ZeroHour

Search: “cve-2026-55040”

40 stories

Smart search ranks by meaning as well as keywords (one row per story, last 45 days).

SharePoint CVE-2026-55040 Comes Under Attack Following Public Exploit

Attackers are actively exploiting critical SharePoint authentication bypass CVE-2026-55040 (CVSS 9.1) days after Rapid7 released a public PoC.

CVE-2026-55040 is a critical authentication bypass (CVSS 9.1) in SharePoint Server Subscription Edition that lets unauthenticated attackers forge JWT tokens and impersonate any user, including administrators. Microsoft patched it in July 2026 Patch Tuesday, but Rapid7 published a technical write-up and Python PoC on GitHub on August 12, and Defused quickly observed attackers running the PoC against SharePoint honeypots. KEVIntel recorded 12 exploitation attempts since July 19, with eight occurring on August 12-13 from IP addresses in Hong Kong, Japan, the Netherlands, Taiwan and the U.S. Admin-level SharePoint access exposes documents and data modification and can serve as a foothold into broader Microsoft 365 infrastructure; unpatched instances should apply the July update immediately.

Security Affairs · Aug 13, 2026Exploit / PoC in the wildCVE-2026-55040

CVE-2026-63520: Microsoft SharePoint Remote Code Execution (FIXED)

Rapid7 and Microsoft disclose CVE-2026-63520, a SharePoint RCE that chains with CVE-2026-55040 for unauthenticated RCE; patches released.

Rapid7 Labs' zero-day research project on Microsoft SharePoint uncovered two vulnerabilities that, when chained, achieve unauthenticated remote code execution. The second flaw in the chain, CVE-2026-63520, affects all supported versions of Microsoft SharePoint and has been disclosed and fixed. The first chain component, CVE-2026-55040, was disclosed by Rapid7 and Microsoft the previous month.

Rapid7 Blog · Aug 11, 2026VulnerabilityCVE-2026-63520CVE-2026-550401

September 2026 Patch Tuesday forecast: All we need is more time

September 2026 Patch Tuesday forecast expects record CVE volume after August's 398 fixes, with SharePoint flaws CVE-2026-55040 and CVE-2026-63520 actively exploited.

This Patch Tuesday forecast column notes August 2026 Patch Tuesday was the second largest ever with 398 resolved CVEs, yet only one was confirmed actively exploited. SharePoint flaws CVE-2026-55040 and CVE-2026-63520 are being chained for authentication bypass and remote code execution in active attacks against unpatched servers. Microsoft Defender's ShieldBreak elevation of privilege flaw (CVE-2026-69414) is publicly disclosed with PoC code and a fix is expected, while Chrome CVE-2026-85046 was reported exploited in the wild. Several products, including Windows 11 24H2 Home/Pro and Exchange Server 2016/2019 ESU, reach end of support in October 2026.

Help Net Security · 8d agoAdvisory in the wildCVE-2026-55040CVE-2026-63520CVE-2026-62911+5 CVEs2

Check Point Patches Critical VPN Vulnerabilities

Check Point patches two critical unauthenticated RCE flaws (CVE-2026-85102, CVE-2026-85103) in VPN gateways and firewalls; no exploitation observed.

Check Point released patches for CVE-2026-85102 and CVE-2026-85103, two critical vulnerabilities (CVSS 9.8) enabling unauthenticated remote code execution in products using VPN functionality. CVE-2026-85102 involves improper validation of certificate data during VPN negotiation, while CVE-2026-85103 is a heap overflow in the VPN certificate ASN.1 decoding flow. Updates cover versions R82.10, R82, and R81.20; manually defining VPN rules is offered as a mitigation, though it does not apply to locally managed Spark Firewall instances. Check Point discovered both flaws internally and reports no evidence of exploitation in the wild.

SecurityWeekupdated · 4h agofirst · 5d agoVulnerability 9 sourcesCVE-2026-85102CVE-2026-85103CVE-2026-16232+1 CVEs1

AL26-019 - Vulnerabilities impacting Citrix NetScaler ADC and NetScaler Gateway - CVE-2026-19490 and CVE-2026-19489

Canadian Cyber Centre alerts on Citrix NetScaler ADC/Gateway flaws CVE-2026-19490 (authentication bypass) and CVE-2026-19489 (buffer overflow), urging emergency patching.

The Canadian Centre for Cyber Security issued alert AL26-019 covering two Citrix NetScaler vulnerabilities disclosed in a vendor advisory on August 19, 2026. CVE-2026-19490 (CWE-288) allows a remote unauthenticated attacker to bypass authentication on appliances configured as a Gateway for SSL VPN, ICA Proxy, CVPN, RDP Proxy, or as an AAA virtual server. CVE-2026-19489 (CWE-120) is a classic buffer overflow that may cause memory overflow, unpredictable behavior, or denial-of-service conditions. Affected appliances are vulnerable when configured as a SAML IdP; fixed versions include 14.1-73.32, 13.1-63.21, and 13.1-37.277 for FIPS.

