• Request consultation
  • Newsletter
  • Deutsch Deutsch German de
  • English English English en
  • Italiano Italiano Italian it
  • Nederlands Nederlands Dutch nl
Greenbone
  • Products
    • OPENVAS BASIC
      • OPENVAS BASIC: Order
    • OPENVAS SCAN
    • Upcoming Solutions
      • OPENVAS SECURITY INTELLIGENCE
      • OPENVAS AI
    • Solutions for Your Sector
      • Educational Sector
      • Healthcare Sector
      • Public Sector
    • Technology
      • Feed Comparison
      • Product Comparison
        • OPENVAS vs. Nessus
      • Roadmap & Lifecycle
  • Service & Support
    • Professional Services
    • Documents
    • Technical Support
  • Events
    • MSP GLOBAL 2026
    • Webinars
  • Partners
    • MSSP
  • About Greenbone
    • Our History
    • Careers
    • Contact
  • Blog
    • Know-how
      • Attack Vector Timeline
      • Cyberattacks and Defense
      • Cyber Defense Security
      • Cyber Resilience Act
      • Data Security
      • Digital Operational Resilience Act
      • Exposure Management
      • IT and Information Security
      • NIS2 Directive
      • Open Source Vulnerability Management
      • The Vulnerability Timeline
  • Click to open the search input field Click to open the search input field Search
  • Menu Menu
  • Products
    • OPENVAS BASIC
      • OPENVAS BASIC: Order
    • OPENVAS SCAN
    • Upcoming Solutions
      • OPENVAS SECURITY INTELLIGENCE
      • OPENVAS AI
    • Solutions for your sector
      • Educational Sector
      • Healthcare Sector
      • Public Sector
    • Technology
      • Feed Comparison
      • Product Comparison
        • OPENVAS vs. Nessus
      • Roadmap and Lifecycle
    • Request IT Security
  • Service & Support
    • Professional Services
    • Documents
    • Technical Support
  • Events
    • MSP GLOBAL 2026
    • Webinars
  • Partners
    • MSSP
  • About Greenbone
    • Our History
    • Careers
    • Contact
    • Newsletter
  • Our Blog
    • Know-how
      • Attack Vector Timeline
      • Cyberattacks and Defense
      • Cyber Defense Security
      • Cyber Resilience Act
      • Data Security
      • Digital Operational Resilience Act
      • Exposure Management
      • IT and Information Security
      • NIS2 Directive
      • Open Source Vulnerability Management
      • The Vulnerability Timeline
  • German
  • English
  • Italian
  • Dutch
Joseph Lee

August 2026 Threat Report: The Vulnpocalypse Hits Full Force

Blog

The so-called Vulnpocalypse is now in full force. This August 2026 threat report only scratches the surface of new high-risk vulnerabilities that emerged in August 2026. To see how Greenbone’s industry leading vulnerability detection can benefit your IT security operations, visit our SecInfo portal and view our complete coverage portfolio.

August 2026 threat report banner: Vulnpocalypse continues

August reinforced a now too familiar pattern: high-impact vulnerabilities in common enterprise software offerings are moving rapidly from disclosure to exploitation. The following sections highlight the vulnerabilities and related attack campaigns that demand immediate attention.

Start Your Free Trial

For defenders seeking to detect and protect, a trial copy of OPENVAS SCAN includes a free two-week trial of the OPENVAS ENTERPRISE FEED. Greenbone’s cyber security products are a surefire way to gain the deepest insight into where software vulnerabilities exist across your organization’s infrastructure.

Microsoft: New Actively Exploited CVEs, Espionage, Ransomware, and PoCs

Microsoft’s August 2026 patch release was another large disclosure. Of 457 new CVEs, 36 were assigned a critical-severity CVSS score. 80 were assigned an EPSS score above the 50th percentile and 16 above the 80th percentile. Microsoft designated 34 of the CVEs as “Exploitation More Likely“. Earlier in August, the Greenbone blog covered an espionage campaign leveraging CVE-2026-68820 (CVSS 7.0, EPSS ≥ 93rd pctl), which affects the Windows Ancillary Function Driver for WinSock.

