CVE Tools

Security news, decoded.

What happened, who is affected, and what to do next. Every story is linked to CVEs and enriched with product, exploitation, and patch context.

RSS
Latest signal BleepingComputer PoC public Active Directory Certificate Services privilege-escalation Microsoft

Certighost and the Privilege Hiding in Your Certificate Authority

Read full story

Researchers have made a proof-of-concept available for "Certighost" (CVE-2026-54121), a vulnerability in Microsoft Active Directory Certificate Services that enables privilege escalation. By exploiting a defect in the "chase" enrollment process, standard domain users can coerce an Enterprise CA into issuing valid authentication certificates for a Domain Controller, granting full control over the domain's identity infrastructure. Microsoft resolved this issue on July 14, 2026, assigning it a CVSS score of 8.8. Organizations are urged to apply the patch immediately and also review their default configuration, particularly by setting the MachineAccountQuota to zero, to mitigate further reliance on insecure defaults.

Earlier39 stories
Aug 17
Check Point Research Exploited Windows ransomware6 min read

17th August – Threat Intelligence Report

Microsoft released its August 2026 patch updates to address 421 vulnerabilities, critically including CVE-2026-68820, a Windows Ancillary Function Driver for WinSock zero-day that is currently being exploited by Lazarus-linked actors to achieve SYSTEM privileges via local privilege escalation. Simultaneously, Adobe deployed an urgent fix for CVE-2026-71362 in Adobe Commerce and Magento Open Source, reporting immediate attacks shortly after public disclosure that allow unauthorized session switching and account takeover. Additionally, Zoom issued patches for three critical flaws, such as CVE-2026-53413, which permit remote code execution without user interaction through meeting annotations.

Aug 17
The Hacker News Exploited Lazarus Group ransomware22 min read

⚡ Weekly Recap: VMware Exploits, Windows 0-Day, MCP Attacks, Browser Hijacks and More

This week's security landscape was dominated by active exploitation of critical vulnerabilities, including a severe directory traversal flaw in VMware vCenter identified as CVE-2026-59310. A suspected China-linked APT group leveraged this bug to deploy backdoors and Babuk-derived ransomware, which researchers assess served primarily as a distraction for forensic evasion rather than the final objective. Concurrently, North Korea’s Lazarus Group targeted defense and aerospace sectors across Europe, South America, and Asia using a zero-day privilege escalation vulnerability in Microsoft Windows, tracked as CVE-2026-68820. The actor delivered new malware strains, ForestTiger and Troy, under the guise of their long-running “Dream Job” social engineering campaign. Additional notable developments include the release of patches for a critical SQL injection issue in GeoServer (fixed in versions 3.0.1, 2.28.5, and 2.27.6), the discovery of GhostSplice, an attack technique that fragments malicious prompts to evade AI coding assistant guardrails, and the emergence of Amnesia Stealer, a macOS tool capable of live-controlling victim browsers via the Chrome DevTools Protocol.

Aug 17
Help Net Security Exploited macOS auth-bypass2 min read

Attackers exploit patched macOS Screen Sharing flaw to deploy cryptominer

Apple's recently patched vulnerability, tracked as CVE-2026-65400, is currently under active attack, allowing malicious actors to bypass authentication in macOS Screen Sharing and deploy cryptominers. The Dutch National Cyber Security Centre (NCSC) confirmed that root access was gained on multiple systems with port 5900 exposed to the internet, leading to the installation of a Monero miner. Apple has released fixes for this issue through macOS Sequoia (15.7.9), Sonoma (14.8.9), and Tahoe (26.6.1). Users should immediately apply these updates; alternatively, manually disabling Screen Sharing in System Settings can mitigate the risk until patching is complete.