GitLab CVE-2026-19478 Comes Under Active Exploitation Within Days of Disclosure

Unauthenticated attackers are actively exploiting GitLab CVE-2026-19478 (CVSS 9.4) to modify or delete public projects days after disclosure.

GitLab CVE-2026-19478, a CVSS 9.4 code injection flaw exploitable via a GraphQL directive without authentication, allows attackers to modify or delete publicly accessible projects, rewrite repository data, forge merge records, and ban maintainers. Affected versions include GitLab CE/EE 18.2 before 18.11.11, 19.0 before 19.0.8, 19.1 before 19.1.6, and 19.2 before 19.2.4. watchTowr reproduced the flaw within minutes of disclosure and observed in-the-wild exploitation against its honeypot network. Fixes shipped in 19.2.4, 19.1.6, 19.0.8, and 18.11.11; interim mitigations include restricting unauthenticated access to /api/graphql or removing public repository access.

The Hacker News · 27d agoExploit / PoC in the wildCVE-2026-194781

Attackers exploit critical SharePoint flaw after PoC goes public (CVE-2026-55040)

Attackers use Rapid7's public PoC to exploit CVE-2026-55040, a critical SharePoint authentication bypass patched in July 2026.

Rapid7 researcher Stephen Fewer published technical analysis and PoC exploit code for CVE-2026-55040, an authentication bypass in SharePoint caused by flaws in the JWT token validation pipeline. Threat intelligence firm Defused observed attackers using the PoC against SharePoint honeypots, though Microsoft has not yet confirmed in-the-wild exploitation. Chained with CVE-2026-63520, the flaw can yield unauthenticated remote code execution, per NHS England Digital. CISA is urging administrators to harden SharePoint deployments by limiting direct internet exposure and using Layer 7 reverse proxies.

Help Net Security · Aug 13, 2026Exploit / PoC in the wildCVE-2026-55040CVE-2026-63520

You’re Back In The Room (Citrix NetScaler Pre-Auth RCE CVE-2026-8452(?))

watchTowr Labs details a pre-authentication remote code execution flaw, tracked as CVE-2026-8452, in Citrix NetScaler appliances.

watchTowr Labs published technical analysis of a pre-authentication remote code execution vulnerability in Citrix NetScaler, tentatively assigned CVE-2026-8452. The CVE identifier is marked as provisional in the write-up. No confirmation of in-the-wild exploitation is provided in the available text.

watchTowr Labs · Aug 14, 2026Exploit / PoCCVE-2026-8452

Rapid7 Analysis: Microsoft SharePoint JWT Token Authentication Bypass (CVE-2026-55040)

Rapid7's analysis of SharePoint auth bypass CVE-2026-55040 includes a PoC for unauthenticated admin-level operations.

Rapid7 and Microsoft disclosed CVE-2026-55040, an authentication bypass in Microsoft SharePoint, on July 14, 2026. The flaw stems from multiple issues in SharePoint's JWT token validation pipeline, allowing a remote unauthenticated attacker to bypass authentication and perform operations as a site user or administrator. Rapid7 has now published a technical analysis and a proof-of-concept script, based on SharePoint Server Subscription Edition.

Rapid7 Blog · Aug 11, 2026VulnerabilityCVE-2026-550401

CVE-2026-73749: HPE ArubaOS-CX RCE

HPE patched CVE-2026-73749, a critical unauthenticated remote code execution flaw in ArubaOS-CX network switch software; affected devices need prompt updates.

HPE released patches for CVE-2026-73749, a critical unauthenticated remote code execution vulnerability in HPE Aruba Networking AOS-CX switch operating system. Published details are limited, but the flaw allows unauthenticated attackers to execute code on affected AOS-CX devices. Administrators running ArubaOS-CX should prioritize applying HPE's update.

SOCRadar · 12d agoVulnerabilityCVE-2026-73749

Attackers Exploit SharePoint Authentication Bypass After Public PoC Release

Attackers exploit SharePoint authentication bypass CVE-2026-55040 (CVSS 9.1) after Rapid7's PoC release, with 12 exploitation attempts recorded since July 19, 2026.

Microsoft patched CVE-2026-55040 in its July 2026 Patch Tuesday; the 9.1-severity flaw chains four weaknesses in SharePoint's JWT token validation pipeline, letting unauthenticated attackers forge valid JWTs and impersonate any SharePoint site user or administrator. Threat actors began exploiting the bug after Rapid7 released a Python PoC that forges tokens and enumerates domain users by SID. KEVIntel telemetry shows 12 exploitation attempts since July 19, 2026, eight of them on August 12-13 following the PoC release, originating from eight IPs across Hong Kong, Japan, the Netherlands, Taiwan, and the U.S. This is the fifth SharePoint vulnerability exploited this year, alongside CVE-2026-45659, CVE-2026-56164, CVE-2026-58644, and CVE-2026-50522.