The newly disclosed CVE-2026-33824, which affects the Windows IKE Extension was added to CISA’s KEV list, along with CVE-2026-55040, affecting SharePoint, which was first disclosed in July. In addition to these new CVEs, and older vulnerability, CVE-2019-1068, affecting Microsoft SQL Server was also added to CISA’s KEV list. CISA also added ransomware distinctions to CVE-2026-45659, a deserialization flaw [CWE-502] affecting Microsoft SharePoint Server, and CVE-2025-60710, a Windows link-following flaw [CWE-59] allowing privilege escalation [1][2].

Microsoft’s battle with zero-day disclosures from third-party security researchers also continued into August 2026 [1][2][3]. Additional high-risk threats to Microsoft environments that emerged in August 2026 include:

  • CVE-2026-54121 (CVSS 8.8, EPSS ≥ 77th pctl): Dubbed “Certighost”, the flaw is caused by improper authorization [CWE-285] in Active Directory Certificate Services (AD CS). An authenticated attacker can obtain a certificate from AD CS and then elevate privileges via Kerberos. Detailed technical analysis [4][5] and a PoC exploit [6] are publicly available, increasing the risk of attacks.
  • CVE-2026-70329 (CVSS 8.8, EPSS ≥ 50th pctl): An integer overflow [CWE-190] in Microsoft Office Outlook allows an attacker to execute code over a network via social engineering; the victim must open a malicious Office file.
  • CVE-2026-42897 (CVSS 6.1, EPSS ≥ 99th pctl): An Outlook Web Access (OWA) XSS flaw was used to target government, telecommunications, financial, hospitality, and aerospace organizations [7]. Opening a malicious email in OWA was sufficient to execute attacker-controlled JavaScript. Attackers deployed OWAReaper, a browser-resident JavaScript implant to steal credentials and OAuth tokens, maintain persistent access to the victim’s computer, execute arbitrary commands, and exfiltrate data over HTTPS and DNS tunneling.

The four additional high-risk Microsoft CVEs from August 2026, each shown with its CVSS severity band and EPSS exploitation-probability score

CVE-2026-68820
CVSS 7.0 · High EPSS 6.2% (93rd)

Affects the Windows Ancillary Function Driver for WinSock; exploited in an espionage campaign combining social engineering with this Windows privilege-escalation flaw.

CVE-2026-54121
CVSS 8.8 · High EPSS 1.8% (77th)

Dubbed “Certighost” — an improper authorization [CWE-285] flaw in Active Directory Certificate Services (AD CS) lets an authenticated attacker obtain a certificate and elevate privileges via Kerberos.

CVE-2026-70329
CVSS 8.8 · High EPSS 0.7% (50th)

An integer overflow [CWE-190] in Microsoft Office Outlook lets an attacker execute code via a malicious Office file opened through social engineering.

CVE-2026-42897
CVSS 6.1 · Medium EPSS 71.2% (99th)

An Outlook Web Access XSS flaw let attackers execute JavaScript via a single malicious email, deploying the OWAReaper implant to steal credentials and OAuth tokens.

Greenbone’s OPENVAS ENTERPRISE FEED includes regular vulnerability detection across many Microsoft products, including all the CVEs referenced above.

New Cisco Risks: Critical Flaws, Public PoCs, and New Attacks

Cisco disclosed several high-risk vulnerability clusters in August 2026 spanning its firewall, network-management, endpoint-security, server-management, and workload-security products. The vendor chose to group the new vulnerabilities by Common Weakness Enumeration (CWE) class and release multiple flaws under a single CVE identifier. This practice was officially discouraged recently by the CVE program.

Greenbone’s OPENVAS ENTERPRISE FEED provides regular detection checks for vulnerabilities in Cisco products. Here are some of the most significant risks affecting Cisco products from August 2026:

CVE-2026-20349: Secure Firewall ASA/FTD: Actively Exploited for DoS

CVSS 8.6 · HighEPSS 2.2% (81st)Actively exploitedIn CISA KEV

CVE-2026-20349 (CVSS 8.6, EPSS ≥ 81st pctl) affects the Remote Access SSL VPN service in Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD). An unauthenticated remote attacker can use a crafted HTTP request to cause a denial-of-service (DoS) condition on affected devices. Exploitation requires the IKEv2 Remote Access VPN with client services, SSL VPN, or, on FTD, Zero Trust Network Access to be enabled.

The CVE has been added to CISA’s KEV, indicating active exploitation. According to Cisco, there are no workarounds, making available hotfixes the primary remediation. See the official advisory for more information.

