August 2026 CVE Landscape
Insikt Group catalogs 73 high-impact August 2026 CVEs (43 Very Critical), including PaperCut, Zimbra, and Metabase flaws actively exploited or weaponized.
Recorded Future's Insikt Group identified 73 high-impact vulnerabilities in August 2026, 43 rated Very Critical, spanning 45 vendors with Microsoft accounting for roughly 11%. 31 vulnerabilities surfaced via CISA's KEV catalog, with others validated via open sources, vendor telemetry, and honeypot data. New Nuclei detection templates were released for CVE-2025-62593 (Ray), CVE-2026-72898 (Metabase), and CVE-2026-9198 (IBM Langflow). The report also highlights two AI-assisted operations: UAT-10147 exploited Zimbra, AjaxPro, Nacos, and Telerik servers before using DeepAudit and PentestGPT post-compromise, while a separate Chinese-speaking actor weaponized Hermes Agent and DeepSeek in a failed attempt.
2026-003: Multiple Vulnerabilities in Citrix NetScaler and Citrix ADC
Citrix NetScaler ADC and Gateway flaws enable memory information disclosure and user session mix-up; no active exploitation is observed yet.
Citrix patched CVE-2026-3055 (CVSS 9.3), an out-of-bounds read that can expose sensitive memory on systems configured as a SAML Identity Provider, and CVE-2026-4368 (CVSS 7.7), a race condition causing user session mix-up on Gateway and AAA virtual server configurations. Affected builds include NetScaler ADC and Gateway versions prior to 14.1-66.59 and 13.1-62.23. At publication there was no public evidence of active exploitation; CERT-EU recommends prioritizing internet-facing appliances, applying the Global Deny List mitigation, and terminating all sessions after patching.