← All briefings

Adobe Campaign Classic · FreeRDP · GitPython

Date: 2026-08-02 Prepared for: SOC Analysts | Incident Responders | Vulnerability Management | Security Leadership


Executive Summary

Today’s most significant new items are a CVSS 10.0 flaw in Adobe Campaign Classic enabling unauthenticated RCE, a large-scale FreeRDP security release addressing 15+ vulnerabilities including heap overflows and TLS validation bypasses, multiple critical GitPython command-injection and exfiltration flaws, and a confirmed Midnight Blizzard sub-cluster (Storm-2945) delivering surveillance malware via hijacked hotel Wi-Fi. A Coldcard hardware wallet firmware flaw has been linked to a $70M Bitcoin theft. No new CISA KEV additions in the last 24 hours.


Critical Vulnerabilities

CVE-2026-48449 — Adobe Campaign Classic

  • Severity: CVSS 10.0
  • EPSS: Not yet scored
  • Technical detail: Incorrect authorization in Adobe Campaign Classic (ACC) allows an unauthenticated remote attacker to execute arbitrary code without user interaction. ACC is an enterprise marketing automation platform widely deployed in large European organizations; internet-facing ACC instances are at immediate risk. The vulnerability requires no privileges and no user interaction, placing it in the highest exploitability tier.
  • Exploitation status: No confirmed in-the-wild exploitation reported; CVSS 10.0 with no authentication requirement warrants urgent treatment.
  • Remediation: Apply Adobe’s security update for Campaign Classic immediately. Restrict ACC management and API interfaces to trusted internal networks pending patching. Review ACC access logs for anomalous unauthenticated requests.

CVE-2026-67305 / CVE-2026-67292 / CVE-2026-66402 / CVE-2026-67289 et al. — FreeRDP (< 3.29.0)

  • Severity: CVSS 9.4 (heap buffer overflow, CVE-2026-67305); 9.3 (multiple); 8.7 (multiple)
  • EPSS: 0 (newly published across all entries)
  • Technical detail: FreeRDP 3.29.0 resolves 15+ distinct vulnerabilities spanning: a heap buffer overflow in clipboard virtual channel processing (CVE-2026-67305); buffer over-disclosure in gateway WebSocket transport (CVE-2026-67292); multiple TLS certificate identity validation weaknesses including improper EKU validation and wildcard hostname matching bypasses (CVE-2026-66402, CVE-2026-67294, CVE-2026-67293); CRLF injection in RDP redirection TargetNetAddress (CVE-2026-67289); heap use-after-free in async update message proxy (CVE-2026-67299, CVE-2026-67300); heap out-of-bounds reads in glyph cache and TSMF FFmpeg decoder; and a server-side heap buffer overflow in the RAIL channel handler (CVE-2026-67298). The TLS validation flaws are particularly significant as they enable MitM attacks against RDP sessions. FreeRDP is embedded in numerous enterprise remote desktop clients and thin-client solutions.
  • Exploitation status: No confirmed exploitation reported; breadth of the release and severity of memory corruption flaws elevate urgency.
  • Remediation: Upgrade FreeRDP to 3.29.0. Audit deployments of FreeRDP-based clients (Remmina, xfreerdp, embedded OEM clients). Disable --async-update where not required to mitigate use-after-free class.

CVE-2026-67324 / CVE-2026-67325 / CVE-2026-67323 / CVE-2026-67322 — GitPython

  • Severity: CVSS 9.3 (CVE-2026-67324); 8.7 (CVE-2026-67322, CVE-2026-67325); 8.6 (CVE-2026-67323)
  • EPSS: 0 (newly published)
  • Technical detail: Four command-injection and exfiltration vulnerabilities patched across GitPython 3.1.50–3.1.52. CVE-2026-67324 (fix in 3.1.51): the unsafe-option gate fails to recognize joined short-option forms (e.g., -u<value>), allowing bypass. CVE-2026-67325 (fix in 3.1.51): incomplete blocklist misses Git’s long-option prefix abbreviation feature. CVE-2026-67323 (fix in 3.1.51): Repo.archive() and git.ls_remote() do not guard keyword-argument options such as --exec/--upload-pack. CVE-2026-67322 (fix in 3.1.52): Repo.clone_from() passes caller-supplied URLs through Git.polish_url(), enabling environment-variable exfiltration. GitPython is pervasive in CI/CD pipelines, developer tooling, and security automation; exploitation of these flaws in pipeline contexts could lead to secret theft or arbitrary command execution on build agents.
  • Exploitation status: No confirmed exploitation reported.
  • Remediation: Upgrade GitPython to 3.1.52 (addresses all four CVEs). Audit CI/CD pipelines and automation scripts that pass user-controlled input to GitPython APIs. Treat build agent environments as potentially compromised if running vulnerable versions with untrusted input.