Integrated Management Controller: Authenticated Root-Level RCE Has Public Exploit

CVSS 8.8 · HighEPSS 5.7% (93rd)No known exploitationPublic PoC

CVE-2026-20200 (CVSS 8.8, EPSS ≥ 93rd pctl) is an argument-injection vulnerability in the web interface of Cisco Integrated Management Controller (IMC). A low-privilege attacker can manipulate parameters used when IMC retrieves an SSH public key, inject additional curl arguments, and ultimately execute arbitrary commands with root privileges.

Several technical explanations [1][2] and a PoC exploit toolkit are publicly available [3]. The PoC supports arbitrary file upload and download, and reverse-shell command execution. Active exploitation has not been reported. The risk is also amplified because IMC operates below the host OS and can interact with firmware, BIOS, and Secure Boot.

No workarounds are available. See the official advisory for more information, including a full list of affected products.

Seven ClamAV Flaws: CVE-2026-20337 Has a Public Exploit

Seven ClamAV parsing flaws affect Secure Endpoint Connector and can allow unauthenticated remote attackers to submit malicious ZIP, PESpin, GPT, PDF, Mach-O, or XAR content to crash the ClamAV process. Cisco rates the impact higher on Windows because ClamAV executes in a privileged security context, while Linux and macOS connectors run it with lower privileges. Most importantly, Cisco PSIRT confirms the existance of public PoC exploit code for CVE-2026-20337 and CVE-2026-20338. No active exploitation has been reported.

Catalyst SD-WAN: Multiple Critical Vulnerability Groups

Cisco has addressed five CVE groups affecting Catalyst SD-WAN in all configurations. CVE-2026-20303 and CVE-2026-20304 (both rated CVSS 9.9) cover improper input validation [CWE-20] and improper access control [CWE-284] vulnerabilities, respectively. CVE-2026-20310 (CVSS 9.1) covers improper link resolution flaws [CWE-59]. CVE-2026-20312 (CVSS 8.8) and CVE-2026-20313 (CVSS 7.7) cover cleartext storage of sensitive information [CWE-312] and improper input-quantity validation [CWE-1284].

The five Cisco Catalyst SD-WAN CVE groups from August 2026, each shown with its CVSS severity band and EPSS exploitation-probability score

CVE-2026-20303
CVSS 9.9 · Critical EPSS 0.3% (25th)

Improper input validation [CWE-20] in Cisco Catalyst SD-WAN.

CVE-2026-20304
CVSS 9.9 · Critical EPSS 0.3% (20th)

Improper access control [CWE-284] in Cisco Catalyst SD-WAN.

CVE-2026-20310
CVSS 9.1 · Critical EPSS 0.4% (34th)

Improper link resolution [CWE-59] in Cisco Catalyst SD-WAN.

CVE-2026-20312
CVSS 8.8 · High EPSS 0.3% (18th)

Cleartext storage of sensitive information [CWE-312] in Cisco Catalyst SD-WAN.

CVE-2026-20313
CVSS 7.7 · High EPSS 0.3% (19th)

Improper input-quantity validation [CWE-1284] in Cisco Catalyst SD-WAN.

No detailed technical information or PoC exploits are publicly available. No active exploitation has been reported. No workarounds are available. See the official advisory for more information.

CVE-2026-20272: Unauthenticated Injection in IOS XE

CVSS 9.8 · CriticalEPSS 0.4% (34th)No known exploitation

Cisco published seven vulnerability groups that affect IOS XE running in autonomous or controller mode in all configurations. The standout is CVE-2026-20272 (CVSS 9.8), a group caused by improper neutralization of special elements [CWE-74] that contains at least one unauthenticated, network-exploitable item. No detailed technical information or PoC exploits are publicly available. No active exploitation has been reported. No workarounds are available. See the official advisory for more information.

CVE-2026-72898: CVSS 10 Flaw in Metabase Actively Exploited

CVSS 10 · CriticalEPSS 82.3% (100th)Actively exploitedIn CISA KEVPublic PoC

CVE-2026-72898 (CVSS 10, EPSS = 100th pctl) is an SQL injection flaw [CWE-89] that allows an unauthenticated remote attacker to inject arbitrary SQL commands via the /reset_password endpoint. Exploitation allows administrator access to the connected Metabase instance. CVE-2026-72898 has been added to CISA’s KEV list. Several detailed technical analyses [1][2][3] and PoC exploits [4][5][6] are publicly available. Security firm VeraniX identified 15 victims by August 10th. However, the list has likely grown significantly.

