Rosetta Daily · Aug 12, 2026
Scanned 33 enabled sources — 1,139 raw items captured in the 36-hour window (including 758 MSRC entries from Microsoft's August Patch Tuesday) — 38 selected.
Critical Vulnerabilities (CVSS ≥ 8.0)
- SAP Commerce Cloud unauthenticated code execution — CVE-2026-58231 (CVSS 10.0)— A default authentication client can be abused by an unauthenticated attacker with crafted input to achieve arbitrary code execution, with high impact on confidentiality, integrity, and availability of internal components. Source
- Adobe ColdFusion OS command injection — CVE-2026-48362 (CVSS 10.0)— Adobe also patched several high-severity flaws in Campaign Classic and Commerce this week, all leading to arbitrary code execution or privilege escalation. Source
- Dassault SIMULIA Execution Engine deserialization RCE — CVE-2026-17061 (CVSS 10.0)— Affects releases 2023 through 2026; an unauthenticated attacker can achieve remote code execution directly. Source
- Siemens SIMATIC IoT2050 (running Node-RED) unauthenticated command execution — CVE-2026-58115 (CVSS 10.0)— Affected industrial gateway devices do not enforce authentication on the Node-RED HTTP interface; an unauthenticated attacker can build malicious flows to execute system commands with maximum privileges. Source
- wg-easy WireGuard admin panel command injection — CVE-2026-72603 (CVSS 9.9)— Users with client-create permission can inject newline-delimited PostUp directives via the client name field; the config file does not neutralize newlines, letting an attacker execute arbitrary commands as root on the host. Source
- Three open-source CMS/social platforms disclose unauthenticated SQL injection— YesWiki (CVE-2026-46670, versions before 4.6.4, exposes user password hashes), e107 (CVE-2026-72599, version 2.4.0), and Friendica (CVE-2026-72550, through the 2026.08-dev branch) all let unauthenticated attackers read, modify, or delete the entire database; all rated CVSS 9.8.
- PicketLink SAML identity spoofing — CVE-2026-10579 (CVSS 9.8)— The unsolicited-response handler accepts forged assertions with no verification, letting an unauthenticated attacker authenticate as any principal in any role, leading to information disclosure or unauthorized operations. Source
- AI-assisted SharePoint exploit chain reaches unauthenticated RCE — CVE-2026-55040 (CVSS 9.1)— Researchers say much of the discovery work was done by an AI agent; affects SharePoint Server Subscription Edition, 2019, and 2016, fully bypassing authentication to impersonate any user, including an administrator. Source
Actively Exploited / New CISA KEV Additions
- Windows AFD for WinSock use-after-free — CVE-2026-68820 (CVSS 7.0)— The only confirmed actively-exploited zero-day in this Patch Tuesday, added to CISA's KEV catalog on August 11; Bleeping Computer reports North Korea's Lazarus group exploited it against defense contractors as part of Operation Dream Job. Source
- Cisco ASA/FTD heap inspection flaw — CVE-2026-20349 (CVSS 8.6)— Added to KEV the same day; Cisco confirmed it is being used to remotely crash devices (DoS). Source
- Metabase SQL injection — CVE-2026-72898— The third of three vulnerabilities CISA added to KEV on August 11; our sources carry no further detail beyond confirming the KEV listing. Source
- VMware vCenter directory traversal — CVE-2026-59310 (CVSS 9.8)— Threat intel firm QUIRSO reports the flaw is being exploited for persistent remote access to vCenter; not yet on CISA's KEV catalog. Source
- A previously-KEV'd SharePoint deserialization flaw is now used in ransomware attacks— CISA confirmed a high-severity SharePoint RCE bug — flagged as actively exploited since early July — is now being abused by ransomware gangs; our sources did not give a specific CVE number for this report. Source
- Microsoft Defender "ShieldBreak" patch-bypass PoC — targets CVE-2026-50656/RoguePlanet (CVSS 7.8)— Researcher Chaotic Eclipse published a PoC claiming to bypass this month's patch and gain SYSTEM access; no in-the-wild exploitation reported yet. Source
Vendor Advisories
- Microsoft's August Patch Tuesday— Counts vary slightly by outlet: The Hacker News and Krebs on Security report 398 flaws, Bleeping Computer reports 400 flaws and 3 zero-days, CrowdStrike reports 415 CVEs with 62 rated critical and one actively-exploited zero-day. All confirm the fixed Windows kernel driver zero-day (CVE-2026-68820 above) plus two other previously publicly-disclosed flaws. Source
