In August 2026, a significant cybersecurity alert was issued following the discovery of a zero-day vulnerability that is currently being exploited in the wild. Alongside this, researchers identified 62 other critical vulnerabilities among a total of 415 Common Vulnerabilities and Exposures (CVEs) reported this month. This situation places numerous software products and systems at risk, affecting a wide range of users, including businesses and individual consumers. Companies are urged to prioritize patching these vulnerabilities to protect their networks and sensitive data. The presence of an actively exploited zero-day highlights the urgency for immediate action in cybersecurity measures to prevent potential breaches.
Microsoft Threat Intelligence has reported that a group known as Storm-1175, which is believed to operate from China, has exploited an authentication-bypass vulnerability (CVE-2026-18577) in N-able's N-central remote monitoring and management tool. This exploitation allowed the attackers to gain initial access to systems and subsequently deploy a new ransomware variant called StormEncryptor. Organizations using N-central are at risk, as the vulnerability could lead to significant data loss and operational disruption. The incident emphasizes the importance of monitoring for vulnerabilities in remote management tools, as they can be entry points for cybercriminals. Companies should ensure they are using the latest security updates and patches to protect against such threats.
A severe vulnerability has been discovered in Metabase, a popular business analytics platform. This flaw allows attackers to gain remote administrative access, posing a significant risk not just to the platform itself but also to its users and their data. As of now, there is no official CVE identifier for this vulnerability, which raises concerns about the urgency and scale of potential attacks. Organizations using Metabase should take immediate steps to assess their security posture and implement protective measures to mitigate the risk. The implications of this vulnerability could be far-reaching, affecting any business relying on Metabase for data analytics.
N-able has released a second hotfix for its N-central remote monitoring and management solution due to ongoing exploitation of the vulnerability identified as CVE-2026-18577. This new hotfix, referred to as Hotfix 2, is critical even for those who have already applied the first hotfix, as it includes additional security measures aimed at protecting users and their customers from active attacks. The company has also shared indicators of compromise that have been observed in these attacks, highlighting the seriousness of the situation. Managed service providers using N-central should prioritize applying this hotfix to enhance their defenses against these threats and protect their clients' systems.
Metabase has issued a warning about a serious security vulnerability in its data visualization software, which is currently being exploited by attackers. This zero-day flaw, rated with a CVSS score of 10.0, allows unauthorized individuals to execute arbitrary SQL commands in the Metabase application database without needing to log in. As a result, attackers can gain administrative access to sensitive data. Since this vulnerability does not have a CVE identifier, it adds another layer of urgency for users to secure their systems. Organizations using Metabase should take immediate action to protect their data, as the exploit is actively being used in the wild.
WordPress has addressed a serious vulnerability in its login screen that affects all versions of the platform. This flaw, known as CVE-2026-64638 and rated with a CVSS score of 8.9, allows for pre-authentication reflected cross-site scripting (XSS). Researchers from pwn.ai have demonstrated that this vulnerability could potentially be exploited to execute PHP code on the server, particularly if an administrator interacts with a malicious page. As this issue impacts every WordPress installation, users and website administrators are strongly encouraged to apply the patch immediately to secure their sites and prevent potential exploitation.
The Cybersecurity and Infrastructure Security Agency (CISA) has added a new vulnerability, identified as CVE-2026-8037, to its Known Exploited Vulnerabilities (KEV) Catalog. This vulnerability affects the Progress LoadMaster and allows for command injection, which can grant attackers total control over the affected system. CISA emphasizes that federal agencies must prioritize the rapid remediation of such high-risk vulnerabilities, especially those that are actively exploited. While this directive specifically targets Federal Civilian Executive Branch agencies, CISA encourages all organizations to adopt similar risk-based approaches to managing vulnerabilities. Organizations aware of other exploited vulnerabilities not listed in the KEV Catalog can submit them for consideration through CISA's nomination process.
Recent research has identified several vulnerabilities in the Controller-Pilot Data Link Communications (CPDLC) system that operates over the Aeronautical Telecommunications Network (ATN-B1). These vulnerabilities stem from the use of legacy, unauthenticated radio frequency links, which could allow attackers to inject unauthorized messages, disrupt communications, and reset sessions. Although these issues do not directly compromise aircraft safety, they could create confusion and increase the workload for pilots and air traffic controllers, potentially impacting operational safety. The vulnerabilities affect all versions of CPDLC over ATN-B1, with several specific CVEs (CVE-2025-71409 to CVE-2025-71413) documented. Currently, there are no available mitigations or patches for these vulnerabilities, and while they can be exploited in laboratory settings, there have been no reports of active exploitation in the wild.
