Anyscale Ray · GitLab CE/EE · Microsoft Defender / Malware Protection Engine
Date: 2026-08-18 Prepared for: SOC Analysts | Incident Responders | Vulnerability Management | Security Leadership
Executive Summary
Today’s most critical new developments: CISA added CVE-2025-62593 (Anyscale Ray) to the KEV catalog with a three-day remediation deadline of 2026-08-20, confirming active exploitation of this code injection flaw. A critical GitLab GraphQL vulnerability (CVE-2026-19478, CVSS 9.4) allows unauthenticated deletion of public projects. Apple released a major iOS/macOS update fixing 108 vulnerabilities. A Microsoft Defender zero-day (CVE-2026-69414, “ShieldBreak”) remains unpatched. A French tax authority breach affecting 678,000 individuals and a claim of 3.6 million Azure account records stolen from Fortune 500 companies add significant European and enterprise urgency.
Critical Vulnerabilities
CVE-2025-62593 — Anyscale Ray (Code Injection / RCE)
- Severity: Not yet assigned (CWE-94, CWE-352)
- EPSS: Not yet scored; CISA KEV confirmed active exploitation
- Technical detail: Ray, a widely used distributed AI/ML compute framework, contains a code injection vulnerability exploitable via Firefox and Safari. The flaw can be triggered remotely, enabling arbitrary code execution on Ray cluster nodes. Ray is commonly deployed in data science and ML engineering environments, including cloud-hosted and on-premises clusters. The CSRF component (CWE-352) suggests browser-based attack vectors are in scope.
- Exploitation status: Actively exploited in the wild — CISA KEV added 2026-08-17.
- Remediation: Apply vendor patch immediately. CISA KEV deadline: 2026-08-20. Isolate Ray dashboard endpoints from public internet access; enforce authentication on Ray cluster APIs.
CVE-2026-19478 — GitLab CE/EE (Unauthenticated Project Deletion via GraphQL)
- Severity: CVSS 9.4
- EPSS: 0.0 (newly published; no exploitation confirmed yet)
- Technical detail: A flaw in the GitLab GraphQL API affects all CE/EE versions from 18.2 through 19.2.3. Under certain conditions, an unauthenticated remote attacker can modify or delete public projects and associated user data. The attack surface is broad: any internet-facing GitLab instance running an affected version is potentially vulnerable. Self-hosted GitLab deployments common in European enterprises are at risk.
- Exploitation status: No confirmed in-the-wild exploitation; critical severity and unauthenticated attack vector warrant urgent treatment.
- Remediation: Upgrade to GitLab 18.11.11, 19.0.8, 19.1.6, or 19.2.4. If immediate patching is not possible, restrict public project visibility and consider temporarily disabling unauthenticated GraphQL access.
CVE-2026-69414 — Microsoft Defender / Malware Protection Engine (“ShieldBreak” Zero-Day)
- Severity: Not yet assigned (BSI: hoch / high)
- EPSS: Not yet scored
- Technical detail: A local privilege escalation zero-day in Microsoft Defender and the Malware Protection Engine, publicly disclosed by researcher “Nightmare Eclipse” and tracked as CVE-2026-69414. A local attacker can exploit this flaw to obtain Administrator-level privileges. The vulnerability is currently unpatched — Microsoft has confirmed it is working on a fix. Defender is ubiquitous across Windows enterprise environments, making this a high-priority item despite requiring local access.
- Exploitation status: No confirmed in-the-wild exploitation; publicly disclosed, no patch available.
- Remediation: No patch available. Monitor Microsoft Security Response Center for emergency update. Apply principle of least privilege; monitor for anomalous Defender process behavior. BSI advisory:
WID-SEC-2026-2856.
CVE-2026-15748 — Forminator Forms WordPress Plugin (Unauthenticated RCE via File Upload)
- Severity: CVSS 9.8
- EPSS: 0.0 (newly published)
- Technical detail: Forminator Forms, a WordPress plugin with over 600,000 active installations, contains a critical file upload vulnerability allowing unauthenticated attackers to upload malicious PHP files and achieve remote code execution. No authentication is required; exploitation is straightforward from the public internet. The plugin’s wide deployment makes this a high-priority mass-exploitation candidate.
- Exploitation status: No confirmed exploitation; CVSS 9.8 unauthenticated RCE in a 600K+ install plugin warrants immediate action.
- Remediation: Update Forminator Forms to the patched version immediately. If patching is delayed, disable file upload functionality or deploy WAF rules blocking PHP file uploads to WordPress plugin endpoints.
