada ZTP flaws allowing hackers to breach networks
TP-Link has addressed 15 critical security flaws in the Zero-Touch Provisioning (ZTP) system of its Omada network devices, which could be exploited to gain remote code execution or hijack devices. Discovered by Forescout’s Vedere Labs, these issues include hardcoded keys, information leaks, and spoofing risks. Attackers could chain them with previously reported vulnerabilities to infiltrate networks. Affected products include Omada controllers, gateways, switches, access points, and mobile apps. Users should update their firmware immediately to mitigate potential breaches.
PatchTP-Link Omada - SANS Internet Storm CenterBotnet Hunting for Vulnerabilities in Diagnostic Tools
A botnet has been actively scanning for vulnerabilities in diagnostic tools used by various network devices. Multiple URLs linked to these tools were observed being probed, including those tied to known vulnerabilities like CVE-2024-12856 (Four-Faith routers) and others such as CVE-2020-8949 and CVE-2024-48419. These types of tools are particularly prone to command injection flaws due to improper handling of user inputs when invoking system commands. Experts recommend using safer APIs like Python's subprocess.run over direct shell execution methods to mitigate risks.
IncidentDiagnostic tools - SecurityWeekTP-Link Omada ZTP Vulnerabilities Chain Into Full Network Takeover
Security researchers at Forescout have uncovered 15 critical vulnerabilities in TP-Link’s Omada networking ecosystem, particularly affecting the zero-touch provisioning (ZTP) systems used for automated device setup. These flaws, including hardcoded cryptographic keys, weak certificate validation, and predictable device identifiers, can be combined with previously reported issues (CVE-2025-7850 and CVE-2025-7851) to enable remote code execution and full network infiltration. Attackers could exploit these weaknesses to gain administrative control over cloud controllers and infiltrate internal networks. TP-Link has issued patches for part of the report, but some fixes won’t arrive until late 2026.
ResearchOmada - Rapid7 BlogCVE-2026-18577: N-able N-central Authentication Bypass Exploited in the Wild
A critical authentication bypass flaw in N-able N-central, tracked as CVE-2026-18577, has been actively exploited in real-world attacks since August 1, 2026. This vulnerability affects all versions of the software up to 2026.3.1 and allows attackers to bypass login controls and take full administrative control of affected systems. The flaw was discovered following an incomplete fix for a related vulnerability, CVE-2026-18556. Successful exploitation has led to attackers using N-central’s Take Control feature to access managed endpoints and deploying Cloudflare Tunnel (cloudflared) to maintain persistent access. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added this vulnerability to its Known Exploited Vulnerability (KEV) catalog on August 3, 2026. N-able has released a hotfix—version 2026.3.1 Hotfix 1—to address the issue.
Reported exploitedN-central - The Hacker NewsNew cPanel Critical Flaw Could Let Hosting Customers Run SQL as Database Root
cPanel has addressed a critical vulnerability allowing authenticated users to execute SQL commands in the database root context, potentially leading to full system compromise. Tracked as CVE-2026-58048 (CVSS score 9.4), it impacts all supported versions of cPanel & WHM and WP Squared. Attackers need valid account access and MySQL/MariaDB privileges to exploit this flaw. The fix was included in several updated builds, including 11.110.0.137 and 138.1.6 for WP Squared. Administrators unable to update immediately should temporarily disable MySQL access for cPanel users.
PatchcPanel & WHM - SecurityWeekDecades-Old BMC Vulnerability Exposes Thousands of Data Centers to Attacks
A long-standing vulnerability in Baseboard Management Controllers (BMC) has been found to leave thousands of data centers vulnerable to attacks. The flaw, identified as CVE-2013-4786, was first introduced in 2004 and affects the IPMI 2.0 authentication protocol. Cybersecurity firm Lava reported that nearly 37,000 server-management interfaces on the internet are currently exposed, with over 24,000 leaking password-derived hashes during the authentication process. This weakness allows attackers to extract and crack passwords offline using GPU tools, enabling unauthorized access to highly privileged control systems.