Aug 17
The Hacker News Research Model Context Protocol (MCP) ai-ml7 min read

How MCP Servers Can Expose Enterprise Secrets

Recent analysis from Keeper Security highlights significant security gaps in the adoption of the Model Context Protocol (MCP), originally introduced by Anthropic. The study identifies several mechanisms through which MCP servers can inadvertently expose enterprise credentials, including storing plaintext tokens in configuration files and failing to enforce the principle of least privilege during deployment. A critical concern involves the "mcp-remote" OAuth proxy, where vulnerabilities such as CVE-2025-6514 allow for operating system command injection and remote code execution. This specific flaw could enable attackers to steal credentials directly from the client machine running the proxy. To mitigate these risks, the authors recommend centralizing secret management, using short-lived rotating credentials, and maintaining strict visibility over all MCP servers operating within an enterprise environment.

Aug 17
BleepingComputer Exploited PTC Windchill Clop6 min read

Philips and GE investigating Clop ransomware data theft claims

General Electric, Philips, and Shell are currently investigating reports that the Clop ransomware group accessed their networks and exfiltrated data. These breaches stem from active exploitation of CVE-2026-12569, a critical input validation vulnerability affecting Internet-exposed instances of PTC Windchill and PTC FlexPLM. While Philips has stated its response contained the incident without impacting customer environments, GE is still assessing the scope of the potential compromise. This campaign involves Clop deploying JSP webshells to steal sensitive assets such as blueprints and project plans from enterprises relying on these PLM platforms. As CISA has added this flaw to its Known Exploited Vulnerabilities catalog, organizations should apply available patches and audit their systems for signs of intrusion.

Aug 17
The Hacker News PoC Unisoc T606 mobile5 min read

Unisoc VoLTE Video Call Exploit Chain Can Give Attackers Full Android Kernel Access

Security researchers have released a public proof-of-concept for a two-stage attack chain targeting Unisoc modem firmware that achieves full Android kernel access. By combining a previously disclosed remote code execution flaw in SIP video handling with a new privilege-escalation bug classified as CWE-1189, attackers can bypass hardware boundaries to map and modify kernel memory. The vulnerability affects devices utilizing the Unisoc T606, T612, and T7250 chipsets, including the Motorola E13, Realme C33, and Xiaomi Redmi A5. Exploiting the chain requires an attacker-controlled private 4G network and victim interaction, specifically answering a malicious video call. As of the August 2026 disclosure, no CVE ID has been assigned, and neither UNISOC nor the device manufacturers have issued patches or confirmed mitigation plans.

Aug 17
The Hacker News Exploited Alcatel OmniPCX Enterprise ddos-botnet5 min read

Evooo1Bot Linux Botnet Exploits Known Flaws to Turn Edge Devices Into SOCKS5 Proxies

Fortinet FortiGuard Labs identified Evooo1Bot, a newly documented Linux botnet derived from Mirai source code that has been actively compromising internet-facing devices since July 2026. The malware employs an integrated exploit arsenal targeting multiple known vulnerabilities, including CVE-2007-3010 in Alcatel OmniPCX Enterprise, CVE-2016-6277 in NETGEAR routers, and command injection flaws such as CVE-2018-14558 in Tenda AC7/AC9/AC10 models. Beyond standard DDoS capabilities, Evooo1Bot introduces encrypted C2 communication over port 443, credential sniffing, and a distinct feature that converts infected hosts into SOCKS5 proxies. This infrastructure allows threat actors to route malicious traffic through compromised edge devices, effectively using victim IPs to mask their origin and access internal networks.

Aug 17
BleepingComputer PoC Microsoft Defender zero-day5 min read

Microsoft working on Defender patch for ShieldBreak zero-day

Microsoft has confirmed it is developing a security update for CVE-2026-69414, a privilege escalation vulnerability in the Microsoft Malware Protection Engine known as "ShieldBreak." This flaw enables local attackers with limited permissions to gain SYSTEM-level access on fully patched versions of Windows 10, Windows 11, and Windows Server. Disclosed by security researcher Nightmare Eclipse alongside a working proof-of-concept, ShieldBreak functions as a complete bypass for the previously addressed RoguePlanet vulnerability (CVE-2026-50656). While the exploit requires Microsoft Defender to be active, independent verification has confirmed its 100% success rate across modern Windows environments. Microsoft stated that it is actively working on a high-quality fix and will release further details once the patch becomes available.