A newly discovered vulnerability in the Zapscape Linux kernel, tracked as CVE-2026-64561, poses a significant risk to systems using KVM (Kernel-based Virtual Machine) technology. This flaw allows attackers with kernel privileges in an L1 guest virtual machine to potentially escape the isolation that KVM provides, enabling them to execute arbitrary code on the host system. The issue primarily arises when nested virtualization is deployed with untrusted guests, which increases the likelihood of exploitation. As companies and organizations increasingly rely on virtualized environments, this vulnerability underscores the need for vigilance in managing and securing these systems to prevent unauthorized access and potential breaches.
A recent study by researchers at 1Password reveals that about 75% of AI-generated patches for real vulnerabilities fail to provide a complete fix. The researchers evaluated 6,080 patches for six newly disclosed Common Vulnerabilities and Exposures (CVEs). While the AI-generated patches often resemble human-written fixes and can pass tests, they frequently leave unaddressed issues that could still be exploited. This finding raises concerns about the reliability of AI in cybersecurity, particularly as organizations increasingly rely on automated solutions to address vulnerabilities. The study suggests that companies should exercise caution when implementing AI-generated fixes and ensure thorough manual reviews before deployment.
A vulnerability has been discovered in Medixant's RadiAnt DICOM software that could allow attackers to exploit specially crafted DICOM files. Versions 2025.2 and earlier of the software are affected, which could lead to application crashes or even remote code execution due to an out-of-bounds write triggered by malicious JPEG-compressed pixel data. Users are advised to upgrade to version 2026.1 to mitigate this risk. The vulnerability is particularly concerning for healthcare and public health sectors worldwide, as it could compromise patient data and system integrity. While there are currently no reports of this vulnerability being actively exploited, users should remain cautious and only open DICOM files from trusted sources.
A recently discovered vulnerability in Johnson Controls Inc.'s TL280 device could allow attackers to access sensitive information. Specifically, versions of the TL280 prior to 5.63 are impacted due to the use of hardcoded credentials in the device's firmware. This presents a significant risk, particularly for sectors such as critical manufacturing, government services, and energy. To mitigate the threat, Johnson Controls recommends updating to firmware version 5.63 and implementing several network security measures, such as restricting access to trusted VLANs and monitoring device access logs for unusual activity. Although no active exploitation of this vulnerability has been reported, organizations should take proactive steps to protect their systems.
ABB Ability Zenon is facing significant vulnerabilities that could allow attackers to bypass security measures, crash systems, and compromise data. The issues primarily affect the IIoT services bundled with MongoDB version 4.2 across all versions of ABB Ability Zenon. Notably, vulnerabilities such as improper handling of length parameters and exploitation of uninitialized memory could lead to unauthorized actions. ABB has recommended urgent remediation steps, including replacing the bundled MongoDB with a supported version and uninstalling IIoT services if they are not needed. Given that these vulnerabilities impact critical infrastructure sectors like energy and healthcare, organizations using ABB Ability Zenon must act quickly to secure their systems.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning about a serious security flaw in JetBrains TeamCity, specifically affecting on-premise versions. The vulnerability, identified as CVE-2026-63077, has a high severity score of 9.8 and involves deserialization of untrusted data. This flaw allows unauthenticated attackers to potentially gain access to a TeamCity server, making it a significant risk for organizations using this software. As the vulnerability is currently being exploited in the wild, it is crucial for users to take immediate action to protect their systems. The timely patching of affected versions is paramount to mitigate this risk and ensure the security of sensitive data and operations.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added three vulnerabilities to its Known Exploited Vulnerabilities catalog, indicating that these issues are actively being targeted by attackers. The vulnerabilities include a critical flaw in IBM's Langflow, an issue in Apache Tomcat, and a flaw in N-able N-central. These vulnerabilities could allow unauthorized access or remote code execution, putting various organizations at risk. Companies using these platforms should take immediate action to address these vulnerabilities to avoid potential breaches and data loss. Being listed in CISA's catalog emphasizes the urgency for affected users to implement the necessary security measures.