Greenbone’s OPENVAS ENTERPRISE FEED includes a remote banner check for CVE-2026-72898 and other CVEs included in the recent patch to Metabase. The vendor advises blocking access to the /api/session/reset_password endpoint as a temporary mitigation until upgrading is possible. A table showing affected versions is included below, and users should urgently upgrade to a patched version.

Edition Release Branch Affected Versions Patched Version

Metabase OSS

0.58.x

Prior to 0.58.24

0.58.24 or later

Metabase OSS

0.59.x

Prior to 0.59.21

0.59.21 or later

Metabase OSS

0.60.x

Prior to 0.60.17

0.60.17 or later

Metabase OSS

0.61.x

Prior to 0.61.11

0.61.11 or later

Metabase OSS

0.62.x

Prior to 0.62.9

0.62.9 or later

Metabase OSS

0.63.x

Prior to 0.63.5

0.63.5 or later

Metabase Enterprise

1.58.x

Prior to 1.58.24

1.58.24 or later

Metabase Enterprise

1.59.x

Prior to 1.59.21

1.59.21 or later

Metabase Enterprise

1.60.x

Prior to 1.60.17

1.60.17 or later

Metabase Enterprise

1.61.x

Prior to 1.61.11

1.61.11 or later

Metabase Enterprise

1.62.x

Prior to 1.62.9

1.62.9 or later

Metabase Enterprise

1.63.x

Prior to 1.63.5

1.63.5 or later

CVE-2026-60004: Gitea Actively Exploited Again

CVSS 9.8 · CriticalEPSS 86.8% (100th)Actively exploitedIn CISA KEVPublic PoC

In July, our blog reported active exploitation of Gitea. Since then, CVE-2026-60004 (CVSS 9.8, EPSS ≥ 100th pctl) has been disclosed and added to CISA’s KEV list. The new flaw affects Gitea before version 1.27.1. Exploitation allows RCE via the diffpatch API during Git hook installation. Gitea and a third party have published PoC exploits [1][2], increasing the risk.

The OPENVAS ENTERPRISE FEED includes a remote banner check for CVE-2026-60004. Users should upgrade to Gitea version 1.27.1 immediately.

CVE-2026-73570: New Actively Exploited Zimbra Flaw

CVSS 8.9 · HighEPSS 32.4% (98th)Actively exploitedIn CISA KEV

CVE-2026-73570 (CVSS 8.9, EPSS ≥ 98th pctl), affecting Zimbra Collaboration Suite (ZCS) was published in mid-August and quickly added to CISA’s KEV list. In total, nine security issues were patched in the ZCS version 10.1.20 release. The root cause is improper sanitization of untrusted input during SNMP notification processing. Exploitation of CVE-2026-73570 allows an unauthenticated attacker to achieve RCE as the ZCS process via specially crafted SMTP requests when the optional zimbra-snmp package is installed and SNMP notifications are enabled.

The OPENVAS ENTERPRISE FEED includes a remote banner check that covers all recent security issues affecting ZCS. Users should upgrade to version 10.1.20 as soon as possible.

CVE-2026-34486: Apache Tomcat Actively Exploited

CVSS 7.5 · HighEPSS 98.6% (100th)Actively exploitedIn CISA KEVPublic PoC

CVE-2026-34486 (CVSS 7.5, EPSS = 100th pctl), disclosed in April, was added to CISA’s KEV list in early-August. Detailed technical analysis [1] and proof of concept exploit kits are publicly available [2][3], further increasing the risk of ongoing attacks.

The root cause is missing encryption of sensitive data [CWE-311], allowing the bypass of the EncryptInterceptor component of the Tribes clustering subsystem. EncryptInterceptor is used to encrypt and decrypt cluster communications between Tomcat nodes using a pre-shared key. CVE-2026-34486 was introduced by a flawed patch for CVE-2026-29146 and allows cluster traffic to bypass encryption, leaving inter-node communications in plaintext.