Aug 17
SecurityWeek Exploited macOS Screen Sharing mobile3 min read

Recent macOS Screen Sharing Vulnerability Exploited in Attacks

Attackers are actively leveraging CVE-2026-65400, a high-severity authentication bypass in Apple's macOS Screen Sharing feature, to seize root privileges and deploy cryptocurrency miners. The vulnerability allows remote adversaries to authenticate without valid credentials by simply specifying an existing account name, a method made easier by public proof-of-concept exploits. Apple addressed this defect in updates released on August 6 for macOS Tahoe 26.6.1, Sequoia 15.7.9, and Sonoma 14.8.9, alongside other fixes for the screensharingd daemon. The Dutch NCSC confirmed in-the-wild abuse targeting systems with port 5900 open to the internet, warning that approximately 40,000 exposed devices remain vulnerable. Administrators should ensure all macOS instances are patched and restrict unnecessary external access to Screen Sharing ports.

Aug 17
SecurityWeek Exploited SAP Commerce Cloud cloud2 min read

Critical SAP Commerce Cloud Vulnerability Exploited 3 Days After Disclosure

Threat intelligence firms have confirmed active exploitation of CVE-2026-58231, a critical vulnerability in SAP Commerce Cloud, beginning just three days after the patch release on August 11. This flaw involves inadequate authorization checks and input validation, enabling attackers to execute arbitrary code and compromise internal systems with a perfect CVSS score of 10. While CISA has not yet added this specific ID to its Known Exploited Vulnerabilities catalog, independent sensors have detected attack attempts since August 14.

Aug 17
The Hacker News Exploited VMware vCenter Babuk9 min read

Suspected China-Nexus Actor Exploits VMware vCenter Flaw, Deploys Babuk-Derived Ransomware

A suspected Chinese state-aligned APT group is actively exploiting CVE-2026-59310, a critical directory traversal vulnerability in Broadcom's VMware vCenter Server, to establish root-level control over victim infrastructure. The campaign, which began shortly after the July 29, 2026 patch release, has compromised hundreds of servers across 47 countries, with researchers observing distinct Chinese-language artifacts and operational timing consistent with UTC+08:00. Upon gaining access via the unauthenticated code execution flaw, attackers deploy a custom Linux implant and create backdoor accounts to maintain persistence. The intrusion culminates in the deployment of a Babuk-derived ransomware variant targeting ESXi hosts, although analysts suggest this may serve as a distraction to obscure broader espionage or sabotage activities.

Aug 17
Help Net Security Research Windows 11 privilege-escalation5 min read

Windows 11’s strongest security defenses can be bypassed without a screwdriver

University researchers identified a method to circumvent Virtualization-Based Security and Hypervisor-Enforced Code Integrity on Windows 11 by exploiting unprotected Serial Presence Detect (SPD) chips in DDR4 and DDR5 memory modules. The attack allows privileged users to rewrite memory configuration data, effectively aliasing physical memory to access isolated kernel regions and disable security tools like EDR and blocklisted drivers. Microsoft addressed the issue as CVE-2026-23670 through mitigations released in its April 2026 security updates, though systems without Secure Boot remain vulnerable if using affected RAM.

Aug 16
Help Net Security Exploited Salesforce data-breach18 min read

Week in review: Salesforce and ServiceNow portals exposed for 17 months, exploited Metabase 0-day

A long-running campaign dubbed City-Forum has been extracting data from Salesforce and ServiceNow portals globally for 17 months without triggering traditional breach alerts. Meanwhile, Framework confirmed a data breach stemming from an exploited zero-day vulnerability in the Metabase business intelligence platform. N-able released a second hotfix for N-central to counter active exploitation of CVE-2026-18577, while Cisco addressed CVE-2026-20349, a high-severity flaw currently being used to disrupt firewall operations.

