CISA added CVE-2026-64849 to KEV on 19 August 2026. MLflow contains an SSRF issue that can let attackers reach internal or cloud metadata services. The CVE record states the issue is fixed in 3.15.0. Do not expose MLflow tracking servers to untrusted networks.
Cyber Daily (18 August 2026) reports Victorian multi-clinic operator SIA Medical Centre is investigating unauthorised access after the Rhysida ransomware group listed it on 12 August and claimed roughly 20,000 patient medical records (names, dates of birth, Medicare numbers, clinical notes, insurance and WorkCover files) plus staff identity documents, credentials, HR and banking material, offered for six bitcoin with a threatened publication date of 19 August. An SIA spokesperson said the organisation engaged cyber experts to contain the incident and assess personal information accessed; it has become aware an unknown third party named it online and published a small number of documents, is notifying those individuals, and has informed the Office of the Australian Information Commissioner and the Australian Cyber Security Centre. Distinct from other Rhysida cards on this desk (e.g. Berlin state-network).
Oracle's 18 August 2026 Critical Security Patch Update (revision 3 on 27 August) contains 943 new security patches. Oracle says it continues to receive reports of attempts to exploit already-patched issues where customers had not applied available updates. Fusion Middleware includes unauthenticated WebLogic Server Core issues CVE-2026-60698 (IIOP, 9.8), CVE-2026-60672 and CVE-2026-60696 (T3/IIOP, 9.8) on 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0, plus CVE-2026-60977 (RMI, 9.8) on 12.2.1.4.0, 14.1.1.0.0 and 14.1.2.0.0, and Oracle Internet Directory LDAP Server CVE-2026-61241 at 10.0 on 12.2.1.4.0 and 14.1.2.1.0. Database Server includes adjacent-network Portable Clusterware issues CVE-2026-71063 and CVE-2026-71064 at 9.6. Apply the August 2026 CSPU for each product family you run. This is separate from CVE-2026-21962 (January 2026 CPU, later added to CISA KEV).
Broadcom VMSA-2026-0006 (29 July 2026; updated 19 August) covers CVE-2026-59310, a Critical directory-traversal flaw in the VMware vCenter Syslog server. A malicious actor with network access to vCenter can execute arbitrary code; Broadcom rates maximum CVSSv3 9.8; NVD CVSS 3.1 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). No workarounds — apply fixed builds per the VMSA response matrix / FAQ (brcm.tech/vmsa-2026-0006). CISA added the CVE to KEV on 18 August 2026 (FCEB due 21 August) after QUIRSO reported 361+ compromised IPs across 47 countries with reverse-SSH persistence. UPDATE 15 September 2026 (BleepingComputer; CISA KEV catalog field knownRansomwareCampaignUse=Known): CISA now flags the flaw as used in ransomware campaigns; Shadowserver still tracks 450+ internet-exposed vCenter instances. Treat unpatched vCenter as emergency. Primary: Broadcom VMSA-2026-0006; CISA KEV; wire: BleepingComputer 15 Sep.
Weak authentication in on-premises Microsoft SharePoint (CVE-2026-55040) lets an unauthorised attacker bypass a security feature over the network. CISA added it to KEV on 18 August 2026 after evidence of active exploitation. NVD scores it 9.1 (CVSS 3.1). It is the auth-bypass half of an unauthenticated RCE chain with August's CVE-2026-63520 (Business Connectivity Services RCE). Apply the July/August SharePoint security updates for Subscription Edition, 2019 and 2016, and keep farms off the public internet unless required.
CISA added CVE-2026-33824 to the Known Exploited Vulnerabilities catalog on 18 August 2026: a double-free in Microsoft Internet Key Exchange (IKE) Service Extensions. Treat internet-reachable IKE as known-exploited and apply Microsoft's update.