- CISA published three ICS/medical-device advisories the same day— Johnson Controls C-CURE 9000 / victor application server (CVE-2026-21655, CVSS 9.6, SSRF enabling unauthenticated remote code execution affecting physical access-control systems); Pulsetto Vagus Nerve Stimulator (CVE-2026-18844, CVSS 8.1, undocumented, unencrypted, unauthenticated hidden commands over BLE; vendor has not responded to CISA's outreach); Mira Hormone Monitor and companion app (8 CVEs including CVE-2026-66875, CVSS 9.8, unauthenticated BLE-range device rebinding and cleartext exposure of health data). Source
- Cisco ClamAV (Secure Endpoint Connector)— Two high-severity flaws now have public exploit code and can crash the scanning process, causing denial of service. Source
Web Security Research
- Zoom annotation flaws let meeting participants hijack each other's clients— No click, download, or on-screen prompt required; a screen-sharing presenter and any viewer could take over each other's computers. Already patched. Source
- "Plug and Pwn": Windows Plug and Play abuse leads to SYSTEM access— Researchers used an emulated USB device to trick Windows into installing vulnerable, vendor-signed software and chained it to SYSTEM access on a fully patched Windows 11 machine; the same path can be triggered over Remote Desktop without physical hardware when low-level USB redirection is enabled. Source
- A malicious SIM card can run attacker code inside cellular IoT modems— Researchers at the University of Birmingham and Fuzzware tested 26 phones and cellular modules and found the flaw sufficient to fully take over EV chargers, industrial routers, and car telematics units. Source
AI Security
- OpenAI/Anthropic/Google API flaw lets weaker models decode stronger models' reasoning— Encrypted reasoning objects used by all three providers to carry hidden reasoning between API calls could be replayed across sessions; testing recovered internal reasoning and secrets, including API keys and passwords, from session logs. Source
- Malicious MCP servers can split instructions to make AI coding agents exfiltrate secrets— Even after a blunt theft request is refused, an attacker can fragment the request into routine-looking pieces spread across channels the agent already trusts, and still walk off with SSH keys, environment secrets, and source code without ever sending one obviously harmful instruction. Source
- OpenAI launches GPT-5.6-Cyber with reduced safeguards for exploit development— Aimed at vulnerability research, pentesting, and incident response; OpenAI says it reduced refusals for higher-risk tasks like zero-day discovery and exploit-chain development, available only to vetted partners via the Daybreak Red program. Source
Threat Intel & Supply Chain
- Sandworm/UAC-0145 uses fake job interviews to push a trojanized WireGuard client— Targeting Ukrainian and foreign IT/sysadmin staff since at least May with recruiter-themed social engineering; reported by both CERT-UA and Bleeping Computer, attributed to a Sandworm (aka APT44) subcluster. Source
- Kimwolf v7 botnet evolves— Unit 42 reports the Android/IoT botnet added HTTP/2 DDoS traffic fingerprinting, Ethereum ENS-based C2 resolution, and Tor backup routing. Source
- DeadLock ransomware adopts blockchain-backed infrastructure— Microsoft Threat Intelligence says the group now combines the Session messaging network with blockchain-backed storage for victim communications and leak-site content to resist takedowns. Source
- US and South Korea warn of Gunra ransomware— Exploiting Fortinet and Schneider Electric flaws to breach healthcare, financial, government, and critical-infrastructure networks. Source
- Polish power plant breached via private cellular network, turbine shut down— Attackers entered through the private cellular network the grid operator uses to reach remote equipment, shutting down a turbine and water-treatment system at a plant supplying heat to roughly 50,000 residents; intruders were still active when recovery began. Source
- Three supply-chain poisoning stories— AnquanKe (安全客) reports 1,300 npm packages poisoned; CloudSEK says two malicious LiteLLM releases sat on PyPI for roughly 40 minutes in March, stealing cloud and SSH keys, with potential exposure to 2,100+ organizations; WordPress plugin vendor BdThemes suffered a supply-chain compromise where attackers poisoned JSON data rather than official repository source code, to create rogue admin accounts. Source 1· Source 2
Other
- Wesco confirms a security incident— The global supply-chain and distribution giant told Bleeping Computer it is investigating a cybersecurity incident after the ExfilSquad group claimed to have stolen its data. Source
Bug Bounty intelligence has been consolidated into the weekly feature and is not listed daily; see
intel/bug-bounty/(data source currently disconnected — see repo notes).