Aug 15
The Hacker News Exploited SAP Commerce Cloud cloud3 min read

SAP Commerce Cloud CVE-2026-58231 Targeted in Exploitation Attempts Days After Patch

SAP Commerce Cloud is facing active exploitation attempts for CVE-2026-58231, a critical vulnerability rated 10.0 on the CVSS scale. The flaw allows unauthenticated attackers to bypass authorization checks and send invalid input to specific functions, potentially enabling arbitrary code execution and compromising internal components. Although no public proof-of-concept was previously available, threat intelligence firm Defused Cyber detected attacks beginning just three days after the patch was released. SAP advises customers to update to the fixed release levels or configure IP filters as a temporary mitigation.

Aug 15
The Hacker News Exploited macOS auth-bypass6 min read

Apple macOS Screen Sharing Flaw Exploited on Internet-Exposed Macs to Install Monero Miner

The Dutch National Cyber Security Centre (NCSC) has confirmed that CVE-2026-65400, a critical authentication bypass in Apple macOS Screen Sharing, is being actively exploited to deploy cryptocurrency mining software. This flaw, rated 9.8 on the CVSS scale, permits attackers to gain unauthorized root access to remote desktop services without valid credentials, particularly affecting Macs with port 5900 exposed to the internet. Apple released emergency patches for this vulnerability in macOS Tahoe 26.6.1, Sequoia 15.7.9, and Sonoma 14.8.9. Users should immediately apply these updates or disable Screen Sharing via System Settings to mitigate the risk of compromise.

Aug 14
Rapid7 Blog PoC Metasploit rce16 min read

Metasploit Wrap Up: Lot of summer shells and fit http profiles

Rapid7's Metasploit framework has released a major update featuring thirteen new modules that provide working proof-of-concepts for recent vulnerabilities in popular platforms such as WordPress, Ghost CMS, Joomla, and the Linux kernel. Notable additions include exploit paths for CVE-2026-60137 in WordPress core, unauthenticated remote code execution in Joomla JCE via CVE-2026-48907, and a local privilege escalation module for the Fragnesia Linux kernel tracked as CVE-2026-46300. This release also introduces new AArch64 payloads for Windows on ARM and enhanced HTTP malleable profiles, significantly expanding the offensive capabilities available to security teams.

Aug 14
Ars Technica (Security) Exploited macOS mobile2 min read

Vulnerability giving attackers full control of Macs is under active exploitation

Dutch cyber officials have confirmed active exploitation of a high-severity vulnerability in macOS that grants attackers full system control. Known as CVE-2026-65400, the flaw exists within the operating system's screen sharing feature and allows unauthorized remote execution of malicious code. Attackers have successfully obtained root access to compromised machines, often deploying Monero cryptocurrency miners. Apple has released patches for macOS Tahoe, Sequoia, and Sonoma to address this issue.

Aug 14
BleepingComputer Exploited macOS mobile2 min read

Hackers exploit macOS Screen Sharing flaw to deploy Monero miner

The Netherlands' National Cyber Security Centre (NCSC) reports active exploitation of an authentication bypass in macOS Screen Sharing, specifically affecting TCP port 5900. This vulnerability, identified as CVE-2026-65400, allows unauthenticated remote access to the system. Threat actors have leveraged the flaw to obtain root privileges and deploy a Monero cryptocurrency miner. Apple addressed the issue in recent updates, including macOS Tahoe 26.6.1, Sequoia 15.7.9, and Sonoma 14.8.9.

