August 2026 CVE Landscape
Insikt Group catalogs 73 high-impact August 2026 CVEs (43 Very Critical), including PaperCut, Zimbra, and Metabase flaws actively exploited or weaponized.
Recorded Future's Insikt Group identified 73 high-impact vulnerabilities in August 2026, 43 rated Very Critical, spanning 45 vendors with Microsoft accounting for roughly 11%. 31 vulnerabilities surfaced via CISA's KEV catalog, with others validated via open sources, vendor telemetry, and honeypot data. New Nuclei detection templates were released for CVE-2025-62593 (Ray), CVE-2026-72898 (Metabase), and CVE-2026-9198 (IBM Langflow). The report also highlights two AI-assisted operations: UAT-10147 exploited Zimbra, AjaxPro, Nacos, and Telerik servers before using DeepAudit and PentestGPT post-compromise, while a separate Chinese-speaking actor weaponized Hermes Agent and DeepSeek in a failed attempt.
Unpatched Zimbra servers are falling to CVE-2026-73570 attacks
Attackers are exploiting unpatched Zimbra servers via CVE-2026-73570; 274 instances compromised, and CISA added the flaw to its KEV catalog.
The Shadowserver Foundation counted at least 274 compromised internet-facing Zimbra Collaboration Suite instances exploited through CVE-2026-73570, up from 155 on August 20. The unauthenticated code injection flaw affects servers with the optional zimbra-snmp package and SNMP notifications enabled, allowing arbitrary OS command execution via crafted SMTP requests. Synacor patched the issue in ZCS v10.1.20 on July 20, 2026, and at least 8,200 instances remain unpatched. CISA added the flaw to its Known Exploited Vulnerabilities catalog and gave US federal civilian agencies three days to remediate and check for compromise.