ash-project AshAi · Dell PowerStore
Date: 2026-08-31 Prepared for: SOC Analysts | Incident Responders | Vulnerability Management | Security Leadership
Executive Summary
Two newly published critical vulnerabilities require prioritisation: CVE-2026-77956 enables unauthenticated remote Elixir code execution in AshAi, while CVE-2026-58574 permits unauthenticated access to critical functions on Dell PowerStore management interfaces. German reporting also indicates that a public proof of concept for a high-risk Exchange vulnerability leaves approximately 85% of German on-premises servers exposed. No confirmed exploitation was reported for the new CVEs in the supplied data.
Critical Vulnerabilities
CVE-2026-77956 — ash-project AshAi
- Severity: CVSS 10.0
- EPSS: 0 — no elevated exploitation probability estimate was provided; this does not exclude future exploitation.
- Technical detail: AshAi versions before 1.0.0 contain improper control of code generation in
AshAi.Actions.Prompt. A remote, unauthenticated client can cause the application to evaluate attacker-controlled Elixir code. Risk is highest for internet-accessible applications exposing AshAi prompt or API functionality. - Exploitation status: No confirmed exploitation reported in the supplied data.
- Remediation: Upgrade AshAi to version 1.0.0 or the vendor-fixed commit. Until upgraded, restrict exposed prompt/API endpoints, apply authentication and network controls, and review application logs for unexpected prompt execution or process activity.
CVE-2026-58574 — Dell PowerStore
- Severity: CVSS 9.8
- EPSS: 0 — no elevated exploitation probability estimate was provided.
- Technical detail: Dell PowerStore contains missing authentication for a critical function in the restricted management interface. An unauthenticated attacker with network access to that interface may exploit the issue; impact could include compromise of storage-management operations and associated enterprise data. The affected product range includes multiple PowerStore 1000T, 1200T, 3000T, 3200T, 500T, 5000T, 5200T, 7000T, 9000T and 9200T variants.
- Exploitation status: No confirmed exploitation reported in the supplied data.
- Remediation: Upgrade affected systems to Dell’s fixed releases, including
4.1.0.6-2771237or4.3.1.2-2771239as applicable to the appliance model. Immediately verify that management interfaces are not internet-accessible, restrict access to trusted administration networks, and review authentication and management-plane logs.
CVE-2026-81315 — ash-project AshAi
- Severity: CVSS 7.4
- EPSS: Not available.
- Technical detail: AshAi versions before 1.0.0 contain an origin-validation error that can bypass MCP server DNS-rebinding protection. A malicious web page may issue cross-site requests to a user’s local MCP server, potentially invoking locally available tools or accessing connected services. Exposure depends on local MCP deployment and the privileges of configured tools.
- Exploitation status: No confirmed exploitation reported in the supplied data.
- Remediation: Upgrade to the vendor-fixed version or commit. Restrict MCP listeners to loopback or trusted interfaces, enforce robust origin validation and authentication, and review MCP activity for unexpected requests originating from browser sessions.
CVE-2026-82564 — ash-project AshAi
- Severity: CVSS 7.1
- EPSS: Not available.
- Technical detail: AshAi versions before 1.0.0 contain an authorization bypass involving user-controlled record keys. A caller of an identity-configured tool may update or destroy records that were not identified by that caller, potentially affecting records across a tenant or application scope. The issue is relevant to applications using AshAi tools for data modification.
- Exploitation status: No confirmed exploitation reported in the supplied data.
- Remediation: Upgrade to the fixed AshAi release. Temporarily disable identity-configured update and delete tools where feasible, validate object-level authorization server-side, and audit data-modification events for cross-record or cross-tenant access.
CVE-2026-75760 — ash-project AshAi
- Severity: CVSS 7.1
- EPSS: Not available.
- Technical detail: Affected AshAi versions may disclose provider request state and credentials through user-facing validation errors. Applications that expose these errors to untrusted users could leak AI-provider credentials or sensitive request metadata. The impact depends on the provider integration and error-handling configuration.
