Latest cyber news, threats, security, and guidelines. Stack up.

Vulnerabilities

Fri 14 Aug

Microsoft Defender ShieldBreak (CVE-2026-69414) patched Sep 2026; ShieldCrash incomplete-fix PoC

Microsoft Security Update Guide CVE-2026-69414 is an elevation of privilege in the Microsoft Malware Protection Engine (ShieldBreak): CVSS 3.1 base 7.8 (AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H), Important. August reporting described a public local PoC to SYSTEM when Defender is enabled, including as a bypass of RoguePlanet (CVE-2026-50656). BleepingComputer (9 September 2026) says Microsoft shipped a ShieldBreak fix in the September 2026 Patch Tuesday set, and that researcher Nightmare Eclipse then released a "ShieldCrash" proof-of-concept claiming the patch is incomplete under specific conditions — arbitrary file read as SYSTEM on fully patched Windows 10/11/Server, without write access in the published skeleton PoC. Treat ShieldCrash as secondary researcher claim until MSRC documents a new CVE or revises 69414. Watch MSRC for engine build requirements; do not equate a public PoC with confirmed in-the-wild exploitation.

Microsoft Security Update Guide (CVE-2026-69414)

vulnerabilities microsoft endpoint cloud identity

Vulnerabilities

Thu 13 Aug

PostgreSQL logical decoding PostGREShell (CVE-2026-6471): REPLICATION role to arbitrary dlopen/RCE

PostgreSQL's own security page for CVE-2026-6471 (fix published 13 August 2026) describes missing authorisation in logical decoding: a non-superuser with REPLICATION privilege can cause the server to dlopen any file visible to the OS account running PostgreSQL by choosing the logical decoding plugin path, which runs arbitrary code as that account. Affected before 18.6, 17.11, 16.15, 15.19, and 14.24; fixed in those builds. Vendor CVSS 3.0 is 7.2 (AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H). Cyera's PostGREShell research (covered by SecurityWeek on 4 September 2026) explains how replication-protocol plugin loading can be abused for RCE, privilege escalation and persistence when REPLICATION is granted to backup or monitoring accounts. Inventory roles with REPLICATION, patch to the fixed minor releases, and do not treat REPLICATION as a low-privilege convenience grant.

PostgreSQL CVE-2026-6471 (fix 13 Aug 2026)

vulnerabilities cloud

Vulnerabilities

Wed 12 Aug

WordPress 7.0.4: authenticated Imagick/Ghostscript upload RCE (CVE-2026-65640)

WordPress 7.0.4 (12 August 2026) is a security release. An Author or anyone with upload_files can upload a malicious PostScript file and reach remote code execution, but only where Imagick and Ghostscript are both in use. WordPress credits pwn.ai. GitHub advisory GHSA-8vr3-7mxf-gx8w scores it 8.8 (CVSS 3.0). Fixed in 7.0.4, with backports through the 4.7 branch (6.9.7, 6.8.8, and the matching older branch builds). No exploitation claim on the WordPress or GitHub notices.

WordPress 7.0.4 release

vulnerabilities cloud

Vulnerabilities

Wed 12 Aug

Palo Alto GlobalProtect local privilege escalation (CVE-2026-0299)

Palo Alto Networks 12 August 2026 advisory: local privilege-escalation bugs in the GlobalProtect app let a local user reach NT AUTHORITY\SYSTEM on Windows and root on macOS and Linux, then run commands with administrative privileges. iOS, Android and Chrome OS are not affected. Vendor CVSS-BT is 5.9 (CVSS 4.0); the same advisory lists CVSS-B 8.5 without the exploit-maturity modifier. Palo Alto Networks says it is not aware of malicious exploitation. Same-day GlobalProtect app advisories cover CVE-2026-0295 (macOS race-condition LPE, CVSS-BT 4.1), CVE-2026-0296 (certificate-validation bypass of app traffic, not the VPN tunnel, CVSS-BT 4.5), CVE-2026-0297 (UDP tunnel handshake buffer overflow, CVSS-BT 5.2) and CVE-2026-0298 (Windows PLAP MitM code execution, CVSS-BT 5.2 / CVSS-B 7.7). Those sibling advisories show Updated 2026-09-12 on the PSIRT hub; Palo Alto Networks still says it is not aware of malicious exploitation. PAN-OS URL Filtering information disclosure CVE-2026-0301 (CVSS 1.7) was also published 12 August. Prisma Access Agent LPE CVE-2026-0294 (CVSS-BT 6.0; patch 26.3+) remains a related same-day PSIRT item.