The Hacker News · Aug 15, 2026Exploit / PoC in the wildCVE-2026-55040CVE-2026-45659CVE-2026-56164+2 CVEs

SAP Commerce Cloud CVE-2026-58231 Targeted in Exploitation Attempts Days After Patch

A maximum-severity (CVSS 10.0) unauthenticated RCE flaw in SAP Commerce Cloud, CVE-2026-58231, is under active exploitation days after patching.

CVE-2026-58231, rated 10.0 on CVSS, stems from insufficient authorization checks and input validation in SAP Commerce Cloud, enabling unauthenticated arbitrary code execution. Defused Cyber's honeypots detected exploitation attempts three days after the patch, and KEVIntel independently confirmed two attempts on August 14 from a US IP address. Onapsis urges customers to patch and rebuild, with an IP Filter Set offered as a temporary workaround. No actor attribution yet, though prior SAP NetWeaver flaw CVE-2025-31324 was exploited by China-nexus and criminal groups.

The Hacker News · Aug 17, 2026Exploit / PoC in the wildCVE-2026-58231CVE-2025-31324

Researchers Disclose AI-Assisted SharePoint Exploit Chain Reaching Unauthenticated RCE

Rapid7 disclosed CVE-2026-55040, a SharePoint JWT validation bypass chaining into CVE-2026-63520 unauthenticated RCE, with research substantially AI-agent-assisted; patches released.

Rapid7 disclosed CVE-2026-55040 (CVSS 9.1), several JWT validation pipeline issues letting unauthenticated attackers impersonate chosen SharePoint users by SID or UPN, chained with CVE-2026-63520 (CVSS 8.1), an unsafe .NET type instantiation in Business Connectivity Services yielding RCE as the service account. An AI agent contributed significantly across 96 sessions and roughly 80,000 tool calls over 24 active days, though an expert had to steer it and it repeatedly overstepped its threat model. No exploitation of the bypass had been reported as of CISA's July 14 assessment. The RCE affects SharePoint Subscription Edition, 2019, and 2016, plus Project Server 2013 SP1 and Office Web Apps 2013 SP1; the July updates break the chain.

CVE-2026-34908, CVE-2026-34909, CVE-2026-34910: Ubiquiti UniFi OS ...

Ubiquiti UniFi OS flaws CVE-2026-34908, CVE-2026-34909, and CVE-2026-34910 were added to CISA's KEV, chaining auth bypass into command injection.

Ubiquiti UniFi OS vulnerabilities CVE-2026-34908, CVE-2026-34909, and CVE-2026-34910 were added to CISA's KEV catalog. CVE-2026-34908 (CVSS 10.0, CWE-284) is an unauthenticated improper access control flaw allowing unauthorized system changes, described as the initial entry point. It enables attackers to then leverage chained path traversal and command injection flaws for deeper compromise.

September 2026 Patch Tuesday roundup: Plugs for two zero day holes among almost 1,000 fixes in Windows

Microsoft's September 2026 Patch Tuesday ships 964 fixes including two exploited Windows zero-days (CVE-2026-85880, CVE-2026-81963) and a wormable DNS RCE.

Microsoft's September 2026 Patch Tuesday includes 964 Microsoft vulnerabilities requiring customer action, a record attributed to AI-assisted bug discovery, plus 174 third-party/open-source and 23 Chromium/Edge CVEs. Two zero-days are exploited in the wild: CVE-2026-85880, a Windows ALPC heap overflow enabling AppContainer sandbox escape and privilege escalation, and CVE-2026-81963, a Windows Update Stack escalation to SYSTEM. CVE-2026-69730, an unauthenticated Windows DNS RCE, is not yet exploited but Microsoft expects exploitation, and roughly 20 bugs could be wormable. Separately, SAP issued a critical CVSS 10.0 fix for the EPP component used in S/4HANA and NetWeaver.

CSO Online · 8d agoVulnerability in the wildCVE-2026-85880CVE-2026-81963CVE-2026-69730+2 CVEs1

Microsoft Patches 398 Flaws Including a Windows Driver Zero

Microsoft's August Patch Tuesday fixes 398 CVEs, including actively exploited Windows zero-day CVE-2026-68820 used by Lazarus for SYSTEM privilege escalation.

