Latest cyber news, threats, security, and guidelines. Stack up.

Vulnerabilities

Wed 26 Aug

ILIAS unauth PHP object injection RCE via Shibboleth logout (CVE-2026-80428); public exploit

CVE-2026-80428 is an unauthenticated PHP object injection in ILIAS LMS (before 9.22 / 10.10 / 11.3). NVD: attackers inject serialized objects through the LTI authentication endpoint into session storage, then trigger unrestricted deserialization via the auth-exempt Shibboleth back-channel logout endpoint (SoapServer LogoutNotification), chaining a GuzzleHttp FileCookieJar POP gadget to write attacker-controlled PHP to a web-accessible path and achieve RCE as the web server user. CVSS 3.1 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H); CVSS 4.0 9.3 Critical (VulnCheck). Fixed in ILIAS 9.22, 10.10 and 11.3 (vendor docu advisories linked from NVD). NEW 11 September 2026: Exploit-DB 52682 publishes a remote exploit (DigiProSec) for the chain; notes v9/v10 exploitable as packaged, v11.x packaged shib_logout.php may not reach the vulnerable path. Category tech (LMS stack). No Australian exploitation reports on this pass. Primary: NVD/CVE; vendor: ILIAS docu; wire: Exploit-DB.

NVD — CVE-2026-80428

tech cloud

Vulnerabilities

Wed 26 Aug

Citrix NetScaler ADC/Gateway memory overflow (CVE-2026-8452)

CISA added CVE-2026-8452 to KEV on 26 August 2026 (federal due date 29 August 2026). NVD describes a memory-overflow issue in NetScaler ADC and NetScaler Gateway that can cause unpredictable behaviour and denial of service when the appliance is configured as a Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server. Apply the fixed builds in Citrix bulletin CTX696604. This desk does not invent build numbers the bulletin page would not yield over a plain fetch.

Citrix CTX696604

vulnerabilities network

Vulnerabilities

Wed 26 Aug

Microsoft SQL Server remote code execution (CVE-2019-1068)

CISA added CVE-2019-1068 to KEV on 26 August 2026 (federal due date 29 August 2026). NVD: a remote code execution issue when SQL Server incorrectly handles processing of internal functions. Apply the Microsoft security update from the MSRC advisory. Do not invent a cumulative update number here.

Microsoft MSRC

vulnerabilities

Vulnerabilities

Tue 25 Aug

All-in-One WP Migration ≤7.109: second-order SQLi to RCE (CVE-2026-19949)

Wordfence (CNA) published CVE-2026-19949 for ServMask's All-in-One WP Migration and Backup WordPress plugin: unauthenticated second-order SQL injection in archive restore through 7.109. Jack Taylor reported it; Wordfence notified ServMask on 15 August 2026; fixed in 7.110 on 20 August 2026; CVE disclosed about 25 August. Incorrect parsing of escaped backslashes and quotes while rewriting database content lets an attacker plant SQL via trackbacks that runs when an admin restores a backup — core plugin use. Injected SQL can leak ai1wm_secret_key (e.g. via a public comment), then import a malicious .wpress archive for code execution and site takeover. Wordfence/BleepingComputer (2 September) cite about five million active installs and roughly 35% on the fixed build (~3.25 million still vulnerable). CVSS 3.1 8.8 High (Wordfence CNA). Patch to 7.110 or later; treat dormant installs that may be reactivated as in-scope.

Wordfence CVE-2026-19949 (CNA)

vulnerabilities cloud

Vulnerabilities

Tue 25 Aug

Chrome 152 Critical sandbox-escape flaws (CVE-2026-79290, CVE-2026-79282)

Google's Stable Channel Update for Desktop (25 August 2026) promotes Chrome 152 and ships 152.0.7977.64 on Linux and 152.0.7977.64/.65 on Windows and Mac. Among Critical fixes, CVE-2026-79290 is a use-after-free in Aura that Google rates Critical and says can let a remote attacker run code outside the browser sandbox via a crafted HTML page (fixed prior to 152.0.7977.65). CVE-2026-79282 is a Critical use-after-free in ANGLE (reported by Goodluck). WA SOC shared advisory 20260831001 (31 August, TLP:CLEAR) points operators at this Chrome update for Windows, macOS and Linux prior to 152.0.7977.65, rates the Critical issues CVSS 9.6, and says it has not received reports of exploitation on Western Australian Government networks at the time of writing. WASOC's advisory table display text for the second CVE does not match its NVD href (CVE-2026-79282); this card follows the Google release notes and that href. Patch promptly to the fixed Chrome 152 builds.

Chrome Releases (25 Aug 2026)

vulnerabilities australia

Vulnerabilities

Tue 25 Aug

Veeam ONE SMB authentication coercion (CVE-2026-65641)

Veeam KB4905 (published 25 August 2026) documents CVE-2026-65641: an unauthenticated network attacker can coerce SMB authentication from the Veeam ONE service account. Vendor severity Critical, CVSS 4.0 score 9.3 (vector AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:H/SI:L/SA:L), reported via HackerOne. Affected: Veeam ONE 13.1.0.7034 and all earlier version 13 builds. Veeam states older 12.x builds are not affected. Fixed in Veeam ONE 13.1 Patch 0 (build 13.1.0.7233) and Veeam ONE 13.0.2 Patch 1 (build 13.0.2.7159). WA SOC shared advisory 20260828001 pointed operators at this class of issue. Patch promptly; Veeam notes attackers often reverse-engineer disclosed patches.