Aug 14
BleepingComputer Exploited SAP Commerce Cloud rce4 min read

Max severity SAP Commerce Cloud flaw now targeted in attacks

Threat intelligence firm Defused reports that a critical remote code execution vulnerability in SAP Commerce Cloud is being actively targeted despite having only recently been patched. Tracked as CVE-2026-58231 with a maximum CVSS score of 10.0, this flaw allows unauthenticated attackers to execute arbitrary code by abusing a default authentication client within the Data Hub Adapter extension. Although SAP has not yet updated its official advisory to confirm widespread exploitation, shadow server data indicates over 4,200 internet-exposed instances remain vulnerable across Europe and North America. Organizations should apply the latest security fixes immediately to mitigate the risk of system compromise.

Aug 14
BleepingComputer Exploited PTC Windchill Clop4 min read

Shell investigates 'potential incident' after Clop data theft claims

Major energy firm Shell has begun investigating a potential security incident following claims by the Clop ransomware group that they exfiltrated 89GB of sensitive data, including engineering drawings and facility reports. The theft is attributed to active exploitation of CVE-2026-12569, a critical input validation flaw in internet-facing instances of PTC Windchill and FlexPLM. CISA has added this vulnerability to its Known Exploited Vulnerabilities catalog, urging organizations to apply patches released by PTC and check for indicators of compromise.

Aug 14
watchTowr Labs PoC Citrix NetScaler ADC watchTowr Labs23 min read

You’re Back In The Room (Citrix NetScaler Pre-Auth RCE CVE-2026-8452(?))

watchTowr Labs has published a proof-of-concept exploit for a pre-authentication remote code execution vulnerability in Citrix NetScaler ADC and NetScaler Gateway, identified as CVE-2026-8452. The flaw is a heap overflow triggered during the canonicalization of SAML signature data, specifically when processing an overly large PrefixList element within the SignedInfo block. Successful exploitation allows attackers to gain root-level code execution on affected appliances, which are widely used for enterprise remote access. Citrix addressed the issue in recent security bulletins; administrators must update NetScaler ADC and Gateway to version 14.1-72.61 or 13.1-63.18 immediately.

Aug 14
SecurityWeek Exploited macOS malware3 min read

AmnesiaStealer macOS Malware Steals Data, Controls Browser Sessions

Researchers have identified active exploitation of a new Rust-based macOS information stealer called AmnesiaStealer, which is distributed through malicious ClickFix campaigns involving counterfeit GitHub download pages. The malware utilizes a three-stage infection chain that includes leveraging the TCC bypass vulnerability CVE-2020-9771 to harvest sensitive data from Chromium-based browsers and Apple Notes. Notably, the tool allows attackers to establish live, interactive control over victim browser sessions via a headless module, distinguishing it from other similar macOS threats.

Aug 13
Dark Reading Exploited VMware vCenter APT actor (unnamed)6 min read

Global Threat Campaign Hits Critical VMware vCenter Flaw

A suspected advanced persistent threat actor has launched a global campaign exploiting CVE-2026–59310, a critical directory traversal vulnerability in VMware vCenter with a CVSS score of 9.8. German security firm QUIRSO reported observing active exploitation beginning on August 3, just days after Broadcom and VMware disclosed the flaw on July 29. The attack targets allow remote code execution in virtual environments, affecting infrastructure across 47 countries including the US, France, Iran, and Turkey. Notably, attackers establish post-exploitation persistence using the reversessh tool, meaning that simply applying the patch may not remove existing backdoors from compromised systems. Organizations are advised to conduct forensic investigations and isolate management interfaces to prevent continued command-and-control access.

Aug 13
The Hacker News Exploited GeoServer rce4 min read

GeoServer Zero-Day Targeted in Active Exploitation Attempts, Can Lead to RCE

WatchTowr has confirmed active exploitation attempts against a critical SQL injection vulnerability in GeoServer, which allows for remote code execution when specific PostGIS configurations are used. Although the flaw was initially reported without a CVE identifier, the vendor has since issued patches in versions 3.0.1, 2.28.5, and 2.27.6, assigning the issue the identifier GHSA-mqjf-5f49-2fjh with a CVSS score of 9.8. The vulnerability stems from improper escaping in the jsonArrayContains function within the GeoTools library, enabling attackers to inject malicious SQL commands. This represents a regression of previously fixed issues, specifically CVE-2023-25158. Organizations are strongly advised to upgrade to the latest patched versions immediately to mitigate the risk of system compromise.

