Windows Ancillary Function Driver for WinSock · Broadcom VMware vCenter Server · Adobe ColdFusion
Date: 2026-08-13 Prepared for: SOC Analysts | Incident Responders | Vulnerability Management | Security Leadership
Executive Summary
Lazarus Group (North Korea) has been confirmed exploiting CVE-2026-68820 (Windows zero-day) against defense and aerospace firms in France, Germany, Brazil, and India as part of Operation Dream Job — elevating this from a generic Windows patch priority to an active nation-state targeting concern for European organizations. A critical SharePoint PoC is now being actively leveraged in attacks. Adobe ColdFusion and SAP Commerce Cloud carry CVSS 10.0 flaws with exploitation activity confirmed on the Adobe Commerce/Magento side. Canonical LXD received a cluster of CVSS 9.9 vulnerabilities requiring urgent patching.
Critical Vulnerabilities
CVE-2026-68820 — Windows Ancillary Function Driver for WinSock (AFD)
- Severity: CVSS 7.0
- EPSS: Not yet scored — exploitation confirmed in the wild
- Technical detail: Use-after-free in
afd.sysenabling SYSTEM-level privilege escalation. Check Point Research has now formally attributed active exploitation to Lazarus Group as part of Operation Dream Job, targeting defense and aerospace companies in France, Germany, Brazil, and India. The European targeting dimension (France, Germany) materially elevates priority for this report’s audience. - Exploitation status: STATUS CHANGE — nation-state attribution confirmed (Lazarus/Operation Dream Job); CISA KEV deadline 2026-08-25.
- Update: Apply August 2026 Patch Tuesday immediately if not already done. Hunt for anomalous SYSTEM-level process chains from user-mode processes, particularly on endpoints belonging to defense, aerospace, or government-adjacent staff.
CVE-2026-59310 — Broadcom VMware vCenter Server
- Severity: CVSS 9.8
- EPSS: Not yet scored — exploitation confirmed in the wild
- Technical detail: Directory-traversal vulnerability in VMware vCenter Server allowing a network-adjacent unauthenticated attacker to execute arbitrary code. No authentication or user interaction required. Patches were previously released; threat actors have now begun active exploitation to gain persistent remote access, per QUIRSO research published 2026-08-12.
- Exploitation status: NEW — actively exploited in the wild as of 2026-08-12.
- Remediation: Apply Broadcom VMware vCenter patches immediately. Restrict vCenter management interfaces to trusted administrative networks. Audit vCenter for signs of unauthorized persistent access (new accounts, scheduled tasks, unexpected API calls).
CVE-2026-48362 — Adobe ColdFusion (and Campaign Classic)
- Severity: CVSS 10.0
- EPSS: Not yet scored
- Technical detail: OS command injection vulnerability in Adobe ColdFusion enabling unauthenticated arbitrary code execution. Adobe also patched two additional CVSS 10.0 flaws in Campaign Classic on the same patch day. ColdFusion is widely deployed in enterprise environments; unauthenticated OS command injection at maximum severity warrants immediate action. A companion critical flaw (
CVE-2026-71362) in Adobe Commerce/Magento is already being actively exploited to hijack customer accounts per Bleeping Computer reporting. - Exploitation status:
CVE-2026-48362— no confirmed exploitation yet;CVE-2026-71362(Adobe Commerce/Magento) — actively exploited in the wild. - Remediation: Apply Adobe August 2026 security updates for ColdFusion, Campaign Classic, and Commerce/Magento immediately. Treat internet-facing ColdFusion and Magento instances as highest priority. Review Commerce/Magento customer account activity for unauthorized access.
CVE-2026-58231 — SAP Commerce Cloud (Data Hub Adapter)
- Severity: CVSS 10.0
- EPSS: Not yet scored
- Technical detail: Insufficient authorization checks and input validation in SAP Commerce Cloud’s Data Hub Adapter allow an unauthenticated remote attacker to execute arbitrary code. Described by SAP as a maximum-severity flaw; Heise Security characterizes the platform as “fully compromisable.” Affects SAP Commerce Cloud deployments using the Data Hub Adapter component.
- Exploitation status: No confirmed exploitation; patch released 2026-08-12 (SAP Patch Day).
- Remediation: Apply SAP August 2026 Security Notes immediately; prioritize Commerce Cloud. Restrict Data Hub Adapter endpoints at the network perimeter pending patching. This was covered in BSI advisory
WID-SEC-2026-2746(yesterday); see European Advisories for cross-reference.
