2026-W33 vulnerability status roll-up — eight flaws crossed into confirmed exploitation or the federal catalogue this week, two of them within seventy-two hours of their own disclosure, against a critical tail led by two unauthenticated CVSS 10.0 flaws in industrial edge devices
Newly exploited or newly catalogued this week. Two flaws crossed into exploitation within seventy-two hours of their own disclosure and are treated at length in this week's lead entry, alongside a third whose exploit was rebuilt from the patch diff in four hours but whose confirmed exploitation followed six days later: CVE-2026-58231 in the SAP Commerce Cloud Data Hub Adapter, where Defused recorded the first honeypot hits three days after SAP's patch day and stated the flaw had no public proof-of-concept (BleepingComputer, 2026-08-14) and NCSC-NL published a national advisory recording active scanning (NCSC-NL, 2026-08-15); CVE-2026-55040 in SharePoint Server, where Rapid7's proof-of-concept was being replayed against honeypots the morning after publication, against a population of over 8,500 internet-reachable servers (BleepingComputer, 2026-08-12); and CVE-2026-65400 in the macOS Screen Sharing daemon, which NCSC-NL revised to record active abuse on internet-reachable port-5900 systems where "In al deze gevallen was root toegang verkregen op het getroffen systeem en een Monero crypto miner geplaatst" (NCSC-NL, 2026-08-12).
Five more moved on the exploitation axis on their own timelines. CVE-2026-20349 is the week's clearest edge item: Cisco disclosed it on 11 August stating its PSIRT had become aware of active exploitation that month, with one crafted HTTP request to the Remote Access SSL VPN reloading the device, no workaround and only per-train hot fixes (Cisco PSIRT, 2026-08-11); CISA added it the same day (CISA, 2026-08-11). CVE-2026-68820 was fixed in August's Microsoft updates as an exploitation-detected flaw, and Check Point's analysis records that "During the intrusion, the threat actor exploited CVE-2026-68820, a zero-day vulnerability in the Microsoft AFD.sys driver, to deploy a new version of FudModule, Lazarus' kernel-mode rootkit" (Check Point Research, 2026-08-11). CVE-2026-72898 is the Metabase zero-day this pipeline covered on 9 August when no identifier existed: it now carries CVSS 10.0 and entered the KEV catalogue on 11 August, which matters because a flaw with no CVE was invisible to every scanner and SBOM pipeline in the estate. CVE-2026-59310 in the VMware vCenter Syslog server, reported unexploited at disclosure on 29 July, was found by QUIRSO to have 361 unique victim IP addresses across 47 countries with first attacker contact on 3 August, concentrated in Germany, the United States, Turkey, Iran and France (The Hacker News, 2026-08-12). CVE-2026-71362 in Adobe Commerce is an unauthenticated customer-account takeover which Adobe's own bulletin records as needing no authentication, privileges or user interaction, and while stating in the same bulletin that it is not aware of any exploits in the wild (Adobe PSIRT, 2026-08-11); the exploitation signal is a forensics vendor's, which reviewed the patch and reports its own web application firewall already blocking attempts (Sansec Forensics Team, 2026-08-11).
One entry on this list is a status refinement rather than a new finding, and the distinction matters for planning: CVE-2026-45659 in SharePoint has been catalogued as exploited since 1 July and gained the catalogue's "Known" ransomware-campaign-use flag this week. Nothing about its exploitation changed; what changed is the expected outcome for an unpatched farm, which moves from data access toward encryption and extortion — a recovery-planning input, not a patch-priority one, since the fix has been available since May.
Exploited with no identifier, and unpatched. The GeoServer jsonArrayContains SQL injection is the week's hardest case for any CVE-keyed process: disclosed by a researcher on 12 August with no CVE assigned and no vendor patch available, it drew "hundreds of attempts originating from a small number of source IP addresses" within hours per watchTowr (SecurityWeek, 2026-08-14). GeoServer underpins public-sector geoportals and INSPIRE spatial-data services across Europe, and Switzerland's NCSC issued its own advisory on 14 August; with no patch, exposure reduction is the entire remediation.
The critical tail. Two unauthenticated CVSS 10.0 flaws landed on industrial edge devices and neither is reported exploited. Siemens ProductCERT disclosed CVE-2026-58115, where SIMATIC IoT2050 Advanced devices running Industrial OS with Node-RED installed do not enforce authentication on the Node-RED HTTP interface, exposing programming nodes capable of running system commands as root (Siemens ProductCERT, 2026-08-11); CISA's ICS advisory for CVE-2026-19188 covers a command injection in the Haiwell IoT Cloud HMI Gateway's diagnostic ping endpoint reaching root without credentials, in a product CISA reports deployed in energy, critical manufacturing and water and wastewater and assesses automatable. Alongside them, this week's disclosures left eight flaws with no fix in existence: the ShieldBreak bypass of Microsoft's July Defender fix, the three FreeBSD CTL HA pre-authentication kernel primitives behind TCP/999, the GeoServer injection, and three of the five NatJack NAT primitives. The NetScaler pair is the week's most consequential reclassification rather than a new flaw — watchTowr's published chain shows CVE-2026-8452 reaching a pre-authentication root shell rather than the availability issue its public description suggested, and NCSC-CH has carried the sibling CVE-2026-8451 as actively exploited with a public proof-of-concept since 3 July.
First exploitation attempts against CVE-2026-58231 (unauth RCE in SAP Commerce Cloud, CVSS 10.0) is now hitting our honeypots - 3 days after patch day
In al deze gevallen was root toegang verkregen op het getroffen systeem en een Monero crypto miner geplaatst.
During the intrusion, the threat actor exploited CVE-2026-68820, a zero-day vulnerability in the Microsoft AFD.sys driver, to deploy a new version of FudModule, Lazarus’ kernel-mode rootkit.
ATT&CK mapping
6 techniques mapped from the cited reporting · MITRE ATT&CK v19.2
Initial Access TA0001
T1078Valid Accounts
Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.
T1190Exploit Public-Facing Application
Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.
Persistence TA0003
T1078Valid Accounts
Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.
Privilege Escalation TA0004
T1068Exploitation for Privilege Escalation
Adversaries may exploit software vulnerabilities in an attempt to elevate privileges. Exploitation of a software vulnerability occurs when an adversary takes advantage of a programming error in a program, service, or within the operating system software or kernel itself to execute adversary-controlled code. Security constructs such as permission levels will often hinder access to information and use of certain techniques, so adversaries will likely need to perform privilege escalation to include use of software exploitation to circumvent those restrictions.
T1078Valid Accounts
Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.
Stealth TA0005
T1078Valid Accounts
Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.
Credential Access TA0006
T1606Forge Web Credentials
Adversaries may forge credential materials that can be used to gain access to web applications or Internet services. Web applications and services (hosted in cloud SaaS environments or on-premise servers) often use session cookies, tokens, or other materials to authenticate and authorize user access.
Impact TA0040
T1496Resource Hijacking
Adversaries may leverage the resources of co-opted systems to complete resource-intensive tasks, which may impact system and/or hosted service availability.
T1499.004Endpoint Denial of Service: Application or System Exploitation
Adversaries may exploit software vulnerabilities that can cause an application or system to crash and deny availability to users. Some systems may automatically restart critical applications and services when crashes occur, but they can likely be re-exploited to cause a persistent denial of service (DoS) condition.
Sources
AI-generated · no human review · this permalink is the shareable record for the finding · verify operationally critical claims against the linked primary source.