CVE-2026-8457 — WooCommerce Social Login (WordPress)

  • Severity: CVSS 9.8
  • EPSS: 0 (newly published)
  • Technical detail: Authentication bypass in WooCommerce – Social Login plugin ≤ 2.8.7 for WordPress. The Apple login handler accepts the Apple ID token without proper server-side validation, allowing an unauthenticated attacker to authenticate as any user including administrators. WordPress e-commerce sites using this plugin are at risk of full account takeover without credentials.
  • Exploitation status: No confirmed exploitation reported; CVSS 9.8 unauthenticated auth bypass warrants immediate action.
  • Remediation: Update WooCommerce – Social Login to 2.8.8 or later. Audit WordPress user accounts for unauthorized privilege changes; review authentication logs for anomalous Apple login activity.

CVE-2026-18556 — N-able N-central

  • Severity: CVSS 8.2
  • EPSS: 0 (newly published)
  • Technical detail: Authentication bypass via alternate path or channel in N-able N-central through version 2026.1. N-central is an enterprise remote monitoring and management (RMM) platform widely used by managed service providers (MSPs) across Europe. Compromise of an RMM platform provides an attacker with privileged access to all managed endpoints — a high-value target for ransomware operators and supply-chain attackers.
  • Exploitation status: No confirmed exploitation reported; RMM platforms are a priority target for threat actors.
  • Remediation: Apply N-able’s patch for N-central beyond 2026.1 immediately. Restrict N-central management interfaces to dedicated management networks; enforce MFA on all N-central accounts; audit for unauthorized access or configuration changes.

ONGOING:

  • CVE-2026-66066 (Ruby on Rails Active Storage): Upgrade Rails + libvips ≥ 8.13; rotate all application secrets — also see new Bleeping Computer/Heise coverage confirming RCE escalation path.
  • CVE-2026-52887 (NocoBase): Upgrade to 2.0.61+; restrict to internal networks.
  • CVE-2026-17561 (Logsign SIEM): Upgrade to 6.4.108+; isolate management interfaces.
  • CVE-2026-17566 et al. (pgAdmin 4): Upgrade to 9.18.
  • CVE-2026-16232 (Check Point SmartConsole): Actively exploited; treat unpatched instances as compromised.
  • CVE-2026-0257 (PAN-OS GlobalProtect): Qilin ransomware exploitation ongoing — patch immediately.
  • CVE-2026-20316 (Cisco FMC): CISA KEV deadline passed 2026-08-01 — verify patch completion.
  • CVE-2026-59309/CVE-2026-59310 (VMware vCenter): No workarounds; patch urgently.

European Advisories

No new BSI WID or CERT-EU advisories were published in the last 24 hours.

Heise Security (German-language) published two relevant items: a detailed analysis of the Ruby on Rails Active Storage flaw (CVE-2026-66066) confirming that crafted images can be used to read server environment variables including application secrets, enabling further system compromise — this reinforces the urgency of the ONGOING remediation item. Heise also reported on the German Foreign Ministry (Auswärtiges Amt) issuing a warning about North Korean IT workers infiltrating Western companies (see Active Threats).