Palo Alto Networks PSIRT (CVE-2026-0299)

vulnerabilities network

Vulnerabilities

Tue 11 Aug

Microsoft Exchange CVE-2026-62911 auth bypass; ~22k internet-exposed hosts still unpatched

Microsoft patched CVE-2026-62911 in the August 2026 Patch Tuesday cycle: authentication bypass by capture-replay in Exchange Server that lets an authorised attacker elevate privileges over the network and take over user mailboxes (send, read, download attachments). Affected products named in coverage include Exchange Server 2016, 2019 and Subscription Edition. On 1 September 2026 BleepingComputer reported Shadowserver observing 21,899 internet-exposed Exchange fingerprints still unpatched (largest counts in the United States and Germany), and relayed NCSC-NL guidance that exploit code is available and that Exchange 2016/2019 security updates require the Extended Security Updates programme. Germany's BSI separately warned that a large share of on-premises Exchange in Germany remained vulnerable. This desk has not seen a CISA KEV listing for CVE-2026-62911 at write-up. NEW 8 Sep AU: iTnews cites Shadowserver counts of 382 Australian and 56 New Zealand Exchange hosts still vulnerable as of 31 August 2026; NCSC-NL (28 Aug) said public PoC exists and warned unauthenticated attackers could potentially achieve arbitrary code execution; ASD urges patching or network segmentation for legacy Exchange; coverage rates CVSS 3.1 as 8.0. Patch promptly; do not leave legacy Exchange on the public internet.

Microsoft MSRC (CVE-2026-62911)

vulnerabilities australia

Vulnerabilities

Tue 11 Aug

Microsoft SharePoint Server remote code execution (CVE-2026-63520)

Microsoft's 11 August 2026 Patch Tuesday fix (MSRC CVE-2026-63520) addresses improper input validation in on-premises SharePoint that lets an unauthorised attacker execute code over the network. NVD scores it 8.1 (CVSS 3.1, High, attack complexity High). Rapid7, which co-disclosed with Microsoft, says the bug is unsafe .NET type instantiation in Business Connectivity Services and that chaining it with the July auth bypass CVE-2026-55040 yields unauthenticated RCE. August security updates cover SharePoint Server Subscription Edition (KB5002893), SharePoint Server 2019 (KB5002894 / KB5002896), and SharePoint Enterprise Server 2016 (KB5002905 / KB5002906). Public PoC material for the RCE half appeared around 24 August; Defused later reported honeypot probes of the 55040+63520 chain (JWT bypass exercised, BCS probing, no code execution observed in that report). Microsoft had not labelled 63520 as exploited in the wild at last magazine check. Prefer the August updates; do not leave on-prem SharePoint internet-facing without need.

Microsoft MSRC (CVE-2026-63520)

vulnerabilities

Vulnerabilities

Tue 11 Aug

Windows WinSock AFD elevation of privilege (CVE-2026-68820), exploited

Microsoft's 11 August 2026 security update for CVE-2026-68820 fixes a use-after-free in the Windows Ancillary Function Driver for WinSock. A locally authenticated attacker who wins a race with a crafted application can elevate to SYSTEM. Microsoft rates it Important, CVSS 3.1 7.0 (AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H), and marks Exploitation Detected. CISA added it to the Known Exploited Vulnerabilities catalog on 11 August 2026 with the same-day Cisco ASA/FTD and Metabase KEV batch. Apply the August 2026 cumulative update for your Windows build and reboot so the kernel driver replacement takes effect. Distinct from SharePoint CVE-2026-55040 already on this desk.

