← All briefings

Broadcom VMware vCenter Server · Microsoft SharePoint · Microsoft Windows

Date: 2026-08-14 Prepared for: SOC Analysts | Incident Responders | Vulnerability Management | Security Leadership


Executive Summary

Active exploitation of CVE-2026-59310 (VMware vCenter) continues with reverse SSH persistence confirmed in new reporting. Microsoft has patched a Windows zero-day (“LegacyHive”) disclosed after July Patch Tuesday. Apple is issuing mercenary spyware threat notifications to iPhone users globally. A new Cisco Talos report details the “JWR” phishing framework targeting payment platforms. No new CISA KEV additions in the last 24 hours.


Critical Vulnerabilities

CVE-2026-59310 — Broadcom VMware vCenter Server

  • Severity: CVSS 9.8
  • EPSS: Not yet scored — exploitation confirmed in the wild
  • Technical detail: Directory-traversal in vCenter Syslog Server allowing unauthenticated RCE. New reporting from Bleeping Computer and Heise Security confirms threat actors are deploying a reverse SSH tool for persistent remote access post-exploitation. No authentication or user interaction required; any internet-reachable vCenter management interface is at risk.
  • Exploitation status: STATUS CHANGE — active campaign now confirmed to establish reverse SSH persistence; previously reported as exploited but persistence mechanism was not documented.
  • Remediation: Apply Broadcom patches immediately if not already done. Audit vCenter for unexpected SSH processes, new local accounts, and outbound SSH connections. Isolate vCenter management interfaces from untrusted networks.

CVE-2026-55040 — Microsoft SharePoint

  • Severity: CVSS 9.1
  • EPSS: Not yet scored — exploitation confirmed in the wild
  • Technical detail: Critical authentication bypass in SharePoint stemming from weak authentication logic, patched in July 2026 Patch Tuesday. Following public PoC release, threat actors are now actively exploiting this vulnerability in the wild per The Hacker News reporting. Internet-facing SharePoint deployments without the July patch applied are at immediate risk of authentication bypass and potential data access or lateral movement.
  • Exploitation status: STATUS CHANGE — active exploitation confirmed following PoC release; previously reported as PoC-available only.
  • Remediation: Apply July 2026 Patch Tuesday immediately if not done. Audit SharePoint authentication logs for anomalous access patterns. Treat unpatched internet-facing instances as potentially compromised.

LegacyHive — Microsoft Windows (Zero-Day)

  • Severity: Not yet assigned (zero-day, out-of-band patch)
  • EPSS: Not yet scored
  • Technical detail: Microsoft released an out-of-band patch for a Windows zero-day vulnerability dubbed “LegacyHive,” disclosed after the July 2026 Patch Tuesday cycle. Technical details are limited at time of writing; the name suggests registry hive handling as the attack surface. Out-of-band disclosure indicates elevated urgency.
  • Exploitation status: Exploitation status unclear — patch released proactively following disclosure; monitor for CVE assignment and exploitation confirmation.
  • Remediation: Apply the LegacyHive out-of-band Windows patch immediately. Monitor Microsoft Security Response Center for CVE assignment and technical details.

CVE-2026-72642 — Elastic Elasticsearch

  • Severity: CVSS 8.8
  • EPSS: 0 — newly published
  • Technical detail: The native ML inference process in Elasticsearch accepts a model operation that computes a memory address from an attacker-supplied offset embedded in an uploaded model. This can allow an authenticated user with ML model upload privileges to achieve arbitrary memory read/write, potentially leading to code execution within the inference process. Affects Elasticsearch 8.19.0–8.19.19 and 9.4.0–9.4.4, as well as 9.5.0. Elasticsearch is widely deployed in enterprise SIEM, logging, and analytics pipelines.
  • Exploitation status: No confirmed exploitation; published 2026-08-13.
  • Remediation: Upgrade Elasticsearch to 8.19.20+ or 9.4.5+. Restrict ML model upload permissions to trusted administrators only.