This issue affects Apache Tomcat versions 11.0.20, 10.1.53, 9.0.116. Tomcat users should upgrade to version 11.0.21, 10.1.54, or 9.0.117. The OPENVAS ENTERPRISE FEED includes numerous detection checks for CVE-2026-34486 across Linux distributions, general detection tests covering Tomcat servers for Windows and Linux, and other products that package Tomcat including: various Oracle and Dell products, Atlassian Jira, Apache OFBiz, IBM Storage Protect Plus.

CVE-2026-9198: IBM Langflow Actively Exploited

CVSS 9.8 · CriticalEPSS 57.0% (99th)Actively exploitedIn CISA KEVPublic PoC

CVE-2026-9198 (CVSS 9.8, EPSS ≥ 99th pctl) allows unauthenticated attackers to chain the /api/v1/auto_login and /api/v1/validate/code API endpoints to achieve RCE on default Langflow deployments. An attacker can chain these two flaws to obtain a SUPERUSER token and then submit malicious Python code to be executed. Exploitation can result in a complete compromise of the host.

20 CVEs were patched in total; six exploitable without authentication. However, only CVE-2026-9198 has been added to CISA’s KEV list so far. A public PoC exploit is available, further increasing the risk of ongoing exploit campaigns. Langflow has appeared five times on the CISA KEV list in 2026. The flaw affects Langflow 1.0.0 through 1.10.0. Greenbone’s OPENVAS ENTERPRISE FEED includes a remote banner version check to detect affected instances. Users should upgrade to Langflow version 1.10.1 or later immediately.

CVE-2026-66384: JFrog Artifactory Actively Exploited

CVSS 5.3 · MediumEPSS 0.6% (45th)Actively exploitedIn CISA KEV

CVE-2026-66384 (CVSS 5.3) allows an authenticated attacker to write data outside the intended Docker cache path in affected JFrog Artifactory versions. The root cause is improper pathname restriction [CWE-22]. The flaw is being actively exploited and was added to CISA’s KEV catalog.

An OpenAI research agent successfully exploited the flaw during an internal evaluation, poisoning Artifactory’s cache with attacker-controlled content. The poisoned image created a potential path to arbitrary command execution if it were later pulled and run. The poisoned image did not make it into the wild based on OpenAI’s investigation, which includes a full technical description for CVE-2026-66384. CIRCL.lu’s Vulnerability Lookup public threat intelligence platform indicates that a PoC exploit may be available on a public Telegram channel.

JFrog Artifactory versions 7.146.0 through 7.146.34 and 7.161.0 through 7.161.15 are affected. The OPENVAS ENTERPRISE FEED includes a remote banner check, allowing users to identify affected instances.

CVE-2026-71362: Local Privilege Escalation Flaw in Adobe Commerce/Magento

CVSS 9.1 · CriticalEPSS 25.1% (98th)Public PoC

CVE-2026-71362 (CVSS 9.1, EPSS ≥ 98th pctl) is an incorrect authorization vulnerability [CWE-863] that allows privilege escalation and elevated access to sensitive resources on Adobe Commerce/Magento instances. A low-privilege authenticated attacker with a registered customer account can take over any other customer account using only the user id field. A proof-of-concept exploit is publicly available. Adobe’s APSB26-92 advisory disclosed seven new CVEs in total; five rated critical severity. Affected products and versions are shown below.

Affected Product Affected Versions Fixed Versions

Adobe Commerce

2.4.9-2026-jul and earlier

2.4.8-2026-jul and earlier

2.4.7-2026-jul and earlier

2.4.6-2026-jul and earlier

2.4.5-2026-jul and earlier

2.4.4-2026-jul and earlier

2.4.9-2026-aug

2.4.8-2026-aug

2.4.7-2026-aug

2.4.6-2026-aug

2.4.5-2026-aug

2.4.4-2026-aug

Adobe Commerce B2B

1.5.3-2026-jul and earlier

1.5.2-2026-jul and earlier

1.4.2-2026-jul and earlier

1.3.4-2026-jul and earlier

1.3.3-2026-jul and earlier

1.5.3-2026-aug

1.5.2-2026-aug

1.4.2-2026-aug

1.3.4-2026-aug

1.3.3-2026-aug

Magento Open Source

2.4.9-2026-jul and earlier

2.4.8-2026-jul and earlier

2.4.7-2026-jul and earlier

2.4.6-2026-jul and earlier

2.4.9-2026-aug

2.4.8-2026-aug

2.4.7-2026-aug

2.4.6-2026-aug

The OPENVAS ENTERPRISE FEED detects all CVEs in Adobe’s APSB26-92 advisory with a remote banner check. See the vendor’s release notes for more information [1][2][3][4].

