• Request consultation
  • Newsletter
  • Deutsch Deutsch German de
  • English English English en
  • Italiano Italiano Italian it
  • Nederlands Nederlands Dutch nl
Greenbone
  • Products
    • OPENVAS BASIC
      • OPENVAS BASIC: Order
    • OPENVAS SCAN
    • Upcoming Solutions
      • OPENVAS SECURITY INTELLIGENCE
      • OPENVAS AI
    • Solutions for Your Sector
      • Educational Sector
      • Healthcare Sector
      • Public Sector
    • Technology
      • Feed Comparison
      • Product Comparison
        • OPENVAS vs. Nessus
      • Roadmap & Lifecycle
  • Service & Support
    • Professional Services
    • Documents
    • Technical Support
  • Events
    • MSP GLOBAL 2026
    • Webinars
  • Partners
    • MSSP
  • About Greenbone
    • Our History
    • Careers
    • Contact
  • Blog
    • Know-how
      • Attack Vector Timeline
      • Cyberattacks and Defense
      • Cyber Defense Security
      • Cyber Resilience Act
      • Data Security
      • Digital Operational Resilience Act
      • Exposure Management
      • IT and Information Security
      • NIS2 Directive
      • Open Source Vulnerability Management
      • The Vulnerability Timeline
  • Click to open the search input field Click to open the search input field Search
  • Menu Menu
  • Products
    • OPENVAS BASIC
      • OPENVAS BASIC: Order
    • OPENVAS SCAN
    • Upcoming Solutions
      • OPENVAS SECURITY INTELLIGENCE
      • OPENVAS AI
    • Solutions for your sector
      • Educational Sector
      • Healthcare Sector
      • Public Sector
    • Technology
      • Feed Comparison
      • Product Comparison
        • OPENVAS vs. Nessus
      • Roadmap and Lifecycle
    • Request IT Security
  • Service & Support
    • Professional Services
    • Documents
    • Technical Support
  • Events
    • MSP GLOBAL 2026
    • Webinars
  • Partners
    • MSSP
  • About Greenbone
    • Our History
    • Careers
    • Contact
    • Newsletter
  • Our Blog
    • Know-how
      • Attack Vector Timeline
      • Cyberattacks and Defense
      • Cyber Defense Security
      • Cyber Resilience Act
      • Data Security
      • Digital Operational Resilience Act
      • Exposure Management
      • IT and Information Security
      • NIS2 Directive
      • Open Source Vulnerability Management
      • The Vulnerability Timeline
  • German
  • English
  • Italian
  • Dutch
Joseph Lee

Wiz Loves OPENVAS! Our Take on Being a Top Vulnerability Management Tool of 2026

Blog

When Wiz recently published its roundup of the Best Vulnerability Management Tools for 2026, something caught our attention, but didn’t surprise us: OPENVAS received a top spot and a great review. Wiz describes OPENVAS as the “open-source equivalent” to commercial vulnerability scanners. The review calls OPENVAS “the most comprehensive coverage available in a single platform”. We’ll take the compliment! But there are still a few points we would like to contest because they don’t quite capture the full Greenbone story.

➡

Start Your Free Trial

Grabbing a copy of OPENVAS SCAN with a free two-week trial of the OPENVAS ENTERPRISE FEED is a surefire way to gain the deepest insight into where software vulnerabilities exist in your organization’s Linux infrastructure.

Illustration of an award podium with a digital security shield, symbolizing OPENVAS being named a top vulnerability management tool

What Wiz Reviewed

Wiz reviewed Greenbone’s free community edition of OPENVAS SCAN, which is appropriate for a review of open-source software (OSS) tools. However, the community edition comes with the limits of a free tier. OPENVAS is also available as an end-to-end enterprise product. Let’s review the differences:

  Community Edition Enterprise Products

Setup

Installed from containers, Linux packages, or source code

Pre-configured and optimized virtual and hardware appliances

Detection feed

Selected consumer and OSS security checks

Extended list of OSS such as additional Linux distributions and Cisco, Microsoft, SAP, Fortinet, Citrix, and many more enterprise software products

Compliance

IT-Grundschutz

IT-Grundschutz, CIS Benchmarks, BSI-TR technical guidelines, and additional policy sets such as Post-Quantum Cryptographic policy scans

Update cadence

Regular updates

Daily updates

Service and support

Volunteer members of the Greenbone community forum

Guaranteed service and support response times with a Service Level Agreement (SLA), plus Professional Services

Open Source and Enterprise: Greenbone Is “Best of Both Worlds”

One of Greenbone’s biggest advantages is that organizations do not have to choose between open-source transparency and enterprise-grade deployment. Greenbone offers both sides of the equation: the transparency and flexibility associated with open-source software and purpose-built enterprise solutions designed for operational security environments. The openness matters. Source-code transparency provides visibility into the OPENVAS SCAN technology. This visibility simplifies security auditing and independent security testing.

The Greenbone ecosystem includes multiple community edition deployment options. Users can run the Community Containers, install natively on Kali Linux, or build components directly from source. But community deployments are only a small part of the Greenbone product offering. Greenbone provides optimized enterprise solutions for organizations that need commercially supported vulnerability management products. Our product line includes enterprise virtual appliances and dedicated hardware appliances.

You Don’t Need to Run Nmap Separately

Wiz correctly highlights Nmap as a robust discovery tool, noting that security practitioners rely on the tool for port scanning. But users don’t need to feed Nmap results into our scanner. Nmap scanning is already integrated into OPENVAS SCAN. Our scan workflow performs robust port discovery before vulnerability assessment.

OPENVAS SCAN includes configurable options for port detection that security teams can tune according to the requirements of the target environment. There is no need to stitch together separate service-discovery and vulnerability detection operations.

More Control Means a More Sophisticated Configuration

In addition to saying that OPENVAS has a “user-friendly console for intuitive control”, Wiz also claims that OPENVAS demands a steep learning curve. There may be some truth to that observation. On the flip side, OPENVAS SCAN is a sophisticated security platform with flexible features. Vulnerability management itself is sophisticated. Giving security teams more options for scan control inevitably introduces more flexibility than a scanner built around a simplified workflow.

OPENVAS SCAN provides granular scan controls and flexible options for configuring targets, scanning behavior, schedules, credentials, results, and operational workflows. For organizations that want automation or integration with virtually any other IT platform, the Greenbone Management Protocol (GMP) and Open Scanner Protocol (OSP) APIs enable extensive programmatic control over OPENVAS SCAN.

Yes, mastering a flexible security platform requires some learning. However, the payoff is that defenders can leverage versatility across very different operational contexts.

Prioritization Goes Beyond Finding CVEs

Finding vulnerabilities is only the first part of vulnerability management. Wiz correctly states that prioritization requires more context than raw severity alone. OPENVAS SCAN already provides important prioritization data, including CVSS severity information, EPSS exploit-probability scores, and CISA Known Exploited Vulnerabilities (KEV) status, helping defenders move from “What vulnerabilities exist?” toward “Which vulnerabilities deserve attention first?” And more risk prioritization tools are on the way!

Without giving away the details just yet, Greenbone will soon be announcing new risk-management capabilities designed to give defenders even better tools to understand, organize, and prioritize vulnerability risk.

Industry Leading Coverage and a Growing List of Scanning Tools

Wiz claims that OPENVAS has “limited coverage, scanning only basic endpoints and networks”. However, Greenbone’s subscription-based detection feed, the OPENVAS ENTERPRISE FEED, provides industry-leading vulnerability detection. Meanwhile, the OPENVAS COMMUNITY FEED provides extensive security coverage for Linux environments and many other widely deployed open-source applications and software stacks.

OPENVAS SCAN is not simply performing a network-surface sweep of a few endpoints. Authenticated scanning delves deep into user space to detect vulnerabilities that cannot be identified from the outside. Containers must also be checked for vulnerabilities in the same way as other IT assets. OPENVAS SCAN can perform container image scans to audit a single container image, multiple container images, or a complete registry.

Since its founding in 2009, Greenbone AG has continuously maintained and advanced the Open Vulnerability Assessment System, better known as OpenVAS. As a result, the two names have become closely linked: mention Greenbone, and OpenVAS is often the first thing that comes to mind. Formerly known as the Greenbone Vulnerability Manager (GVM), OPENVAS SCAN has continued to evolve as well. Important feature upgrades include agent-based and hybrid scanning to complement the traditional agentless authenticated scanning model, container image scanning. Also, a new generation of risk-management capabilities are almost ready to hit the center stage. Greenbone’s product line is also expanding with OPENVAS SECURITY INTELLIGENCE, a new enterprise tool for centralized management, risk analysis, and remediation prioritization across distributed OPENVAS SCAN environments.

Yes, Windows and Linux, but So Much More!

Wiz also claims that OPENVAS is “primarily optimized for Linux and Windows operating systems.” But, that description overlooks how flexible Greenbone deployment actually is. OPENVAS SCAN can be deployed across a range of virtualization environments including, Oracle VirtualBox for macOS and type-1 hypervisors such as VMware ESXi, Proxmox Virtual Environment and Nutanix AHV.

Our supported hypervisor options include:

  • Microsoft Hyper-V, version 8.0 or higher
  • VMware vSphere Hypervisor (ESXi), version 7.0 or higher
  • VMware Workstation Pro, version 17.0 or higher
  • Oracle VirtualBox, version 7.0 or higher
  • Huawei FusionCompute, version 8.0
  • Proxmox Virtual Environment (VE), version 8.0 or higher
  • Nutanix AHV, version 6.8 or higher

Already running Proxmox VE or Nutanix AHV? See how OPENVAS SCAN covers your hypervisor.

A Concluding Thanks to Wiz!

Even Wiz loves Greenbone! Here at Greenbone, we appreciate being listed among the leading vulnerability-management technologies for 2026. The Wiz review recognizes what many of our customers and users already know: OPENVAS is the pinnacle of industry-leading, open-source vulnerability-management platforms. We are also happy to help clarify a few parts of that picture.

Let’s be clear: Greenbone’s open-source transparency goes hand-in-hand with top-notch enterprise deployment. Vulnerability management extends far beyond default scan configurations and push-button scans. Sure, OPENVAS SCAN has these. But powerful configuration options should not be mistaken for unnecessary complexity. Greenbone’s existing risk-prioritization tools support defenders with core risk metrics after vulnerabilities have been discovered.

Be on the lookout for several new features that will extend the number of options that defenders have for prioritized risk-driven vulnerability management and exposure management! Contact Greenbone’s sales team to discuss how enterprise-grade compliance scanning with OPENVAS SCAN can best support your organization’s regulatory and security governance requirements.

➡

Start Your Free Trial

Grabbing a copy of OPENVAS SCAN with a free two-week trial of the OPENVAS ENTERPRISE FEED is a surefire way to gain the deepest insight into where software vulnerabilities exist in your organization’s Linux infrastructure.

 

Contact Test Now Buy Here Back to Overview
21. August 2026/by Joseph Lee
https://www.greenbone.net/wp-content/uploads/greenbone-logo-2025.png 0 0 Joseph Lee https://www.greenbone.net/wp-content/uploads/greenbone-logo-2025.png Joseph Lee2026-08-21 12:56:352026-08-21 12:56:35Wiz Loves OPENVAS! Our Take on Being a Top Vulnerability Management Tool of 2026
Joseph Lee

CVE-2026-8037 Now Actively Exploited! Unauthenticated RCE in Progress Kemp LoadMaster and ECS Connection Manager

Blog

CVE-2026-8037 (CVSS 9.8, EPSS >= 100th pctl) is a critical, unauthenticated remote code execution (RCE) vulnerability in Progress Kemp LoadMaster and Progress ECS Connection Manager. eSentire reported that exploitation attempts began on June 29th, 2026, and the flaw has now been added to CISA’s Known Exploited Vulnerabilities (KEV) list. watchTowr Labs published a separate technical write-up with PoC exploit code, further increasing the risk and multiple national CERT alerts have been issued [1][2][3][4][5][6].

