Latest cyber news, threats, security, and guidelines. Stack up.

Vulnerabilities

Wed 19 Aug

NetScaler ADC/Gateway CVE-2026-19490 on CISA KEV (due 2026-09-12); exploited since 3 Sep

Cloud Software Group bulletin CTX696939 (19 August 2026, Critical) covers an authentication bypass using an alternate path in customer-managed NetScaler ADC and NetScaler Gateway. CVSS v4.0 9.3. It applies when the appliance is a Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or an AAA virtual server; on some later 14.1/13.1 builds only when a SAML action is also configured. Not Citrix-managed cloud. No workaround. Patch to 14.1-73.32, 13.1-63.21, 14.1-73.32 FIPS, or 13.1-37.277 FIPS/NDcPP, as applicable. Secure Private Access Hybrid using customer-managed NetScaler also needs those builds. BleepingComputer (4 September 2026) reports Previdian honeypot sensors saw requests matching a public PoC on 3 September from three source IPs geolocated to Australia, the United States and Germany — evidence of exploitation attempts, not confirmed successful compromise of production systems. The Centre for Cybersecurity Belgium also warned of exploitation attempts the same week. Citrix’s August bulletin had not yet flagged active exploitation. WA SOC advisory 20260907003 (7 September 2026, TLP:CLEAR) covers CVE-2026-19490 at CVSS 9.3 for the same build floors, and reports no exploitation on Western Australian Government networks at the time of writing. Distinct from CVE-2026-8452 on this desk. NEW 9–10 September 2026: CISA added CVE-2026-19490 to the Known Exploited Vulnerabilities catalog on 9 September 2026 (due 12 September 2026 for FCEB under BOD 26-04, including forensic triage requirements). SecurityWeek (10 September) summarises ongoing exploitation since at least 3 September after a public PoC, matching earlier Previdian sensor notes. Patch floors unchanged: 14.1-73.32 / 13.1-63.21 and FIPS mates.

Citrix CTX696939

vulnerabilities network australia

Vulnerabilities

Wed 19 Aug

NetScaler ADC/Gateway memory overflow (CVE-2026-19489)

Same CTX696939 bulletin: memory overflow that can cause unpredictable behaviour or denial of service when SIP ALG is enabled on a Large Scale NAT (LSN) group. CVSS v4.0 8.8. Customer-managed NetScaler ADC and Gateway only. No workaround. Same patched builds as CVE-2026-19490: 14.1-73.32, 13.1-63.21, 14.1-73.32 FIPS, or 13.1-37.277 FIPS/NDcPP. Distinct from the earlier CVE-2026-8452 memory-overflow card.

Citrix CTX696939

vulnerabilities network

Vulnerabilities

Wed 19 Aug

N-able N-central authentication bypass, exploited in Australia

CVE-2026-18556 and CVE-2026-18577 are authentication-bypass issues in N-able N-central that may allow unauthorised access through an alternate path. ASD's ACSC has observed targeting of the product in Australia. Affects current versions including 2026.3. Vendor Hotfix 2 (build 2026.3.1.10, 6 August 2026) supersedes Hotfix 1. Review whether the console needs to face the internet.

ASD's ACSC advisory

vulnerabilities australia

Vulnerabilities

Wed 19 Aug

MLflow server-side request forgery (CVE-2026-64849)

CISA added CVE-2026-64849 to KEV on 19 August 2026. MLflow contains an SSRF issue that can let attackers reach internal or cloud metadata services. The CVE record states the issue is fixed in 3.15.0. Do not expose MLflow tracking servers to untrusted networks.

CVE record

tech ai

Vulnerabilities

Tue 18 Aug

Oracle August 2026 CSPU: 943 patches, including WebLogic 9.8 and OID 10.0

Oracle's 18 August 2026 Critical Security Patch Update (revision 3 on 27 August) contains 943 new security patches. Oracle says it continues to receive reports of attempts to exploit already-patched issues where customers had not applied available updates. Fusion Middleware includes unauthenticated WebLogic Server Core issues CVE-2026-60698 (IIOP, 9.8), CVE-2026-60672 and CVE-2026-60696 (T3/IIOP, 9.8) on 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0, plus CVE-2026-60977 (RMI, 9.8) on 12.2.1.4.0, 14.1.1.0.0 and 14.1.2.0.0, and Oracle Internet Directory LDAP Server CVE-2026-61241 at 10.0 on 12.2.1.4.0 and 14.1.2.1.0. Database Server includes adjacent-network Portable Clusterware issues CVE-2026-71063 and CVE-2026-71064 at 9.6. Apply the August 2026 CSPU for each product family you run. This is separate from CVE-2026-21962 (January 2026 CPU, later added to CISA KEV).