Veeam KB4905

vulnerabilities australia network cloud

Vulnerabilities

Tue 25 Aug

Gitea CVE-2026-60004: Red Heron campaign compromises 13 orgs (Acronis TRU)

Gitea GHSA-rcr6-4jqh-j84m / CVE-2026-60004 (28 July 2026 advisory; CISA KEV 25 August 2026): diffpatch API can let a user with repository write access (including self-registered users on open instances) run commands as the Gitea service account. Affected 1.17 through versions before 1.27.1; patch to 1.27.1+. UPDATE 14 September 2026: The Hacker News cites Acronis Threat Research Unit attributing a China-linked cluster (moderate confidence) tracked as Red Heron that weaponised CVE-2026-60004 from ~29 July 2026, scanning 1,386 Gitea instances across seven countries (plus a 477-instance Taiwan dataset) and confirming compromises at 13 organisations in Canada (2), Argentina (1), Taiwan (4), the US (4), Qatar (1), and Sri Lanka (1). Campaign progressed from repository theft to credentials, persistence, and lateral movement (including root on a three-node Proxmox cluster). Tooling includes C++ Linux implant JITTERLY (30+ commands; overlaps AdaptixC2) and LD_PRELOAD rootkit SIXZUT. Primary remains Gitea advisory; secondary: THN / Acronis TRU reporting. Distinct from generic KEV listing alone.

Gitea advisory GHSA-rcr6-4jqh-j84m / CVE-2026-60004

vulnerabilities source control

Vulnerabilities

Mon 24 Aug

TeamCity On-Premises unauthenticated RCE (CVE-2026-63077), exploited in Australia

Unauthenticated remote code execution in JetBrains TeamCity On-Premises via the agent polling protocol. ASD's ACSC observed active exploitation against On-Premises servers in Australia. All On-Premises versions are affected. TeamCity Cloud is not. Patch to 2025.11.7 or 2026.1.3, or apply the vendor security patch plugin if you cannot upgrade.

ASD's ACSC advisory

vulnerabilities australia

Vulnerabilities

Mon 24 Aug

Zscaler Client Connector unauthenticated RCE (CVE-2026-59568)

Zscaler's 24 August 2026 CVE record describes multiple Client Connector flaws that allow remote code execution, giving an unauthenticated, unprivileged user the ability to execute arbitrary code in the ZCC context. Zscaler scored it 9.1 (CVSS 3.1). The CNA points administrators to the 2026 Client Connector app release summary for fixed builds. Affected version strings in that record include Windows before 4.6.0.457 / 4.7.0.317 / 4.8.0.232 / 4.9.0.372, macOS before 4.5.2.312 / 4.7.0.292 / 4.8.0.191, Linux before 3.7.2.64 / 4.2.1.64, Android and ChromeOS before 4.2, and iOS before 4.5.1. Confirm the exact build from the vendor release summary before declaring a fleet patched. Zscaler's release summary also lists CVE-2026-59564 (auth bypass to the portal), CVE-2026-59567 (local privilege escalation) and CVE-2026-59565 (local/kernel denial of service). Not in CISA KEV at last check.

CVE-2026-59568 (Zscaler CNA)

vulnerabilities network cloud

Vulnerabilities

Mon 24 Aug

Oracle HTTP Server / WebLogic proxy plug-in access control (CVE-2026-21962)

Oracle Critical Patch Update (January 2026) lists CVE-2026-21962 in Oracle HTTP Server and Oracle WebLogic Server Proxy Plug-in for Apache HTTP Server and IIS. Supported affected versions: 12.2.1.4.0, 14.1.1.0.0, and 14.1.2.0.0. NVD rates CVSS 10.0. Unauthenticated network access via HTTP. Apply the January 2026 CPU for the plug-in builds you run.

Oracle CPU January 2026

vulnerabilities

Vulnerabilities

Fri 21 Aug

Zimbra Collaboration Suite SNMP command injection (CVE-2026-73570)

Unauthenticated OS command injection in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp package is installed and SNMP notifications are enabled. NVD: crafted SMTP requests can run commands as the zimbra user. CERT Polska reported active exploitation. Patch to 10.1.20. If you cannot upgrade, remove zimbra-snmp / disable snmp_notify and hunt per CERT Polska.

Zimbra Security Advisories

vulnerabilities email

Vulnerabilities

Thu 20 Aug

TrueConf Server missing authentication on port 4307 (CVE-2026-72529)

Kaspersky ICS CERT (KLCERT-26-057): an unauthenticated attacker with network access to TrueConf Server on TCP 4307 can call an undocumented function and run an arbitrary script. Affects 5.3.x before 5.3.9, 5.4.x before 5.4.9, 5.5.x before 5.5.5, and earlier than 5.3. NVD CVSS 9.8. Related CVE-2026-72530 is a code-injection issue in the same product line. Patch to the fixed builds and do not expose 4307 to the internet.

Kaspersky ICS CERT KLCERT-26-057

vulnerabilities