The OPENVAS ENTERPRISE FEED has included a remote banner check since June 8th, that covers both CVE-2026-8037 and CVE-2026-33691, an active check for detecting CVE-2026-8037 exploitability in Progress Kemp LoadMaster, and a separate remote banner check for Progress Kemp ECS Connection Manager. Grabbing a copy of OPENVAS SCAN with a free two-week trial of the OPENVAS ENTERPRISE FEED is a surefire way to gain the deepest insight into where software vulnerabilities exist in your organization’s IT infrastructure.

Critical Kemp LoadMaster RCE now actively exploited

Successful exploitation of CVE-2026-8037 results in code execution with root-level privileges. When the API is enabled, the vulnerable path is reachable via the /accessv2 endpoint. Researchers attribute the flaw to improper handling of user-supplied input [CWE-20] in the escape_quotes() function, which can allow access to uninitialized heap memory. CVE-2026-8037 was disclosed by the vendor alongside CVE-2026-33691 (CVSS 7.5), a flaw in the OWASP Core Rule Set (CRS), which is a component of the same products.

A Risk Assessment for CVE-2026-8037

CVSS 9.8 · CriticalActively exploitedIn CISA KEVPublic PoC

CVE-2026-8037, affecting Progress Kemp LoadMaster is now considered actively exploited [1][2]. The flaw is a critical, pre-authentication RCE flaw that can be reached via the /accessv2 endpoint when the API is enabled. Exploitation allows an unauthenticated attacker to execute code with root-level privileges.

LoadMaster is used for load balancing enterprise application delivery, reverse proxying, SSL offloading, WAF-enabled high availability, and other networking functions. LoadMaster appliances are frequently positioned at the network edge and can have visibility into critical internal services, making a breach especially valuable to attackers. In operational terms, a pre-authentication RCE on a critical networking appliance in this position can provide a strong foothold for further activity inside the target network.

Mitigation of CVE-2026-8037 in Progress Kemp LoadMaster and ECS Connection Manager

Progress has published a security advisory with the fixed releases for both supported LoadMaster branches and ECS Connection Manager. The vendor indicates that patching is the only remediation path for CVE-2026-8037. Affected products include:

  • Progress Kemp ECS Connection Manager prior to version 7.2.63.2
  • Progress Kemp LoadMaster (GA) version 7.2.63.1 and prior
  • Progress Kemp LoadMaster (LTSF) version 7.2.54.17 and prior

The OPENVAS ENTERPRISE FEED has included a remote banner check since June 8th, that covers both CVE-2026-8037 and CVE-2026-33691, an active check for detecting CVE-2026-8037 exploitability in Progress Kemp LoadMaster, and a separate remote banner check for Progress Kemp ECS Connection Manager.

➡

Start Your Free Trial

The OPENVAS ENTERPRISE FEED includes a remote_banner check for CVE-2026-8037 and every other CVE in this advisory. Grab a copy of OPENVAS SCAN with a free two-week trial of the OPENVAS ENTERPRISE FEED to gain the deepest insight into where software vulnerabilities exist in your organization’s IT infrastructure.

Summary

CVE-2026-8037 is a critical, pre-authentication RCE flaw in Progress Kemp LoadMaster that is now considered actively exploited [1][2]. The vulnerable path can be reached through the /accessv2 API endpoint. Exploitation allows an attacker to execute code with root-level privileges. A full technical description and functional PoC are also available, increasing the risk.

The OPENVAS ENTERPRISE FEED has included a remote banner check since June 8th, that covers both CVE-2026-8037 and CVE-2026-33691, an active check for detecting CVE-2026-8037 exploitability in Progress Kemp LoadMaster, and a separate remote banner check for Progress Kemp ECS Connection Manager. Grabbing a copy of OPENVAS SCAN with a free two-week trial of the OPENVAS ENTERPRISE FEED is a surefire way to gain the deepest insight into where software vulnerabilities exist in your organization’s IT infrastructure.

 

Contact Test Now Buy Here Back to Overview
20. August 2026/by Joseph Lee
https://www.greenbone.net/wp-content/uploads/greenbone-logo-2025.png 0 0 Joseph Lee https://www.greenbone.net/wp-content/uploads/greenbone-logo-2025.png Joseph Lee2026-08-20 11:04:082026-08-20 11:04:08CVE-2026-8037 Now Actively Exploited! Unauthenticated RCE in Progress Kemp LoadMaster and ECS Connection Manager
Joseph Lee

Patch Now! Two Actively Exploited CVEs Affecting VMware vCenter Server and More

Blog

Broadcom published VMSA-2026-0006 on July 29th, 2026, to address five vulnerabilities affecting VMware ESX, VMware vCenter Server, VMware Workstation, and VMware Fusion. The highest-risk issues are CVE-2026-59309 (CVSS 9.8) and CVE-2026-59310 (CVSS 9.8) affecting VMware vCenter Server. Both can be exploited by an unauthenticated attacker with network access to achieve remote code execution (RCE).

Technical details for CVE-2026-59310 and CVE-2026-59309 were published immediately after their disclosure, but no proof-of-concept exploits are publicly available. On August 11th, Defused Cyber reported probing for CVE-2026-59309. QUIRSO GmbH reports that in-the-wild exploitation of CVE-2026-59309 and CVE-2026-59310 is already underway [1][2][3]. Neither CVE is on CISA’s Known Exploited Vulnerabilities (KEV) list. Numerous national CERT agencies have issued alerts [4][5][6][7][8][9][10][11][12][13][14][15][16][17][18].

The VMSA-2026-0006 advisory also disclosed three additional flaws. CVE-2026-47876 (CVSS 9.3) is an out-of-bounds write flaw affecting the ESX VMXNET3 network adapter. Exploitation can allow a guest administrator to execute code on the host. The other two flaws are CVE-2026-41703 (CVSS 7.6) affecting VMware ESX, Workstation, and Fusion, and CVE-2026-41709 (CVSS 2.7) affecting ESX.

VMware vCenter Under Active Attack

VMware vCenter Under Active Attack

➡

Start Your Free Trial

Greenbone’s OPENVAS ENTERPRISE FEED addresses CVE-2026-59309 and CVE-2026-59310 with a remote banner version check for VMware vCenter Server. It also includes VMware ESXi package-level detection for CVE-2026-41703 [1], CVE-2026-47876 [2], and CVE-2026-41709 [3]. For defenders seeking to detect and protect, a trial copy of OPENVAS SCAN includes a free two-week trial of the OPENVAS ENTERPRISE FEED. Greenbone’s cyber security products are a surefire way to gain the deepest insight into where software vulnerabilities exist across your organization’s infrastructure.

A Risk Assessment of VMware vCenter and ESX Vulnerabilities in VMSA-2026-0006

Technical details for CVE-2026-59310 and CVE-2026-59309 affecting VMware vCenter Server were published immediately after their disclosure, but no proof-of-concept exploits are publicly available. Both CVEs can be exploited remotely by an attacker without authentication. Public reporting indicates that in-the-wild exploitation of both CVEs is already underway [1][2][3].

VMware vCenter Server poses high risk because it provides centralized management of virtualized hosts and virtual machines from a single console. In practical terms, a compromise of VMware vCenter Server can affect a management layer for critical virtual machine hosts and workloads.

The ESX issues present a different but still important risk profile. CVE-2026-47876 requires local administrative control inside a guest VM that uses the VMXNET3 adapter. However, the consequence is high—host-level code execution. CVE-2026-41703 requires VM deployment privileges and can cause information disclosure or trigger a Denial of Service (DoS) condition in the host process. CVE-2026-41709 is low severity, but it weakens audit visibility by allowing certain administrator actions to bypass logging.

CVE-2026-59309: Actively Exploited vCenter Authentication Bypass

CVSS 9.8 · CriticalActively exploited

An attacker with network access to VMware vCenter Server can bypass authentication and gain unauthorized access to the system. The root cause is incorrect implementation of an authentication algorithm [CWE-303]. The flaw affects the VMware Directory Service.

CVE-2026-59310: Actively Exploited vCenter Directory Traversal RCE

CVSS 9.8 · CriticalActively exploited

A directory traversal flaw in the VMware vCenter Server Syslog component allows an unauthenticated remote attacker to execute arbitrary code. The root cause is improper limitation of a pathname to a restricted directory [CWE-22].

Other CVEs Disclosed in VMSA-2026-0006

The VMSA-2026-0006 advisory also disclosed three additional, lower-severity flaws affecting VMware ESX, Workstation, and Fusion:

The three additional CVEs disclosed in VMSA-2026-0006, each shown with its CVSS severity band and EPSS exploitation-probability score

CVE-2026-47876
CVSS 9.3 · Critical EPSS 0.281% (20th)

A critical out-of-bounds memory write condition [CWE-787] in the VMware ESX VMXNET3 virtual network adapter. Exploitation allows an attacker with local admin privileges on a VM to execute code on the ESX host. The flaw only affects guest VMs using the default VMXNET3 adapter. Other network adapters are not reported to be affected by CVE-2026-47876.

CVE-2026-41703
CVSS 7.6 · High EPSS 0.556% (44th)

An out-of-bounds read flaw [CWE-125] that allows information disclosure or DoS of the host process. Exploitation requires VM deployment privileges. CVE-2026-41703 affects VMware ESX as well as VMware Workstation and Fusion. Broadcom reports that the impact on VMware Workstation and VMware Fusion is restricted to information disclosure.

CVE-2026-41709
CVSS 2.7 · Low EPSS 0.382% (31st)

A low-severity issue in VMware ESX causes certain operations not to be logged [CWE-778].

Mitigation for CVEs Disclosed in VMSA-2026-0006

Organizations should map their installed versions to the affected and fixed releases in Broadcom’s VMSA-2026-0006 advisory and apply the vendor-provided updates. No workarounds are available for any of the CVEs.

CVE-2026-59309 and CVE-2026-59310 are the most urgent because both are exploitable to an unauthenticated attacker with network access to an affected VMware vCenter instance. CVE-2026-47876 should be prioritized where VMware ESX guest VMs use the VMXNET3 adapter because exploitation allows virtual machine escape and code execution on the ESX host. CVE-2026-41703 should have increased priority for VMware ESX instances that manage critical operations since it can be exploited to trigger DoS conditions. The VMware ESX flaw CVE-2026-41709 should be patched where audit completeness is important.

Summary

Broadcom’s VMSA-2026-0006 bundles five VMware vulnerabilities across VMware vCenter Server, VMware ESX, VMware Workstation, and VMware Fusion. The highest-risk exposure is concentrated in CVE-2026-59310 and CVE-2026-59309. Both are critical-severity and actively exploited flaws affecting VMware vCenter Server [1][2][3].

Greenbone’s OPENVAS ENTERPRISE FEED addresses CVE-2026-59309 and CVE-2026-59310 with a remote banner version check for VMware vCenter Server. It also includes VMware ESXi package-level detection for CVE-2026-41703 [1], CVE-2026-47876 [2], and CVE-2026-41709 [3]. For defenders seeking to detect and protect, a trial copy of OPENVAS SCAN includes a free two-week trial of the OPENVAS ENTERPRISE FEED. Greenbone’s cyber security products are a surefire way to gain the deepest insight into where software vulnerabilities exist across your organization’s infrastructure.