Aug 13
The Hacker News Exploited UNC6671 data-breach18 min read

ThreatsDay: GhostJacking AI Attacks, EtherHiding ClickFix, Cursor CLI Flaw + 17 More Stories

This weekly security roundup highlights a new AI attack vector called GhostJacking, which manipulates autonomous agents into executing arbitrary code and exfiltrating data via poisoned logs. Additionally, a pre-trust code execution flaw in the Cursor CLI coding agent has been resolved following responsible disclosure. The bulletin also covers active in-the-wild exploitation by threat actor UNC6671 using the Work Panel platform for large-scale voice phishing campaigns against identity providers. Other notable updates include blockchain-based C2 obfuscation techniques like EtherHiding, industrial ransomware trends, and various supply chain compromises across cloud and software ecosystems.

Aug 13
BleepingComputer PoC Windows User Profile Service zero-day4 min read

Microsoft patches LegacyHive Windows zero-day vulnerability

Microsoft has addressed a zero-day vulnerability in the Windows User Profile Service, tracked as CVE-2026-62832, through its August Patch Tuesday updates. The flaw, dubbed "LegacyHive" by researcher Nightmare Eclipse, involves improper link resolution that permits local attackers to escalate privileges to administrator level. Although a proof-of-concept exploit was made public shortly after the July security release, it requires specific local credentials for successful exploitation. Analysts have confirmed that the exploit can modify registry hives to grant automatic code execution upon admin login, and unofficial mitigations were previously provided by ACROS Security for recent Windows versions.

Aug 13
BleepingComputer Exploited VMware vCenter rce3 min read

Critical VMware vCenter RCE flaw exploited for reverse SSH access

An active exploitation campaign is targeting a critical directory traversal vulnerability, CVE-2026-59310, within the VMware vCenter Syslog Server to deploy a reverse SSH tool for persistence and remote access. Disclosed by Broadcom on July 29, the flaw enables unauthenticated attackers with network access to execute arbitrary code, impacting numerous organizations across 47 countries. To remediate the risk, administrators should immediately apply the emergency updates for VMware vCenter releases 9.1.0.0300, 9.0.2.0100, or 8.0 U3k/U2f, as no other workarounds are currently available.

Aug 13
The Hacker News Exploited PATCHCORD APT366 min read

New PATCHCORD Backdoor Targets Afghan Telecom and Indian Critical Infrastructure

Acronis TRU revealed an active campaign by APT36 (Transparent Tribe) targeting Afghan telecommunications providers and critical infrastructure in India. The operation deploys two previously undocumented backdoors, PATCHCORD and SHEETCORD, using lures that impersonate the state-owned Afghan Telecom (AFTEL) and India's National Informatics Center (NIC). These implants establish persistence via browser shortcut hijacking and utilize unconventional C2 channels, including Google Sheets and GitHub Gists, while a staging server exposed open-source frameworks and the exploit for CVE-2024-6387.

Aug 13
SecurityWeek Patch Adobe Commerce auth-bypass2 min read

Adobe Commerce Bug Targeted Immediately After Disclosure

Adobe has released a security update to address CVE-2026-71362, a critical authorization flaw affecting Adobe Commerce and Magento Open Source that was rapidly targeted following its public disclosure. With a CVSS score of 9.1, this vulnerability allows unauthenticated remote attackers to hijack customer sessions and access private data by switching account identities. Although Adobe reported no prior in-the-wild exploitation before the advisory, security firm Sansec confirmed they intercepted initial exploitation attempts shortly after the bug was made public. The fix modifies how customer identity is handled in sessions and applies to all versions up to and including the July 2026 patches.

