← All briefings

ash-project AshAi · Dell PowerStore

Date: 2026-08-31 Prepared for: SOC Analysts | Incident Responders | Vulnerability Management | Security Leadership

Executive Summary

Two newly published critical vulnerabilities require prioritisation: CVE-2026-77956 enables unauthenticated remote Elixir code execution in AshAi, while CVE-2026-58574 permits unauthenticated access to critical functions on Dell PowerStore management interfaces. German reporting also indicates that a public proof of concept for a high-risk Exchange vulnerability leaves approximately 85% of German on-premises servers exposed. No confirmed exploitation was reported for the new CVEs in the supplied data.

Critical Vulnerabilities

CVE-2026-77956 — ash-project AshAi

  • Severity: CVSS 10.0
  • EPSS: 0 — no elevated exploitation probability estimate was provided; this does not exclude future exploitation.
  • Technical detail: AshAi versions before 1.0.0 contain improper control of code generation in AshAi.Actions.Prompt. A remote, unauthenticated client can cause the application to evaluate attacker-controlled Elixir code. Risk is highest for internet-accessible applications exposing AshAi prompt or API functionality.
  • Exploitation status: No confirmed exploitation reported in the supplied data.
  • Remediation: Upgrade AshAi to version 1.0.0 or the vendor-fixed commit. Until upgraded, restrict exposed prompt/API endpoints, apply authentication and network controls, and review application logs for unexpected prompt execution or process activity.

CVE-2026-58574 — Dell PowerStore

  • Severity: CVSS 9.8
  • EPSS: 0 — no elevated exploitation probability estimate was provided.
  • Technical detail: Dell PowerStore contains missing authentication for a critical function in the restricted management interface. An unauthenticated attacker with network access to that interface may exploit the issue; impact could include compromise of storage-management operations and associated enterprise data. The affected product range includes multiple PowerStore 1000T, 1200T, 3000T, 3200T, 500T, 5000T, 5200T, 7000T, 9000T and 9200T variants.
  • Exploitation status: No confirmed exploitation reported in the supplied data.
  • Remediation: Upgrade affected systems to Dell’s fixed releases, including 4.1.0.6-2771237 or 4.3.1.2-2771239 as applicable to the appliance model. Immediately verify that management interfaces are not internet-accessible, restrict access to trusted administration networks, and review authentication and management-plane logs.

CVE-2026-81315 — ash-project AshAi

  • Severity: CVSS 7.4
  • EPSS: Not available.
  • Technical detail: AshAi versions before 1.0.0 contain an origin-validation error that can bypass MCP server DNS-rebinding protection. A malicious web page may issue cross-site requests to a user’s local MCP server, potentially invoking locally available tools or accessing connected services. Exposure depends on local MCP deployment and the privileges of configured tools.
  • Exploitation status: No confirmed exploitation reported in the supplied data.
  • Remediation: Upgrade to the vendor-fixed version or commit. Restrict MCP listeners to loopback or trusted interfaces, enforce robust origin validation and authentication, and review MCP activity for unexpected requests originating from browser sessions.

CVE-2026-82564 — ash-project AshAi

  • Severity: CVSS 7.1
  • EPSS: Not available.
  • Technical detail: AshAi versions before 1.0.0 contain an authorization bypass involving user-controlled record keys. A caller of an identity-configured tool may update or destroy records that were not identified by that caller, potentially affecting records across a tenant or application scope. The issue is relevant to applications using AshAi tools for data modification.
  • Exploitation status: No confirmed exploitation reported in the supplied data.
  • Remediation: Upgrade to the fixed AshAi release. Temporarily disable identity-configured update and delete tools where feasible, validate object-level authorization server-side, and audit data-modification events for cross-record or cross-tenant access.

CVE-2026-75760 — ash-project AshAi

  • Severity: CVSS 7.1
  • EPSS: Not available.
  • Technical detail: Affected AshAi versions may disclose provider request state and credentials through user-facing validation errors. Applications that expose these errors to untrusted users could leak AI-provider credentials or sensitive request metadata. The impact depends on the provider integration and error-handling configuration.
  • Exploitation status: No confirmed exploitation reported in the supplied data.
  • Remediation: Upgrade to the fixed version, suppress sensitive provider details in user-facing errors, rotate exposed API credentials where disclosure is possible, and search logs and application responses for leaked tokens or provider request data.