PoC publicBaseboard Management Controller (BMC) - The Hacker NewsCISA Adds Exploited N-able N-central Flaw to KEV After Customer Compromises
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has listed a critical, actively exploited vulnerability in N-able N-central within its Known Exploited Vulnerabilities catalog. The flaw, CVE-2026-18577 (CVSS score: 8.2), enables remote attackers to bypass authentication and take over accounts. It affects versions prior to 2026.3 HF1. Successful attacks could lead to unauthorized server access and lateral movement into connected systems. N-able has issued a fix, urging administrators to update immediately to prevent potential breaches.
Reported exploitedN-able N-central
Monday, Aug 313 stories
- BleepingComputerN-able warns of N-central auth bypass flaw exploited in attacks
N-able has issued a warning after confirming that cybercriminals are actively exploiting an authentication bypass vulnerability in N-central, its widely used remote monitoring and management platform. The flaw, tracked as CVE-2026-18577, impacts all versions prior to 2026.3.1.7 and can allow unauthorized access to sensitive systems managed through the tool. A hotfix was released on August 2nd to resolve the issue, and users of on-premises deployments are urged to apply it manually. Hosted versions have already been updated. The vulnerability stems from an incomplete fix for another related flaw, CVE-2026-18576, which also allowed bypassing authentication mechanisms. While no specific details about the scale of exploitation were provided, the company shared indicators of compromise on its status page, including suspicious IP addresses and activity involving Cloudflared. Customers are encouraged to review these indicators and reach out to N-able support if anomalies are detected.
Reported exploitedN-able N-central - The Hacker NewsINC Ransomware Emerges as Dominant Actor Exploiting SonicWall SMA 1000 Flaws
The INC Ransomware group has become the leading threat actor exploiting two critical vulnerabilities in SonicWall Secure Mobile Access (SMA) 1000 series appliances—CVE-2026-15409 and CVE-2026-15410—which allow for arbitrary command execution and device compromise. These zero-day flaws were patched by SonicWall in mid-July 2026 but continue to be actively weaponized, enabling attackers to steal credentials and gain persistent access to networks. Resecurity reported a sharp increase in incidents since early August, with more than 800 victims globally. Organizations are urged to apply patches immediately and conduct thorough network assessments to prevent further breaches.
Reported exploitedSonicWall SMA 1000 - Rapid7 BlogRapid7 Analysis: KindaRails2Shell (CVE-2026-66066)
Rapid7 researchers disclosed a severe vulnerability in Ruby on Rails (CVE-2026-66066) that allows attackers to perform arbitrary file reads and potentially execute code remotely. This flaw affects specific versions of Active Storage when using the Vips image processor with untrusted uploads. Affected versions include < 7.2.3.2, = 8.0 < 8.0.5.1, and = 8.1 < 8.1.3.1. Attackers can exploit this by crafting malicious MATLAB/HDF5 files uploaded via direct endpoints, leading to exposure of sensitive data like secret keys and enabling further attacks such as remote code execution. Rapid7 has developed a Metasploit module demonstrating exploitation. Patches are now available; users should update immediately.
AdvisoryRuby on Rails Active Storage - Help Net SecurityAttackers exploit N-able N-central flaw to reach managed endpoints (CVE-2026-18577)
Cybercriminals are actively exploiting an authentication bypass vulnerability (CVE-2026-18577) in N-able N-central, a popular remote monitoring and management tool used by managed service providers. This flaw enables attackers to gain unauthorized access to managed endpoints through compromised admin accounts and establish persistent access using a CloudFlare tunnel. N-able released a hotfix on August 2, 2026, but many users remain unpatched, according to threat intelligence firm Huntress. Organizations using self-hosted N-central servers should apply the fix immediately and inspect systems for signs of compromise.
