ctipilot.ch
← Back to Weekly 2026-W34
HIGHexploitedNATOA1vulnerability

2026-W34 vulnerability status roll-up — seven flaws crossed into reported exploitation this week; six were catalogue listings against fixes that had existed for weeks or months, and the seventh went from out-of-band patch to exploitation in two days with no catalogue involved at all

discovered 2026-08-23 23:55 UTCrun 2026-08-23T2311Z-weekly15 sourcesmulti-source

Newly exploited or newly catalogued this week

Seven flaws crossed the line. Six of them share a property more instructive than any of them individually — all six already had a fix, and three had had one for a month or more — and the seventh, at the end of this list, is the exception that shows what the other six are missing.

  • CVE-2025-62593 — Ray. CISA catalogued it as exploited on 2026-08-17 (CISA KEV catalog v2026.08.21, 2026-08-21). The dashboard's only guard against browser-borne requests is a User-Agent prefix check that Firefox and Safari let a page overwrite, so with DNS rebinding a developer's own browser becomes the path into a cluster that was never internet-exposed. Fixed in Ray 2.52.0 — the first release to offer authentication at all, and it is off by default. First covered 2026-08-18.
  • CVE-2026-33824 — Windows IKE and AuthIP IPsec Keying Modules. Catalogued 2026-08-18, four months after the April cumulative updates carried the fix. Pre-authentication double free on UDP 500 and 4500, code execution in the Local System context. First covered 2026-08-10 as patched-but-not-exploited; that is the field that changed.
  • CVE-2026-55040 — Microsoft SharePoint Server. Catalogued 2026-08-18. Pre-authentication weak-authentication bypass allowing impersonation, patched in July for Subscription Edition, 2019 and Enterprise Server 2016. First covered 2026-08-13 as proof-of-concept-public on honeypot replay evidence. For this constituency it lands on an estate this pipeline has already covered two intrusions into — the Swiss federal IT provider BIT and canton Graubünden each disclosed an on-premises SharePoint breach in early August, and no source ties either to this identifier.
  • CVE-2026-64849 — MLflow. Catalogued 2026-08-19 with a 2026-09-02 remediation date. The webhook URL guard resolves the hostname, rejects non-public addresses at registration, then throws the answer away and follows redirects without re-validating — so one redirect turns an unauthenticated tracking server into a reader of its own cloud instance-metadata service. Fixed in MLflow 3.15.0. First covered 2026-08-20.
  • CVE-2026-73570 — Zimbra Collaboration. ENISA's database recorded it exploited since 2026-08-18, and CISA catalogued it on 2026-08-21 — after this pipeline's operational coverage, so this is a fresh delta for the week (CISA KEV catalog v2026.08.21, 2026-08-21). Pre-authentication command injection in the SNMP monitoring component reaching OS command execution as the Zimbra user; only where the optional zimbra-snmp package is installed and notifications are enabled. Fixed 2026-07-21 in ZCS 10.1.20 — a month before the identifier existed. First covered 2026-08-20.
  • CVE-2026-72529 and CVE-2026-72530 — TrueConf Server. Both catalogued 2026-08-20 (CISA KEV catalog v2026.08.21, 2026-08-21). Chained, they take an unauthenticated attacker from port 4307/TCP — open by default per the vendor's documentation — to command execution as SYSTEM. Fixed 2026-06-18 in 5.3.9, 5.4.9 and 5.5.5 — two months before the listing — by the coordinating CNA's account (Kaspersky ICS CERT, 2026-08-12); the same research places the operators' use of the chain from at least July 2026, and the referenced operational entry carries that detail with its own citation. First covered 2026-08-23.
  • CVE-2026-19478 — GitLab. Released outside the scheduled cadence on 2026-08-17 at CVSS 9.4, with the companion CSRF flaw CVE-2026-19650 at 7.1; an unauthenticated caller can modify or delete public projects and user data, every release line from 18.2 onward is affected, and GitLab.com and Dedicated were already patched, so the exposure is entirely self-managed instances (GitLab, 2026-08-17). Exploitation began roughly two days after public disclosure, per an attack-surface-management firm reported by SecurityWeek (SecurityWeek, 2026-08-20), and Switzerland's NCSC amended its own advisory on 2026-08-21 to change the recorded exploitation status from unknown to actively exploited, citing that coverage (NCSC-CH, 2026-08-21). Unlike the six above, no catalogue was involved and the fix was six days old — this is the one flaw on the week's list a normal patch queue would most plausibly still be holding.

Continuing exploitation

  • CVE-2026-12569 — PTC Windchill. Cl0p's extortion wave continues; the week's delta is a published reverse engineering of the custom implant rather than a change in exploitation status. Status detail in this week's long-running entry.
  • CVE-2026-72898 — Metabase. The exploited CVSS 10.0 password-reset SQL injection is unchanged; the delta is the downstream count, now nine publicly confirmed organisations reached through credentials the compromised instances held.
  • GeoServer jsonArrayContains SQL injection — still no CVE. Exploited since before it had a fix; GeoServer 3.0.1, 2.28.5 and 2.27.6 shipped on 2026-08-14, which the project calls an urgent update for production systems (GeoServer project, 2026-08-14), and Switzerland's NCSC appended the fixed versions to its own advisory on 2026-08-17 while still recording the flaw as actively exploited (NCSC-CH, 2026-08-17). The absence of an identifier keeps it invisible to a purely CVE-driven patch process.