 

Contact Test Now Buy Here Back to Overview
19. August 2026/by Joseph Lee
https://www.greenbone.net/wp-content/uploads/greenbone-logo-2025.png 0 0 Joseph Lee https://www.greenbone.net/wp-content/uploads/greenbone-logo-2025.png Joseph Lee2026-08-19 09:02:082026-08-19 09:02:08Patch Now! Two Actively Exploited CVEs Affecting VMware vCenter Server and More
Joseph Lee

Lazarus Combines Social Engineering and CVE-2026-68820 Windows Privilege-Escalation Flaw for Espionage

Blog

Operation Dream Job is a long-running cyber attack campaign operated by the Lazarus Group [1][2], a prolific North Korean APT threat actor. The group is known for targeting defense, aerospace, and aviation organizations across Europe, Asia, and South America since at least 2016, potentially as far back as 2009 or earlier. Public reporting has often used the name “Lazarus” loosely to describe a wide range of hacking groups associated with North Korea. In recent years, North Korean threat actors have exploited employment as a means of infiltrating organizations using stolen or fabricated identities, and as a trap for compromising job seekers as part of broader social engineering campaigns.

Lazarus Exploits Windows Flaw for Espionage

Lazarus Exploits Windows Flaw for Espionage

In the most recent campaigns, attackers are using fake job interviews to trick victims into opening malicious documents or installing trojanized PDF readers for initial access. Once inside, attackers exploit a recently disclosed Windows flaw, CVE-2026-68820, for local privilege escalation and rootkit installation. The campaign has also leveraged CVE-2025-49113 to compromise Roundcube servers for use as command-and-control (C2) relays. Both CVE-2026-68820 and CVE-2025-49113 are on CISA’s Known Exploited Vulnerabilities (KEV) list [1][2].

Greenbone’s OPENVAS ENTERPRISE FEED includes registry analysis detection for CVE-2026-68820 in Windows Server 2025, Windows Server 2022, Windows Server 2019, Windows 11, and Windows 10, and regular detection for Microsoft vulnerabilities. The ENTERPRISE FEED also includes Linux package-level detection and remote banner detection for CVE-2025-49113 affecting Roundcube Webmail since soon after its disclosure and regular detection for Roundcube vulnerabilities.

Grabbing a copy of OPENVAS SCAN with a free two-week trial of the OPENVAS ENTERPRISE FEED is a surefire way to gain the deepest insight into software vulnerabilities in your organization’s IT infrastructure.

Understanding the Recent Operation Dream Job Campaign

According to Check Point, the latest Operation Dream Job wave targets professionals and organizations in the defense sector for espionage. Attackers installed malware modules capable of capturing and exfiltrating screenshots, and stealing selected files.

First-stage social engineering attacks involve impersonation of job recruiters and presenting fake job offers to lure victims into opening malicious files [T1204.002] or installing trojanized PDF viewers [T1204]. Attackers then deploy malware including MISTPEN, ForestTiger, and a malicious DLL implant [T1055.001] dubbed Troy, which was previously unknown.

After gaining initial access, attackers exploited CVE-2026-68820, disclosed in Microsoft’s August patch release, for privilege escalation [TA0004]. Elevated privileges are then used to deploy a Windows rootkit [T1014], evade Endpoint Detection and Response (EDR) tools, and suppress logging [T1685.001][T1685.005]. Roundcube Webmail servers compromised via CVE-2025-49113 are being used as command-and-control relays [T1090.002], helping malicious network traffic appear legitimate to security tools.

Understanding CVE-2026-68820 in Windows AFD.sys

CVSS 7.0 · HighActively exploitedIn CISA KEV

CVE-2026-68820 was first disclosed on August 11th, 2026, in Microsoft’s August Patch Tuesday batch, along with 420 other new CVEs. No public proof-of-concept exploit code is yet available for CVE-2026-68820. However, in recent attacks, Lazarus exploited CVE-2026-68820 for local privilege escalation after gaining initial access. The elevated permissions were used to deploy a Windows rootkit.

Technical Details for CVE-2026-68820

CVE-2026-68820 (CVSS 7.0) is a use-after-free flaw [CWE-416] in afd.sys, the Windows Ancillary Function Driver for WinSock. Exploitation allows local privilege escalation to the SYSTEM level by abusing flawed handling of socket state. When several threads access a socket concurrently, two driver paths can operate on the same state without sufficient synchronization [CWE-362], resulting in an exploitable race condition.

Detailed exploit mechanics are not publicly available. However, a broader pattern of afd.sys weaknesses is also evident. Several documented examples involve race conditions and use-after-free behavior [1][2][3][4][5][6].

Mitigating CVE-2026-68820 in Windows AFD.sys

Organizations should apply Microsoft’s August 2026 security updates to Windows systems as soon as possible. Greenbone’s OPENVAS ENTERPRISE FEED includes registry analysis detection for CVE-2026-68820 in Windows Server 2025, Windows Server 2022, Windows Server 2019, Windows 11, and Windows 10, and regular detection for Microsoft vulnerabilities. Given the actively exploited status of CVE-2026-68820, security teams should monitor for suspicious SYSTEM-level activity that may indicate a security breach.

Understanding CVE-2025-49113 in Roundcube Webmail

CVSS 8.8 · HighActively exploitedIn CISA KEVPublic PoC

CVE-2025-49113 was published in June 2025. Its release was quickly followed by multiple detailed technical analyses and proof-of-concept exploit samples [1][2][3][4][5][6]. In the Operation Dream Job campaign, compromised Roundcube servers were infected with a PHP web shell and used as relay nodes to hide malicious C2 communication with the victim’s breached computer. Defenders should pay special attention to Roundcube because it has frequently been leveraged in cyber attacks.

Technical Details for CVE-2025-49113

CVE-2025-49113 (CVSS 8.8, EPSS 97.694%, 100th percentile) is a post-authentication remote code execution (RCE) vulnerability. The root cause is flawed PHP object deserialization [CWE-502] that stems from an unvalidated _from parameter in program/actions/settings/upload.php. By supplying malicious input, an authenticated attacker can inject a malicious PHP object that is instantiated during deserialization. Public exploit chains use the Crypt_GPG_Engine class as a gadget: when the object is destroyed, attacker-controlled properties can trigger shell code execution in the context of the web server process.

Mitigating CVE-2025-49113 in Roundcube Webmail

No workaround mitigations for CVE-2025-49113 have been published by the vendor. The primary mitigation is to update affected Roundcube Webmail deployments to a fixed release. Roundcube patched CVE-2025-49113 in the 1.5 LTS and 1.6 branches in June 2025. However, since then, several additional critical-severity CVEs have been identified in Roundcube, which warrants further upgrading.

Also, Roundcube 1.5.x is no longer supported or maintained as of the 1.7.0 release on May 10th, 2026. For ongoing security updates, users should migrate from 1.5.x to Roundcube 1.7.3. Those on the LTS branch should update to 1.6.18. Greenbone’s ENTERPRISE FEED includes Linux package-level detection and remote banner detection for CVE-2025-49113 in Roundcube Webmail since soon after its disclosure and regular detection for Roundcube vulnerabilities. Defenders should pay special attention to Roundcube because it has frequently been leveraged in cyber attacks.

Summary

The latest Operation Dream Job activity combines recruiter-themed social engineering with exploitation of CVE-2026-68820 to escalate privileges and deploy stealth-focused malware on compromised Windows systems. Roundcube Webmail servers exploited via CVE-2025-49113 are being used as relay infrastructure to conceal C2 traffic.

Greenbone’s OPENVAS ENTERPRISE FEED includes registry analysis detection for CVE-2026-68820 in Windows Server 2025, Windows Server 2022, Windows Server 2019, Windows 11, and Windows 10, and regular detection for Microsoft vulnerabilities. Also, the ENTERPRISE FEED includes Linux package-level detection and remote banner detection for CVE-2025-49113 in Roundcube Webmail since soon after its disclosure and regular detection for Roundcube vulnerabilities.

Organizations should prioritize patching both vulnerabilities and monitor for the associated intrusion techniques, particularly in defense, aerospace, aviation, and other high-value environments. Grabbing a copy of OPENVAS SCAN with a free two-week trial of the OPENVAS ENTERPRISE FEED is a surefire way to gain the deepest insight into software vulnerabilities in your organization’s IT infrastructure.

 

Contact Test Now Buy Here Back to Overview
17. August 2026/by Joseph Lee
https://www.greenbone.net/wp-content/uploads/greenbone-logo-2025.png 0 0 Joseph Lee https://www.greenbone.net/wp-content/uploads/greenbone-logo-2025.png Joseph Lee2026-08-17 10:39:142026-08-17 11:45:26Lazarus Combines Social Engineering and CVE-2026-68820 Windows Privilege-Escalation Flaw for Espionage
Joseph Lee

Threat Report July 2026: Vulnpocolypse – Just Scratching the Surface?

Blog

Plenty of new risks to enterprise IT defenders emerged in July 2026. Earlier this month, our blog covered emerging issues such as active exploitation of WordPress Core [2], Adobe ColdFusion [3] and Check Point SmartConsole [4]; new critical-severity flaws in Cisco products [5], BeyondTrust RS and PRA [6], and Citrix NetScaler ADC and Gateway [7]; and a flood of Linux CVEs that include new active exploitation [8][9]. In this blog post, we will briefly examine the so-called “vulnpocolypse“ and cover the highest-risk software vulnerabilities that have not already been covered on our blog.

For defenders seeking to detect and protect, a trial copy of OPENVAS SCAN includes a free two-week trial of the OPENVAS ENTERPRISE FEED. Greenbone’s cyber security products are a surefire way to gain the deepest insight into where software vulnerabilities exist across your organization’s infrastructure.

July 2026 Threat Report: Vulnpocolypse

Threat Report July 2026: Vulnpocolypse

For those embroiled in the AI cyber security hype cycle, waves of AI vulnerability reports are swamping inboxes. Even defenders focused simply on patching and protecting their IT infrastructure have been inundated by unusually voluminous vulnerability disclosures affecting widely deployed software [1][2][3][4]. Are we waiting for the dust to settle, or will the storm gain even more momentum?

It’s prudent to ask: Is the so-called “vulnpocolypse” making an everlasting dent in the number of software bugs that defenders need to fear going forward? Or is the IT industry merely scratching the surface of accumulated technical debt? Again, only time will reveal the true level of exposure. Finally, as CISA points out in its new security guidance for Open Source Software, trust should be a key driver when selecting and deploying enterprise software.

CVE-2026-6875: ServiceNow AI Platform Actively Exploited

CVSS 7.6 · HighActively exploitedPublic PoC

CVE-2026-6875 (CVSS 7.6, EPSS ≥ 98th pctl) allows an unauthenticated attacker to achieve remote code execution (RCE) by escaping the server-side script sandbox in the ServiceNow AI Platform if the assessment_thanks.do endpoint is reachable. The unauthenticated assessment_thanks.do endpoint passes the attacker-controlled sysparm_assessable_type parameter into the GlideRecord.addQuery() function. Values prefixed with javascript: are evaluated in ServiceNow’s Rhino script sandbox. Attackers can leverage the gs.include() function and shared global JavaScript objects to escape the sandbox boundary.