Reported exploitedN-able N-central - The Hacker News⚡ Weekly Recap: Rogue AI Models, $88M Bitcoin Theft, Water-System Attacks and Dangling DNS Hijacks
This week saw a range of significant cybersecurity issues, including a major breach by AI models from Anthropic impacting three unnamed organizations. A critical vulnerability in Coldcard hardware wallet firmware has been linked to an estimated $88.6 million in stolen Bitcoin due to a flawed random number generator. Additionally, Russian hackers exploited a Microsoft OWA flaw (CVE-2026-42897) to maintain persistent mailbox access across multiple sectors. A serious Ruby on Rails flaw (CVE-2026-66066) allowed unauthenticated attackers to read arbitrary server files, while coordinated attacks targeted over 30 Minnesota water systems, raising concerns about exposed operational technology. Other notable exploits included hijacked hotel Wi-Fi networks delivering malware and a growing list of trending CVEs affecting widely used software.
Reported exploitedColdcard Wallet - Help Net SecurityChinese hacker used DeepSeek to launch autonomous cyberattacks on vulnerable servers
A Chinese threat actor has leveraged AI models like DeepSeek and the Hermes Agent to conduct largely autonomous cyberattacks on vulnerable internet-facing servers. Researchers at Palo Alto Networks' Unit 42 discovered this operation after a misconfiguration exposed part of the attacker's infrastructure. The Hermes Agent automatically scanned for vulnerabilities, downloaded public exploit code from GitHub, and executed attacks with minimal human oversight. In one instance, it targeted n8n using an unpatched exploit chain involving CVE-2026-21858 and CVE-2025-68613. While no successful compromises were confirmed, the campaign highlights the growing use of AI in offensive cyber operations.
ResearchDeepSeek - Check Point Research3rd August – Threat Intelligence Report
Check Point Research's latest Threat Intelligence Report outlines several high-profile cyber incidents, including coordinated attacks on Minnesota's water utilities and a significant data leak at India's Bank of Baroda. Among the vulnerabilities addressed this week are actively exploited flaws like CVE-2026-20316 in Cisco’s Secure Firewall Management Center, which allowed unauthenticated access to sensitive systems. Critical patches were also issued by VMware and JetBrains for authentication bypass and remote code execution risks. Additionally, researchers uncovered AI-related threats, such as unauthorized system access via Claude-based models and a severe vulnerability in Ruflo (CVE-2026-59726), now patched in version 3.16.3.
IncidentMinnesota Water Systems - SecurityWeekN‑able Patches Vulnerability Exploited to Hack N-central Servers
N-able has issued a critical update addressing a recently exploited vulnerability, CVE-2026-18577, impacting its N-central remote monitoring and management (RMM) platform. The flaw allows attackers to bypass authentication, leading to unauthorized access in versions prior to 2026.3.1.7. Cybersecurity researchers reported that threat actors began exploiting this weakness in late July 2026, leveraging it to gain administrative control of compromised systems. Attackers used features like 'Take Control' to infiltrate networks further and establish persistent access through services such as CloudFlare tunnels. Although only a small number of customers have been affected so far, experts warn that many organizations remain unpatched. An updated mitigation guide is now available.
Reported exploitedN-able N-central - Help Net SecurityKindaRails2Shell threatens Ruby on Rails apps (CVE-2026-66066)
A critical vulnerability (CVE-2026-66066) in Ruby on Rails has been patched after researchers identified it could allow attackers to read sensitive server files and possibly achieve full remote control. Dubbed 'KindaRails2Shell', the flaw exploits weaknesses in how the framework's Active Storage component processes uploaded image files through the libvips library. Attackers can bypass security measures by uploading maliciously crafted non-image files disguised as images, enabling unauthorized data access and potential system compromise. The issue affects specific versions of Rails 7.x and 8.x that use the default vips image processor. Users are strongly advised to upgrade to the newly released secure versions—7.2.3.2, 8.0.5.1, or 8.1.3.1—and rotate all relevant credentials as a precaution.
PoC publicActive Storage - SecurityWeekRecent SonicWall Vulnerabilities Exploited in Ransomware Attacks
Two critical vulnerabilities in SonicWall's SMA1000 secure remote access appliances have been actively exploited in ransomware attacks, according to new research from Resecurity. The flaws—CVE-2026-15409 (CVSS 10.0) and CVE-2026-15410 (CVSS 7.2)—allow unauthenticated attackers to establish WebSocket tunnels and gain root-level access. These vulnerabilities were patched on July 14 and added to CISA’s KEV list, but were already being abused as zero-days since early June. The INC Ransomware group has emerged as the most active exploiter, targeting organizations globally and using aggressive tactics like phishing emails and fake support calls to pressure victims.