Zabbix's 18 August 2026 advisory (ZBX-28071) says that in Zabbix 7.4 the cryptographic key used for signing frontend sessions was erroneously written to the database seed. The only known exploitation scenario is deployments that use both SAML authentication and guest users: the key can be used to forge valid session cookies and gain unauthorised frontend access. Other deployments have no known impact. Affected: 7.4.0 through 7.4.10. Fixed: 7.4.11. Vendor CVSS 4.0 is 7.7 (High). Workaround: clear settings.session_key in the Zabbix database so the frontend generates a new random key. Zabbix credited Daniel Shemesh and Or Ida via HackerOne. Not in CISA KEV at last check.
Red Hat's 17 August 2026 CVE record (threat severity Critical, CVSS 3.1 9.1) describes a reset-credentials flaw in keycloak-services for Red Hat Build of Keycloak. An unauthenticated remote attacker can force password reset for any user without the email verification step and set new credentials, taking over the account. Temporary mitigation if you cannot patch yet: turn Forgot password off for every realm (Realm settings → Login). Fixed packages include Keycloak 26.4 builds at or after rhbk/keycloak-operator-bundle 26.4.15-1 / keycloak-rhel9 26.4-23 (RHSA-2026:56519 / 56520) and 26.6 builds at or after 26.6.6-1 / 26.6-12 (RHSA-2026:56523 / 56524). Red Hat marks Red Hat Single Sign-On 7 and JBoss EAP Expansion Pack as not affected. No in-the-wild exploitation stated on the Red Hat CVE page at last check.
Ray is an AI compute engine. CISA added CVE-2025-62593 to KEV on 17 August 2026. The GitHub advisory and NVD describe a code-injection issue in versions before 2.52.0. Patch to 2.52.0. Do not expose developer Ray services to untrusted networks.
Brighton East Dental Clinic's official notice says ASD's ACSC alerted it on 13 August 2026 to a potential incident. On 17 August 2026 the clinic identified unauthorised access to data on on-premises file servers through its firewall, contained that access, and analysed leaked data. It assesses the access occurred in early April 2026 and involves records from before April 2026: patient contact details (name, address, date of birth, email, mobile), treatment plans, oral X-rays, referrals and treatment history, and private health insurance membership numbers. The clinic has not published a count of affected records. It says it notified OAIC, ACSC and Victoria Police, partnered with IDCARE, and that remediation is complete. This desk does not take actor names or leak sizes from secondary leak-site indexes.
Apple released iOS 26.6.1 and iPadOS 26.6.1 and macOS Tahoe 26.6.2 on 17 August 2026 (security-content pages published 20 August). The iOS advisory includes ImageIO integer overflow CVE-2026-65346, where processing an image may lead to arbitrary code execution; Telephony CVE-2026-65329, where an attacker in a privileged network position may be able to bypass IPSec authentication and intercept network traffic (iPhone 11 and later); Kernel use-after-free CVE-2026-65343 (remote unexpected system termination); and multiple WebKit memory-safety issues. Apple does not publish CVSS scores on that page. Safari 26.6.1 followed on 18 August for macOS Sonoma and Sequoia. This is separate from CVE-2026-65400 (macOS Screen Sharing), which CISA added to KEV on 18 August.
Apple: iOS 26.6.1 and iPadOS 26.6.1 security content
Microsoft Security Update Guide CVE-2026-69414 is an elevation of privilege in the Microsoft Malware Protection Engine (ShieldBreak): CVSS 3.1 base 7.8 (AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H), Important. August reporting described a public local PoC to SYSTEM when Defender is enabled, including as a bypass of RoguePlanet (CVE-2026-50656). BleepingComputer (9 September 2026) says Microsoft shipped a ShieldBreak fix in the September 2026 Patch Tuesday set, and that researcher Nightmare Eclipse then released a "ShieldCrash" proof-of-concept claiming the patch is incomplete under specific conditions — arbitrary file read as SYSTEM on fully patched Windows 10/11/Server, without write access in the published skeleton PoC. Treat ShieldCrash as secondary researcher claim until MSRC documents a new CVE or revises 69414. Watch MSRC for engine build requirements; do not equate a public PoC with confirmed in-the-wild exploitation.