Microsoft's August 2026 Patch Tuesday release addresses 398 new vulnerabilities, 62 rated Critical by the Zero Day Initiative, with CVE-2026-68820 (CVSS 7.0), a use-after-free in the afd.sys Windows kernel driver, the only flaw flagged as actively exploited. Check Point Research attributed exploitation of the privilege escalation bug to Lazarus' Operation Dream Job campaign. Four unauthenticated remote code execution flaws rated 9.8 affect Windows DNS Server (CVE-2026-62878, called wormable by ZDI), Windows Deployment Services (CVE-2026-62893), Microsoft QUIC (CVE-2026-62815) and HPC Pack (CVE-2026-59124). The release also completes a two-part SharePoint fix with RCE component CVE-2026-63520, following July's authentication bypass fix CVE-2026-55040.

The Hacker News · Aug 11, 2026Exploit / PoC in the wildCVE-2026-68820CVE-2026-62878CVE-2026-62893+4 CVEs

Microsoft’s September 2026 Patch Tuesday addresses 964 CVEs (CVE-2026-81963, CVE-2026-85880)

Microsoft's September 2026 Patch Tuesday fixes a record 964 CVEs, including two zero-days actively exploited in the wild.

Microsoft patched a record 964 CVEs in its September 2026 Patch Tuesday release, with 101 rated critical and 824 rated important, making it the largest Patch Tuesday to date. The release includes fixes for two zero-days that were exploited in the wild, with CVE-2026-81963 and CVE-2026-85880 highlighted in the release. Affected products span Windows core components, Office, Exchange, .NET, Visual Studio, Active Directory services (including AD CS and AD FS) and numerous Azure services. Tenable notes the release surpasses July's as the biggest ever.

Tenable Blog · 8d agoVulnerability in the wildCVE-2026-81963CVE-2026-858801

U.S. CISA adds Apple macOS, Microsoft SharePoint, Broadcom VMware vCenter, and Microsoft IKE flaws to its Known Exploited Vulnerabilities catalog

CISA adds actively exploited flaws in Microsoft IKE, SharePoint, VMware vCenter, and macOS Screen Sharing to KEV catalog, due August 21.

CISA added four vulnerabilities to its Known Exploited Vulnerabilities catalog: CVE-2026-33824 (Windows IKE remote code execution, CVSS 9.8), CVE-2026-55040 (SharePoint JWT authentication bypass, CVSS 9.1), CVE-2026-59310 (VMware vCenter Syslog path traversal, CVSS 9.8), and CVE-2026-65400 (macOS Screen Sharing improper authentication). The SharePoint flaw combines four weaknesses including alg:none JWT forging to impersonate any user, with Defused researchers observing attackers using Rapid7's PoC against honeypots. The Dutch NCSC confirmed active exploitation of the macOS Screen Sharing flaw on August 15, 2026. Federal agencies must patch by August 21, 2026.

Security Affairs · 29d agoExploit / PoC in the wildCVE-2026-33824CVE-2026-55040CVE-2026-59310+1 CVEs

CVE-2026-86218 | N-able N-central Pre-Authentication Remote Code Execution Vulnerability

N-able N-central pre-auth RCE CVE-2026-86218 (CVSS 10.0) is actively exploited; CISA added it to KEV and a hotfix is available.

CVE-2026-86218 is a critical pre-authentication remote code execution flaw (CWE-96 static code injection) in N-able N-central servers, scored 10.0 CVSS 4.0 by N-able and 9.8 CVSS 3.1 by NIST. N-able fixed it in N-central 2026.3 Hotfix 4 (build 2026.3.1.14) on September 5, 2026, and has already patched hosted NCOD environments. CISA added the CVE to its Known Exploited Vulnerabilities catalog on September 8, 2026, citing evidence of active exploitation, though researchers have not attributed every reported N-central compromise to this flaw. Horizon3 released a NodeZero Rapid Response test to validate exposure and recommends log review for prior compromise.

Horizon3.ai · 18h agoExploit / PoC in the wildCVE-2026-862183· 1 read

Week in review: Salesforce and ServiceNow portals exposed for 17 months, exploited Metabase 0-day

Weekly digest: exploited Metabase zero-day breached Framework; Salesforce/ServiceNow portals read for 17 months; Microsoft patched 400+ flaws.

Help Net Security's week in review aggregates top stories: a 'City-Forum' campaign tracked by Reco has been pulling records from Salesforce and ServiceNow portals worldwide for 17 months, and Framework suffered a breach via an exploited Metabase zero-day exposing customer contact and IP data. It also covers Microsoft's August 2026 Patch Tuesday fixing 400+ flaws including exploited zero-day CVE-2026-68820, Cisco's fix for exploited firewall DoS bug CVE-2026-20349 (added to CISA KEV), and a second N-able N-central hotfix for actively exploited CVE-2026-18577. Other items include GitHub expanding Dependabot malware alerts to eight package ecosystems and EU AI Act enforcement beginning on 2 August 2026.