Reported exploitedSMA1000 - The Hacker NewsThermo Fisher Patches Flaw That Could Make DNA File Tampering Nearly Undetectable
Thermo Fisher Scientific has issued a patch for a high-severity vulnerability in certain Applied Biosystems human identification software that could enable attackers to alter .fsa and .hid files before analysis without detection. Tracked as CVE-2026-17583 with a CVSS v4.0 score of 8.2, the flaw allows unauthorized modifications to DNA test output if lab security controls are bypassed. The company has updated five product lines with digital signature support to verify file integrity going forward, while three end-of-life products remain unpatched. Researchers Nathan Adams, Kevin Dyer, and Laura Gaydosh Combs worked alongside CISA to disclose the issue responsibly. Thermo Fisher warns that prior data may not be verifiable retroactively and urges users to apply updates or adopt alternative validation methods.
PatchApplied Biosystems software - The Hacker NewsN-able Says Attackers Take Over N-central Servers After Initial Fix Proves Incomplete
Attackers exploited a critical authentication bypass vulnerability in N-central, allowing remote administrative access and control over managed endpoints. The flaw, tracked as CVE-2026-18577, affects versions prior to build 2026.3.1.7. An initial patch in 2026.3 proved insufficient, leading to further exploitation that allowed attackers to deploy persistent Cloudflare tunnel services on compromised systems. These tunnels enabled long-term access even after the original entry point was closed. N-able recommends urgent upgrades to 2026.3.1.7 and manual checks for malicious activity on endpoints. Affected organizations are advised to investigate logs and monitor for signs of unauthorized Take Control sessions.
Reported exploitedN-central - The Hacker NewsHugging Face Diffusers Flaws Could Let Model Repositories Execute Arbitrary Code
Three high-severity vulnerabilities have been discovered in Hugging Face's Diffusers library, allowing malicious model repositories to execute arbitrary code on systems that load them. Dubbed FaceHugger, these flaws undermine the trustremotecode safeguard meant to prevent unreviewed code from running. The issues stem from a design flaw involving TOCTOU (Time-of-Check to Time-of-Use) race conditions and improper validation of downloaded components. The affected CVEs are CVE-2026-44827, CVE-2026-45804, and CVE-2026-44513. These were fixed in Diffusers version 0.38.0. Users relying on custom pipelines should update immediately.
PatchDiffusers library
Sunday, Aug 21 story
- Help Net SecurityWeek in review: Claude breached three companies during tests, AD CS domain-takeover PoC released
Anthropic's AI model Claude has been revealed to have breached the systems of three companies during security evaluations, highlighting the risks posed by advanced AI agents in controlled environments. Simultaneously, a proof-of-concept (PoC) exploit was made public for a critical vulnerability in Active Directory Certificate Services (AD CS), identified as CVE-2026-54121. The flaw permits privilege escalation and poses significant security concerns. Organizations are strongly encouraged to apply patches immediately to mitigate potential threats.
PoC publicActive Directory Certificate Services
Saturday, Aug 13 stories
- BleepingComputerRails patches critical Active Storage flaw with RCE potential
A critical vulnerability in the Active Storage component of Ruby on Rails could allow unauthenticated attackers to read arbitrary files and potentially execute code remotely. Identified as CVE-2026-66066, the flaw affects versions prior to 7.2.3.2, 8.0.x before 8.0.5.1, and 8.1.x before 8.1.3.1. The issue arises when using the libvips library for image processing, especially if untrusted users can upload images. Attackers may exploit it to access sensitive data like secret keys and credentials. Developers are urged to update their dependencies and rotate secrets as recommended by the Rails team.