CVE-2026-47686 / CVE-2026-47698 — vm2 Node.js Sandbox (Multiple Sandbox Escapes)
- Severity: CVSS 9.9 / 9.8
- EPSS: 0.0 (newly published)
- Technical detail: Two critical sandbox escape vulnerabilities in vm2 (Node.js), both fixed in 3.11.6.
CVE-2026-47686exploits incomplete sanitization ofSuppressedErrorandAggregateErrorin the sandbox setup, whileCVE-2026-47698bypasses host prototype protections via stacked indirection throughFunction.prototype.call. vm2 is widely used in Node.js applications to execute untrusted code; a sandbox escape enables full host-level code execution. A third DoS-class issue (CVE-2026-47683, CVSS 8.7) is also fixed in 3.11.6. BSI advisoryWID-SEC-2026-2865rates this critical. - Exploitation status: No confirmed exploitation; CVSS 9.9 sandbox escape with public disclosure warrants urgent patching.
- Remediation: Upgrade vm2 to 3.11.6 immediately. Audit all Node.js applications using vm2 for exposure to untrusted input.
ONGOING:
CVE-2026-73056(SiYuan < 3.7.4): Auth brute-force bypass — upgrade to v3.7.4.CVE-2026-74251(Phoca Cart 5.0.0–6.1.6): Unauthenticated SQLi — update to 6.1.7+, deploy WAF rules.CVE-2026-48907(Joomla JCE): Public Metasploit module available — treat unpatched instances as compromised.CVE-2026-50602(Acer Planet9): LPE — apply Acer patch, restrict service executable permissions.CVE-2026-74796(OpenTofu < 1.11.7): CI/CD symlink attack — upgrade, audit pipeline directories.CVE-2026-18438(Templately ≤ 3.7.1): EPSS 0.98 RCE — update immediately.CVE-2026-15826(User Profile Builder ≤ 3.16.4): EPSS 0.81 auth bypass — update immediately.CVE-2026-74764(Pandora ≤ 1.12.5): CVSS 10.0 RCE — upgrade and isolate.CVE-2026-58231(SAP Commerce Cloud): Active exploitation — patch and initiate IR review.CVE-2026-59310(VMware vCenter): China-nexus APT exploitation confirmed — patch immediately.CVE-2026-68820(Windows AFD/Lazarus): CISA KEV deadline 2026-08-25 — apply August Patch Tuesday.CVE-2026-55040(SharePoint): Active exploitation — apply July 2026 Patch Tuesday.CVE-2026-63077(JetBrains TeamCity): Actively exploited — upgrade to 2026.1.3.CVE-2026-0257(PAN-OS GlobalProtect): Qilin ransomware exploitation — patch immediately.CVE-2026-16232(Check Point SmartConsole): Actively exploited — treat unpatched as compromised.CVE-2026-8037(Progress Kemp LoadMaster): Ransomware exploitation — patch immediately.
European Advisories
BSI — New and Updated Advisories (2026-08-17):
WID-SEC-2026-2865 (vm2 — kritisch): Covered in Critical Vulnerabilities above.
WID-SEC-2026-2856 (Microsoft Defender ShieldBreak — hoch, UNGEPATCHT): Covered in Critical Vulnerabilities above.
WID-SEC-2026-2863 (Gitea — hoch): Multiple vulnerabilities in Gitea enabling account takeover, privilege escalation, XSS, and RCE as the Gitea service user. Organizations self-hosting Gitea should apply the latest update immediately.
WID-SEC-2026-2853 (Microsoft Edge — hoch): New advisory for a remote code execution vulnerability in Microsoft Edge. Apply the latest Edge update.
BSI also published updates for Linux Kernel (multiple advisories), AMD Processor, Samba, SAP Patch Day August 2026, GStreamer, IBM AIX/VIOS, Red Hat Enterprise Linux (pcp, nodejs:24), Google Chrome/Edge, and Composer — apply vendor patches per standard cycle.
European Incident — French Tax Authority Breach: The French Ministry of Economy and Finance disclosed a breach of the DGFiP (Direction Générale des Finances Publiques) affecting 678,000 individuals. French prosecutors are investigating what is described as an “unprecedented” cyberattack. European public sector organizations should review access controls on citizen-facing systems. (Bleeping Computer, Heise Security)
Pokémon Center / CEVA Logistics Breach (Germany/UK): Pokémon Center is notifying customers in Germany and the United Kingdom of a third-party breach via logistics provider CEVA Logistics. Customer personal and order data was stolen. Relevant for organizations using CEVA Logistics as a supply chain partner.
