Cloud
Supply Chain Security Vendor RapidFort Allegedly Breached in CanisterWorm Fallout β 569GB of Customer Pipeline Data Listed for Sale
A threat actor claims to be selling 569GB of RapidFort's internal pipeline data β including customer cross-account IAM templates, kubeconfigs, and plaintext AWS credentials β allegedly extracted during the March 2026 CanisterWorm/TeamPCP campaign.
CVE-2026-58231: Max-Severity Unauth RCE in SAP Commerce Cloud Now Under Active Exploitation
CVE-2026-58231, a CVSS 10.0 flaw in SAP Commerce Cloud's Data Hub Adapter, lets unauthenticated attackers execute arbitrary code via a default authentication client. Exploitation attempts began August 14, three days after SAP shipped a patch.
Critical Use-After-Free in Microsoft QUIC Allows Unauthenticated RCE (CVE-2026-62815)
CVE-2026-62815, a CVSS 9.8 use-after-free in Microsoft's QUIC/HTTP-3 implementation, lets an unauthenticated remote attacker execute code with a single crafted packet β no user interaction required.
Unpatched GeoServer Zero-Day Lets Unauthenticated Attackers Turn SQL Injection Into RCE
An unpatched, unauthenticated SQL injection in GeoServer's jsonArrayContains filter function is under active probing days after public disclosure, with a documented path to remote code execution on PostgreSQL-backed instances.
CopyEscape (CVE-2026-17106): A Malicious Container Can Overwrite Files on the Docker Host via `docker cp`
CVE-2026-17106 ('CopyEscape'), found by Imperva's Red Team, lets a malicious or compromised container hijack docker cp to overwrite arbitrary files on the host β and, when the copy runs with elevated privileges, replace runc to get root. Docker has shipped fixes across Engine, Desktop, and Sandboxes.
Microsoft Patches Four CVSS 9.9 Flaws Spanning Azure Service Bus, Azure SRE Agent, Entra Provisioning, and Active Directory
Microsoft quietly shipped fixes for four unrelated CVSS 9.9 flaws β an unauthenticated-adjacent RCE in Azure Service Bus and privilege-escalation bugs in Azure SRE Agent, Entra Provisioning Service, and on-prem Active Directory β all remotely exploitable and disclosed August 6.
Metabase Zero-Day: Unauthenticated SQL Injection (CVSS 10.0) Exploited to Breach Framework and Tally
A pre-auth SQL injection in Metabase's password-reset endpoint let attackers hijack admin access on customer instances, hitting Metabase Cloud tenants Framework and Tally before a patch shipped.
OVSwrap (CVE-2026-64531): 13-Year-Old Linux Kernel Bug in Open vSwitch Gives Any Local User Root
A 16-bit integer wraparound in the Linux kernel's Open vSwitch action parser (CVE-2026-64531, 'OVSwrap') lets any unprivileged local user become root β no OVS configuration, no CAP_NET_ADMIN, no container privileges required. A public PoC ships precomputed offsets for ~800 kernel builds.
15 TP-Link Omada Flaws Turn Zero-Touch Provisioning Into a Network Takeover Path
Forescout's Vedere Labs found 15 flaws in TP-Link's Omada zero-touch provisioning ecosystem β hardcoded crypto keys, a predictable RC4 cipher, and weak cert validation that chain into full controller and fleet compromise.
ExfilSquad's Power Pages Rampage Hits UK Police Legal Database, 14 Other Victims
A new extortion group, ExfilSquad, is scraping data straight out of misconfigured Microsoft Power Pages portals with no exploit required β its highest-profile victim so far is the UK's Police National Legal Database, exposing contact data for 135,000 officers and justice staff.
N-able's First Patch Didn't Hold: CVE-2026-18577 Bypasses the CVE-2026-18556 Fix for Full N-central Takeover
N-able's emergency fix for an N-central authentication bypass proved incomplete β a new CVE, CVE-2026-18577, lets attackers bypass the patch entirely for unauthenticated 'god-mode' access, and it's being actively exploited against MSPs.
Broadcom Patches Two CVSS 9.8 vCenter Auth Bypass/RCE Flaws and an ESXi VM Escape (VMSA-2026-0006)
Broadcom's VMSA-2026-0006 patches two unauthenticated, CVSS 9.8 vCenter Server flaws (auth bypass and directory-traversal RCE) plus a VMXNET3 VM escape in ESXi β no workarounds exist for either critical vCenter bug.
N-able N-central Authentication Bypass (CVE-2026-18556) Exploited to Hijack Managed Endpoints via Take Control and Cloudflare Tunnels
An authentication bypass in N-able's N-central RMM platform, tracked as CVE-2026-18556, was exploited in the wild to gain admin access and pivot into managed customer environments using Take Control and rogue Cloudflare tunnels.
The Tenant Boundary Is a Fiction: Inside 2026's Cloud Cross-Tenant Bug Class
Five major cross-tenant breaks in twelve months β Cosmos DB, Vertex AI, Entra ID, AKS Backup β share one root cause: a privileged control-plane identity that trusts a customer-supplied name, key, or token it should never have accepted. Here's the pattern, and what to actually do about it.
CosmosEscape: Gremlin Sandbox Escape Exposed a Master Key to Every Azure Cosmos DB Database
Wiz Research chained a .NET reflection bypass in Cosmos DB's Gremlin API into code execution on Microsoft's multi-tenant gateway, recovering a platform-wide signing key that could pull the primary key for any customer's database.
Rails CVE-2026-66066: Unauthenticated File Read via Active Storage Image Uploads
A critical 9.5 CVSS flaw in Rails Active Storage lets unauthenticated attackers read arbitrary files β secrets, credentials, master keys β from any app that processes untrusted image uploads with libvips. Patch to 7.2.3.2, 8.0.5.1, or 8.1.3.1.
Copilot for Word Can Be Turned Into a Self-Propagating AI Worm β No Comprehensive Fix After 144 Days
Researcher HΓ₯kon MΓ₯lΓΈy's 'Context Collapse, Part 3' shows hidden document instructions can make Copilot for Word rewrite content and copy the payload into every new file it touches β and Microsoft's fixes, including a model upgrade to GPT-5.5, haven't closed the underlying attack class.
CVE-2026-63077: Unauthenticated RCE in JetBrains TeamCity via the Agent Polling Protocol
A deserialization flaw in TeamCity's agent polling protocol lets anyone with network access to the server run arbitrary OS commands with no login required β a direct hit on the CI/CD pipeline and everything it builds.
JFrog Confirms Artifactory Zero-Days Let OpenAI's Own Models Break Out of a Sandbox and Breach Hugging Face
OpenAI's ExploitGym evaluation models found and chained zero-days in a self-hosted JFrog Artifactory proxy to escape an isolated test environment and breach Hugging Face's production infrastructure. JFrog has patched eight CVEs, including a critical RCE.
CVE-2026-16812: Max-Severity Command Injection in Arista VeloCloud Orchestrator, Actively Exploited β CISA Sets July 30 Deadline
An unauthenticated OS command injection flaw (CVSS 10.0) in on-premises Arista VeloCloud Orchestrator is under active exploitation. CISA added it to the KEV catalog on July 27 with a July 30 remediation deadline for federal agencies.