Help Net Security · Aug 16, 2026Industry in the wildCVE-2026-18577CVE-2026-68820CVE-2026-203491

Microsoft Exchange Vulnerability CVE-2026-62911: What Administrators Should Do and How Zscaler Can Help

High-severity authentication bypass CVE-2026-62911 in Exchange Server has public exploit code; about 22,000 servers remain unpatched and internet-exposed.

Microsoft's August 2026 Patch Tuesday fixed CVE-2026-62911 (CVSS 8.0), an authentication bypass affecting Exchange Server 2016, 2019 and Subscription Edition. Successful exploitation lets an attacker with basic privileges take over all mailboxes on the targeted server, including reading and sending email and downloading attachments. As of September 1, Shadowserver identified roughly 22,000 unpatched, internet-exposed Exchange servers, including about 6,200 in the US and 5,100 in Germany. NCSC-NL confirmed working exploit code is publicly available, while CISA has not yet reported exploitation in the wild.

Zscaler ThreatLabz · 13d agoVulnerabilityCVE-2026-629112

Risky Bulletin: Russia starts blocking DoH and DoT

Russian users report blocks on DoH and DoT servers, including Cloudflare 1.1.1.1 and Google 8.8.8.8, in an apparent censorship crackdown.

Russian internet users began reporting failures connecting to DNS-over-HTTPS and DNS-over-TLS servers, suggesting a government crackdown on the two privacy protocols. The blocks reportedly cover Cloudflare's 1.1.1.1 and Google's 8.8.8.8 resolvers; Roskomnadzor has not officially confirmed the action. The agency tested a similar block in March on Beeline's network and had named DoH for blocking as early as 2021. The bulletin also briefly notes state-sponsored phishing of EU officials, a DDoS against Norway's Digdir, the ReliaQuest/ShinyHunters dispute, and older ransomware and breach disclosures.

Risky Business News · 22d agoPolicy & legal1

CVE-2026-76461: Critical Cisco Secure Email Gateway Vulnerability Exploited in the Wild

Cisco Secure Email Gateway zero-day CVE-2026-76461 (CVSS 9.8) enables unauthenticated root command execution via crafted email; CISA added it to KEV.

CVE-2026-76461 is a critical SQL injection (CVSS 9.8) in Cisco AsyncOS for Secure Email Gateway allowing an unauthenticated remote attacker to execute arbitrary commands with root privileges by sending a specially crafted email through a vulnerable gateway. CISA added it to the KEV catalog on disclosure day, indicating zero-day exploitation, and Cisco PSIRT became aware of active exploitation in September 2026. No public PoC or attribution exists; fixed versions are 15.5.5-014, 16.0.4-302, and 16.5.0-780, and admins should check mail_logs for suspicious SQL statements like 'COPY.*TO PROGRAM'.

Rapid7 Blogupdated · 20h agofirst · 1d agoExploit / PoC in the wild 17 sourcesCVE-2026-76461

August 2026 CVE Landscape

Insikt Group catalogs 73 high-impact August 2026 CVEs (43 Very Critical), including PaperCut, Zimbra, and Metabase flaws actively exploited or weaponized.

Recorded Future's Insikt Group identified 73 high-impact vulnerabilities in August 2026, 43 rated Very Critical, spanning 45 vendors with Microsoft accounting for roughly 11%. 31 vulnerabilities surfaced via CISA's KEV catalog, with others validated via open sources, vendor telemetry, and honeypot data. New Nuclei detection templates were released for CVE-2025-62593 (Ray), CVE-2026-72898 (Metabase), and CVE-2026-9198 (IBM Langflow). The report also highlights two AI-assisted operations: UAT-10147 exploited Zimbra, AjaxPro, Nacos, and Telerik servers before using DeepAudit and PentestGPT post-compromise, while a separate Chinese-speaking actor weaponized Hermes Agent and DeepSeek in a failed attempt.

Recorded Future · 9d agoVulnerability in the wildCVE-2025-62593CVE-2026-72898CVE-2026-9198+4 CVEs1

Critical macOS, SharePoint, vCenter, and Microsoft IKE Flaws Under Active Exploitation

CISA added four critical actively exploited flaws to KEV: macOS Screen Sharing, SharePoint, VMware vCenter, and Microsoft IKE, with APT and ransomware use.

CISA added CVE-2026-65400 (macOS Screen Sharing, CVSS 9.8), CVE-2026-55040 (SharePoint, CVSS 9.1), CVE-2026-59310 (VMware vCenter, CVSS 9.8) and CVE-2026-33824 (Microsoft IKE Service Extensions, CVSS 9.8) to the KEV catalog. The macOS flaw was abused to deliver a Monero miner, while the vCenter bug was exploited by a suspected China-nexus APT to install reverse_ssh backdoors and Babuk-derived ransomware across 361 victim IPs in 47 countries. Unit 42 linked CVE-2026-33824 to a Chinese-speaking actor running an AI-enabled campaign using DeepSeek. FCEB agencies must patch by August 21, 2026 under BOD 26-04.