CVE-2026-63294 / CVE-2026-66898 / CVE-2026-63293 — Canonical LXD (Multiple Critical Flaws)
- Severity: CVSS 9.9 (all three)
- EPSS: 0 — newly published
- Technical detail: Three distinct CVSS 9.9 vulnerabilities in Canonical LXD affecting versions across the 4.x, 5.x, and 6.x branches.
CVE-2026-63294— symlink-following during image/backup archive import enables root command execution on the host.CVE-2026-66898— path traversal during backup import/restore allows arbitrary filesystem manipulation.CVE-2026-63293— symlink-following during image unpacking enables arbitrary file read/write on the host. All three require an authenticated attacker with access to import or restore archives. Two additional authorization-bypass flaws (CVE-2026-62420,CVE-2026-63296,CVE-2026-63297) also scored 9.9 and affect cross-project instance migration. LXD is widely used in cloud and container infrastructure. - Exploitation status: No confirmed exploitation; all published 2026-08-12.
- Remediation: Upgrade LXD to 4.0.12, 5.0.4/5.0.8, 5.21.2/5.21.6, or 6.1/6.10 as applicable per CVE. Restrict LXD API access to trusted users; audit who has archive import/restore permissions.
ONGOING:
CVE-2026-55040+CVE-2026-63520(SharePoint): PoC now being actively used in attacks — patch immediately if not done; see yesterday’s report for full detail.CVE-2026-20349(Cisco ASA/FTD): CISA KEV deadline 2026-08-14 — patch today.CVE-2026-72898/CVE-2026-72899(Metabase): CISA KEV deadline 2026-08-14 — patch today.CVE-2026-65791(Windows iSCSI Target): CVSS 9.8, no exploitation confirmed — apply Patch Tuesday updates.CVE-2026-62832(Windows User Profile Service): Publicly disclosed EoP — apply Patch Tuesday updates.CVE-2026-63077(JetBrains TeamCity): Actively exploited — upgrade to 2026.1.3.CVE-2026-0257(PAN-OS GlobalProtect): Qilin ransomware exploitation ongoing — patch immediately.CVE-2026-16232(Check Point SmartConsole): Actively exploited — treat unpatched instances as compromised.CVE-2026-8037(Progress Kemp LoadMaster): Ransomware exploitation confirmed — patch immediately.
European Advisories
BSI published a large batch of new and updated advisories on 2026-08-12, the day after Microsoft/SAP Patch Tuesday.
New advisories (2026-08-12): BSI issued new critical/high advisories for Microsoft Windows products (WID-SEC-2026-2756) covering RCE, privilege escalation, DoS, information disclosure, file manipulation, XSS, and security bypass across Windows 10/11 and Server 2012–2025 including Exchange — apply August 2026 Patch Tuesday; critical items detailed in Critical Vulnerabilities. New advisories also cover Google Chrome (WID-SEC-2026-2790) — update Chrome immediately; Zoom Workplace and Rooms (WID-SEC-2026-2763) — RCE, information disclosure, DoS — apply Zoom updates; MongoDB (WID-SEC-2026-2794) — multiple flaws including RCE in BI Connector ODBC Driver (upgrade to 1.4.9); IBM InfoSphere Information Server (WID-SEC-2026-2801) — RCE, DoS, information disclosure; Snipe-IT (WID-SEC-2026-2792) — security bypass, data manipulation, information disclosure; and a new Linux Kernel advisory (WID-SEC-2026-2799).
WID-SEC-2026-2756 (Microsoft Windows): covered in Critical Vulnerabilities (CVE-2026-68820 and Patch Tuesday items).
Updated advisories: BSI updated advisories for Microsoft Office products, Samba, GNU libc, Linux Kernel (multiple), NGINX-UI, Cacti, Golang Go, Mozilla Firefox/Thunderbird, Apple macOS, libssh, FreeBSD, GnuTLS, GStreamer, CPython, Red Hat Ansible Automation Platform, and Red Hat OpenShift (oauth-proxy). Apply vendor patches per standard cycle; no material new exploitation data in these updates.
Active Threats and Campaigns
NEW — Lazarus Group / Operation Dream Job (Windows zero-day, European targeting): Check Point Research confirmed Lazarus Group exploited CVE-2026-68820 to deliver a previously unknown backdoor against defense and aerospace companies in France and Germany (also Brazil and India). The campaign uses fake job offer lures consistent with Operation Dream Job’s established social engineering pattern. European defense-sector organizations should treat this as an active, targeted threat. IOCs and YARA rules are available in the Check Point Research publication. Hunt for the backdoor on endpoints belonging to defense, aerospace, and government-adjacent personnel.