Aug 13
The Hacker News Research macOS malware7 min read

AmnesiaStealer Hijacks Chromium Sessions to Give Attackers Live Browser Control on macOS

Jamf Threat Labs identified a new Rust-based macOS information stealer named AmnesiaStealer that combines credential harvesting with the ability to remotely operate Chromium-based browsers such as Google Chrome and Microsoft Edge. Distributed through fraudulent GitHub download pages using ClickFix techniques, the malware extracts system passwords, Keychain data, and browser sessions to exfiltrate sensitive user information. Distinctively, it utilizes the Chrome DevTools Protocol to launch headless browsers, allowing operators to manipulate tabs, input keystrokes, and navigate sites in real-time while spoofing fingerprinting checks. The tool leverages patched vulnerabilities like CVE-2020-9771 to access protected data on older macOS versions, establishing persistence through disguised system services. While no specific threat actor attribution was provided, the combination of automated data theft and interactive session hijacking represents a significant escalation in macOS malware capabilities.

Aug 13
Help Net Security Exploited Microsoft SharePoint auth-bypass3 min read

Attackers exploit critical SharePoint flaw after PoC goes public (CVE-2026-55040)

Threat actors have begun actively exploiting a critical vulnerability in Microsoft SharePoint, identified as CVE-2026-55040, following the public release of proof-of-concept code by Rapid7. This flaw enables remote unauthenticated attackers to bypass authentication mechanisms by manipulating the JWT token validation process, potentially allowing them to access sensitive files or modify data. While Microsoft had previously issued a fix during its July 2026 Patch Tuesday cycle, recent intelligence indicates that adversaries are now leveraging the available exploits against honeypots and live systems.

Aug 13
SecurityWeek Patch WordPress rce2 min read

WordPress 7.0.4 Patches Remote Code Execution Vulnerability

WordPress has released version 7.0.4 to address a high-severity remote code execution vulnerability identified as CVE-2026-65640. This defect, which carries a CVSS score of 8.8, permits attackers with Author-level or higher privileges to execute arbitrary code by uploading malicious Postscript files disguised as images. The issue specifically impacts installations utilizing Imagick and Ghostscript, where a mismatch between WordPress' reliance on file extensions and ImageMagick's content-based processing allows for unintended script execution. While the fix is included in version 7.0.4, maintainers have backported the patch to all supported branches extending back to version 4.7.

Aug 13
SecurityWeek Patch FortiWeb auth-bypass2 min read

Fortinet Patches Authentication Flaws in FortiWeb and FortiManager

Fortinet has released updates addressing eight vulnerabilities across its network security portfolio, prioritizing high-severity authentication defects in FortiWeb and FortiManager. In FortiWeb, CVE-2026-26035 enables unauthenticated remote attackers to gain GUI/CLI access via random credentials when specific non-default wildcard administrator settings are active; this flaw is corrected in versions 8.0.3, 7.6.7, 7.4.12, and 7.2.13. Concurrently, CVE-2026-70468 allows remote impersonation of managed FortiGate devices within FortiManager under specific CLI configurations. The release also resolves a high-severity buffer overflow in FortiClient for Windows (CVE-2026-70465) and various lower-severity issues in FortiSIEM and FortiOS.

Aug 13
SecurityWeek Exploited VMware vCenter rce3 min read

Critical VMware vCenter Vulnerability in Attackers’ Crosshairs

Broadcom addressed a critical remote code execution flaw in VMware vCenter, tracked as CVE-2026-59310, following its disclosure on July 29. Quirso reported that an advanced persistent threat actor is actively exploiting this directory traversal vulnerability to deploy reverse shells for persistent access. The campaign targets exposed systems across 47 countries, with initial compromises observed shortly after the security bulletin was published.