The Hacker News · 28d agoExploit / PoC in the wildCVE-2026-65400CVE-2026-55040CVE-2026-59310+1 CVEs

CVE-2026-33824: CISA Flags Windows IKE RCE as Exploited

CISA added four actively exploited vulnerabilities to its KEV catalog, headlined by CVE-2026-33824, a Windows IKE Service Extensions remote code execution flaw.

CISA's KEV addition, dated August 18, covers CVE-2026-33824 in Windows IKE Service Extensions, CVE-2026-55040 in on-premises Microsoft SharePoint Server, CVE-2026-59310 in Broadcom VMware vCenter, and CVE-2026-65400 in Apple macOS Screen Sharing. KEV listing confirms observed exploitation in the wild. Three of the four products are frequently deployed as high-value enterprise infrastructure, including remote-access endpoints and collaboration platforms.

CVE-2026-19490: Critical Vulnerability Affecting Citrix NetScaler ADC and NetScaler Gateway

CVE-2026-19490 is a critical unauthenticated authentication bypass in Citrix NetScaler ADC and Gateway, remotely exploitable without user interaction.

An advisory published August 19, 2026 describes CVE-2026-19490, a critical authentication bypass affecting Citrix NetScaler ADC and NetScaler Gateway. The flaw carries a CVSS v4.0 base score of 9.3 and is remotely exploitable by unauthenticated attackers over the network without user interaction or elevated privileges. NetScaler ADC and Gateway are widely deployed enterprise products positioned at or near the network perimeter, providing load balancing, SSL/TLS offloading, and secure remote access. The text does not state whether exploitation has been observed in the wild.

Rapid7 Blog · 28d agoVulnerabilityCVE-2026-194901

Microsoft patches 400+ vulnerabilities, one zero-day under attack (CVE-2026-68820)

Microsoft's August 2026 Patch Tuesday fixes 400+ vulnerabilities, including an actively exploited Windows zero-day (CVE-2026-68820) used by North Korean attackers.

Microsoft's August 2026 Patch Tuesday fixes over 400 vulnerabilities, including CVE-2026-68820, a use-after-free in the Windows Ancillary Function Driver exploited in the wild by North Korean actors deploying a kernel-mode rootkit in Operation Dream Job. Critical unauthenticated remote code execution flaws in Microsoft QUIC (CVE-2026-62815) and Windows DNS (CVE-2026-62878) were also patched, alongside a SharePoint RCE chain combining CVE-2026-63520 with CVE-2026-55040. Researcher Nightmare-Eclipse released ShieldBreak, a PoC bypassing the July RoguePlanet Microsoft Defender patch (CVE-2026-50656), confirmed working by Will Dormann on Windows 11.

Help Net Security · Aug 12, 2026Exploit / PoC in the wildCVE-2026-68820CVE-2026-62832CVE-2026-72971+6 CVEs1

Critical SonicWall SMA1000 Vulnerabilities CVE-2026-83548, CVE-2026-83549 Exploited in the Wild

SonicWall SMA1000 appliances face active exploitation of chained CVE-2026-83548 and CVE-2026-83549 enabling unauthenticated RCE; hotfixes released.

SonicWall disclosed on September 1, 2026 that CVE-2026-83548, a critical pre-authentication SSRF in the SMA1000 Appliance Work Place interface (CVSS 10.0), and CVE-2026-83549, an authenticated OS command injection in the Appliance Management Console, can be chained for unauthenticated remote code execution. Both vulnerabilities are confirmed exploited in the wild and were added to CISA's Known Exploited Vulnerabilities catalog. Affected SMA1000 models 6210, 7210 and 8200v on versions 12.4.3-03453 and 12.5.0-02835 platform-hotfix or earlier require upgrades to 12.4.3-03526 or 12.5.0-02952 platform-hotfixes.

Rapid7 Blog · 14d agoExploit / PoC in the wildCVE-2026-83548CVE-2026-83549

Microsoft's August 2026 Patch Tuesday addresses 398 CVEs (CVE-2026-68820)

Tenable reports Microsoft's August 2026 Patch Tuesday addresses 398 CVEs including three zero-days, one exploited in the wild (CVE-2026-68820).

Microsoft patched 398 CVEs in its August 2026 Patch Tuesday release, with 42 rated critical, 355 important, and one moderate, and three zero-days among them. One zero-day is confirmed as exploited in the wild. The release covers components including .NET, .NET Framework, Active Directory Certificate Services (AD CS), Azure services, and Windows. Tenable's count omits two CVEs assigned by MITRE, CVE-2026-6726 and CVE-2026-6727.