Active Threats and Campaigns

NEW — Storm-2945 / Midnight Blizzard sub-cluster (CaptiveCrunch / CornFlake RAT): Microsoft has identified an active campaign in which threat actors hijack hotel Wi-Fi captive portals to serve fake browser update prompts. Victims who accept the update receive CornFlake, a RAT capable of capturing webcam images, microphone audio, and keystrokes. Microsoft attributes the operation to Storm-2945, assessed as an operational sub-cluster of Midnight Blizzard (SVR-linked). The targeting of hotel networks is consistent with intelligence-gathering against traveling government and corporate personnel. European business travelers are a plausible target set. Action: Brief traveling staff on captive portal risks; enforce VPN-before-browsing policy on travel; update endpoint detection for CornFlake indicators.

NEW — AMOS Stealer (macOS) Active Infections: SANS ISC reports fresh Atomic macOS Stealer (AMOS) infections as of 2026-08-02. AMOS targets browser credentials, crypto wallets, and keychain data on macOS endpoints. Action: Update macOS EDR signatures; alert on AMOS IOCs; review macOS endpoint telemetry for credential-harvesting activity.

NEW — Phishing Campaigns Targeting AI Solution Providers: SANS ISC reports phishing campaigns impersonating AI services including ChatGPT to harvest credentials. The campaigns exploit user concern over losing access to AI tools. Action: Update email gateway rules to flag AI-brand impersonation; brief users on AI-themed phishing lures.

ONGOING — XCSSET v40 (macOS/Xcode): No new developments; scan Xcode repos, enforce code-signing. ONGOING — Adform supply-chain (crypto clipboard hijacking): Adform has remediated; audit third-party script integrity and SRI controls. ONGOING — Laundry Bear / Void Blizzard (Exchange OWA): Restrict OWA to VPN/trusted networks. ONGOING — Device Code Phishing (OAuth 2.0): Enforce Conditional Access blocking device code flow where not required.


Security News and Context

  • Coldcard firmware flaw — $70M Bitcoin theft: A March 2021 firmware error routed seed generation to a deterministic software PRNG in Coldcard hardware wallets; an attacker exploited this to drain 1,082 BTC (~$70.2M) across 1,196 addresses in 41 minutes on July 30. Coldcard users should verify firmware integrity and consider key migration.
  • North Korean IT worker infiltration warning: Germany’s Auswärtiges Amt joined an international advisory warning that North Korean nationals are posing as freelance IT workers to infiltrate Western companies, exfiltrate IP, and generate revenue for the DPRK regime. European HR and procurement teams should strengthen contractor vetting procedures.
  • Rails Active Storage RCE confirmed: Bleeping Computer confirms unauthenticated arbitrary file read in Rails Active Storage with RCE escalation potential — reinforces urgency of patching CVE-2026-66066.

  1. Adobe Campaign Classic (CVE-2026-48449): Apply vendor security update immediately; restrict ACC interfaces to trusted networks.
  2. FreeRDP (CVE-2026-67305 et al.): Upgrade to 3.29.0; audit all FreeRDP-based client deployments; disable --async-update where not needed.
  3. GitPython (CVE-2026-67324 et al.): Upgrade to 3.1.52 in all CI/CD pipelines and automation tooling; audit for user-controlled input paths.
  4. WooCommerce Social Login (CVE-2026-8457): Update plugin to 2.8.8+; audit WordPress admin accounts for unauthorized changes.
  5. N-able N-central (CVE-2026-18556): Patch to version beyond 2026.1; enforce MFA; restrict management interface exposure.
  6. Storm-2945 / CornFlake RAT: Brief traveling staff on captive portal risks; enforce VPN-before-browsing; deploy CornFlake detection signatures.
  7. AMOS Stealer (macOS): Update macOS EDR signatures; review endpoint telemetry for credential-harvesting indicators.
  8. North Korean IT worker infiltration: Strengthen contractor identity vetting; audit access granted to recent freelance/contract IT hires.
  9. Rails Active Storage (CVE-2026-66066): Upgrade Rails + libvips ≥ 8.13; rotate all application secrets — RCE escalation path now confirmed.
  10. Continue remediation of previously reported items: VMware vCenter (CVE-2026-59309/10), Cisco FMC (CVE-2026-20316 — KEV deadline passed), Check Point SmartConsole (CVE-2026-16232), PAN-OS (CVE-2026-0257), pgAdmin 4 (CVE-2026-17566), Logsign SIEM (CVE-2026-17561).