Rosetta Daily · Aug 21, 2026
Scanned ~360 raw items from 11 active sources; 16 selected.
Actively Exploited / New to KEV
- MLflow SSRF · CVE-2026-64849— CISA added this to the Known Exploited Vulnerabilities catalog on Aug 19 and warned federal agencies that threat actors are exploiting the server-side request forgery flaw in the open-source MLflow AI engineering platform. https://www.bleepingcomputer.com/news/security/cisa-warns-of-hackers-exploiting-critical-mlflow-vulnerability/
- Windows IKE Service Extensions RCE · CVE-2026-33824— Added to KEV on Aug 18; a double-free enabling remote code execution, now exploited in attacks. Admins should patch immediately. https://www.bleepingcomputer.com/news/security/cisa-critical-windows-ike-extension-flaw-now-exploited-in-attacks/
- macOS / SharePoint / vCenter trio— On Aug 18 CISA added Apple macOS improper authentication (CVE-2026-65400), Microsoft SharePoint weak authentication (CVE-2026-55040), and Broadcom VMware vCenter path traversal (CVE-2026-59310) to KEV, all confirmed exploited in the wild. https://thehackernews.com/2026/08/critical-macos-sharepoint-vcenter-and.html
- Zimbra Collaboration SNMP RCE · CVE-2026-73570— CERT Polska confirms this now-patched flaw is under active exploitation, allowing unauthenticated remote code execution. Not yet in KEV, but active exploitation is confirmed; Zimbra users should upgrade promptly. https://thehackernews.com/2026/08/attackers-exploit-zimbra-snmp-flaw-for.html
Critical Vulnerabilities
- Citrix NetScaler ADC / Gateway auth bypass · CVE-2026-19490 (CVSS 9.3) / CVE-2026-19489 (8.8)— Citrix shipped updates for two flaws; the critical one bypasses authentication on certain Gateway and AAA servers. Citrix urges admins to patch ASAP. Affects multiple 14.1 and 13.1 builds. https://www.bleepingcomputer.com/news/security/citrix-urges-admins-to-patch-new-netscaler-flaws-as-soon-as-possible/
- Elementor Pro unauthenticated RCE · CVE-2026-32475— A critical flaw in the Elementor Pro WordPress builder lets unauthenticated attackers upload PHP files and execute code. https://thehackernews.com/2026/08/elementor-pro-flaw-could-let.html
- Joomla Balbooa Forms pre-auth PHP code injection · CVE-2026-67364 (CVSS 10)— In Balbooa Forms < 2.4.3.2 the optional custom-PHP post-submission handler runs via eval() and a URL-parameter shortcode is substituted unescaped, enabling pre-auth code injection. https://nvd.nist.gov/vuln/detail/CVE-2026-67364
- Joomla Zoo unauthenticated arbitrary file upload · CVE-2026-74803 (CVSS 10)— YOOtheme Zoo < 4.1.64's image element accepts arbitrary files as long as the client-supplied Content-Type falls in the image MIME group. https://nvd.nist.gov/vuln/detail/CVE-2026-74803
- IBM AIX / PowerVM VIOS cluster— IBM AIX 7.2/7.3 and PowerVM VIOS 4.1 disclosed several critical flaws: remote authenticated arbitrary command execution (CVE-2026-16816, 9.9), remote attacker root via improper authentication (CVE-2026-16656, 9.8), and NIM command execution (CVE-2026-15068, 9.9). https://nvd.nist.gov/vuln/detail/CVE-2026-16656
- W3 Total Cache arbitrary file write · CVE-2026-18051 (CVSS 10)— The WordPress cache plugin < 2.10.5 fails to validate the cache file path, letting unauthenticated attackers write a file into any existing directory on the server, overwriting whatever occupies the target name. https://nvd.nist.gov/vuln/detail/CVE-2026-18051
- isolated-vm sandbox escape— A critical flaw in isolated-vm, a popular open-source JS sandbox (2,900+ GitHub stars), lets attackers escape the isolated environment toward host RCE. https://thehackernews.com/2026/08/isolated-vm-flaw-lets-sandboxed.html
Web Security Research
- Cloudflare Workers remote Spectre attack— Researchers ran a remote Spectre attack against a co-located Cloudflare Worker in production, leaking that Worker's JWT at up to ~12 bits/second. https://thehackernews.com/2026/08/cloudflare-workers-spectre-attack-leaks.html
- CDN Tsunami · HTTP/3 translation for up to 350x DoS— Two new DoS attacks abuse how major CDNs convert client HTTP/3 into HTTP/1.1 requests to origins, amplifying a low-bandwidth request by up to 350x. https://thehackernews.com/2026/08/cdn-tsunami-attack-abuses-http3.html
- Grok chat data theft · cryptographic context injection— Adversa AI disclosed a technique letting a web page coax xAI's Grok into sending a user's name, approximate location, subscription tier, and conversation prompts to an attacker-controlled server. https://thehackernews.com/2026/08/new-cryptographic-context-injection.html
AI Security
- US warns of AI-powered attacks on Siemens S7 PLCs— CISA and partners warn that threat actors are using AI-generated scripts to exploit Siemens S7 Series PLCs in US critical infrastructure, with PLC targeting broader than Siemens alone. https://www.bleepingcomputer.com/news/security/us-warns-of-ai-powered-attacks-on-siemens-plcs-in-critical-infrastructure/
Also Worth Noting
- Manic Android malware— A new Android trojan, Manic, targets Ukrainian banks, government, and European financial institutions, with a fallback channel that exfiltrates data from offline phones via nearby infected devices. https://www.bleepingcomputer.com/news/security/new-manic-android-malware-can-exfiltrate-data-through-nearby-devices/
- 14,500 Dahua cameras compromised · CameraSwarm— Researchers detailed a 35-day campaign that compromised 14,500+ Dahua IP cameras (mostly in Ukraine and Russia) via credential attacks, two auth-bypass flaws, and P2P. https://www.bleepingcomputer.com/news/security/hackers-compromise-14-500-dahua-web-cameras-in-35-day-campaign/