- Exploitation status: No confirmed exploitation reported in the supplied data.
- Remediation: Upgrade to the fixed version, suppress sensitive provider details in user-facing errors, rotate exposed API credentials where disclosure is possible, and search logs and application responses for leaked tokens or provider request data.
ONGOING:
CVE-2026-66384(JFrog Artifactory): Actively exploited; patch and audit repositories, credentials, and Docker caches.CVE-2026-8452(Citrix NetScaler ADC/Gateway): Actively exploited; verify patching and management-interface restrictions.CVE-2026-63520(Microsoft SharePoint): Active exploitation and public PoC remain reported; patch and hunt for web shells.CVE-2026-60004(Gitea): KEV remediation deadline passed; patch immediately and audit Git hook directories.CVE-2019-1068(Microsoft SQL Server): Actively exploited; complete remediation immediately.CVE-2026-53362(Linux Kernel): KEV-listed privilege escalation; verify remediation.CVE-2023-49105(ownCloud): Actively exploited; patch and validate signing-key configuration.CVE-2026-19478(GitLab): Actively exploited; upgrade to a fixed release.CVE-2026-75759(erlef oidcc): Patch remains required; review OIDC token-validation and authentication events.
European Advisories
- CERT-Bund updates: CERT-Bund published updates for multiple critical or high-severity advisories affecting Samba, Linux Kernel, DENX U-Boot, FreeRDP, QEMU, OpenSSL, Roundcube Webmail, PostgreSQL, GnuTLS, cURL and Vim. The updates describe potential code execution, privilege escalation, authentication or security-control bypass, information disclosure, data manipulation and denial-of-service impacts. Review the affected package versions and apply vendor updates. Relevant references include Samba, Linux Kernel, Roundcube and PostgreSQL.
WID-SEC-2026-1938(Linux Kernel privilege escalation): status update; review against the previously reported KEV-related Linux Kernel remediation.- No new CERT-EU, BSI BITS or CISA advisories were reported.
Active Threats and Campaigns
- TerminalFix ClickFix variant — NEW: Microsoft reports fake Cloudflare CAPTCHA pages that direct users to execute malicious commands in Windows Terminal or PowerShell. Hunt for browser-to-shell activity, suspicious PowerShell or Terminal child processes, and commands copied from web pages. Reinforce user guidance that CAPTCHA pages should never require command execution.
- PaperCut NG/MF exploitation — ONGOING: Active exploitation and bypasses of initial fixes remain relevant. Apply the latest emergency release and review application, web-server and authentication logs.
- Gitea exploitation — ONGOING: More than 8,300 internet-exposed instances were previously reported vulnerable. Prioritise external instances and inspect Git hook directories after remediation.
- Microsoft 365 phishing — ONGOING: NovaCookies and Mirage2FA remain relevant; hunt for session-token theft, anomalous OAuth activity and conditional-access changes.
Security News and Context
- A public proof of concept for a high-risk Microsoft Exchange vulnerability reportedly leaves around 85% of German on-premises servers exposed, according to Heise. Validate exposure and patch status immediately.
- Microsoft asked users to disregard false Defender “antivirus is turned off” alerts caused by recent Defender updates; monitor for genuine protection-state changes rather than treating all alerts as malicious.
Recommended Actions
- Identify and patch all AshAi deployments; restrict MCP and application interfaces pending remediation.
- Inventory Dell PowerStore appliances and immediately isolate management interfaces from untrusted networks.
- Validate Microsoft Exchange exposure, PoC applicability and patch status across German and European environments.
- Hunt for TerminalFix activity, especially browser-launched PowerShell or Windows Terminal commands.
- Apply updated CERT-Bund package advisories, prioritising Samba, Roundcube, PostgreSQL, OpenSSL and remotely reachable services.
- Complete remediation of actively exploited JFrog, Citrix, SharePoint, SQL Server, ownCloud, GitLab and Gitea vulnerabilities.
- Continue remediation of previously reported items:
CVE-2026-75759,CVE-2026-53362,CVE-2026-8452andCVE-2026-66384.