Active Threats and Campaigns
NEW — Operation ASTERIX (Crypto Fraud Pipeline): Rapid7 researchers exposed infrastructure supporting a large-scale cryptocurrency fraud operation combining vishing, phishing panels, fake wallet apps, and Telegram-based data exfiltration. The operator used AI coding assistants during development. Targets include individuals via phone-number datasets and account-validation tooling. Organizations should brief finance and executive staff on crypto fraud social engineering. (Rapid7)
NEW — Cavern C2 (Iranian APT, DNS/Google Apps Script Tunneling): Kaspersky has published new findings on the Cavern (Cav3rn) C2 framework used by Iranian nation-state actors targeting Israeli entities. The framework tunnels C2 traffic over DNS and Google Apps Script to blend with legitimate traffic, complicating detection. Organizations should review DNS query logs for anomalous patterns and consider blocking Google Apps Script execution in non-business contexts. (The Hacker News)
STATUS CHANGE — Clop / Russian Cybercriminals (Shell, Philips, GE): GE and Philips have now formally confirmed they are investigating Clop ransomware data theft claims, upgrading this from unconfirmed to confirmed investigation status. No public IOCs. European energy and healthcare organizations should continue threat hunting for July 2026 exploitation indicators. (Bleeping Computer)
ONGOING — Azure Account Records Claim: A threat actor claims to be selling 3.6 million employee records from Fortune 500 companies’ Azure infrastructure, allegedly obtained via compromised credentials. Unverified; monitor for credential exposure and enforce MFA on Azure tenants. (Bleeping Computer)
ONGOING — Evooo1Bot Linux Botnet: No new developments; audit for unexpected SOCKS5 outbound connections, apply firmware updates to edge devices.
ONGOING — AmnesiaStealer macOS: No new developments; brief macOS users on ClickFix lures, enforce MFA.
Security News and Context
- Apple iOS/macOS mega-patch: Apple released updates for iOS/iPadOS 26 & 18 and macOS 26, fixing 108 vulnerabilities — apply immediately across all managed Apple devices. (SANS ISC)
- CVE-2026-54121 “Certighost” (Enterprise CA → Domain Controller): A standard domain user can abuse this flaw to elevate an Enterprise CA to Domain Controller equivalence; patch is available but PKI Tier-0 hardening is the broader lesson. (Bleeping Computer)
- Unisoc VoLTE exploit chain: Researchers published a two-stage exploit achieving full Android kernel access via a VoLTE video call on Unisoc modem firmware — no vendor fix available. Relevant for organizations managing Android device fleets with Unisoc chipsets. (The Hacker News)
- Windows Server 2022 EoS in 60 days: Mainstream support ends October 2026; begin migration or extended support planning. (Bleeping Computer)
Recommended Actions
CVE-2025-62593(Ray): Patch immediately — CISA KEV deadline 2026-08-20. Isolate Ray dashboard from public internet.CVE-2026-19478(GitLab): Upgrade to 18.11.11 / 19.0.8 / 19.1.6 / 19.2.4; restrict unauthenticated GraphQL access on unpatched instances.CVE-2026-69414(Defender ShieldBreak): No patch available — monitor MSRC for emergency update; enforce least privilege on all Windows endpoints.CVE-2026-15748(Forminator Forms): Update plugin immediately; deploy WAF rules blocking PHP uploads to WordPress endpoints.CVE-2026-47686/CVE-2026-47698(vm2): Upgrade to 3.11.6; audit all Node.js applications accepting untrusted input via vm2.- Apple iOS/macOS: Deploy the 108-fix update across all managed Apple devices via MDM.
CVE-2026-54121(Certighost): Apply patch; audit Enterprise CA permissions and treat PKI as Tier-0 infrastructure.- French DGFiP / CEVA Logistics breaches: If CEVA Logistics is a supply chain partner, review data sharing agreements and audit access logs.
- Cavern C2: Review DNS query logs for anomalous tunneling patterns; consider restricting Google Apps Script in non-business contexts.
- Continue remediation of previously reported items:
CVE-2026-68820(Windows/Lazarus — KEV deadline 2026-08-25),CVE-2026-58231(SAP Commerce Cloud),CVE-2026-59310(vCenter),CVE-2026-48907(Joomla JCE),CVE-2026-18438(Templately),CVE-2026-15826(User Profile Builder),CVE-2026-63077(TeamCity),CVE-2026-0257(PAN-OS),CVE-2026-16232(Check Point),CVE-2026-8037(LoadMaster).