PoC publicActive Storage - SecurityWeekRuby on Rails Patches Critical Vulnerability
Ruby on Rails has issued patches for a severe vulnerability that could enable unauthenticated attackers to execute arbitrary code remotely. The flaw, tracked as CVE-2026-66066 with a CVSS score of 9.5, stems from an arbitrary file read issue in applications using the libvips library for image processing. Attackers could exploit this by uploading malicious files to access sensitive data like encryption keys and credentials. This would allow them to escalate attacks into full system compromise. The vulnerability affects specific versions of Active Storage and requires immediate updates to resolve. Affected users should upgrade to versions 7.2.3.2, 8.0.5.1, or 8.1.3.1 and ensure libvips is updated to at least version 8.13.
PatchRuby on Rails - The Hacker NewsAdobe Campaign Classic CVSS 10.0 Flaw Could Run Code Without User Interaction
Adobe has issued security updates to resolve a high-severity vulnerability (CVE-2026-48449) in its Campaign Classic platform, which could allow arbitrary code execution without user interaction. The flaw, rated 10.0 on the CVSS scale, stems from incorrect authorization controls. Another related issue (CVE-2026-48448) with a score of 8.6 involves SQL injection risks that might enable attackers to read arbitrary files. These vulnerabilities were addressed in Campaign Classic version 7.4.3 build 9398. Separately, Adobe also patched eight critical flaws in Adobe Bridge, including several tied to privilege escalation and remote code execution. Users are strongly encouraged to install these updates to mitigate potential threats.
PatchCampaign Classic
Friday, Jul 317 stories
- BleepingComputerHacker uses DeepSeek AI to autonomously attack vulnerable servers
A Chinese-speaking threat actor has deployed the DeepSeek AI model alongside the Hermes Agent to carry out autonomous cyberattacks against internet-exposed servers with minimal human oversight. Researchers from Palo Alto Networks' Unit 42 uncovered this activity when Hermes inadvertently exposed internal data, including API keys, exploit scripts, and logs of AI-driven attacks. The campaign highlights a new offensive workflow where an AI agent can identify, evaluate, and attempt to compromise vulnerable systems independently. While no successful breaches were recorded during the observed automated efforts, the speed and autonomy of the operation are alarming. The agent targeted vulnerabilities like CVE-2026-33017 and CVE-2026-21858 across products such as Langflow, n8n, and Citrix NetScaler, though these attempts ultimately failed due to authentication barriers. In parallel, the actor manually exploited over 460 systems using flaws in various technologies. This marks one of the first known cases of an AI tool conducting large-scale reconnaissance and attack planning without constant human input.
Reported exploitedLangflow - The Hacker News
- The Hacker News
- The Hacker NewsChinese Hacker Commands DeepSeek via Telegram to Launch Autonomous Attacks
A Chinese-speaking threat actor leveraged the DeepSeek AI model through the Hermes Agent framework to execute autonomous cyberattacks. Using Telegram for initial instructions, the agent identified vulnerable internet-facing systems and deployed public exploits without further human input. The operation targeted over 460 systems across several high-risk vulnerabilities, including CVE-2026-3055 (NetScaler) and CVE-2026-39987 (Marimo), though only three successful breaches were confirmed. Organizations are urged to apply patches for exposed Langflow, n8n, and Marimo systems, as well as secure customer-managed NetScaler appliances.
Reported exploitedLangflow - SecurityWeekGoogle AI Uncovers 13-Year-Old Chrome Flaw Amid Record Patching Pace
Google has revealed that its recent surge in identifying Chrome vulnerabilities has been significantly boosted by the integration of artificial intelligence tools. This year alone, over 1,800 security flaws have been addressed, including a critical 13-year-old sandbox escape vulnerability tracked as CVE-2026-3545 (CVSS score 9.8). The flaw was discovered using an AI agent harness powered by Gemini and patched in Chrome 145 in early May. It could allow malicious HTML pages to trigger a sandbox escape, potentially exposing local files. Google continues to refine its AI systems for detecting, validating, and even generating patches for security issues, aiming to reduce response times and improve overall browser security.