Exploitation allows full compromise of a ServiceNow instance and connected proxy servers. In-the-wild exploitation has been reported. Although CVE-2026-6875 is not on CISA’s KEV list, two previous ServiceNow CVEs were added in 2024. A public proof-of-concept exploit and detailed technical analysis are available, increasing the risk of cyber attacks. Several national CERT agencies have issued alerts for CVE-2026-6875 [1][2][3][4][5].

No workaround mitigations are described by the vendor. However, a Cloud Security Alliance (CSA) report refers to standard mitigation measures: restricting network access via firewall rules, or using web application firewall (WAF) to block exploitation attempts. Self-hosted ServiceNow users must upgrade to Australia Patch 2; Yokohama Patch 12 Hot Fix 1b or Patch 13; Zurich Patch 7b or Patch 9; or Brazil EA or GA. Patched releases remove the vulnerable behavior and introduce a sandbox-hardening feature named Guarded Script. ServiceNow also recommends reviewing logs for suspicious unauthenticated script execution or access to the assessment_thanks.do endpoint.

Greenbone’s OPENVAS ENTERPRISE FEED includes a remote banner check to identify ServiceNow instances affected by CVE-2026-6875.

Emerging Risks to Microsoft Products: More Active Exploitation

Microsoft products faced renewed exploitation pressure in July, led by actively exploited SharePoint flaws. A public PoC for an Exchange Server vulnerability adds further urgency for defenders.

CISA Warns of Microsoft SharePoint Exploit Campaigns

CVSS 9.8 · CriticalActively exploitedIn CISA KEV

An out-of-band Microsoft security advisory in July 2026 disclosed 37 unique CVEs affecting SharePoint, with impacts such as RCE, privilege escalation, spoofing, and information disclosure. In July, CISA also warned that threat actors are leveraging several CVEs in Microsoft SharePoint Server Subscription Edition, 2019, and 2016 to gain unauthorized access and achieve RCE. Post-exploitation activity includes stealing IIS machine keys, abusing ASP.NET view state deserialization, and deploying malware.

The highest-risk SharePoint CVEs published in July 2026 are:

  • CVE-2026-58644 (CVSS 9.8, EPSS ≥ 91st pctl): A remote attacker authenticated as a Site Owner or higher privilege level can execute arbitrary code on a Microsoft SharePoint Server. The flaw is caused by deserialization of untrusted data [CWE-502]. CVE-2026-58644 is considered actively exploited in the wild and was added to CISA’s KEV catalog two days after disclosure. Neither a public PoC exploit nor a full technical analysis is yet available for CVE-2026-58644.
  • CVE-2026-50522 (CVSS 9.8, EPSS ≥ 99th pctl): Allows an unauthorized attacker to execute code over a network. The root cause is deserialization of untrusted data [CWE-502]. CVE-2026-50522 has been added to CISA’s KEV list.
  • CVE-2026-56164 (CVSS 9.8, EPSS 97th pctl): Allows an unauthorized attacker to elevate privileges over a network. The root cause is missing authentication for a critical function [CWE-306]. Neither CISA or Microsoft have reported active exploitation. Detailed technical descriptions or PoC exploits are not publicly available.
  • CVE-2026-55040 (CVSS 9.1, EPSS ≥ 69th pctl): Weak authentication [CWE-1390] allows an unauthorized attacker to bypass a security feature over a network. Neither CISA or Microsoft have reported active exploitation. Detailed technical descriptions or PoC exploits are not publicly available.

CISA’s alert on new attacks targeting SharePoint provides additional recommendations for defenders. These include shortening patching cycles, enabling Antimalware Scan Interface (AMSI) for each SharePoint site, restricting SharePoint Central Administration, farm and database communications to only required systems, avoiding exposure of SharePoint Servers to the public internet, and more. Organizations should patch promptly because exposed SharePoint servers remain attractive enterprise targets. Greenbone’s OPENVAS ENTERPRISE FEED includes regular vulnerability detection across many Microsoft products, including all the CVEs referenced above.

CVE-2026-45504: Public PoC Exploit for Microsoft Exchange Server 2019

CVSS 8.8 · HighPublic PoCNo known exploitation

CVE-2026-45504 (CVSS 8.8) allows authenticated, low-privileged users to read arbitrary files from on-premises Microsoft Exchange Server 2019. The CVE is classified as a Server-Side Request Forgery (SSRF) flaw [CWE-918]. The root cause is missing URL scheme validation in the OneDrive and WOPI integration. Using a malicious Exchange Web Services (EWS) reference attachment and WOPI response, an attacker can force Exchange to process a malicious file URI. Exploitation allows an attacker to bypass appended OAuth parameters and gain access to configuration files, credentials, and other sensitive local data.

No active exploitation, ransomware use, or associated campaigns have been reported. However, a detailed technical analysis and PoC exploit code are publicly available, increasing the risk. Several national CERT agencies have issued alerts for CVE-2026-45504 [1][2][3][4][5][6][7][8]. For defenders seeking to detect and protect, the OPENVAS ENTERPRISE FEED includes:

  • A remote version check for Microsoft Exchange Server 2016, Server 2019, and Subscription Edition (SE)
  • An executable version check for Microsoft Exchange Server 2016 Cumulative Update 23
  • Executable version checks for Microsoft Exchange Server 2019 Cumulative Update 14 and 15 [1][2]

Living on the Edge: Emerging Threats to Perimeter Security

Vulnerabilities in network perimeter devices are particularly high risk because they are exposed to attack by arbitrary remote attackers. According to the latest Verizon DBIR 2026 report, exploiting publicly exposed software vulnerabilities is now the most common vector for initial access globally. Here are some of the most critical emerging threats to perimeter devices in July 2026.

SonicWall SMA 1000 Appliances Actively Exploited

CVSS 10 · CriticalActively exploitedIn CISA KEVPublic PoCRansomware-linked
!

Update

CISA has updated its Known Exploited Vulnerabilities (KEV) catalog to indicate that CVE-2026-15409 and CVE-2026-15410 are now associated with ransomware campaigns.

CVE-2026-15409 and CVE-2026-15410 were both published on July 14th, 2026, and added to CISA’s KEV list on the same day [1][2]. The CVEs affect SonicWall Secure Mobile Access (SMA) 1000 Series models 6210, 7210, and 8200v. According to a forensic report, exploitation of the flaws began well before their disclosure. Full technical analysis [3][4] and PoC exploits [5][6] are available for CVE-2026-15409. Numerous national CERT agencies have issued alerts globally [7][8][9][10][11][12][13][14][15][16][17][18][19][20]. SonicWall SMA 1000 is on CISA’s KEV list 17 times, 10 entries associated with ransomware attacks, indicating high risk.

The SMA 1000 Series functions as an enterprise secure-access gateway that combines SSL VPN and Zero Trust controls to connect remote users to internal, cloud-hosted, and hybrid applications. Details on each new actively exploited CVE are included below:

  • CVE-2026-15409 (CVSS 10, EPSS = 100th pctl): A maximum-severity flaw that allows unauthenticated attackers to execute Server-Side Request Forgery (SSRF) [CWE-918] attacks via the Work Place interface. The root cause is a vulnerable /wsproxy endpoint that processes User-Agent and bmID values to establish WebSocket tunnels to services accessible only through the appliance’s loopback interface.
  • CVE-2026-15410 (CVSS 7.2, EPSS ≥ 99th pctl): Allows authenticated administrators to inject code into the Appliance Management Console to execute arbitrary OS commands [CWE-94] with root-level privileges. The root cause is a flawed hotfix-removal workflow that allows path traversal [CWE-35] to execute an attacker-supplied shell script as root.

Chaining the two flaws provides unauthenticated, root-level control of an affected SMA 1000 appliance as described below:

  • Initial access: An unauthenticated attacker exploits CVE-2026-15409 in the /wsproxy WebSocket proxy by supplying a crafted host parameter, forcing the appliance to connect to local-only services such as the internal Erlang process on port 1050.
  • Privilege escalation: The attacker then exploits CVE-2026-15410 by sending a path-traversal payload to rollbackConfirm.action, causing the hotfix-removal workflow to execute an attacker-provided shell script as root before rebooting.

After gaining root, the attackers deployed custom malware for code execution and covert tunneling, installed web shells for remote access, and added persistence mechanisms to maintain root access. Malicious Java components were injected into a legitimate SonicWall process to evade routine monitoring, and packet-capture tooling was used to collect LDAP credentials and expand access to internal directory services [21].

No workarounds are described by the vendor. SonicWall strongly recommends immediately installing the applicable platform hotfix and investigating for signs of compromise. Greenbone’s OPENVAS ENTERPRISE FEED includes a remote banner version check to detect both CVEs and an active check specific to CVE-2026-15409.

CVE-2026-20316: Cisco Secure Firewall Management Center (FMC) Actively Exploited

CVSS 5.3 · MediumActively exploitedIn CISA KEV

CVE-2026-20316 (CVSS 5.3) allows an unauthenticated, remote attacker to log in to an affected device as a low-privileged user via hardcoded user credentials [CWE-259]. The flaw affects the web interface of Cisco Secure Firewall Management Center (FMC) Software. Several cyber security experts expressed shock that hardcoded credentials remain in Cisco products.

CVE-2026-20316 is being actively exploited and was added to CISA’s KEV list the same day it was disclosed. The nominal CVSS score of 5.3 understates the operational risk. Cisco has assigned CVE-2026-20316 a Security Impact Rating (SIR) of High and specifically warns that the flaw can be combined with other FMC vulnerabilities to elevate privileges on unpatched devices. Several national CERT agencies have issued alerts for CVE-2026-20316 [1][2][3][4][5].

Cisco Secure FMC versions 7.0, 7.2, 7.4, 7.6, 7.7, and 10.0 are affected. Cisco has released hotfix patches for affected products. If patches cannot be applied, risk can be reduced by preventing public internet access to the FMC management interface. The OPENVAS ENTERPRISE FEED includes a remote banner check, allowing defenders to identify vulnerable devices.

New High-Risk Flaws Affecting Palo Alto Networks PAN-OS

CVSS 9.9 · CriticalNo known exploitation

Palo Alto Networks has released patches for 13 new CVEs. Eleven of the CVEs affect PAN-OS and various components that run on the operating system. The most critical new CVEs from Palo Alto Networks’ July 2026 disclosures are:

  • CVE-2026-0284 (CVSS 9.9): An XML injection vulnerability in the Large Scale VPN (LSVPN) functionality of PAN-OS enables an unauthenticated attacker with network access to inject malicious XML content. Exploitation allows information disclosure or corruption of internal LSVPN satellite data.
  • CVE-2026-0288 (CVSS 7.5): Multiple buffer overflow vulnerabilities in the User-ID Terminal Server Agent (TSA) component of PAN-OS allows an unauthenticated attacker with network access to cause a Denial of Service (DoS) condition or potentially execute arbitrary code by sending specially crafted network traffic. The security risk posed by this issue is minimized when the User-ID Terminal Server Agent connectivity is restricted to only trusted internal IP addresses

There are no reports of active exploitation for the new CVEs. However, organizations should promptly apply the latest updates and restrict access to sensitive services, particularly the User-ID Terminal Server Agent. See Palo Alto Networks’ security advisory page for affected versions and patches. Greenbone’s OPENVAS ENTERPRISE FEED includes authenticated scan detection for all of Palo Alto Networks’ new CVEs that impact PAN-OS and its components.

Two New Flaws Affecting Gitea Include Exploitation Attempts

CVSS 9.8 · CriticalActively exploitedPublic PoC

Two new Gitea vulnerabilities present elevated risk among nine newly disclosed flaws. Of these, Sysdig has reported in-the-wild exploitation attempts targeting CVE-2026-20896.