CVE-2026-17106 (aka CopyEscape): PoC Available for Container-to-Host Arbitrary File in moby/go-archive

CVSS 7.1 · HighEPSS 0.3% (25th)No known exploitationPublic PoC

CVE-2026-17106 (CVSS 7.1, EPSS 25th pctl), dubbed CopyEscape, allows a malicious container to escape isolation and achieve root code execution on a Docker host. The root cause is a combination of a path traversal flaw [CWE-35] and improper symlink resolution [CWE-59]. Exploitation allows a trojanized container to overwrite arbitrary host files, including root-owned binaries such as /usr/bin/runc on the Docker host via tar extraction during docker cp. Although no active exploitation has been confirmed, multiple detailed technical write-ups [1][2][3][4] and functional public PoC exploits [1][2][3] are available.

CVE-2026-17106 affects the moby/go-archive tar extraction routines in the following Docker products:

Affected Product Affected Versions Fixed Version

moby/go-archive

< 0.3.0

0.3.0

Docker Engine

< 29.7.0

29.7.0

Docker CLI

< 29.7.0

29.7.0

Docker Desktop

< 4.86.0

4.86.0

Docker Compose

< 5.4.0

5.4.0

Docker Sandboxes

< 0.38.0

0.38.0

The OPENVAS ENTERPRISE FEED includes a registry detection for Docker Desktop for Windows, a remote banner check for Docker Engine, and Linux package detection for specific distributions as security advisories are issued.

CVE-2026-53413: Zoom Forfeits Remote Code Execution to Any Meeting Attendee

CVSS 8.3 · HighEPSS 5.6% (92nd)No known exploitation

CVE-2026-53413 (CVSS 8.3, EPSS ≥ 92nd pctl) allows an attacker participating in a Zoom meeting to achieve RCE on all meeting participants across all native clients without any user interaction. Exploitation allows code execution with the Zoom application’s permissions. A demonstrated macOS technical write-up demonstrates calling execvp() from the compromised zoom.us process, replacing that process with Safari.

Although no active exploitation has been reported, CVE-2026-53413 has an elevated EPSS score indicating high risk of future exploitation. If weaponized, the flaw creates a social engineering risk, allowing attackers to impersonate potential customers or other business communications to execute arbitrary code on the victim’s computer. Users should verify their Zoom patch level and configure all Zoom clients for “Fast” automatic-updates. The OPENVAS ENTERPRISE FEED includes package-level detection for Windows, Linux, and macOS [1][2][3].

CVE-2023-49105: Three-Year-Old ownCloud Flaw Actively Exploited

CVSS 9.8 · CriticalEPSS 43.2% (99th)Actively exploitedIn CISA KEVPublic PoC

CVE-2023-49105 (CVSS 9.8, EPSS ≥ 99th pctl), affecting ownCloud, was published in late-2023 and added to CISA’s KEV list in August. A Philippine nuclear naval contractor is the only publicly identified victim so far. Several detailed technical write-ups [1][2] and PoC exploits [3][4] have been available for CVE-2023-49105 since late 2023.

ownCloud is an open-source file synchronization, sharing, and collaboration platform. The product is similar to Dropbox or Google Drive and popular for self-hosted file sharing when data sovereignty is important.

The flaw is caused by pre-signed URLs being accepted even when no signing key is configured for the owner of a file. Exploitation requires the attacker to possess an existing username for which no signing key is configured. Successful exploitation allows an attacker to access, modify, or delete any file without other forms of authentication.

CVE-2023-49105 affects ownCloud versions 10.6.0 and later, before 10.13.1. The OPENVAS ENTERPRISE FEED has included a remote banner check for CVE-2023-49105 since its disclosure in November 2023.

Other Notable Emerging Threats from August 2026

Here are some other notable high-risk IT security threats that emerged in August 2026.