ONGOING:

  • CVE-2026-66384 (JFrog Artifactory): Actively exploited; patch and audit repositories, credentials, and Docker caches.
  • CVE-2026-8452 (Citrix NetScaler ADC/Gateway): Actively exploited; verify patching and management-interface restrictions.
  • CVE-2026-63520 (Microsoft SharePoint): Active exploitation and public PoC remain reported; patch and hunt for web shells.
  • CVE-2026-60004 (Gitea): KEV remediation deadline passed; patch immediately and audit Git hook directories.
  • CVE-2019-1068 (Microsoft SQL Server): Actively exploited; complete remediation immediately.
  • CVE-2026-53362 (Linux Kernel): KEV-listed privilege escalation; verify remediation.
  • CVE-2023-49105 (ownCloud): Actively exploited; patch and validate signing-key configuration.
  • CVE-2026-19478 (GitLab): Actively exploited; upgrade to a fixed release.
  • CVE-2026-75759 (erlef oidcc): Patch remains required; review OIDC token-validation and authentication events.

European Advisories

  • CERT-Bund updates: CERT-Bund published updates for multiple critical or high-severity advisories affecting Samba, Linux Kernel, DENX U-Boot, FreeRDP, QEMU, OpenSSL, Roundcube Webmail, PostgreSQL, GnuTLS, cURL and Vim. The updates describe potential code execution, privilege escalation, authentication or security-control bypass, information disclosure, data manipulation and denial-of-service impacts. Review the affected package versions and apply vendor updates. Relevant references include Samba, Linux Kernel, Roundcube and PostgreSQL.
  • WID-SEC-2026-1938 (Linux Kernel privilege escalation): status update; review against the previously reported KEV-related Linux Kernel remediation.
  • No new CERT-EU, BSI BITS or CISA advisories were reported.

Active Threats and Campaigns

  • TerminalFix ClickFix variant — NEW: Microsoft reports fake Cloudflare CAPTCHA pages that direct users to execute malicious commands in Windows Terminal or PowerShell. Hunt for browser-to-shell activity, suspicious PowerShell or Terminal child processes, and commands copied from web pages. Reinforce user guidance that CAPTCHA pages should never require command execution.
  • PaperCut NG/MF exploitation — ONGOING: Active exploitation and bypasses of initial fixes remain relevant. Apply the latest emergency release and review application, web-server and authentication logs.
  • Gitea exploitation — ONGOING: More than 8,300 internet-exposed instances were previously reported vulnerable. Prioritise external instances and inspect Git hook directories after remediation.
  • Microsoft 365 phishing — ONGOING: NovaCookies and Mirage2FA remain relevant; hunt for session-token theft, anomalous OAuth activity and conditional-access changes.

Security News and Context

  • A public proof of concept for a high-risk Microsoft Exchange vulnerability reportedly leaves around 85% of German on-premises servers exposed, according to Heise. Validate exposure and patch status immediately.
  • Microsoft asked users to disregard false Defender “antivirus is turned off” alerts caused by recent Defender updates; monitor for genuine protection-state changes rather than treating all alerts as malicious.
  1. Identify and patch all AshAi deployments; restrict MCP and application interfaces pending remediation.
  2. Inventory Dell PowerStore appliances and immediately isolate management interfaces from untrusted networks.
  3. Validate Microsoft Exchange exposure, PoC applicability and patch status across German and European environments.
  4. Hunt for TerminalFix activity, especially browser-launched PowerShell or Windows Terminal commands.
  5. Apply updated CERT-Bund package advisories, prioritising Samba, Roundcube, PostgreSQL, OpenSSL and remotely reachable services.
  6. Complete remediation of actively exploited JFrog, Citrix, SharePoint, SQL Server, ownCloud, GitLab and Gitea vulnerabilities.
  7. Continue remediation of previously reported items: CVE-2026-75759, CVE-2026-53362, CVE-2026-8452 and CVE-2026-66384.