ZeroHour

Search: “anonymization”

173 stories

FreeIPA Flaw Chain Lets Anonymous Clients Create Reusable Administrator Credentials

Critical FreeIPA flaw chain (CVE-2026-76578, CVSS 9.8) lets anonymous clients create reusable admin credentials on default installs; fixed in 4.13.4.

Red Hat warns that chaining FreeIPA's CVE-2026-76578 (CVSS 9.8) with a 389 Directory Server flaw (CVE-2026-76560, CVSS 7.5) lets an anonymous client write a Kerberos identity into the directory and land in the administrators group on default installations; Red Hat reproduced the chain twice, including on a machine with no access at all. FreeIPA 4.13.4 fixes both flaws, and fourteen 389-ds advisories shipped September 8, with RHSA-2026:64785 rated critical. A separate flaw, CVE-2026-79678 (CVSS 8.1), allows reading the server's environment variables one at a time via a Python eval() in idp-add, potentially exposing Directory Manager and administrator passwords in container installs. No real-world exploitation has been reported.

Microsoft’s massive Patch Tuesday releases continue as AI reshapes bug discovery

Microsoft patches 419 vulnerabilities in record-breaking Patch Tuesday; Windows Winsock zero-day CVE-2026-68820 is actively exploited by Lazarus Group.

Microsoft's August Patch Tuesday fixes 419 vulnerabilities (62 critical, 357 important), among the largest monthly counts on record, following 206 fixes in June and 622 in July as AI-assisted discovery drives unprecedented volume. Three flaws are zero-days; Windows Winsock bug CVE-2026-68820 is exploited in the wild by Lazarus Group in job-themed attacks using PDFs with a trojanised reader. CVE-2026-62832, publicly disclosed by researcher Nightmare Eclipse via the LegacyHive PoC, is also patched. Microsoft now lists bugs by product family instead of itemized CVEs, which defenders warn complicates triage.

The Record · Aug 12, 2026Vulnerability in the wildCVE-2026-68820CVE-2026-628321