Rce
CVE-2026-8452: 'DoS-Only' NetScaler Flaw Turns Out to Be Pre-Auth Root RCE, Now Under Active Exploitation
watchTowr Labs turned a Citrix NetScaler bug Citrix rated as a crash-only memory overflow into pre-auth root code execution; CISA confirms in-the-wild exploitation with web shells on unpatched appliances.
PaperCut Ships Emergency Out-of-Cycle Build After Zero-Day Hits Every Supported NG/MF Version
PaperCut confirmed active zero-day exploitation of an unpatched flaw affecting every currently supported PaperCut NG/MF release and shipped emergency out-of-cycle builds hours after a university's forensics team caught it in the wild.
CVE-2026-60004: Gitea diffpatch Code Injection Now Under Active Exploitation, Added to CISA KEV
A critical Gitea flaw lets any repository writer install a malicious Git hook via the diffpatch endpoint and run shell commands as the Gitea OS user. CISA confirms in-the-wild exploitation and gave federal agencies until August 28 to patch.
CVE-2026-21962: Max-Severity Oracle HTTP Server / WebLogic Proxy Flaw Added to CISA KEV After Months of Exploitation
CISA added CVE-2026-21962, a CVSS 10.0 auth-bypass and path-traversal flaw in Oracle HTTP Server and the WebLogic Server Proxy Plug-in, to its KEV catalog on August 24 — seven months after Oracle patched it and after mass automated scanning had already begun.
CVE-2026-69836: Perfect-10 Entra ID Deserialization RCE Exploited in the Wild
Microsoft confirms in-the-wild exploitation of CVE-2026-69836, a maximum-severity unauthenticated deserialization RCE in Entra ID's backend — already patched server-side, but the identity plane behind Microsoft 365 and Azure was exposed with no customer visibility into the attack.
CVE-2026-73570: Unauthenticated Zimbra RCE via SNMP Notifications Under Active Exploitation
CERT Polska confirms in-the-wild exploitation of CVE-2026-73570, an unauthenticated OS command injection in Zimbra Collaboration's SNMP notification handling — patched in 10.1.20, but plenty of mail servers haven't updated.
CVE-2025-62593: Browser-Based DNS Rebinding RCE in Ray Added to CISA KEV Amid ShadowRay 2.0 Exploitation
CISA has added CVE-2025-62593, a critical DNS-rebinding RCE in the Ray AI compute framework, to its KEV catalog after RondoDox botnet operators weaponized it and ShadowRay 2.0 continued hijacking exposed clusters for GPU cryptomining.
SharePoint JWT Bypass (CVE-2026-55040) Chains With BCS Gadget Chain (CVE-2026-63520) for Unauthenticated RCE
A JWT validation bypass under active exploitation since mid-August now chains with a newly disclosed Business Connectivity Services gadget chain, giving unauthenticated attackers full RCE on on-prem SharePoint farms.
CVE-2026-58231: Max-Severity Unauth RCE in SAP Commerce Cloud Now Under Active Exploitation
CVE-2026-58231, a CVSS 10.0 flaw in SAP Commerce Cloud's Data Hub Adapter, lets unauthenticated attackers execute arbitrary code via a default authentication client. Exploitation attempts began August 14, three days after SAP shipped a patch.
Critical Use-After-Free in Microsoft QUIC Allows Unauthenticated RCE (CVE-2026-62815)
CVE-2026-62815, a CVSS 9.8 use-after-free in Microsoft's QUIC/HTTP-3 implementation, lets an unauthenticated remote attacker execute code with a single crafted packet — no user interaction required.
Unpatched GeoServer Zero-Day Lets Unauthenticated Attackers Turn SQL Injection Into RCE
An unpatched, unauthenticated SQL injection in GeoServer's jsonArrayContains filter function is under active probing days after public disclosure, with a documented path to remote code execution on PostgreSQL-backed instances.
Microsoft Patches a Wormable Windows DNS Server RCE Alongside Three More Critical DNS Flaws
CVE-2026-62878, a CVSS 9.8 stack-based buffer overflow in Windows DNS Server, is wormable and needs no authentication — and it shipped alongside three more critical DNS Server RCEs in the same Patch Tuesday round.
CopyEscape (CVE-2026-17106): A Malicious Container Can Overwrite Files on the Docker Host via `docker cp`
CVE-2026-17106 ('CopyEscape'), found by Imperva's Red Team, lets a malicious or compromised container hijack docker cp to overwrite arbitrary files on the host — and, when the copy runs with elevated privileges, replace runc to get root. Docker has shipped fixes across Engine, Desktop, and Sandboxes.
Langflow's Third KEV Entry of the Year: CVE-2026-9198 Chains Auto-Login Bypass to Unauthenticated RCE
CVE-2026-9198 chains an unauthenticated auto-login token mint with an unsandboxed code-validation endpoint to give attackers full RCE on default IBM Langflow deployments, now under active exploitation and CISA KEV.
XSS2Shell: WordPress Pre-Auth Login XSS Chains to Full RCE (CVE-2026-64638)
CVE-2026-64638 lets an unauthenticated attacker plant XSS on WordPress's login screen with a single failed-login attempt, then chain DOM clobbering and a REST API JSONP callback to steal an admin's Application Password and execute PHP. Patch to 7.0.3.
Jenkins CVE-2026-70426: Remoting Deserialization Filter Bypass Enables Controller RCE
CVE-2026-70426 (CVSS 9.0) lets an attacker with agent-level access bypass Jenkins' JEP-200 class filter via a fallback path in Remoting, achieving code execution on the controller. Patch to 2.576 / LTS 2.568.2 now.
Microsoft Patches Four CVSS 9.9 Flaws Spanning Azure Service Bus, Azure SRE Agent, Entra Provisioning, and Active Directory
Microsoft quietly shipped fixes for four unrelated CVSS 9.9 flaws — an unauthenticated-adjacent RCE in Azure Service Bus and privilege-escalation bugs in Azure SRE Agent, Entra Provisioning Service, and on-prem Active Directory — all remotely exploitable and disclosed August 6.
CVE-2026-34486: Apache Tomcat's EncryptInterceptor Fix Was Incomplete — Now Under Active Exploitation
A second, incomplete patch for a Tomcat clustering flaw lets attackers bypass pre-shared-key encryption and reach Java deserialization on the cluster port — CISA gave federal agencies until today to fix it.
Broadcom Patches Two CVSS 9.8 vCenter Auth Bypass/RCE Flaws and an ESXi VM Escape (VMSA-2026-0006)
Broadcom's VMSA-2026-0006 patches two unauthenticated, CVSS 9.8 vCenter Server flaws (auth bypass and directory-traversal RCE) plus a VMXNET3 VM escape in ESXi — no workarounds exist for either critical vCenter bug.
Rails CVE-2026-66066: Unauthenticated File Read via Active Storage Image Uploads
A critical 9.5 CVSS flaw in Rails Active Storage lets unauthenticated attackers read arbitrary files — secrets, credentials, master keys — from any app that processes untrusted image uploads with libvips. Patch to 7.2.3.2, 8.0.5.1, or 8.1.3.1.