Tenable Blog · Aug 11, 2026Vulnerability in the wildCVE-2026-68820CVE-2026-6726CVE-2026-67271

SAP Patches Critical Extended Passport Processing Vulnerability

SAP patches CVSS 10.0 flaw CVE-2026-44756 (OVERPASS) enabling unauthenticated RCE in S/4HANA and NetWeaver, plus three other criticals; no in-the-wild exploitation reported.

CVE-2026-44756 is a CVSS 10.0 memory corruption flaw in Extended Passport (EPP) deserialization, triggered when a user session opens across web, SAP GUI, and RFC vectors. Exploitation yields command execution as the SAP OS account, database credential and password hash recovery, session reading, and data or binary modification; affected products include S/4HANA, ERP/ECC, NetWeaver, Web Dispatcher, and BW/4HANA. Three other criticals were patched: CVE-2026-58240 (S4GET, missing authentication affecting all S/4HANA 2025 and earlier releases), CVE-2026-76969 (CAP credential disclosure), and CVE-2026-66768 (NetWeaver access control). Onapsis and SAP report no indicators of in-the-wild exploitation.

CVE-2026-0770: Langflow exec_globals RCE Vulnerability

CVE-2026-0770 is a critical unauthenticated remote code execution vulnerability in Langflow's exec_globals, endangering exposed deployments.

CVE-2026-0770 is a critical remote code execution vulnerability in Langflow, a popular open-source framework for building language model applications. It allows remote attackers to execute arbitrary code on affected installations without authentication, making internet-exposed deployments particularly dangerous. The flaw resides in the exec_globals component; the available disclosure does not state active exploitation or provide patch details.

CVE-2026-76646: Apache MyFaces: Denial of Service via Unbounded Request Parsing

Apache MyFaces fixes critical CVE-2026-76646, a remote denial-of-service flaw triggered by crafted request parameters across versions 2.2.0-4.1.3.

Apache MyFaces disclosed CVE-2026-76646, a critical denial-of-service vulnerability in which remote attackers can cause excessive resource consumption by supplying specially crafted request parameters. Affected versions span 2.2.0-2.2.15, 2.3.0-2.3.11, 3.0.0-3.0.3, 4.0.0-4.0.3, 4.1.0-4.1.3 and 2.3-next-*. The disclosure notes older versions may also be impacted.

StyleSmuggler (CVE-2026-75650): Frequently asked questions about Adobe Commerce and Magento zero-day

Critical unauthenticated RCE zero-day CVE-2026-75650 (StyleSmuggler) in Adobe Commerce and Magento is actively exploited; Adobe shipped hotfix VULN-39341 on September 7.

CVE-2026-75650 is a CVSS 10.0 unauthenticated remote code execution flaw in Adobe Commerce 2.4.4-2.4.9, Adobe Commerce B2B 1.3.3-1.5.3, and Magento Open Source 2.4.6-2.4.9, exploited via malicious style properties that inject PHP code executed through a transactional email template. Active exploitation began September 4, 2026, three days before Adobe released Hotfix VULN-39341 (APSB26-146) on September 7, with multiple victim stores confirmed by Sansec and Disrex across at least two distinct campaigns. Attackers deploy a persistent implant at ~/.local/share/.gvfsd/gvfsd-user masquerading as kworker, fc-cache, or chronyd, sustained by a cron job, while a second operator dropped a PHP web shell in product image caches. Tenable classified it as a Vulnerability of Interest; it is not yet in CISA KEV as of September 8, and Adobe also recommends rotating encryption keys and all protected credentials.

Tenable Blogupdated · 8d agofirst · 8d agoExploit / PoC in the wild 2 sourcesCVE-2026-75650CVE-2025-54236CVE-2024-34102+1 CVEs

Back-to-back N-able bugs send admins on a patching spree

CVE-2026-86218, a CVSS 10.0 pre-auth RCE in N-able N-central, is being exploited in the wild; Hotfix 4 mitigates it immediately.

N-able disclosed CVE-2026-86218 on September 6, a pre-authentication remote code execution flaw with CVSS 10.0 in its N-central RMM platform, and both N-able and Huntress report it is being exploited in the wild. It follows Huntress's disclosure of an exploit chain combining CVE-2026-86206 and CVE-2026-86207 that bypasses access controls to create unauthorized administrative accounts, investigated after a September 4 compromise of a fully patched customer environment. N-able has applied mitigations to all hosted N-central instances; on-premises customers must upgrade to Hotfix 4 (build 2026.3.1.14) immediately.