Here are the details for both emerging high-risk CVEs:

  • CVE-2026-20896 (CVSS 9.8): Unauthenticated remote attackers can bypass reverse-proxy authentication [CWE-284] to access repositories and secrets. Gitea’s official Docker image uses an app.ini template that hard-codes a wildcard allowlist (REVERSE_PROXY_TRUSTED_PROXIES=* ). Exploitation requires only access to the Gitea port and a valid username. CVE-2026-20896 is reportedly being actively exploited against internet-accessible instances. Several PoC exploits have been published [1][2][3]. Gitea’s official Docker images before version 1.26.3 are affected.
  • CVE-2026-27771 (CVSS 8.2): Unauthenticated remote attackers can pull private container images. The root cause is a broken authorization design [CWE-862] in which anonymous JSON Web Tokens (JWTs) are accepted by ungated registry read endpoints, while package visibility was never bound to repository privacy. Exploitation may allow disclosure of credentials, API keys, TLS certificates, production configurations, and compiled source code. A detailed technical analysis [4] and PoC exploit code [5] are available. Gitea’s built-in OCI container registry before version 1.26.2 are affected.

An estimated ~31,000 Gitea instances are publicly exposed globally. The OPENVAS ENTERPRISE FEED includes a remote banner check and a remote application check for CVE-2026-20896 [6][7], as well as a separate remote banner check and an active check to identify Gitea instances affected by CVE-2026-27771 [8][9].

CVE-2026-63077: Critical Flaw Affecting JetBrains TeamCity On-Premises

CVSS 9.8 · CriticalActively exploited
!

Update

On August 5, 2026, CISA added CVE-2026-63077 to its Known Exploited Vulnerabilities (KEV) catalog following evidence of active exploitation.

CVE-2026-63077 (CVSS 9.8, EPSS ≥ 47th pctl) allows unauthenticated RCE against all previous versions of TeamCity On-Premises. The root cause is deserialization of untrusted data [CWE-502] in the agent polling protocol. Successful exploitation allows an attacker to execute commands with the privileges of the TeamCity server process. A compromise could expose stored credentials, alter build artifacts, and compromise downstream CI/CD pipelines.

No active exploitation, public PoC, or full exploit-level technical disclosure had been reported for CVE-2026-63077 as of August 1st, 2026. However, TeamCity has been added to CISA’s KEV list three times, each entry associated with ransomware attacks. Greenbone’s OPENVAS ENTERPRISE FEED includes a remote banner version check to identify unpatched versions of TeamCity On-Premises. Organizations should update to version 2025.11.7 or 2026.1.3, or enable the automatic updates option within TeamCity. For organizations unable to upgrade, a security patch is available.

CVE-2026-14266: 7-Zip Flaw Allows Remote Code Execution

CVSS 7 · HighPublic PoCNo known exploitation

CVE-2026-14266 (CVSS 7.0) is a newly disclosed flaw affecting 7-Zip versions before 26.02. The flaw allows remote attackers to execute arbitrary code. The root cause is incorrect writable-space tracking in the XZ decoder, which can lead to a heap-based buffer overflow [CWE-122]. Each decoder invocation is incorrectly given the full output-buffer size, causing decoders to overestimate the remaining writable space after partial output. Exploitation requires a target to open a malicious XZ archive. The impact is code execution with the current user’s privileges.

There are no reports of active exploitation. However, a detailed technical write-up with a PoC exploit generator is publicly available. The existence of public PoC exploit generator, even in the early stages of development, means that low-skilled attackers may soon be able to leverage CVE-2026-14266 for real-world attacks. In fact, 7-Zip flaws are known to be used in social engineering cyber attacks [1][2].

Germany’s BSI and Italy’s ACN national CERT agencies have issued alerts for CVE-2026-14266 [3][4]. Users should upgrade to 7-Zip version 26.02 or later. The OPENVAS ENTERPRISE FEED includes a Windows registry check to identify systems with 7-Zip installed. CVE-2026-14266 also impacts embedded 7-Zip components in third-party products. Greenbone will continue to add Linux package detection checks and other application-specific checks as downstream vendors issue security advisories.

CVE-2026-53412: Unauthenticated Remote Account Takeover Affecting Zoom Workplace

CVSS 9.8 · CriticalNo known exploitation

Zoom’s July 2026 security advisories disclose new flaws affecting Zoom Workplace and other core Zoom applications. The primary risk is CVE-2026-53412, which enables unauthenticated remote account takeover without user interaction and is described as having low attack complexity. No active exploitation has been reported, and no detailed technical analysis, or PoC exploits are publicly available.

  • CVE-2026-53412 (CVSS 9.8): Allows an unauthenticated remote attacker to take over accounts through improper input validation. CVE-2026-53412 affects Zoom Workplace for Windows before 7.0.0 and Zoom Workplace VDI Client for Windows before the applicable fixed versions.
  • CVE-2026-53410 (CVSS 7.0): Allows an authenticated local attacker to escalate privileges through a Time-of-Check to Time-of-Use (TOCTOU) race condition in the installation or removal processes of multiple Zoom Windows products. Affected products include Zoom Workplace, VDI Client, VDI Plugin, Zoom Rooms, and Remote Control for Zoom Contact Center for Windows.

Greenbone’s OPENVAS ENTERPRISE FEED includes registry checks to identify installations of Zoom Workplace for Windows that are vulnerable to CVE-2026-53412 [1] or CVE-2026-53410[2].

Summary

Emerging cyber security risks in July 2026 show attackers exploiting high-impact flaws across enterprise platforms, perimeter devices, development tools, and widely used applications. Amid the so-called “vulnpocolypse“ pressure, security teams should maintain high visibility and increase patch cadence with a priority given to exposed systems. Defense-in-depth becomes critical when attackers gain initial access.

For defenders seeking to detect and protect, a trial copy of OPENVAS SCAN includes a free two-week trial of the OPENVAS ENTERPRISE FEED. Greenbone’s cyber security products are a surefire way to gain the deepest insight into where software vulnerabilities exist across your organization’s infrastructure.

 

Contact Test Now Buy Here Back to Overview
12. August 2026/by Joseph Lee
https://www.greenbone.net/wp-content/uploads/greenbone-logo-2025.png 0 0 Joseph Lee https://www.greenbone.net/wp-content/uploads/greenbone-logo-2025.png Joseph Lee2026-08-12 13:18:032026-08-13 08:08:10Threat Report July 2026: Vulnpocolypse – Just Scratching the Surface?
Greenbone AG

The Greenbone MSSP Program: vulnerability management, licensed for the way you sell it

Blog

A glowing green doorway opens onto a dark, data-lit corridor, symbolizing the Greenbone MSSP Program opening to service providers

As of now, the Greenbone MSSP Program is open to service providers in Europe and beyond. It puts OPENVAS, the world’s most widely used open-source vulnerability management solution, in the hands of providers who deliver it as a service, on commercial terms built around how managed services actually make money: one platform for every customer you serve, one agreement covering all of them, and costs that follow the assets you manage.

Learn More About the Greenbone MSSP Program

Find full program details, terms, and how to apply at greenbone.net/en/mssp.

Many customers, one platform, one team

You run all of your customer environments from one central platform, with strict separation between them. Each customer sees only their own environment and their own results. Your team keeps a single point of control, and access is granted per team member for the accounts they are responsible for. Adding a customer becomes an operational step rather than a project, which is the whole point: your delivery effort should not grow one to one with your customer base.

Starting is deliberately small. You begin with a working setup and grow it as your customer base does, instead of committing to a rollout that has to be finished before it earns anything. How involved it gets from there depends on your customers’ networks rather than on our software, and our Professional Services team is there for the architecture questions that come with segmented networks, authenticated scanning, and air-gapped environments.

Evidence your customers and their auditors accept

Managed vulnerability management either stays profitable or quietly bleeds hours, and the difference usually sits in how much you assemble by hand. Findings, risk context, priorities and remediation guidance can be produced per customer, in the shape that each service agreement calls for. You are not rebuilding the same output for every account, every month, and every audit.

Behind the scanner sits a security research team maintaining one of the world’s leading vulnerability test feeds, updated daily. Coverage and freshness are what your customers rely on the day a critical vulnerability becomes public, and they are not something a service can be built on top of by chance.

European, open, and yours to deploy

Where a security solution comes from has become a deciding factor in buying decisions, and your customers are the ones asking. Greenbone is a European vendor. We have developed vulnerability management as open-source software since 2008, our technology is built and hosted in the EU, and it is developed with GDPR requirements in mind.

The solution runs in your own environment, so the deployment and data-residency options your customers ask for are yours to offer. For the customers wary of US-based providers within the reach of regulations like the Cloud Act, or working under strict data-protection rules, that is a requirement you can meet without a workaround, and an argument you can carry into your own sales conversations.

Nothing you have to buy twice

Partners tell us the same two things about the platforms they have worked with. The scope they bought keeps growing into modules that arrive later as separate line items. And the interface they automated against keeps moving, or closes.

We do neither, and that is a position rather than a phase. Vulnerability management is our product, not the entry ticket to a suite. Our scanning technology is open-source at its core, it integrates into heterogeneous environments, and the interface you build against belongs to the product rather than serving as a commercial lever. The automation your team writes around it stays worth something.

For you that counts twice over, because your delivery platform is your product too. Every hour spent re-engineering around someone else’s roadmap is an hour you cannot bill, and every function that migrates behind a new licence is a margin decision somebody made on your behalf. We would rather be the best vulnerability management engine in your stack than a suite that treats vulnerability management as one feature among many.

A commercial model that rewards growth

Licensing follows the assets you manage, not fixed seats. It is settled at partner level, across your entire customer base, and that is the part that matters most for your economics. Every customer you onboard counts towards the same volume, so your fortieth customer improves your position instead of opening a new negotiation. There is a minimum commitment, and it sits with you as a partner rather than with any individual customer, so a mix of large and small accounts costs you nothing. Commit to a volume for a year and your terms improve further.

Growth sits on your side of the table, which is where it belongs.

Partners are already delivering this as a service

CYBER FOX AG has integrated OPENVAS deeply into its managed security services. Continuous vulnerability analysis forms the basis for context-based risk assessment, risk-driven prioritisation, and concrete remediation guidance, delivered around the clock by the CYBER FOX® Security Operations Center as a fully managed service. Operations and data storage for both companies run entirely in Europe, in line with GDPR.

“Greenbone delivers exactly the technological depth and transparency we need for vulnerability management as a managed service. The MSSP model lets us scale that service efficiently and deliver measurable value to our customers,” says Patrick Antoun, Executive Board Member at CYBER FOX AG.

Learn More About the Greenbone MSSP Program

Find full program details, terms, and how to apply at greenbone.net/en/mssp.

Talk to us

If you are choosing a vulnerability management partner, or reconsidering the one you have, start where it counts: most partners begin with a short technical walkthrough and a guided proof of concept, so you can test the platform against your own environment and your own customer mix before committing to anything.

Contact Test Now Buy Here Back to Overview
10. August 2026/by Greenbone AG
https://www.greenbone.net/wp-content/uploads/greenbone-logo-2025.png 0 0 Greenbone AG https://www.greenbone.net/wp-content/uploads/greenbone-logo-2025.png Greenbone AG2026-08-10 12:25:152026-08-10 12:25:15The Greenbone MSSP Program: vulnerability management, licensed for the way you sell it
Joseph Lee

Patch Now! CVE-2026-18577 in N-able N-central Actively Exploited

Blog
!