NEW — “City-Forum” data theft campaign (Salesforce / ServiceNow portals): An ongoing campaign uses custom tooling to exfiltrate data exposed to anonymous users through Salesforce Experience Cloud and ServiceNow customer portals. Organizations using these platforms should audit anonymous/guest access configurations and review portal data exposure.
NEW — WindRelay / SpyNote Android malware combo: A new Android NFC relay malware (WindRelay) is being deployed alongside the SpyNote RAT to steal live payment card data in real time. Primarily a consumer threat but relevant for organizations with BYOD policies or mobile payment workflows.
NEW — 737 malicious Chrome VPN extensions: Over 737 Chrome Web Store extensions impersonating VPN/proxy services were found routing user traffic through a single SOCKS5 proxy infrastructure, primarily targeting Russian-speaking users but with broader reach (75,486 installs, 274 impersonating 66 legitimate services). Enforce browser extension allowlisting in managed enterprise environments.
ONGOING — Sandworm/UAC-0145 trojanized WireGuard campaign: No new developments; brief IT staff on fake recruiter lures and verify VPN software integrity. ONGOING — Gunra ransomware targeting European critical infrastructure: No new IOCs; validate Fortinet and Schneider Electric patch status. ONGOING — DeadLock ransomware (blockchain C2): No new developments.
Security News and Context
- Lazarus / Operation Dream Job (European targets): Check Point Research confirmed nation-state exploitation of
CVE-2026-68820against French and German defense firms — covered in Active Threats. - SharePoint PoC actively exploited: Hackers are now leveraging Rapid7’s published PoC for the SharePoint RCE chain in live attacks, per Bleeping Computer — patch urgency elevated to critical.
- AI reasoning API flaw (OpenAI, Anthropic, Google): Researchers disclosed a flaw allowing weaker AI models to decode encrypted reasoning objects from stronger models’ API sessions, recovering secrets including API keys and passwords from session logs — The Hacker News. Organizations using these APIs should rotate credentials and review session log exposure.
- Threema DDoS disruption: Ongoing DDoS attacks via a third-party provider caused multi-hour outages for the Threema messenger on 2026-08-12 and continued into 2026-08-13 — Heise Security. Relevant for European organizations using Threema for secure communications.
- TPM security coprocessor vulnerability: Heise Security reports a newly disclosed vulnerability affecting the Trusted Platform Module (TPM) in many CPUs, undermining the hardware root of trust — Heise. Details limited; monitor for CVE assignment and vendor guidance.
Recommended Actions
- Lazarus/CVE-2026-68820: Hunt for the Operation Dream Job backdoor on defense/aerospace endpoints using Check Point IOCs; verify August Patch Tuesday is applied enterprise-wide.
- SharePoint (CVE-2026-63520 + CVE-2026-55040): PoC now in active use — treat any unpatched internet-facing SharePoint as compromised; audit authentication logs immediately.
- VMware vCenter (CVE-2026-59310): Apply patches now; restrict management interface network access; audit for persistent access indicators.
- Adobe ColdFusion (CVE-2026-48362) and Commerce/Magento (CVE-2026-71362): Apply Adobe August updates; review Magento customer accounts for unauthorized access.
- Cisco ASA/FTD (CVE-2026-20349) and Metabase (CVE-2026-72898/72899): CISA KEV deadline is today (2026-08-14) — patch immediately.
- SAP Commerce Cloud (CVE-2026-58231): Apply SAP August Security Notes; restrict Data Hub Adapter endpoints at the perimeter.
- Canonical LXD: Upgrade to patched versions (4.0.12 / 5.0.8 / 5.21.6 / 6.10); restrict archive import permissions.
- Chrome VPN extensions: Audit and enforce browser extension allowlisting in managed environments; remove unauthorized VPN/proxy extensions.
- AI API credentials: Rotate API keys for OpenAI, Anthropic, and Google AI services; review session log access controls.
- Continue remediation of previously reported items:
CVE-2026-63077(TeamCity),CVE-2026-0257(PAN-OS),CVE-2026-16232(Check Point SmartConsole),CVE-2026-8037(LoadMaster), BdThemes WordPress supply chain.