Critical, no exploitation reported

  • CVE-2026-18963 — Keycloak, CVSS 9.1. The reset-credentials flow can be driven to completion without the verification email being clicked, yielding unauthenticated takeover of any account including administrators. Fixed 2026-08-18 in Red Hat build of Keycloak 26.4.15 and 26.6.6, and the two fixed streams are not equivalent: 26.6.6 closes five flaws, two of them further account-takeover and credential-disclosure paths on the same identity surface. A correction to this pipeline's coverage of 19 August belongs here. That entry recorded the keycloak-services component as Affected with no erratum in the JBoss Enterprise Application Platform Expansion Pack, and therefore part of the estate as having nothing to apply. Re-read this week, Red Hat's own product-state table for this CVE carries eleven Fixed rows and two Not-affected rows, and the Expansion Pack is one of the two — state "Not affected", justification "Component not Present"; Red Hat Single Sign-On 7 is the other, justified as vulnerable code not present (Red Hat Product Security, 2026-08-18). No Red Hat product is recorded as affected and unfixed. An estate that deferred this flaw on the basis of that earlier reading should treat it as fully patchable today.
  • CVE-2026-19490 — Citrix NetScaler ADC and Gateway, CVSS 9.3, with CVE-2026-19489 alongside it. The exposure boundary is wider than the headline: on 14.1-43.56 and 13.1-61.28 and later the bypass applies only where a SAML action is configured, but on earlier builds and 13.1 FIPS any Gateway or AAA virtual server configuration is enough (CERT-EU, 2026-08-19). Its exploitation status is itself contested: Switzerland's NCSC amended its advisory on 2026-08-21 to record the flaw as actively exploited, and the only supporting coverage it cites for that change is a single post on a social-media platform (NCSC-CH, 2026-08-21) — a basis this pipeline does not treat as establishing exploitation, so the flaw stays in this section with the divergence recorded.
  • Cisco Crosswork and Secure Workload — eight critical flaws, five of them at CVSS 10.0. Not previously covered by this pipeline and recovered by this week's review: CVE-2026-20030 (SQL injection in Crosswork applications), CVE-2026-20357 (missing authentication for a critical function in Crosswork), CVE-2026-20358 (external control of the file system in Crosswork), CVE-2026-20315 (improper access control in Secure Workload) and CVE-2026-20317 (improper authentication in Secure Workload) all carry CVSS 3.1 10.0; CVE-2026-20359 (insufficiently protected credentials) and CVE-2026-20231 (command injection) carry 9.9, and CVE-2026-20318 (path traversal) 9.6. Switzerland's NCSC relayed the two Cisco advisories on 2026-08-21, recording that successful exploitation lets unauthenticated remote attackers execute arbitrary commands, bypass authentication and gain full control over affected systems, with vendor patches available and exploitation status unknown (NCSC-CH, 2026-08-21). Affected are Crosswork Data Gateway, Crosswork Network Controller, Crosswork Planning and Secure Workload in both SaaS and on-premises deployments — network-management and workload-security platforms that sit above the estate they manage, which is what makes a 10.0 on them worth sequencing ahead of its score.
  • Oracle August 2026 Critical Security Patch Update — 943 patches, three of them unauthenticated CVSS 10.0 with Privileges Required and User Interaction both None: CVE-2026-61241 in the LDAP server of Oracle Internet Directory, and CVE-2026-70880 and CVE-2026-70921 in the Hyperion products (Oracle, 2026-08-18).
  • Two WordPress plugin flaws at CVSS 9.8 — CVE-2026-15748 in Forminator Forms (600,000+ installs, unauthenticated arbitrary file upload to code execution, fixed 1.56.2) and CVE-2026-15826 in User Profile Builder (40,000+ installs, a type coercion that logs an anonymous registrant in as user ID 1, fixed 3.16.5). Both were patched before their root causes went public, and both reached this pipeline through Switzerland's NCSC Cyber Security Hub bundle of 2026-08-18 (NCSC-CH, 2026-08-18).

No fix exists

  • CVE-2026-69414 — the ShieldBreak Defender privilege-escalation bypass. Microsoft acknowledged it, rated it Important at CVSS 7.8, records it publicly disclosed but not exploited, assesses exploitation as more likely, and states a security update is still being worked on (Microsoft Security Response Center, 2026-08-14). Switzerland's NCSC and France's CERT-FR both relayed the identifier on 2026-08-17.
  • The misp-stix trio (CVE-2026-77710, CVE-2026-77755, CVE-2026-77761). Disclosed 2026-08-21 against the library MISP and other platforms use to convert between MISP and STIX. No tagged release carries the fixes; remediation is individual commits. Directly relevant to anyone running an intelligence-ingestion pipeline, including this one.

ATT&CK mapping

1 technique mapped from the cited reporting · MITRE ATT&CK v19.2

Initial Access TA0001
T1190Exploit Public-Facing Application

Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.

overlap matrix · ATT&CK page ↗

PROVENANCE

AI-generated · no human review · this permalink is the shareable record for the finding · verify operationally critical claims against the linked primary source.