Monthly Vuln Summary 2026-08 (31)

In-the-Wild CVE Review · 2026-08

31 CVEs were added to the CISA KEV catalog this month (actively exploited; [RANSOMWARE] = tied to ransomware).

本月收录

  • CVE-2026-82078 — 0.0 — PaperCut NG/MF — PaperCut NG/MF contains an unsafe reflection vulnerability that allows an attacker to manipulate system configuration parameters and execute arbitrary Java bytecode residing on the… [KEV]
  • CVE-2026-81578 — 0.0 — PaperCut NG/MF — PaperCut NG/MF contains a missing authentication for critical function vulnerability which allows an unauthenticated remote attacker to modify certain system configurations. This v… [KEV]
  • CVE-2023-49105 — 0.0 — ownCloud ownCloud — ownCloud contains an improper authentication vulnerability that allows an attacker to access, modify, or delete any file without authentication if the username of a victim is known… [KEV]
  • CVE-2026-53362 — 0.0 — Linux Kernel — Linux Kernel contains an unspecified vulnerability that can allow for privilege escalation via IPv6 networking subsystem. This vulnerability can impact multiple products, including… [KEV]
  • CVE-2026-66384 — 0.0 — JFrog Artifactory — JFrog Artifactory contains an improper limitation of a pathname to a restricted directory vulnerability. This can allow an authenticated user to write data outside the intended Doc… [KEV]
  • CVE-2021-23758 — 0.0 — Ajax.NET Professional Ajax.NET Professional — Ajax.NET Professional (AjaxPro) contains a deserialization of untrusted data vulnerability that could allow for remote code execution via arbitrary .NET classes. The impacted produ… [KEV]
  • CVE-2015-3246 — 0.0 — Red Hat Libuser — Red Hat libuser contains a race condition vulnerability that allows authenticated local users to corrupt the /etc/passwd file to cause a denial of service or privilege escalation. [KEV]
  • CVE-2015-5287 — 0.0 — Red Hat Automatic Bug Reporting Tool — Red Hat Automatic Bug Reporting Tool (ABRT) contains a privilege escalation vulnerability that could allow local users with certain permissions to gain privileges via a symlink att… [KEV]
  • CVE-2022-0995 — 0.0 — Linux Kernel — Linux Kernel contains an out-of-bounds memory write vulnerability which could allow a local user to gain privileged access or cause a denial of service on the system. [KEV]
  • CVE-2026-8452 — 0.0 — Citrix NetScaler ADC and NetScaler Gateway — Citrix NetScaler ADC and NetScaler Gateway contain an improper restriction of operations within the bounds of a memory buffer vulnerability which could lead to denial of service. [KEV]
  • CVE-2019-1068 — 0.0 — Microsoft SQL Server — Microsoft SQL Server contains a remote code execution vulnerability that could allow an attacker to execute code in the context of the SQL Server Database Engine service account. [KEV]
  • CVE-2026-60004 — 0.0 — Gitea Gitea — Gitea contains a code injection vulnerability that allows an attacker with repository write access to send a malicious patch to the diffpatch API endpoint to plant an executable Gi… [KEV]
  • CVE-2026-21962 — 0.0 — Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in — Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in contain an improper access control vulnerability that can result in unauthorized creation, deletion or modification acce… [KEV]
  • CVE-2026-73570 — 0.0 — Synacor Zimbra Collaboration Suite (ZCS) — Zimbra Collaboration Suite (ZCS) contains an OS command injection vulnerability which could allow an unauthenticated attacker to send specially crafted SMTP requests that may resul… [KEV]
  • CVE-2026-72530 — 0.0 — TrueConf Server — TrueConf Server contains a code injection vulnerability that could allow an unauthorized remote attacker with network access via port 4307/TCP to use a specially crafted script to … [KEV]
  • CVE-2026-72529 — 0.0 — TrueConf Server — TrueConf Server contains a missing authentication for critical function vulnerability which could allow a remote unauthorized attacker with network access via port 4307/TCP to exec… [KEV]
  • CVE-2026-64849 — 0.0 — MLflow MLflow — MLflow contains a server-side request forgery vulnerability that can allow attackers to reach internal or cloud metadata services and receive response_status and response_body. [KEV]
  • CVE-2026-33824 — 0.0 — Microsoft Internet Key Exchange (IKE) Service Extensions — Microsoft Internet Key Exchange (IKE) Service Extensions contains a double free vulnerability that could enable remote code execution. [KEV]
  • CVE-2026-59310 — 0.0 — Broadcom VMware vCenter — Broadcom VMware vCenter contains a path traversal vulnerability which could allow a threat actor with network access to vCenter to execute arbitrary code. [KEV] [RANSOMWARE]
  • CVE-2026-55040 — 0.0 — Microsoft SharePoint — Microsoft SharePoint contains a weak authentication vulnerability which allows an unauthorized attacker to bypass a security feature over a network. [KEV]
  • CVE-2026-65400 — 0.0 — Apple macOS — Apple macOS contains an improper authentication vulnerability that could allow an attacker on the network to authenticate to Screen Sharing without valid credentials. [KEV]
  • CVE-2025-62593 — 0.0 — Ray-Project Ray — Ray-Project Ray contains a code injection vulnerability that could allow remote code execution. Developers using Ray as a development tool may be exposed to this vulnerability expl… [KEV]
  • CVE-2026-20349 — 0.0 — Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) ** — Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) contain a heap inspection vulnerability that could allow an unauthenticated, remote… [KEV]**
  • CVE-2026-68820 — 0.0 — Microsoft Windows Ancillary Function Driver for WinSock ** — Microsoft Windows Ancillary Function Driver for WinSock contains a use-after-free vulnerability that allows an authorized attacker to elevate privileges locally. [KEV]**
  • CVE-2026-72898 — 0.0 — Metabase Metabase — Metabase contains a SQL Injection vulnerability that allows an unauthenticated remote attacker to inject arbitrary SQL into the Metabase application database, which can give them a… [KEV]
  • CVE-2026-8037 — 0.0 — Progress LoadMaster — Progress LoadMaster contains a command injection vulnerability that allows an un-authenticated attacker to execute arbitrary commands on the LoadMaster appliance by exploiting unsa… [KEV]
  • CVE-2026-63077 — 0.0 — JetBrains TeamCity — JetBrains TeamCity contains a deserialization of untrusted data vulnerability that could allow unauthenticated remote code execution via the agent polling protocol. [KEV] [RANSOMWARE]
  • CVE-2026-18556 — 0.0 — N-able N-central — N-able N-central contains an authentication bypass using an alternate path or channel that allows for authentication bypass. [KEV]
  • CVE-2026-34486 — 0.0 — Apache Tomcat — Apache Tomcat contains a missing encryption of sensitive data vulnerability that allows the bypass of the EncryptInterceptor. This vulnerability can be chained with CVE‑2025‑24813. [KEV]
  • CVE-2026-9198 — 0.0 — IBM Langflow — Langflow contains a code injection vulnerability that allows unauthenticated attackers to achieve full remote code execution on default Langflow deployments. [KEV]
  • CVE-2026-18577 — 0.0 — N-able N-central — N-able N-central contains an authentication bypass using an alternate path or channel allows for authentication bypass and account takeover in N-central. This vulnerability is the … [KEV]

Source: CISA KEV. Auto-compiled by CaptainAI Labs AI agents.