Aug 13
SecurityWeek PoC Microsoft Defender zero-day3 min read

Nightmare Eclipse Drops Windows Zero-Day Exploit ‘ShieldBreak’

Security researcher Nightmare Eclipse has published the proof-of-concept exploit 'ShieldBreak' for CVE-2026-50656, a vulnerability in Microsoft Defender that enables local privilege escalation to System level. The exploit affects recent versions of Windows 11 and Windows Server 2025, and researchers indicate it likely impacts Windows 10 systems as well. While described by the researcher as a bypass to the earlier RoguePlanet flaw, technical analysts note that ShieldBreak operates via Cloud Filter API hooks rather than the filesystem race condition used in its predecessor.

Aug 13
Help Net Security Exploited Cisco Secure Firewall ASA ddos-botnet2 min read

Cisco fixes vulnerability exploited to DoS its firewalls (CVE-2026-20349)

Cisco has confirmed that attackers are actively exploiting a high-severity vulnerability, CVE-2026-20349, to trigger denial-of-service conditions on its firewall appliances. The flaw affects the Remote Access SSL VPN service running on Cisco Secure Firewall Adaptive Security Appliance (ASA) and Cisco Secure Firewall Threat Defense (FTD) software, specifically when IKEv2, SSL VPN, or ZTNA features are enabled. An unauthenticated attacker can send a specially crafted HTTP request to force the device to reload unexpectedly, interrupting network operations. Cisco PSIRT detected the active exploitation in August 2026, and CISA has since added the issue to its Known Exploited Vulnerabilities catalog with a remediation deadline for US civilian federal agencies of August 14, 2026. To mitigate the risk, administrators should apply the recently released hot fixes for ASA versions 9.16 through 9.24 and FTD versions 7.0 through 7.7 and 10.0, as no workarounds are available.

Aug 13
The Hacker News Exploited Microsoft SharePoint auth-bypass4 min read

Attackers Exploit SharePoint Authentication Bypass After Public PoC Release

Microsoft is actively addressing CVE-2026-55040, a critical authentication bypass in SharePoint that allows unauthenticated attackers to forge JWTs and impersonate administrators or site users. Following the release of a public proof-of-concept by Rapid7 this week, threat actors have begun exploiting the vulnerability, which was patched in Microsoft's July 2026 Patch Tuesday update. With a CVSS score of 9.1, the flaw stems from weak token validation logic that enables file disclosure and data modification without affecting system availability. Administrators should immediately apply the latest updates to prevent unauthorized access.

Aug 12
BleepingComputer Exploited Adobe Commerce web-app3 min read

Hackers exploit critical Adobe Commerce flaw to hijack customer accounts

Attackers are actively exploiting a critical incorrect authorization vulnerability, CVE-2026-71362, in Adobe Commerce and Magento platforms to hijack customer accounts without requiring authentication or administrative privileges. Security firm Sansec confirmed that their WAF is already blocking these attempts, noting that the flaw allows attackers to switch a customer session to another account. This issue was part of a security update released alongside six other vulnerabilities, including high-severity XSS flaws like CVE-2026-48413 and CVE-2026-48414. Administrators should apply the isolated August 2026 patch files after ensuring they have installed the latest point release for their specific supported version.

Aug 12
The Hacker News Exploited Windows Lazarus Group8 min read

Lazarus Exploits Windows Zero-Day to Gain SYSTEM Access and Deploy Backdoor

Check Point Research has attributed the exploitation of CVE-2026-68820 to the Lazarus Group, a North Korean state-sponsored threat actor targeting defense and aerospace firms in France, Germany, Brazil, and India. This privilege escalation vulnerability in the Windows Ancillary Function Driver for WinSock (AFD.sys) allows attackers to gain SYSTEM-level control, enabling them to deploy the ForestTiger backdoor and evade detection via Smart App Control manipulation. The campaign, part of the ongoing 'Dream Job' operation, lures victims with fraudulent job offers to install trojanized PDF viewers or malicious DLLs. These payloads execute MISTPEN modules to harvest system information and trigger the AFD.sys exploit. Organizations should immediately apply the fixes released in Microsoft's August 2026 Patch Tuesday updates and monitor for suspicious activity associated with compromised web infrastructure.