TrueConf Actively Exploited Again to Deliver PhantomCore Malware

CVE-2026-72529 (CVSS 9.8, EPSS ≥ 73rd pctl) and CVE-2026-72530 (CVSS 9.0, EPSS ≥ 77th pctl) affecting TrueConf Server can be chained to execute arbitrary scripts, escape the isolated execution environment, and achieve host-level RCE. Exploitation does not require authentication. CISA added both flaws to its KEV catalog in August [3][4]. CVE-2026-3502 was also added to CISA’s KEV list in April 2026, indicating a persistent threat to the conferencing platform’s users.

The two chained TrueConf Server CVEs from August 2026, each shown with its CVSS severity band and EPSS exploitation-probability score

CVE-2026-72529
CVSS 9.8 · Critical EPSS 1.6% (73rd)

Can be chained with CVE-2026-72530 to execute arbitrary scripts, escape the isolated execution environment, and achieve host-level RCE in TrueConf Server.

CVE-2026-72530
CVSS 9.0 · Critical EPSS 1.8% (77th)

Chainable with CVE-2026-72529 for host-level RCE in TrueConf Server; exploited by the Head Mare APT to deploy PhantomCore malware.

In the most recent attacks, Kaspersky observed the Head Mare APT exploiting the chain against Russian organizations to deploy a web shell, compromise TrueConf Server databases, and install malicious versions of TrueConf client installers. The trojanized installers delivered PhantomCore malware to conference participants. The vendor advises users to upgrade to version 5.5.2 or later.

PaperCut NG/MF Actively Exploited for Unauthenticated RCE

CVE-2026-81578 (CVSS 9.8) and CVE-2026-82078 (CVSS 9.1) affecting PaperCut NG/MF can be chained for unauthenticated RCE. The attack chain involves first modifying the system configuration and then abusing unsafe dynamic class loading to execute arbitrary Java bytecode. PaperCut confirmed active exploitation of its customers. Post-exploitation activity included deployment of SimpleHelp and AnyDesk remote-access software.

The two chained PaperCut NG/MF CVEs from August 2026, each shown with its CVSS severity band and EPSS exploitation-probability score

CVE-2026-81578
CVSS 9.8 · Critical EPSS 0.8% (53rd)

Chainable with CVE-2026-82078 for unauthenticated RCE in PaperCut NG/MF via unsafe dynamic class loading; actively exploited to deploy SimpleHelp and AnyDesk.

CVE-2026-82078
CVSS 9.1 · Critical EPSS 0.9% (58th)

Chainable with CVE-2026-81578 for unauthenticated RCE in PaperCut NG/MF.

CISA added both flaws to its KEV catalog [1][2]. A public Metasploit module is available, as well as a detailed technical write-up, and public PoC exploits [3][4]. The OPENVAS ENTERPRISE FEED includes a remote banner check, allowing users to identify affected instances. At least three successive security patches have been issued to remediate the CVEs, so users should check the vendor’s official advisory for the latest information.

Critical Flaws in Veeam ONE and Service Provider Console

Critical-severity flaws were disclosed for both Veeam ONE via KB4892 and Veeam Provider Console (VSPC) in KB4893. The flaws affecting Veeam ONE impact all version 13 builds through 13.0.2.6723, resolved in Veeam ONE 13.1 (build 13.1.0.7034) or Veeam ONE 13.0.2 Patch 1 (build 13.0.2.7159). All flaws in VSPC affect all version 9 builds through 9.2.1.33875, resolved in Veeam Service Provider Console 9.3 (build 9.3.0.35057). The highest-risk CVEs are:

  • CVE-2026-64633 (CVSS 10) in Veeam ONE: Allows remote, unauthenticated code execution on the agent host
  • CVE-2026-58073 (CVSS 9.5) in Veeam Service Provider Console: Allows an unauthenticated attacker to impersonate a managed agent and obtain that agent’s credentials

The two highest-risk Veeam ONE and Service Provider Console CVEs from August 2026, each shown with its CVSS severity band and EPSS exploitation-probability score

CVE-2026-64633
CVSS 10 · Critical EPSS 0.5% (38th)

Allows remote, unauthenticated code execution on the agent host in Veeam ONE.

CVE-2026-58073
CVSS 9.5 · Critical EPSS 0.3% (24th)

Allows an unauthenticated attacker to impersonate a managed agent and obtain that agent’s credentials in Veeam Service Provider Console.