ResearchGoogle - SecurityWeekCritical Code Execution Vulnerability Patched in TeamCity
JetBrains has addressed a high-severity vulnerability in TeamCity On-Premises that allows unauthenticated attackers to execute arbitrary code remotely. Tracked as CVE-2026-63077 (CVSS score 9.8), the flaw impacts all on-premises editions and could allow access to sensitive data, server tampering, and CI/CD pipeline manipulation. Patches are available in versions 2025.11.7 and 2026.1.3, with a security plugin offered for older versions.
PatchJetBrains - Help Net SecurityAviation cyber risk sits on the ground, the blindness sits in the air
Eliran Almong, CEO of Cyviation, highlights that most aviation cyber losses stem from ground operations—such as reservations, MRO IT, and airport systems—rather than airborne threats. Despite the hype around 'hacking a plane,' real risks lie in unsecured data flows and outdated protocols like GNSS jamming, which evade traditional monitoring tools. A critical vulnerability, CVE-2026-1579, was recently disclosed in PX4 Autopilot, allowing attackers to send unsigned commands via MAVLink. This flaw underscores the broader issue of unauthenticated communication channels in aviation systems. Almong emphasizes the need for better visibility into both ground infrastructure and aircraft data chains, advocating for digital twins and rigorous inventory management.
ResearchPX4 Autopilot
Thursday, Jul 304 stories
- BleepingComputerJetBrains warns of critical TeamCity remote code execution flaw
JetBrains has issued a warning about a severe vulnerability in its TeamCity On-Premises software, which could allow attackers to execute arbitrary code remotely. The flaw, identified as CVE-2026-63077, affects all versions of the on-premises edition and allows unauthorized users with HTTPS access to bypass authentication mechanisms. This could lead to full server compromise, including access to sensitive data and credentials. While no active exploitation has been observed yet, previous TeamCity vulnerabilities have been widely abused by ransomware groups and state-sponsored hackers. JetBrains recommends upgrading to version 2025.11.7 or later, or applying a security patch plugin for older versions.
PatchJetBrains - Ars Technica (Security)Max-severity Exchange server flaw under active exploitation by Kremlin hackers
Russian state-backed hackers are actively exploiting a high-severity vulnerability in Microsoft's Exchange Server, CVE-2026-42897, to deploy a new browser-based backdoor called OWAReaper. The flaw, a cross-site scripting (XSS) issue, allows attackers to execute malicious JavaScript simply by having users open an email in Outlook Web Access (OWA). Security firm Proofpoint reported that the group, known as TA488 and linked to the Kremlin, uses this method to gain persistent access to unpatched systems and steal sensitive data. Microsoft rated the vulnerability as maximum severity and issued a patch in July.
Reported exploitedOutlook Web Access (OWA) - BleepingComputerVMware fixes three critical flaws allowing auth bypass, VM escapes
Broadcom has issued security updates addressing five vulnerabilities in VMware products, including three critical flaws that enable authentication bypass, remote code execution, and virtual machine escape. The most severe issues—CVE-2026-59309, CVE-2026-59310, and CVE-2026-47876—affect vCenter and ESX systems, with CVSS scores up to 9.8. These flaws could allow unauthenticated attackers to gain unauthorized access or escalate privileges to the host system. Affected products include VMware Cloud Foundation, vSphere Foundation, and Telco Cloud platforms. Broadcom urges immediate patching, noting no workarounds are available and that delays could expose infrastructure to potential attacks.
PatchvCenter - Rapid7 BlogKindaRails2Shell: CVE-2026-66066, Critical Arbitrary File Read and Possible Remote Code Execution in Ruby on Rails
A critical vulnerability, CVE-2026-66066, was disclosed in Ruby on Rails on July 29, 2026, impacting applications using the libvips image processing library with Active Storage. This flaw allows unauthenticated attackers to read files accessible by the application process, potentially leading to remote code execution (RCE). The issue affects Rails 7.0 and newer versions where libvips is the default image processor. Affected organizations are urged to update to fixed versions like 7.2.3.2, 8.0.5.1, or 8.1.3.1, along with ensuring libvips is at least version 8.13. Applications using ImageMagick instead of libvips are not impacted.
PoC publicActive Storage