Daily Threat Briefing
Briefings
TrueConf Server · Zimbra Collaboration Suite · SPIP
Two TrueConf Server vulnerabilities — including an unauthenticated code injection exploitable via port 4307/TCP — were added to the CISA KEV catalog with an unusually tight 72-hour remediation…
Citrix NetScaler ADC and NetScaler Gateway · MLflow · Splunk Enterprise
A critical authentication bypass in Citrix NetScaler ADC and NetScaler Gateway (CVE-2026-19490, CVSS 9.3) was disclosed on 2026-08-19 and warrants immediate patching given the perimeter-facing…
Microsoft Internet Key Exchange · Apple macOS · Red Hat Build of Keycloak
CISA added four vulnerabilities to the KEV catalog on 2026-08-18, including CVE-2026-33824 (Microsoft IKE double-free RCE, deadline 2026-08-21) and CVE-2026-65400 (Apple macOS Screen Sharing improper…
Anyscale Ray · GitLab CE/EE · Microsoft Defender / Malware Protection Engine
Today's most critical new developments: CISA added CVE-2025-62593 (Anyscale Ray) to the KEV catalog with a three-day remediation deadline of 2026-08-20, confirming active exploitation of this code…
SiYuan Note-Taking App · Acer Planet9 Background Service · OpenTofu
Today's most notable new developments include a large-scale data theft campaign attributed to Russian cybercriminals targeting Shell, Philips, GE, and other major energy and medical technology firms,…
Templately WordPress Plugin · User Profile Builder WordPress Plugin · Pandora Analysis Platform
Today's new material centers on a cluster of high-severity WordPress plugin vulnerabilities — most notably a Templately RCE flaw with an EPSS of 0.98 and a User Profile Builder authentication bypass…
Tenable Security Center · IBM Db2 Mirror for i · SAP Commerce Cloud
A maximum-severity SAP Commerce Cloud RCE vulnerability is now being actively targeted in attacks within days of patching. A macOS Screen Sharing authentication bypass is under active exploitation…
Broadcom VMware vCenter Server · Microsoft SharePoint · Microsoft Windows
Active exploitation of CVE-2026-59310 (VMware vCenter) continues with reverse SSH persistence confirmed in new reporting. Microsoft has patched a Windows zero-day ("LegacyHive") disclosed after July…
Windows Ancillary Function Driver for WinSock · Broadcom VMware vCenter Server · Adobe ColdFusion
Lazarus Group (North Korea) has been confirmed exploiting CVE-2026-68820 (Windows zero-day) against defense and aerospace firms in France, Germany, Brazil, and India as part of Operation Dream Job —…
Windows Ancillary Function Driver for WinSock · Microsoft SharePoint Server · Cisco Secure Firewall ASA and FTD
August 2026 Patch Tuesday delivered 421 Microsoft vulnerabilities, including one actively exploited zero-day (CVE-2026-68820, Windows AFD for WinSock, CISA KEV), two publicly disclosed zero-days, and…
Metabase · SAP NetWeaver and ABAP Platform · Progress Kemp LoadMaster
Today's most critical new developments are two CVSS 10.0 SQL injection flaws in Metabase with confirmed active exploitation, a CVSS 9.8 unauthenticated memory corruption flaw in SAP NetWeaver ABAP…
JetBrains TeamCity
Today's primary new item is a Rapid7-published proof-of-concept for CVE-2026-63077 (JetBrains TeamCity unauthenticated RCE), providing full technical detail on the XStream deserialization gadget…
WordPress AI Copilot · MSI Radix AXE6600 Router · D-Link DWR-M961 Router
Today's new material centers on three clusters: a WordPress plugin authorization bypass (CVE-2026-14526, CVSS 9.8, EPSS 0.61) with high exploitation probability; ten-plus command injection flaws…
Progress LoadMaster · JetBrains TeamCity · WordPress Core
CISA added CVE-2026-8037 (Progress LoadMaster command injection) to the KEV catalog with a three-day remediation deadline of 2026-08-10 — unauthenticated exploitation is confirmed. Rapid7 published a…
Google Chrome · Apache CXF · Microsoft Teams
Google Chrome 151 received a critical security update patching two sandbox-escape flaws (CVE-2026-19149, CVE-2026-19170) alongside multiple high-severity V8 RCE vulnerabilities — update all…