Microsoft MSRC (CVE-2026-68820)

vulnerabilities identity

Vulnerabilities

Tue 11 Aug

Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) (CVE-2026-20349)

Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) Heap Inspection Vulnerability. Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) contain a heap inspection vulnerability that could allow an unauthenticated, remote attacker to cause the device to reload unexpectedly, resulting in a denial of service (DoS) condition. Apply vendor mitigations. Check the NVD record and the vendor advisory for affected versions and the patch.

NVD

vulnerabilities network

Vulnerabilities

Fri 7 Aug

Progress LoadMaster (CVE-2026-8037)

Progress LoadMaster Command Injection Vulnerability. Progress LoadMaster contains a command injection vulnerability that allows an un-authenticated attacker to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in multiple command endpoints. Apply vendor mitigations. Check the NVD record and the vendor advisory for affected versions and the patch.

NVD

vulnerabilities network

Vulnerabilities

Thu 6 Aug

Apple macOS Screen Sharing authentication bypass (CVE-2026-65400), exploited

Apple's 6 August 2026 security content for macOS Tahoe 26.6.1 (and matching Sequoia/Sonoma notes) says an authentication issue in Screen Sharing was addressed with improved state management. Impact: an attacker on the network may be able to authenticate to Screen Sharing without valid credentials. Fixed in macOS Tahoe 26.6.1, macOS Sequoia 15.7.9 and macOS Sonoma 14.8.9. CISA added the CVE to KEV on 18 August 2026 (due 21 August for federal agencies under BOD 26-04) and CISA-ADP rates CVSS 3.1 9.8. Apply the Apple builds above; if Screen Sharing is not required, disable it and keep TCP 5900 off the public internet. Distinct from the 17 August iOS/macOS content card already on this desk.

Apple: macOS Tahoe 26.6.1 security content

vulnerabilities identity

Vulnerabilities

Thu 6 Aug

Metabase unauth SQLi to admin (CVE-2026-72898); CVSS 10.0; exploited in the wild

Metabase GHSA-vwf4-m7j8-wcjf (published 6 August 2026; CVE-2026-72898) is an unauthenticated SQL injection on /api/session/reset_password that lets a remote attacker inject SQL into the Metabase application database and obtain administrator access, then steal connected-database credentials and export data. CVSS 3.1 10.0 (AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H). Metabase confirmed active exploitation. Affected OSS lines include ≥0.58.0 before the patched builds; fixed releases are 0.58.24, 0.59.21, 0.60.17, 0.61.11, 0.62.9 and 0.63.5 (Enterprise 1.x counterparts on the same minors). Temporary workaround: block /api/session/reset_password. After upgrade on a previously exposed instance: delete core_session rows, review API keys and admin accounts, rotate connected-database credentials, and review warehouse and Metabase query history. This CVE is the Metabase flaw referenced in the Mathspace AU/NZ education breach and in third-party reporting on the ShipMonk/Trezor supply-chain incident. Primary: Metabase GitHub security advisory.

Metabase GHSA-vwf4-m7j8-wcjf

vulnerabilities cloud australia

Vulnerabilities

Tue 4 Aug

CyberArk / Idira: CA26-37 Privilege Cloud CPM and CA26-38 Secrets Manager

CyberArk (now Idira, the Palo Alto Networks identity security platform) published security bulletins CA26-37 and CA26-38. The public Technical Community notice, edited 4 August 2026, says CA26-37 is High severity and affects Privilege Cloud Central Policy Manager (CPM), all versions prior to 15.0, and CA26-38 is High severity and affects Secrets Manager, Self Hosted, version 13.9.0. Full technical detail sits behind the CyberArk/Idira Technical Community login. No CVE identifiers or CVSS vectors are in that public post. Idira is the May 2026 rebrand of CyberArk after the Palo Alto Networks acquisition; it is not a separate invented product. Confirm the exact patched builds from the logged-in bulletins before upgrading.

CyberArk/Idira security bulletin topic

vulnerabilities identity cloud