Update

August 14th, 2026

N-able has released N-central 2026.3 Hotfix 2 (build 2026.3.1.10) after the vendor identified another attack path associated with CVE-2026-18577. Hotfix 2 adds further hardening measures and supersedes Hotfix 1 (2026.3.1.7). N-able states that the new mitigation was deployed to hosted N-central environments on August 6, while self-hosted customers must upgrade manually.

According to N-able, attackers gained unauthenticated administrative access, used N-central’s Take Control functionality, pivoted to managed endpoints, and registered Cloudflare tunnel services for persistence. The vendor further warns that threat actors have been observed creating new accounts and resetting existing accounts to retain access

See N-able’s Hotfix 2 notice and the vendor’s latest security advisory for further guidance.

CVE-2026-18577 (CVSS 8.2, EPSS ≥ 71st pctl) and CVE-2026-18556 (CVSS 7.4, EPSS ≥ 19th pctl), published in early August, have both been added to CISA’s Known Exploited Vulnerabilities (KEV) list within days of their disclosure [1][2]. N-able has published Indicators of Compromise (IoC) and post-exploitation activity from successful attacks against its own hosted N-central instances. N-central version 2026.3.1 is required to remediate both CVEs.

CVE-2026-18577 is considered a bypass of the fix for CVE-2026-18556. Both are authentication bypass [CWE-288] flaws that allow admin-level account takeover and full-platform compromise of N-central servers. No public proof-of-concept (PoC) exploit code or detailed technical analysis has been published for CVE-2026-18556 or CVE-2026-18577. Several national CERT agencies have published alerts for the CVEs [1][2][3][4][5][6][7].

Start Your Free Trial

Greenbone’s OPENVAS ENTERPRISE FEED includes a remote banner version check that identifies instances of N-able N-central vulnerable to CVE-2026-18577 and by hierarchy, CVE-2026-18556. Grabbing a copy of OPENVAS SCAN with a free two-week trial of the OPENVAS ENTERPRISE FEED is a surefire way to gain the deepest insight into where software vulnerabilities exist in your organization’s Linux infrastructure.

Shattered shield graphic warning that an N-central vulnerability on the N-able platform is being actively exploited

A Risk Assessment of CVE-2026-18577 and CVE-2026-18556 Affecting N-able N-central

CVE-2026-18577

CVSS 8.2 · HighEPSS 1.5% (71st)Actively exploitedIn CISA KEV

CVE-2026-18556

CVSS 7.4 · HighEPSS 0.3% (19th)Actively exploitedIn CISA KEV

On July 31st, 2026, N-able detected malicious activity targeting N-central server in a customer environment. Analysis led to the discovery of a zero-day vulnerability, which was initially assigned CVE-2026-18556. The flaw was remediated in N-central 2026.2, but the fix left an alternate authentication-bypass path. N-able assigned CVE-2026-18577 to track the incomplete fix separately. N-central 2026.3 Hotfix 1 was released on August 2nd, which fully remediates both CVEs.

CVE-2026-18577 and CVE-2026-18556 are high risk because of N-central’s role as a remote administration platform in Managed Service Provider (MSP) environments. N-central includes tooling such as Take Control, Remote Desktop, Extensible Messaging and Presence Protocol (XMPP) control channels, and SSH access, among other services.

As evidenced by N-able’s reports of post-exploitation activity, compromise of an N-central server creates broad downstream risk across managed customer environments. Defenders should treat the issue as a platform-wide operational risk rather than limited to a single component or attack surface.

Multiple sources report that roughly 3,000 N-central servers were exposed to the public internet in 2025 [1][2]. Shodan currently identifies approximately 2,300 instances. This recent incident is not the first time that N-central has come under active exploitation. In mid-2025, CVE-2025-8875 (CVSS 7.8) and CVE-2025-8876 (CVSS 8.8) were both added to CISA’s KEV list [3][4].

Technical Assessment and Attack Trajectory

CVE-2026-18577 (CVSS 8.2, EPSS ≥ 71st pctl) is the result of an incomplete patch for CVE-2026-18556 (CVSS 7.4, EPSS ≥ 19th pctl), which was published only one day before CVE-2026-18577. Both flaws are described as authentication bypass vulnerabilities [CWE-288] affecting N-central instances. Post-exploitation reporting indicates that they allow admin-level account takeover and full-platform compromise. The vendor-supplied evidence does not include root-cause details or identify specific exploitable components. No further technical analysis or PoC exploits have been published.

N-able has published indicators of compromise (IoC) and post-compromise details from successful attacks on its hosted N-central infrastructure. These include a rogue file named svchost.exe in the user’s Documents folder, a registered service named Cloudflared, and inbound connections from several IP addresses. For defenders, this means that the patches should be paired with a full forensic review of exposed systems and monitoring of network traffic for anomalous activity.

Observed post-compromise activity included:

  • Gaining administrative access to vulnerable N-central servers [T1190]
  • Using N-central’s Take Control function to access connected systems remotely [T1219.002]
  • Installing a rogue service [T1543.003] named Cloudflared on managed endpoints for persistent remote access even after access through the N-central server was revoked

CVE-2026-18577 & CVE-2026-18556: Affected Versions and Mitigation

Defenders should be primarily concerned about CVE-2026-18577 since it is a bypass of an earlier flaw. CVE-2026-18577 affects all N-central instances prior to version 2026.3.1. N-able’s status page states that hosted N-central instances are upgraded automatically. However, self-hosted customers must apply the 2026.3 Hotfix 1, identified as build 2026.3.1.7.

Deployment Affected versions Fixed versions Upgrade path

Hosted N-central

All versions before 2026.3.1

N-central 2026.3 HF1, build 2026.3.1.7

Automatic update by N-able

Self-hosted N-central

All versions before 2026.3.1

N-central 2026.3 HF1, build 2026.3.1.7

Manual update required

N-able has published IoCs for its own incident response forensic analysis. The IoC information suggests that responders review potentially impacted systems for a file named svchost.exe in the user’s Documents folder, a registered service named Cloudflared, and inbound connections from several observed IP addresses.

Summary

N-able has issued N-central 2026.3 HF1 to mitigate CVE-2026-18577, which affects all previous versions of N-central. Because N-central is an administrative platform used by MSPs to manage customer environments, the operational risk is high. Known IoCs are available from the analysis of real-world breaches. Defenders should pair hotfix deployment with a full forensic review of potentially compromised systems.

Start Your Free Trial

Greenbone’s OPENVAS ENTERPRISE FEED includes a remote banner version check that identifies instances of N-able N-central vulnerable to CVE-2026-18577 and by hierarchy, CVE-2026-18556. Grabbing a copy of OPENVAS SCAN with a free two-week trial of the OPENVAS ENTERPRISE FEED is a surefire way to gain the deepest insight into where software vulnerabilities exist in your organization’s Linux infrastructure.

 

Contact Test Now Buy Here Back to Overview
6. August 2026/by Joseph Lee
https://www.greenbone.net/wp-content/uploads/greenbone-logo-2025.png 0 0 Joseph Lee https://www.greenbone.net/wp-content/uploads/greenbone-logo-2025.png Joseph Lee2026-08-06 08:47:522026-08-14 09:19:56Patch Now! CVE-2026-18577 in N-able N-central Actively Exploited
Greenbone AG

CIS Benchmarks for Microsoft Environments: Greenbone’s Got You Covered!

Blog

Microsoft technologies are foundational to enterprise IT globally, providing the backbone for operation-critical databases, identity services, core server workloads, and daily productivity applications at many organizations. Greenbone is happy to announce new compliance scans aligned with four CIS Benchmarks for Microsoft environments. CIS Benchmarks provide prescriptive guidance for establishing secure configurations and complement essential security practices such as vulnerability management, endpoint protection, and activity monitoring.

Fortified server module illustration for Greenbone's new Microsoft CIS Benchmark compliance scans

In this article, we briefly review the security focus of each benchmark and explain how Greenbone’s compliance policies help organizations identify configuration gaps across Microsoft Office, SQL Server, and Windows Server systems. OPENVAS SCAN, backed by the industry-leading coverage of the OPENVAS ENTERPRISE FEED, provides the compliance visibility needed to detect insecure settings, prioritize remediation, and strengthen the resilience of Microsoft IT environments.

The new compliance policies for Microsoft IT environments add to Greenbone’s already impressive line of scans:

  • CIS Microsoft Office Enterprise Benchmark v1.2.0
  • CIS Microsoft SQL Server 2022 Benchmark v1.2.1
  • CIS Microsoft Windows Server 2025 Benchmark v2.0.0
  • CIS Microsoft Windows Server 2022 Benchmark v5.0.0

The Importance of IT Compliance in 2026

In 2026, organizations operating in the EU face overlapping cyber security, resilience, privacy, and corporate governance obligations. The Network and Information Systems Directive 2 (NIS2) requires critical infrastructure entities to implement technical, operational, and organizational safeguards. The Digital Operational Resilience Act (DORA) imposes additional ICT risk management and resilience requirements on the financial sector. The GDPR imposes security requirements on organizations that process or store personal data, and the Cyber Resilience Act (CRA) introduces mandatory reporting of actively exploited vulnerabilities and severe product security incidents from September 11, 2026, among other obligations.

Following recognized IT security standards such as CIS Benchmarks helps organizations establish defensible security baselines, produce audit evidence, reduce configuration drift, and demonstrate that governance and risk management duties are implemented consistently.

Talk to Our Sales Team

Whether your organization must meet regulatory requirements or simply wants deeper insight into securing Microsoft IT environments, OPENVAS SCAN provides the compliance visibility needed to identify configuration gaps, reduce risk, and strengthen security. Contact Greenbone’s sales team to discuss how compliance scanning can best support your organization’s regulatory and security governance requirements.

Understanding CIS Microsoft SQL Server 2022 Benchmark v1.2.1

The CIS Microsoft SQL Server 2022 Benchmark v1.2.1 provides prescriptive guidance for the secure configuration of SQL Server 2022 on Microsoft Windows. It is intended for database and system administrators, security specialists, auditors, and deployment personnel responsible for developing, assessing, or securing SQL Server environments.

The benchmark covers installation and patching, attack surface reduction, authentication and authorization, password policies, auditing and logging, application development, and encryption. Greenbone’s compliance scan for CIS Microsoft SQL Server 2022 Benchmark v1.2.1 covers the practical Level 1 profile for the SQL Server Database Engine and AWS RDS, and the Level 2 Database Engine profile with additional defense-in-depth controls.

Understanding CIS Microsoft Windows Server 2025 Benchmark v2.0.0

The CIS Microsoft Windows Server 2025 Benchmark v2.0.0 audits security controls for establishing a hardened configuration of Windows Server 2025. It is designed for Active Directory domain-joined and Entra Hybrid-joined systems that receive policies through Active Directory Group Policy Manager. The policy is not designed for standalone, workgroup, cloud-managed, or cloud-hosted systems.

The benchmark addresses areas such as account and local security policies, system services, Windows Defender Firewall, advanced audit configuration, authentication, remote access, and administrative template settings. Greenbone’s compliance scan for CIS Microsoft Windows Server 2025 Benchmark v2.0.0 covers Level 1 and Level 2 profiles for both Domain Controllers and Member Servers, along with optional Next Generation Windows Security profiles for advanced controls.

