These news items are automatically aggregated from industry sources and are not individually reviewed. Any inaccuracies are unintentional —
let us know and we'll correct or remove it.
Adobe shipped an out-of-cycle security update, APSB26-92, on 11 August fixing seven Commerce and Magento Open Source flaws, five of them critical. The standout is CVE-2026-71362, a CVSS 9.1 incorrect authorization bug that lets an unauthenticated attacker swap an active session onto a different customer’s account, no password, no admin access, no user interaction required. Adobe said it had no evidence of exploitation at patch time. Within days, eCommerce security firm Sansec said its Shield firewall was already blocking live attempts against it.
The European Commission’s 24 June proposal to reform the Europol Regulation would roughly double the agency’s budget to 3 billion euros for 2028-2034 and expand its staff and technical capabilities. The European Data Protection Supervisor has now weighed in with an opinion stating the proposal, as written, does not provide sufficient safeguards, calling for effective oversight and enforcement mechanisms before Europol’s legal mandate grows. It is the same institution that took legal action over the last Europol reform in 2022 on near-identical grounds.
CVE-2026-55040, a critical JWT validation bypass in on-premises SharePoint Server that lets an unauthenticated attacker forge a token and impersonate any user, including administrators, is now being exploited using a researcher’s own published proof of concept. Honeypot operator Defused recorded eight exploitation attempts on 12 and 13 August alone, and Shadowserver counts more than 8,500 SharePoint servers still reachable from the open internet this week.
Three days after this outlet covered the maximum-severity Metabase SQL injection flaw being exploited against Framework and Tally, Czech hardware wallet maker Trezor has disclosed that the same vulnerability, exploited at its fulfilment partner ShipMonk, exposed names, emails, phone numbers and shipping addresses for 13,689 customers across the US, UK, Sweden, Italy and Portugal. CISA’s federal patch deadline for the underlying CVE, added to its Known Exploited Vulnerabilities catalog on 11 August, falls today.
Fortinet’s 12 August advisory for CVE-2026-26035 describes a maximum-severity flaw in FortiWeb: when an admin account is configured for remote RADIUS authentication with the wildcard option enabled, a non-default but far from rare setup, the appliance will match any username on the RADIUS server against an admin group, letting an unauthenticated remote attacker log into the GUI or CLI with arbitrary credentials. Patched versions are 8.0.3, 7.6.7, 7.4.12 and 7.2.13.
CVE-2026-59310, a maximum-severity directory traversal flaw in VMware vCenter’s Syslog server patched in VMSA-2026-0006 on 29 July, is now being exploited at scale. Researchers have tracked path traversal activity followed by reverse SSH backdoor deployment across 361 unique vCenter IPs in 47 countries, with Germany, the United States, Turkey, Iran and France the most affected. First contact with attacker infrastructure was recorded on 3 August, five days after Broadcom’s advisory went public and while an unknown share of vCenter estates had not yet applied the fix.
CVE-2026-20349, an unauthenticated denial-of-service flaw in the Remote Access SSL VPN service on Cisco Secure Firewall ASA and FTD software, was disclosed as already being exploited in the wild when Cisco published its advisory on 11 August 2026. CISA added it to the Known Exploited Vulnerabilities catalog the same day. Any device running IKEv2 Remote Access VPN with client services, SSL VPN or Zero Trust Network Access is affected, and Cisco’s only supported fix is a hotfix or upgraded release, not a configuration workaround.
New analysis published this week by CloudSEK reconstructs the true blast radius of the March 2026 LiteLLM supply chain compromise, which was itself downstream of the TeamPCP attack on the Trivy scanner that also breached the European Commission’s AWS cloud. Two malicious LiteLLM releases, live on PyPI for roughly three hours, are now linked to more than 2,500 affected organisations and 434,000 CI/CD pipeline runs, with an infostealer that harvested AWS, GCP, GitHub and SSH credentials and installed a persistent systemd backdoor. Exposure does not confirm every one of those organisations was breached, but almost five months later the real scope is only now becoming clear.
A maximum-impact flaw in Rancher’s impersonation middleware, CVSS 9.1, let any authenticated user with permission to register a downstream cluster trick Rancher into checking authorization against that attacker-controlled cluster while actually executing the request against Rancher’s own privileged management plane. Because registering a downstream cluster is a default, low-privilege capability, the practical bar for full platform takeover was a standard Rancher account and a free k3d cluster on a laptop. Patches are out for all four supported release lines.
Microsoft’s August 2026 Patch Tuesday fixes 421 vulnerabilities, including a Windows privilege escalation zero-day that Check Point traces back to Lazarus Group activity starting in early June, weeks before a patch existed. A second publicly disclosed flaw in Windows User Profile Service is expected to see exploitation shortly. With 62 critical bugs and 40 of those remote code execution, most patch teams cannot triage the full list this week, so knowing which two to fix first matters more than the total count.
This site uses cookies. By continuing to use this website, you agree to their use.
We’ll help you resolve your infrastructure challenges
Our team of experts is ready to help you with your infrastructure challenges. We’ll give you honest and personal treatment. Get in touch to learn more.