CSO Online · 9d agoExploit / PoC in the wildCVE-2026-86218CVE-2026-86206CVE-2026-86207+2 CVEs

Cisco warns of max severity ISE zero-day exploited in attacks

Cisco patched CVE-2026-76460, a maximum-severity authentication bypass in Identity Services Engine actively exploited in attacks; CISA added it to KEV with a three-day federal deadline.

CVE-2026-76460 is a maximum-severity authentication bypass in an API endpoint of Cisco Identity Services Engine (ISE) and ISE-PIC, exploitable regardless of configuration, allowing attackers to access the web-based management interface. Cisco PSIRT confirmed active exploitation; no workarounds exist, and fixed releases are available for ISE 3.1 through 3.5, with re-imaging of suspect nodes recommended. CISA added the flaw to its Known Exploited Vulnerabilities Catalog and ordered federal agencies to patch within three days. Cisco also patched CVE-2026-76423 and five other critical ISE flaws (CVE-2026-20176, CVE-2026-20211, CVE-2026-20307, CVE-2026-20284) that are not yet flagged as exploited.

BleepingComputer · 3h agoExploit / PoC in the wildCVE-2026-76460CVE-2026-76423CVE-2026-20176+4 CVEs1· 1 read

2026-008: Critical vulnerabilities in Ivanti Sentry

Ivanti patched Sentry: pre-auth OS command injection CVE-2026-10520 (CVSS 10) enables unauthenticated root RCE, and auth bypass CVE-2026-10523 (CVSS 9.9).

On 9 June 2026 Ivanti released an advisory fixing two critical flaws in Ivanti Sentry versions 10.5.1 and prior, 10.6.1 and prior, and 10.7.0 and prior. CVE-2026-10520 (CVSS 10.0) is an OS command injection allowing a remote unauthenticated attacker to achieve root-level RCE. CVE-2026-10523 (CVSS 9.9) is an authentication bypass letting an unauthenticated attacker create arbitrary administrative accounts and obtain full admin access. CERT-EU recommends updating appliances to fixed versions following Ivanti's guidance.

CVE-2026-50522: Microsoft SharePoint Server RCE Vulnerability

CVE-2026-50522 is an unauthenticated .NET deserialization RCE in SharePoint Server Subscription, 2019, and 2016; Microsoft patched it July 14, 2026.

CVE-2026-50522 (CWE-502) lets unauthenticated attackers send crafted serialized .NET payloads to network-accessible SharePoint endpoints, triggering gadget-chain deserialization and remote code execution under the privileged SharePoint service account. It affects SharePoint Server Subscription Edition, SharePoint Server 2019, and SharePoint Server 2016 Enterprise; Microsoft published the advisory on July 14, 2026. The EPSS score is 20.346%, but no public PoC exists and the flaw is not in CISA's KEV catalog at publication. Mitigations include applying Microsoft updates, rotating SharePoint machine keys, enabling AMSI, and restricting internet exposure.

Microsoft breaks Patch Tuesday record with 974-CVE deluge

Microsoft's record 974-CVE Patch Tuesday ships two exploited Windows zero-days, while Adobe's StyleSmuggler zero-day (CVE-2026-75650) gives unauthenticated RCE in Magento.

Microsoft's September Patch Tuesday addresses 974 CVEs, including two zero-days already under exploitation: CVE-2026-85880, a Windows ALPC privilege escalation leading to SYSTEM via sandbox escape, and CVE-2026-81963, a Windows Update Stack privilege escalation. Adobe patched 172 CVEs, including the max-severity StyleSmuggler zero-day CVE-2026-75650 in Magento and Adobe Commerce, which Sansec reports is being exploited since September 4 to inject PHP into templates and install a C2-connected backdoor. CISA added CVE-2026-85880, CVE-2026-81963, and CVE-2026-75650 to its Known Exploited Vulnerabilities Catalog with patch deadlines of September 22 and September 11. The piece also notes Google-patched Chrome V8 zero-day CVE-2026-85046 lacks a Microsoft advisory for Edge, and flags nine Exchange Server flaws including remote unauthenticated RCE CVE-2026-55007.

CVE-2026-72524: Apache Doris: Authorization bypass allowing a low-privilege user to read/write/drop arbitrary tables

Apache Doris authorization bypass CVE-2026-72524 lets authenticated low-privilege users read, write, or drop arbitrary tables in affected 3.1.x through 4.1.3 versions.

CVE-2026-72524 is an incorrect authorization vulnerability in Apache Doris rated important, allowing an authenticated low-privilege user to bypass privilege checks and read, write, or drop arbitrary tables. Affected versions include Apache Doris 3.1.0 through 3.1.*, 4.0.0 through 4.0.7, and 4.1.0 through 4.1.3. The flaw permits access to or modification of data the user is not authorized to touch.

oss-security · 2d agoVulnerabilityCVE-2026-725241