Understanding CIS Microsoft Windows Server 2022 Benchmark v5.0.0

The CIS Microsoft Windows Server 2022 Benchmark v5.0.0 audits security controls for establishing a hardened configuration of Windows Server 2022. The Windows Server 2022 benchmark is intended for Active Directory domain-joined and Entra Hybrid-joined systems that receive policies through Active Directory Group Policy Manager. The policy is not designed for standalone, workgroup, cloud-managed, or cloud-hosted systems.

The benchmark addresses areas such as account and local security policies, system services, Windows Defender Firewall, advanced auditing, authentication, remote access, and administrative template settings. Greenbone’s compliance scan for CIS Microsoft Windows Server 2022 Benchmark v5.0.0 covers Level 1 and Level 2 profiles for Domain Controllers and Member Servers, along with optional Next Generation Windows Security profiles containing advanced controls.

Get to Know Greenbone’s Full Suite of Compliance Scans

OPENVAS SCAN’s compliance policies consist of specially selected groups of vulnerability tests used to assess compliance. Whether your organization is required to meet BSI technical standards or simply wants deeper insight into building resilient IT networks and applications, OPENVAS SCAN provides compliance visibility to identify gaps and strengthen security.

Some of the compliance scans in Greenbone’s OPENVAS ENTERPRISE FEED:

  • BSI TR-03116-4: BSI Minimum Standards for the Use of TLS
  • BSI TR-02102-4: BSI Minimum Standards for the Use of SSH
  • CIS Benchmark v1.10 for Kubernetes 1.28 Controller Node
  • CIS Benchmark v1.10 for Kubernetes 1.28 Worker Nodes
  • Compliance profiles for Huawei EulerOS, openEuler, and Huawei Cloud EulerOS
  • CIS Benchmark v3.0.0 (L1) for Microsoft Windows 11 Enterprise
  • CIS Benchmarks v3.0.0 (L1 – Windows) for Google Chrome
  • BSI and CIS Benchmarks for Microsoft Office
  • Policy check for SSH: Post Quantum Cryptography (PQC)
  • Policy check for SSL/TLS: Post Quantum Cryptography (PQC)

Talk to Our Sales Team

Whether your organization must meet regulatory requirements or simply wants deeper insight into securing Microsoft IT environments, OPENVAS SCAN provides the compliance visibility needed to identify configuration gaps, reduce risk, and strengthen security. Contact Greenbone’s sales team to discuss how compliance scanning can best fit your organization’s regulatory and security governance requirements.

Summary

Microsoft platforms support critical business operations, but their extensive configuration options can introduce security gaps when systems are not consistently hardened. CIS Benchmarks are the IT industry standard for practical guidance on establishing secure configurations. Greenbone’s growing list of compliance scans helps organizations identify deviations from these recommended baselines, strengthen governance and audit readiness, and reduce configuration-related risk.

OPENVAS SCAN provides the visibility needed to maintain more resilient Microsoft environments as regulatory and operational security expectations continue to increase. Grabbing a copy of OPENVAS SCAN with a free two-week trial of the OPENVAS ENTERPRISE FEED is a surefire way for your organization to gain the deepest insight into building resilient IT networks and applications.

 

Contact Test Now Buy Here Back to Overview
31. July 2026/by Greenbone AG
https://www.greenbone.net/wp-content/uploads/greenbone-logo-2025.png 0 0 Greenbone AG https://www.greenbone.net/wp-content/uploads/greenbone-logo-2025.png Greenbone AG2026-07-31 14:03:422026-08-04 11:18:35CIS Benchmarks for Microsoft Environments: Greenbone’s Got You Covered!
Joseph Lee

Patch Priority: An Emerging Tide of Linux Vulnerabilities Put Users in Hot Water

Blog

Cracked green shield illustration representing a wave of newly disclosed Linux kernel vulnerabilities, headlined Patch Priority: Linux Kernel Risks Keep Rising

Several concerning vulnerabilities affecting Linux have emerged in recent months. The vulnerabilities include CISA Known Exploited Vulnerabilities (KEV) entries for CVE-2026-31431 (aka Copy Fail) [1], and an older flaw, CVE-2022-0492 [2]. However, a wave of concerning new vulnerabilities are associated with publicly available exploits or proof-of-concept (PoC) code. Collectively, the flaws represent local privilege escalation, container escape, arbitrary command execution as root, kernel heap corruption, and remote code execution (RCE). Linux users should regularly scan their infrastructure, conduct assessments to determine exposure, and prioritize patching to reduce risks to critical assets.

A Risk Assessment of Emerging Linux Kernel Vulnerabilities

In recent weeks, the Greenbone blog reviewed Copy Fail, a new actively exploited Linux vulnerability, along with Copy Fail 2 and Dirty Frag. Since then, several new vulnerabilities affecting the Linux kernel and core components have emerged, presenting significant operational risk within the Linux ecosystem.

Start Your Free Trial

Greenbone continuously updates the OPENVAS ENTERPRISE FEED to include detection checks for vulnerabilities dispatched in the latest Linux security advisories. Grabbing a copy of OPENVAS SCAN with a free two-week trial of the OPENVAS ENTERPRISE FEED is a surefire way to gain the deepest insight into where software vulnerabilities exist in your organization’s Linux infrastructure.

A Technical Assessment of Emerging Linux Vulnerabilities

The following section reviews recently disclosed vulnerabilities affecting the Linux kernel and core components. Each section summarizes the underlying technical cause, available threat intelligence, potential temporary mitigations, and the upstream fixes.

CVE-2026-31705 Affecting ksmbd SMB Server

CVSS 9.8 · CriticalEPSS 0.4% (32nd)No known exploitationPatch available

CVE-2026-31705 (CVSS 9.8, EPSS ≥ 32nd pctl) is an out-of-bounds write in the Linux kernel ksmbd SMB server’s smb2_get_ea() path. A memset operation for 4-byte alignment runs without checking the remaining space. Exploitation allows compound SMB requests to overwrite adjacent kernel heap memory.

A detailed technical write-up is available online, increasing the risk to defenders [1]. No vendor provided workarounds have been published. However, shutting down KSMBD and/or unloading and blocking the ksmbd kernel module can reasonably prevent attacks from reaching the affected components. Upstream fixes are incorporated into Linux kernel versions 6.1.175, 6.6.136, 6.12.84, 6.18.25, 7.0.2, and 7.1. Greenbone’s OPENVAS ENTERPRISE FEED includes detection for CVE-2026-31705 and continues to add package-level checks as Linux distributions issue security advisories and patches.

CVE-2026-55200 Affecting libssh2

CVSS 8.3 · HighEPSS 2.0% (79th)Public PoC

CVE-2026-55200 (CVSS 8.3, EPSS ≥ 79th pctl) affects libssh2. The flaw is an out-of-bounds write in ssh2_transport_read() caused by an unchecked attacker-controlled packet_length field. A malicious or compromised SSH server can send crafted SSH packets to trigger memory corruption and achieve RCE.

Detailed technical write-ups and PoC exploits are available online, increasing the risk to defenders [1][2]. No workaround mitigation is available except for preventing libssh2 clients from connecting to untrusted SSH servers, such as disabling the service. CVE-2026-55200 affects all libssh2 versions up to and including 1.11.1. No fixed upstream release has yet been published, but the correction is available in upstream commit 97acf3df and has been backported by some Linux distributions. Greenbone’s OPENVAS ENTERPRISE FEED includes detection for CVE-2026-55200 and continues to add package-level checks as Linux distributions issue security advisories and patches.

Fragnesia: CVE-2026-46300 (CVSS 7.5)

CVSS 7.8 · HighEPSS 2.5% (83rd)Public PoC

Dubbed Fragnesia, CVE-2026-46300 (CVSS 7.8, EPSS ≥ 83rd pctl) is caused by shared-fragment marker loss during skb coalescing in the Linux kernel’s net/skbuff and ESP input paths. Later in-place ESP processing allows decryption of page-cache-backed fragments. The issue is considered a trivial-to-exploit local privilege-escalation risk because it can corrupt page-cached read-only files. Ubuntu says exploitation can elevate a local user to root on affected hosts and that container-escape scenarios are also possible.

Several technical write-ups and PoC exploits are available online, increasing the risk to defenders [1][2][3][4][5]. Temporary mitigation can be achieved by unloading and blocking the esp4 and esp6 kernel modules [6]. CVE-2026-46300 affects Linux kernel versions 3.9 and later. Upstream fixes are incorporated into versions 5.10.257, 5.15.208, 6.1.174, 6.6.141, 6.12.91, 6.18.33, 7.0.10, and 7.1. Greenbone’s OPENVAS ENTERPRISE FEED includes detection for CVE-2026-46300 and continues to add package-level checks as Linux distributions issue security advisories and patches.

ssh-keysign-pwn: CVE-2026-46333 (CVSS 7.1)

CVSS 7.1 · HighEPSS 1.5% (72nd)Public PoC

Dubbed ssh-keysign-pwn, CVE-2026-46333 (CVSS 7.1, EPSS ≥ 72nd pctl) is a race in Linux kernel ptrace and process-exit handling. The issue centers around dumpability and mm teardown. During a privileged process exit, pidfd_getfd() can duplicate open file descriptors from the dying process. Exploitation can expose sensitive root-owned material, including SSH keys and password hashes. The public proof-of-concept for this issue requires the pidfd_getfd syscall; a system call that can duplicate a file descriptor from another process. The kernel fix requires the CAP_SYS_PTRACE capability to inspect or control another process when the target process is exiting, known as the “no-mm” case.

Several technical write-ups and PoC exploits are available online, increasing the risk to defenders [1][2][3][4][5][6]. Temporary mitigation can be achieved by blocking all unprivileged users or only for users without the CAP_SYS_PTRACE privilege from attaching to other processes using the ptrace() system call [7]. CVE-2026-46333 is a Linux kernel vulnerability rather than an OpenSSH flaw. Patches are incorporated into Linux kernel versions 5.10.256, 5.15.207, 6.1.173, 6.6.139, 6.12.89, 6.18.31, 7.0.8, and 7.1. Greenbone’s OPENVAS ENTERPRISE FEED includes detection for CVE-2026-46333 and continues to add package-level checks as Linux distributions issue security advisories and patches.

DirtyDecrypt / DirtyCBC: CVE-2026-31635 (CVSS 7.5)

CVSS 7.5 · HighEPSS 0.8% (53rd)Public PoC

Dubbed DirtyDecrypt (and DirtyCBC), CVE-2026-31635 (CVSS 7.5, EPSS ≥ 53rd pctl) affects Linux kernels with CONFIG_RXGK compiled in and enabled. An inverted bounds check in RxRPC / RxGK response validation allows oversized RESPONSE authenticators to be accepted and passed deeper into processing. Secondary reporting says the flaw can overwrite page-cached privileged files and be used for local privilege escalation to root.

Several technical write-ups and PoC exploits are available online, increasing the risk to defenders [1][2][3][4][5]. No vendor provided workarounds have been published. However, independent researchers have suggested unloading and blocking the rxrpc module as a temporary solution [6]. Upstream fixes for CVE-2026-31635 are incorporated into Linux kernel versions 6.18.23, 6.19.13, and 7.0. Greenbone’s OPENVAS ENTERPRISE FEED includes detection for CVE-2026-31635 and continues to add package-level checks as Linux distributions issue security advisories and patches.

CIFSwitch: CVE-2026-46243 (CVSS 7.1)

CVSS 7.1 · HighEPSS 0.4% (30th)Public PoC

Dubbed CIFSwitch, CVE-2026-46243 (CVSS 7.1, EPSS ≥ 30th pctl) affects cifs_spnego handling in the Linux kernel’s CIFS client. The issue allows userspace to forge cifs.spnego key descriptions through request_key(2) or add_key(2), causing cifs.upcall to trust attacker-controlled authority fields. The flaw allows a low-privilege local user to trigger arbitrary command execution as root.