Oracle CSPU August 2026

vulnerabilities cloud

Vulnerabilities

Tue 18 Aug

VMware vCenter Syslog path traversal RCE (CVE-2026-59310); CVSS 9.8 — CISA KEV ransomware Known

Broadcom VMSA-2026-0006 (29 July 2026; updated 19 August) covers CVE-2026-59310, a Critical directory-traversal flaw in the VMware vCenter Syslog server. A malicious actor with network access to vCenter can execute arbitrary code; Broadcom rates maximum CVSSv3 9.8; NVD CVSS 3.1 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). No workarounds — apply fixed builds per the VMSA response matrix / FAQ (brcm.tech/vmsa-2026-0006). CISA added the CVE to KEV on 18 August 2026 (FCEB due 21 August) after QUIRSO reported 361+ compromised IPs across 47 countries with reverse-SSH persistence. UPDATE 15 September 2026 (BleepingComputer; CISA KEV catalog field knownRansomwareCampaignUse=Known): CISA now flags the flaw as used in ransomware campaigns; Shadowserver still tracks 450+ internet-exposed vCenter instances. Treat unpatched vCenter as emergency. Primary: Broadcom VMSA-2026-0006; CISA KEV; wire: BleepingComputer 15 Sep.

Broadcom VMSA-2026-0006 — vCenter Syslog path traversal (CVE-2026-59310)

vulnerabilities cloud network

Vulnerabilities

Tue 18 Aug

Microsoft SharePoint weak authentication (CVE-2026-55040)

Weak authentication in on-premises Microsoft SharePoint (CVE-2026-55040) lets an unauthorised attacker bypass a security feature over the network. CISA added it to KEV on 18 August 2026 after evidence of active exploitation. NVD scores it 9.1 (CVSS 3.1). It is the auth-bypass half of an unauthenticated RCE chain with August's CVE-2026-63520 (Business Connectivity Services RCE). Apply the July/August SharePoint security updates for Subscription Edition, 2019 and 2016, and keep farms off the public internet unless required.

Microsoft MSRC (CVE-2026-55040)

vulnerabilities

Vulnerabilities

Tue 18 Aug

Microsoft IKE Service Extensions double-free (CVE-2026-33824)

CISA added CVE-2026-33824 to the Known Exploited Vulnerabilities catalog on 18 August 2026: a double-free in Microsoft Internet Key Exchange (IKE) Service Extensions. Treat internet-reachable IKE as known-exploited and apply Microsoft's update.

NVD

vulnerabilities

Vulnerabilities

Tue 18 Aug

Zabbix 7.4 hardcoded frontend session key (CVE-2026-23933)

Zabbix's 18 August 2026 advisory (ZBX-28071) says that in Zabbix 7.4 the cryptographic key used for signing frontend sessions was erroneously written to the database seed. The only known exploitation scenario is deployments that use both SAML authentication and guest users: the key can be used to forge valid session cookies and gain unauthorised frontend access. Other deployments have no known impact. Affected: 7.4.0 through 7.4.10. Fixed: 7.4.11. Vendor CVSS 4.0 is 7.7 (High). Workaround: clear settings.session_key in the Zabbix database so the frontend generates a new random key. Zabbix credited Daniel Shemesh and Or Ida via HackerOne. Not in CISA KEV at last check.

Zabbix ZBX-28071

vulnerabilities

Vulnerabilities

Mon 17 Aug

Red Hat Build of Keycloak account takeover via password-reset bypass (CVE-2026-18963)

Red Hat's 17 August 2026 CVE record (threat severity Critical, CVSS 3.1 9.1) describes a reset-credentials flaw in keycloak-services for Red Hat Build of Keycloak. An unauthenticated remote attacker can force password reset for any user without the email verification step and set new credentials, taking over the account. Temporary mitigation if you cannot patch yet: turn Forgot password off for every realm (Realm settings → Login). Fixed packages include Keycloak 26.4 builds at or after rhbk/keycloak-operator-bundle 26.4.15-1 / keycloak-rhel9 26.4-23 (RHSA-2026:56519 / 56520) and 26.6 builds at or after 26.6.6-1 / 26.6-12 (RHSA-2026:56523 / 56524). Red Hat marks Red Hat Single Sign-On 7 and JBoss EAP Expansion Pack as not affected. No in-the-wild exploitation stated on the Red Hat CVE page at last check.

Red Hat CVE-2026-18963

vulnerabilities identity

Vulnerabilities

Mon 17 Aug

Ray AI compute engine code injection (CVE-2025-62593)

Ray is an AI compute engine. CISA added CVE-2025-62593 to KEV on 17 August 2026. The GitHub advisory and NVD describe a code-injection issue in versions before 2.52.0. Patch to 2.52.0. Do not expose developer Ray services to untrusted networks.

Ray advisory

tech ai

Vulnerabilities

Mon 17 Aug

Apple iOS 26.6.1 / macOS Tahoe 26.6.2 security content (17 Aug 2026)

Apple released iOS 26.6.1 and iPadOS 26.6.1 and macOS Tahoe 26.6.2 on 17 August 2026 (security-content pages published 20 August). The iOS advisory includes ImageIO integer overflow CVE-2026-65346, where processing an image may lead to arbitrary code execution; Telephony CVE-2026-65329, where an attacker in a privileged network position may be able to bypass IPSec authentication and intercept network traffic (iPhone 11 and later); Kernel use-after-free CVE-2026-65343 (remote unexpected system termination); and multiple WebKit memory-safety issues. Apple does not publish CVSS scores on that page. Safari 26.6.1 followed on 18 August for macOS Sonoma and Sequoia. This is separate from CVE-2026-65400 (macOS Screen Sharing), which CISA added to KEV on 18 August.

Apple: iOS 26.6.1 and iPadOS 26.6.1 security content

vulnerabilities