JetBrains TeamCity · Cisco Catalyst SD-WAN Manager & Controller · Progress MarkLogic Server
CISA added CVE-2026-63077 (JetBrains TeamCity unauthenticated RCE via deserialization) to the KEV catalog with a three-day remediation deadline. Cisco disclosed a sweeping set of critical and…
IBM Langflow · Veeam Service Provider Console · HPE EdgeConnect SD-WAN Orchestrator
Three new CISA KEV additions dominate today's briefing: CVE-2026-9198 (IBM Langflow unauthenticated RCE), CVE-2026-34486 (Apache Tomcat encryption bypass), and CVE-2026-18556 (N-able N-central auth…
N-able N-central · Ruby on Rails Active Storage · Adobe Campaign Classic
The most critical new development is active exploitation of CVE-2026-18577 (N-able N-central authentication bypass), now confirmed by N-able and added to the CISA KEV catalog with a 3-day remediation…
Bouncy Castle for Java · N-able N-central · Vikunja
Today's dominant development is a large batch release from Bouncy Castle for Java (BC-JAVA < 1.85, BC-LTS-JAVA < 2.73.12, BC-FJA multiple versions) addressing 15+ cryptographic vulnerabilities rated…
Adobe Campaign Classic · FreeRDP · GitPython
Today's most significant new items are a CVSS 10.0 flaw in Adobe Campaign Classic enabling unauthenticated RCE, a large-scale FreeRDP security release addressing 15+ vulnerabilities including heap…
NocoBase · Logsign SIEM · pgAdmin 4
The most significant new developments today are a critical CVSS 10.0 SQL injection-to-RCE chain in NocoBase (EPSS 0.59 — elevated exploitation probability), a CVSS 9.8 code injection flaw in Logsign…
VMware vCenter Server · Microsoft Azure Cosmos DB · Ruby on Rails
Today's most significant new developments are two critical unauthenticated RCE vulnerabilities in VMware vCenter (CVE-2026-59309/CVE-2026-59310) confirmed by Broadcom with no available workarounds, a…
Cisco Secure Firewall Management Center · VMware vCenter Server · JetBrains TeamCity On-Premises *
The most critical new development today is active zero-day exploitation of CVE-2026-20316, a hard-coded credential flaw in Cisco Secure Firewall Management Center, now added to the CISA KEV catalog…
Check Point SmartConsole / Security Management Server · JetBrains TeamCity On-Premises · IBM WebSphere Application Server
Today's most significant new developments are a public technical analysis and PoC for the actively exploited Check Point SmartConsole authentication bypass (CVE-2026-16232), a critical…
Arista VeloCloud Orchestrator On-Prem · Fortinet FortiOS · vBulletin 5.x / 6.x
Two new CISA KEV entries dominate today's briefing: a Fortinet FortiOS information-disclosure flaw enabling patch-bypass via crafted HTTP requests (CVE-2025-68686, due 2026-08-10) and a…
Microsoft Edge
No new CISA KEV entries, BSI WID advisories, or CERT-EU publications were recorded in the last 24 hours. The most notable new items are two Microsoft Edge information-disclosure vulnerabilities and…
Alibaba Fastjson 1.x · Authenticated RCE via Jupyter Notebook · SiYuan Note-Taking Application
Today's most significant new items are an actively exploited unpatched RCE in Alibaba's Fastjson 1.x library (CVE-2026-16723, CVSS 9.0), a public PoC for a GitLab authenticated RCE flaw (CVE not yet…
Active Directory Certificate Services · Authenticated RCE · Microsoft Kiota
Today's most significant new developments are a working public exploit for Certighost, an Active Directory certificate abuse flaw enabling domain controller impersonation and DCSync by any…
Check Point SmartConsole / Quantum Security Management · Linux Kernel · Microsoft Azure DNS
Three critical Microsoft Azure/cloud service vulnerabilities (CVSS 10.0) were published today affecting Azure DNS, Azure Key Vault, and Exchange Online. A new Linux kernel local privilege escalation…
Check Point SmartConsole / Quantum Security Management · Microsoft SharePoint Server · Fujitsu Linux/Oracle Solaris openFT
Two new CISA KEV entries demand immediate attention: CVE-2026-16232 (Check Point SmartConsole authentication bypass, CVSS 9.1) and CVE-2026-50522 (Microsoft SharePoint RCE) — the latter already…