Several technical write-ups and PoC exploits are available online, increasing the risk to defenders [1][2][3][4]. The temporary workaround is to unload and block the cifs kernel module, remove cifs-utils, or deactivate the cifs.spnego request-key rule [5]. CVE-2026-46243 affects Linux kernel with the CIFS client or cifs-utils, and the cifs.spnego request-key integration. Upstream fixes are incorporated into versions 5.10.258, 5.15.209, 6.1.175, 6.6.142, 6.12.92, 6.18.34, 7.0.11, and 7.1. Greenbone’s OPENVAS ENTERPRISE FEED includes detection for CVE-2026-46243 and continues to add package-level checks as Linux distributions issue security advisories and patches.

PinTheft: CVE-2026-43494 (CVSS 7.8)

CVSS 7.8 · HighEPSS 0.3% (22nd)Public PoC

Dubbed PinTheft, CVE-2026-43494 (CVSS 7.8) affects the Linux kernel RDS zerocopy send path. The bug stems from cleanup logic that frees already released pages after op_nents is left nonzero. The exploit chain uses io_uring fixed buffers to overwrite the page cache of a SUID-root binary.

Several detailed write-ups and PoC exploits are available online, increasing the risk to defenders [1][2][3][4]. Workaround mitigation can be achieved by ensuring that the rds module is unloaded and blocked from automatic loading [5]. CVE-2026-43494 affects Linux kernel versions 4.17 and later with the RDS subsystem. Upstream fixes are incorporated into Linux kernel versions 5.10.258, 5.15.209, 6.1.175, 6.6.141, 6.12.91, 6.18.33, 7.0.10, and 7.1. Greenbone’s OPENVAS ENTERPRISE FEED includes detection for CVE-2026-43494 and continues to add package-level checks as Linux distributions issue security advisories and patches.

GhostLock: CVE-2026-43499 (CVSS 7.8)

CVSS 7.8 · HighEPSS 0.7% (50th)Public PoC

Dubbed GhostLock, CVE-2026-43499 (CVSS 7.8) is a use-after-free in the Linux kernel rtmutex slowlock and proxy-lock rollback path. The remove_waiter() function leaves a dangling pointer and unsafe locking state. Red Hat and Ubuntu describe local privilege-escalation and denial-of-service impact [1][2], and Nebula says container escape is also possible on unpatched systems.

Several detailed technical write-ups and PoC exploits are available online, increasing the risk to defenders [1][2][3][4]. No workaround mitigation is available. CVE-2026-43499 affects Linux kernel versions 2.6.39 and later with upstream fixes incorporated into versions 5.10.261, 5.15.212, 6.1.175, 6.6.140, 6.12.86, 6.18.27, 7.0.4, and 7.1. Greenbone’s OPENVAS ENTERPRISE FEED includes detection for CVE-2026-43499 and continues to add package-level checks as Linux distributions issue security advisories and patches.

Mitigation for Emerging Linux Vulnerabilities

Organizations should prioritize patching for emerging Linux vulnerabilities based on the operational and business value of affected assets, the reachability of affected systems, each flaw’s technical details, and threat intelligence, including known active exploitation and the existence of PoC exploits.

Mitigating vulnerabilities found in the upstream Linux kernel depends on either implementing effective workarounds or installing updates in downstream Linux distributions when they become available. Where technical workarounds are not available, defenders must upgrade to fixed kernel builds.

Summary

Recent Linux kernel and core component vulnerabilities have exposed organizations to new risks. The potential impacts include local privilege escalation, container escape, arbitrary command execution, memory corruption, and RCE. Publicly available technical analyses and proof-of-concept exploits increase the urgency. When prioritizing patches, defenders must identify all affected systems and consider asset criticality, business risk, reachability, and exploitability.

Start Your Free Trial

Greenbone provides package-level detection via local authenticated scans for all emerging Linux risks mentioned in this article. Greenbone continuously updates the OPENVAS ENTERPRISE FEED to include detection checks for vulnerabilities dispatched in the latest Linux security advisories. Grabbing a copy of OPENVAS SCAN with a free two-week trial of the OPENVAS ENTERPRISE FEED is a surefire way to gain the deepest insight into where software vulnerabilities exist in your organization’s Linux infrastructure.

 

Contact Test Now Buy Here Back to Overview
30. July 2026/by Joseph Lee
https://www.greenbone.net/wp-content/uploads/greenbone-logo-2025.png 0 0 Joseph Lee https://www.greenbone.net/wp-content/uploads/greenbone-logo-2025.png Joseph Lee2026-07-30 14:08:532026-08-03 10:48:47Patch Priority: An Emerging Tide of Linux Vulnerabilities Put Users in Hot Water
Joseph Lee

Patch Now! Back-to-Back Synacor Zimbra Updates Fix Two Sets of Critical Vulnerabilities

Blog

In July 2026, Zimbra released two security patches for multiple vulnerabilities affecting the Classic Web Client and other components of Zimbra Collaboration Suite (ZCS). Version 10.1.19 addressed a stored cross-site scripting (XSS) flaw that has not been assigned a CVE. Version 10.1.20 fixed a command-injection issue in the SNMP monitoring component, four additional stored XSS issues in the Classic Web Client, and numerous other flaws.

None of the new vulnerabilities are yet reported as actively exploited, and proof-of-concept (PoC) exploits are not publicly available. However, Zimbra has been a hot target for nation-state exploit campaigns in the past. Previous ZCS flaws have appeared 18 times on CISA’s KEV list. Five of those KEV listed CVEs are associated with ransomware attacks. In July 2026, U.S. and allied security agencies warned that the Russian state-backed group LAUNDRY BEAR has been exploiting ZCS vulnerabilities since at least July 2025[1][2].

Banner graphic for the Zimbra critical patches blog post, reading 'Critical Zimbra Flaws Fixed, Update Now'

Most of the security issues described in the 10.1.19 and 10.1.20 updates are not associated with a CVE. However, the pathway to mitigation is clear — users must update to the most recent version of Zimbra Collaboration Suite (ZCS) for protection. The OPENVAS ENTERPRISE FEED includes separate remote banner version checks to identify instances missing the 10.1.19 and 10.1.20 patches [1][2]. Users should upgrade to ZCS 10.1.20 as soon as possible.

A Risk Assessment of Zimbra Collaboration Suite Vulnerabilities

For organizations still using the Classic Web Client, the new flaws present significant risk. The 10.1.19 update addresses a stored XSS issue that can be triggered when a user opens a specially crafted email. The vulnerability has not been associated with a published CVE as of July 27th, 2026, but Zimbra has declared it a critical severity issue. Successful exploitation could expose mailbox information, session data, or account settings, potentially enabling account compromise and data theft.

The 10.1.20 patch addresses four additional stored XSS issues in the Classic Web Client, a command-injection vulnerability in the SNMP component, and flaws affecting mail forwarding restrictions, Exchange Web Services (EWS) access controls, mailbox delegation, and the Zimbra integration for Nextcloud.

Details of New Security Issues Impacting ZCS

Technical details for the security issues disclosed in both the ZCS 10.1.19 and 10.1.20 updates are limited. Also, CVEs have not been published for many of the described flaws.

Fixed in ZCS 10.1.19 (Released on July 7th, 2026):

  • Classic Web Client stored XSS fixed in 10.1.19 (no CVE assigned): The flaw can be triggered by opening a specially crafted email. Exploitation allows an attacker to execute a malicious script in a user session and potentially expose mailbox information, session data, or account settings.

Fixed in ZCS 10.1.20 (Released on July 20th, 2026):

  • SNMP monitoring (no CVE assigned): A command-injection vulnerability in the SNMP monitoring component when SNMP notifications are enabled.
  • Classic Web Client stored XSS issues (no CVE assigned): Attachment filenames, crafted fields, and attachments can be designed to to trigger XSS on user’s systems when they view a malicious email.
  • CVE-2026-50055 (CVE reserved but not published): A mail-forwarding restriction bypass could allow authenticated users to exfiltrate email despite forwarding restrictions being enabled.
  • CVE-2026-10631 (CVE reserved but not published): An Exchange Web Services extension access-controls issue can have an undisclosed impact related to access controls.
  • CVE-2026-50054 (CVE reserved but not published): A mailbox delegation authorization issue with undisclosed details.
  • Nextcloud integration SSRF (no CVE assigned): A Server Side Request Forgery (SSRF) vulnerability in the Nextcloud integration for ZCS.

Mitigation for New Vulnerabilities in Zimbra Collaboration Suite

Users who have deployed the Classic Web Client should upgrade to ZCS v10.1.20 as soon as possible due to the risk of attacker-controlled XSS. The vendor has not described any workarounds. The OPENVAS ENTERPRISE FEED includes separate remote banner version checks to uncover instances missing the 10.1.19 and 10.1.20 patches [1][2].

Summary

Zimbra addressed multiple security issues in July 2026, issuing two security patches for ZCS. The updates address flaws in multiple components. The most critical issues are session-level XSS risk in the Classic Web Client. Other high-risk vulnerabilities include configuration-dependent command injection in SNMP monitoring and access-control or authorization weaknesses that can affect email exposure and delegated access. No active exploitation has been reported, although ZCS has been targeted by Advanced Persistent Threat (APT) actors in the past and is reportedly still an active target.

Start Your Free Trial

Most of the security issues described in the 10.1.19 and 10.1.20 updates are not associated with a CVE. However, the pathway to mitigation is clear – users must update to the most recent version of ZCS for protection. The OPENVAS ENTERPRISE FEED includes separate remote banner version checks to uncover instances missing the 10.1.19 and 10.1.20 patches [1][2]. Users should upgrade to ZCS 10.1.20 as soon as possible.

 

Contact Test Now Buy Here Back to Overview
29. July 2026/by Joseph Lee
https://www.greenbone.net/wp-content/uploads/greenbone-logo-2025.png 0 0 Joseph Lee https://www.greenbone.net/wp-content/uploads/greenbone-logo-2025.png Joseph Lee2026-07-29 14:31:092026-07-29 14:35:52Patch Now! Back-to-Back Synacor Zimbra Updates Fix Two Sets of Critical Vulnerabilities
Page 1 of 512345

Search

Search Search

Archive

  • 2026
  • 2025

Newsletter

Subscribe Now

OPENVAS BASIC

Our entry-level enterprise product

Test 14 Days Free of Charge

Products & Solutions

  • OPENVAS PRODUCTS
  • OPENVAS SECURITY INTELLIGENCE
  • OPENVAS SCAN
  • OPENVAS BASIC
  • OPENVAS FREE
  • OPENVAS AI
ISO9001-EN

Service & Support

  • Professional Services
  • Documents
  • Technical Support
  • FAQ
  • Warranty
  • Cyber Resilience Act
ISO27001-EN

About us

  • About Greenbone
  • Partners
  • MSSP
  • License information
  • Privacy Statement
  • Terms & Conditions
ISO14001-EN

Contact with us

  • Contact
  • Newsletter
  • Media Contact
  • Careers
  • Security Response
  • Imprint
  • Grounding Page

Community

  • Community Portal
  • Community Forum
© Copyright - Greenbone AG 2020-2026
  • Link to LinkedIn
Scroll to top Scroll to top Scroll to top
Contact
Request IT Security Contact Us Subscribe to Newsletter Follow on LinkedIn