CVE-2026-14525 — IBM WebSphere Application Server Liberty

  • Severity: CVSS 9.4
  • EPSS: 0 — newly published
  • Technical detail: Authentication bypass in WebSphere Application Server Liberty versions 17.0.0.3 through 26.0.0.8 when the rtcomm-1.0 or rtcommGateway-1.0 feature is enabled. A remote unauthenticated attacker can bypass authentication controls on affected deployments. WebSphere Liberty is widely deployed in enterprise Java environments; the bypass is conditional on the rtcomm feature being active.
  • Exploitation status: No confirmed exploitation; published 2026-08-13.
  • Remediation: Apply IBM fix for CVE-2026-14525. If immediate patching is not possible, disable the rtcomm-1.0 and rtcommGateway-1.0 features unless operationally required.

ONGOING:

  • CVE-2026-68820 (Windows AFD/Lazarus): Nation-state exploitation ongoing — CISA KEV deadline 2026-08-25; apply August Patch Tuesday.
  • CVE-2026-48362 (Adobe ColdFusion CVSS 10.0): No confirmed exploitation; apply Adobe August updates.
  • CVE-2026-58231 (SAP Commerce Cloud CVSS 10.0): No confirmed exploitation; apply SAP August Security Notes.
  • CVE-2026-63294/66898/63293 (Canonical LXD CVSS 9.9): No confirmed exploitation; upgrade to patched LXD versions.
  • CVE-2026-20349 (Cisco ASA/FTD): CISA KEV deadline was 2026-08-14 — patch immediately if not done.
  • CVE-2026-72898/72899 (Metabase): CISA KEV deadline was 2026-08-14 — patch immediately if not done.
  • CVE-2026-63077 (JetBrains TeamCity): Actively exploited — upgrade to 2026.1.3.
  • CVE-2026-0257 (PAN-OS GlobalProtect): Qilin ransomware exploitation ongoing — patch immediately.
  • CVE-2026-16232 (Check Point SmartConsole): Actively exploited — treat unpatched instances as compromised.
  • CVE-2026-8037 (Progress Kemp LoadMaster): Ransomware exploitation confirmed — patch immediately.

European Advisories

BSI published a further batch of new and updated advisories on 2026-08-13.

New advisories (2026-08-13): BSI issued new high-severity advisories for Palo Alto Networks GlobalProtect App (WID-SEC-2026-2804) — multiple flaws enabling privilege escalation to administrator, arbitrary code execution, security bypass, data manipulation/disclosure, and DoS; apply GlobalProtect App updates immediately. Kibana (WID-SEC-2026-2824) — credential disclosure, configuration manipulation, privilege bypass, and DoS for authenticated remote attackers; apply Elastic updates. Langflow (WID-SEC-2026-2828) — RCE and security bypass; apply updates. WordPress (WID-SEC-2026-2822) — authenticated RCE; apply WordPress core updates. IBM i (WID-SEC-2026-2820) — covers the cluster of IBM i CVEs (privilege escalation, RCE, DoS, path traversal, SQLi, XSS) published 2026-08-13; apply IBM PTFs. Nagios Core and Nagios XI (WID-SEC-2026-2819) — XSS, RCE, security bypass; apply vendor updates. MongoDB (WID-SEC-2026-2818) — RCE, security bypass, data manipulation, DoS; apply MongoDB updates. Rsync (WID-SEC-2026-2817) — privilege escalation, RCE, data disclosure/manipulation, DoS; apply rsync updates. Absolute Secure Access (WID-SEC-2026-2830) — authenticated remote DoS; apply vendor updates.

BSI also published a new technical guideline (TR-03183 v1.0) to support manufacturers in meeting Cyber Resilience Act requirements — relevant for product security teams.

Updated advisories: BSI updated advisories for Linux Kernel (critical, WID-SEC-2026-2640), Microsoft Windows (critical, WID-SEC-2026-1104), Microsoft Office (critical, WID-SEC-2026-2317), ISC BIND (WID-SEC-2026-2484), Red Hat OpenShift/gRPC-Go (WID-SEC-2026-1136), Apple macOS (WID-SEC-2026-2687), Red Hat Enterprise Linux/Pillow, Golang Go, Helm, Apache Kafka, GStreamer, and multiple Linux Kernel advisories. No material new exploitation data in these updates; apply vendor patches per standard cycle.