VSPC serves as a centralized management and monitoring platform for customer data-protection environments. Because it sits in a privileged, centralized management position and provides remote access across multiple customer backup environments, a breach could serve as a pivot point into managed infrastructure and have severe consequences. Veeam ONE presents lower risk than VSPC because it is primarily a monitoring, reporting, and analytics platform. However, a breach could expose sensitive backup-infrastructure data and credentials, and potentially provide a foothold for further intrusion.

The OPENVAS ENTERPRISE FEED includes remote banner checks for KB4892 affecting Veeam ONE [1][2] and KB4893 affecting VSPC [3].

CVE-2026-10053: Package Registry Path Traversal Enables Authenticated RCE in GitLab CE/EE

CVSS 8.8 · HighEPSS 0.8% (53rd)No known exploitationPublic PoC

CVE-2026-10053 (CVSS 8.8, EPSS ≥ 53rd pctl) allows a low-privileged authenticated attacker to achieve RCE in GitLab CE/EE via a path traversal flaw in the package registry. A public PoC lab is available, but active exploitation has not been reported. The issue follows reports of CVE-2026-19478 being actively exploited earlier in August. The OPENVAS ENTERPRISE FEED provides a remote banner check for CVE-2026-10053 and regular detection for GitLab flaws including the actively exploited CVE-2026-19478. GitLab patched the issue in versions 19.0.6, 19.1.4, and 19.2.2.

Summary

August 2026 delivered another heavy wave of high-risk vulnerabilities, including actively exploited flaws, public PoCs, CVSS 10 issues, and vulnerabilities tied to ransomware and espionage. The month’s disclosures reinforce the need to prioritize internet-facing and privileged enterprise systems for rapid remediation.

Start Your Free Trial

For defenders seeking to detect and protect, a trial copy of OPENVAS SCAN includes a free two-week trial of the OPENVAS ENTERPRISE FEED. Greenbone’s cyber security products are a surefire way to gain the deepest insight into where software vulnerabilities exist across your organization’s infrastructure.

 

Contact Test Now Buy Here Back to Overview
Joseph Lee
Joseph Lee

Joseph has had a varied and passionate background in IT and cyber security since the late 1980s. His early technical experience included working on an IBM PS/2, assembling PCs and programming in C++.

He also pursued academic studies in computer and systems engineering, anthropology and an MBA in technology forecasting.

Joseph has worked in data analytics, software development and, in particular, enterprise IT security. He specialises in vulnerability management, encryption and penetration testing.

LinkedIn

7. September 2026/by Joseph Lee
Share this entry
  • Share on LinkedIn
  • Share by Mail
https://www.greenbone.net/wp-content/uploads/greenbone-logo-2025.png 0 0 Joseph Lee https://www.greenbone.net/wp-content/uploads/greenbone-logo-2025.png Joseph Lee2026-09-07 14:56:592026-09-07 16:23:19August 2026 Threat Report: The Vulnpocalypse Hits Full Force

Search

Search Search

Archive

  • 2026
  • 2025

Newsletter

Subscribe Now

OPENVAS BASIC

Our entry-level enterprise product

Test 14 Days Free of Charge

Products & Solutions

  • OPENVAS PRODUCTS
  • OPENVAS SECURITY INTELLIGENCE
  • OPENVAS SCAN
  • OPENVAS BASIC
  • OPENVAS FREE
  • OPENVAS AI
ISO9001-EN

Service & Support

  • Professional Services
  • Documents
  • Technical Support
  • FAQ
  • Warranty
  • Cyber Resilience Act
ISO27001-EN

About us

  • About Greenbone
  • Partners
  • MSSP
  • License information
  • Privacy Statement
  • Terms & Conditions
ISO14001-EN

Contact with us

  • Contact
  • Newsletter
  • Media Contact
  • Careers
  • Security Response
  • Imprint
  • Grounding Page

Community

  • Community Portal
  • Community Forum
© Copyright - Greenbone AG 2020-2026
  • Link to LinkedIn
Link to: Agent-Based, Agentless, or Both? What Each One Can Actually See Link to: Agent-Based, Agentless, or Both? What Each One Can Actually See Agent-Based, Agentless, or Both? What Each One Can Actually See
Scroll to top Scroll to top Scroll to top
Contact
Request IT Security Contact Us Subscribe to Newsletter Follow on LinkedIn