Active Threats and Campaigns

NEW — Akira ransomware EDR bypass via Safe Mode: An Akira affiliate disabled EDR by rebooting a compromised host into Safe Mode with Networking, preventing security agents from loading. The attacker successfully exfiltrated data but failed to complete encryption. This technique is not novel but its confirmed use by Akira warrants defensive review: ensure EDR agents are configured to protect against Safe Mode bypass (e.g., Safe Mode boot restrictions via GPO, monitored boot events).

NEW — JWR phishing framework (Cisco Talos): Cisco Talos identified a previously undocumented phishing framework internally branded “JWR” by its developer, designed to convincingly impersonate checkout and login pages for major payment and shopping platforms. Organizations should update email and web gateway rules to detect JWR-associated infrastructure; IOCs available in the Talos report.

NEW — Jewelbug dual-track espionage/crypto fraud: The Jewelbug group has been observed conducting government and military webmail intrusions while simultaneously running cryptocurrency fraud operations. Confidence in attribution is limited to open-source reporting; European government entities should review webmail access logs for anomalous authentication.

ONGOING — Lazarus Group / Operation Dream Job (CVE-2026-68820): No new developments beyond yesterday’s report; European defense/aerospace organizations should continue hunting with Check Point IOCs.

ONGOING — Sandworm/UAC-0145 trojanized WireGuard, Gunra ransomware, DeadLock ransomware: No new developments.


Security News and Context

  • VMware vCenter active exploitation: Attackers are exploiting CVE-2026-59310 to deploy reverse SSH tools for persistence — Bleeping Computer; covered in Critical Vulnerabilities.
  • Apple mercenary spyware notifications: Apple is sending “Threat Notification” alerts to iPhone users targeted by mercenary spyware attacks — Bleeping Computer. Organizations with high-value targets (executives, legal, government) should treat these notifications seriously and initiate device forensics.
  • Trezor data breach: Hardware wallet maker Trezor disclosed a breach of ~14,000 customers via compromised logistics provider ShipMonk — Bleeping Computer. Relevant for organizations holding crypto assets or using hardware wallets.
  • LiteLLM supply-chain attack (March 2026): Researchers confirmed data from 2,500+ companies was exfiltrated in the March LiteLLM supply-chain attack — Heise Security. Organizations using LiteLLM should audit for credential exposure.
  • US White House hack-back authorization: A White House memo authorizes vetted private security firms to conduct offensive operations against foreign cybercrime organizations — Bleeping Computer. Policy development to watch for European legal and operational implications.

  1. VMware vCenter (CVE-2026-59310): Patch immediately; hunt for reverse SSH processes and outbound SSH connections from vCenter hosts; audit for new accounts and scheduled tasks.
  2. SharePoint (CVE-2026-55040): Apply July 2026 Patch Tuesday if not done; audit authentication logs for bypass indicators; treat unpatched internet-facing instances as compromised.
  3. Windows LegacyHive zero-day: Deploy Microsoft’s out-of-band patch immediately; monitor MSRC for CVE assignment and exploitation details.
  4. Palo Alto Networks GlobalProtect App (WID-SEC-2026-2804): Apply vendor updates; review for privilege escalation indicators.
  5. Elasticsearch (CVE-2026-72642): Upgrade to 8.19.20+ or 9.4.5+; restrict ML model upload permissions.
  6. IBM WebSphere Liberty (CVE-2026-14525): Apply IBM fix or disable rtcomm-1.0/rtcommGateway-1.0 features as interim mitigation.
  7. Akira ransomware EDR bypass: Enforce Safe Mode boot restrictions via GPO; verify EDR agents load in Safe Mode; alert on unexpected reboots.
  8. Apple spyware notifications: Initiate device forensics for any staff receiving Apple Threat Notifications; consider Mobile Threat Defense tooling for high-risk users.
  9. LiteLLM supply-chain (March 2026): Audit LiteLLM deployments for credential exposure; rotate any API keys or secrets that may have been in scope.
  10. Continue remediation of previously reported items: CVE-2026-20349 (Cisco ASA/FTD — deadline passed), CVE-2026-72898/72899 (Metabase — deadline passed), CVE-2026-68820 (Windows/Lazarus), CVE-2026-48362 (ColdFusion), CVE-2026-58231 (SAP Commerce Cloud), CVE-2026-63077 (TeamCity), CVE-2026-0257 (PAN-OS), CVE-2026-16232 (Check Point SmartConsole), CVE-2026-8037 (LoadMaster).