Rosetta Daily · Aug 22, 2026
Scanned 33 sources, 401 raw items ingested today, 33 selected.
Actively Exploited / New KEV Additions
-
TrueConf Server — two flaws exploited in the wild by Head Mare, added to CISA KEV: CVE-2026-72529 (missing authentication for a critical function) and CVE-2026-72530 (code injection allowing sandbox escape and arbitrary code execution over port 4307/TCP), both added to CISA's Known Exploited Vulnerabilities catalog on 2026-08-20. The Russia-linked Head Mare group has repeatedly abused this pair to trojanize TrueConf client installers with the PhantomCore backdoor, targeting Russian instrumentation, electronics, transport, energy, and IT/software companies. CISA has ordered federal agencies to remediate. Bleeping Computer · The Hacker News
-
Windows IKE Service Extensions RCE (CVE-2026-33824): A double-free flaw, added to CISA KEV on 2026-08-18. NVD
-
MLflow SSRF (CVE-2026-64849) under active exploitation: This open-source AI/ML engineering platform's SSRF flaw was added to CISA KEV on 2026-08-19; CISA warns threat actors are actively exploiting it. Bleeping Computer
-
Microsoft Entra ID max-severity flaw (CVE-2026-69836, CVSS 10.0): Microsoft disclosed on Aug 21 that this RCE flaw had been exploited in the wild, saying no customer action is required. Later the same day, the MSRC advisory page was updated to "Corrected Exploited to No." The two accounts conflict; not yet listed in CISA KEV. Worth watching for further correction. The Hacker News · Bleeping Computer
-
Zimbra Collaboration Suite unauthenticated RCE (CVE-2026-73570, CVSS 8.9) exploited in the wild: CERT Polska warns of active exploitation of this SNMP flaw; not yet KEV-listed. The Hacker News
-
GitLab code injection (CVE-2026-19478, CVSS 9.4) exploited within days of disclosure: Security firm watchTowr observed active exploitation shortly after public disclosure; not yet KEV-listed. The Hacker News
Critical Vulnerabilities
-
OSNEXUS QuantaStor unauthenticated RCE (CVE-2026-18265, CVSS 9.8): Missing authentication in the enterprise storage platform's Kapacitor configuration lets an unauthenticated attacker execute arbitrary code remotely. NVD
-
FreeIPA — two high-severity flaws (CVE-2026-11861 CVSS 9.6, CVE-2026-13097 CVSS 9.1): When FreeIPA trusts Active Directory, an attacker can impersonate a privileged service by forging the client name in a TGS ticket, bypassing portal/SMB/LDAP authentication; a separate flaw in the 389-ds directory server's Kerberos principal-name uniqueness check lets a user with LDAP write privileges impersonate a privileged service principal for unauthorized access.
-
IBM AIX / PowerVM VIOS — two high-severity flaws (CVE-2026-16926 CVSS 9.1, CVE-2026-16932 CVSS 8.8): A remote arbitrary file overwrite via unsanitized input, and a local arbitrary command execution via improper validation of the ODMDIR environment variable, affecting AIX 7.2/7.3 and PowerVM VIOS 4.1.
-
NoMachine authenticated RCE (CVE-2026-18264, CVSS 8.8): A command injection flaw in the getstat function, requires authentication to exploit. NVD
-
n8n — four high-severity flaws (CVSS 8.4–8.7): CVE-2026-77068 (RCE via the workflow-sdk node-schema loader deriving a module path from attacker input), CVE-2026-77080 (arbitrary file read/write via the Snowflake node), CVE-2026-77072 (stored XSS in the Form node's completion page), CVE-2026-77075 (expression injection in resource-locator link previews). All fixed in 2.34.1 — upgrade recommended.
-
jsoup Java HTML parser DoS (CVE-2026-75140, CVSS 8.7): XmlTreeBuilder can exhaust JVM heap memory when parsing a deeply nested, uniquely-namespaced XML document. Affects 1.23.2 and earlier.
-
CVAT stored XSS (CVE-2026-73220, CVSS 8.5): A flaw in the audio-task annotation guide renderer of this popular open-source computer-vision annotation tool, affecting 2.68.0–2.70.0.
-
GraphicsMagick heap out-of-bounds write (CVE-2026-77118, CVSS 8.4): In the PCD decoder's DecodeImage(), the output pointer advances past the heap buffer's end without a bounds check.
Vendor Advisories
-
Citrix NetScaler ADC / Gateway critical authentication bypass: Affects customer-managed NetScaler ADC and Gateway (including certain FIPS/NDcPP builds) and SecurAccess; Citrix has released patches and urges immediate remediation. The Hacker News · Bleeping Computer
-
Cisco patches nine Crosswork and Secure Workload flaws, five scoring CVSS 10.0: Part of the company's ongoing internal security review; four of the flaws affect Crosswork Data Gateway, Network Controller, and Planning regardless of device configuration. The Hacker News
-
Microsoft's August Patch Tuesday batch: Azure Managed Instance for Apache Cassandra argument-injection RCE (CVE-2026-65770); two SQL Server RCEs exploitable with no privileges required (CVE-2026-54118, CVE-2026-54117); plus multiple Azure elevation-of-privilege/information-disclosure flaws across Entra ID, Data Factory, Logic Apps, and Arc. MSRC
Web Security Research / Supply Chain
-
isolated-vm sandbox escape can lead to RCE: A flaw in this popular JavaScript sandboxing library (2,900+ GitHub stars) lets attackers escape the isolated environment. The Hacker News
-
"CDN Tsunami" attack abuses HTTP/3-to-HTTP/1.1 translation for up to 350x DoS amplification: Researchers disclosed how major CDNs' client-facing HTTP/3 to origin HTTP/1.1 translation can be abused to amplify a low-bandwidth request into a much larger flood. The Hacker News
-
"Zombie Card" attack revives expired Visa contactless cards for real purchases: University of Massachusetts Amherst researchers rewrote the expiration date read by a POS terminal over NFC. The Hacker News
-
NASA AIT-GUI flaw chain lets unauthenticated attackers issue spacecraft commands: Cycode disclosed a chain of flaws in AIT-GUI, the browser-based operator console for NASA/JPL's open-source AMMOS Instrument Toolkit. The Hacker News
-
Rust supply-chain attack: 3 crates with a combined 245M downloads carried build-time malware: A compromised maintainer account published releases adding a typosquatted dependency whose build script downloaded and executed a remote payload; the widely used arrayref crate was separately poisoned with infostealer malware. The Rust Project has removed the malicious releases from crates.io. The Hacker News · Bleeping Computer
-
40 malicious Firefox extensions impersonating Web3 products steal wallet secrets: Disguised as OKX, Rabby Wallet, TronLink and other brands, per Socket's threat research team. The Hacker News
AI Security
-
New "cryptographic context injection" attack could let web pages steal Grok chat data: Adversa AI disclosed a technique that can cause xAI's Grok, after being asked to browse a page, to exfiltrate the user's name, approximate location, subscription tier, and conversation prompts to an attacker-controlled server. The Hacker News
-
AI-generated exploit scripts target Siemens S7 PLCs in U.S. critical infrastructure: The U.S. government warned of an active threat using AI-generated exploit scripts against programmable logic controllers. The Hacker News
-
Single-source report: possible Windows Defender zero-day allowing one-click SYSTEM privilege escalation from a standard account, no patch yet: Reported only by Chinese outlet AnQuanKe (安全客) so far; the article body was not captured, only the headline, and no specific CVE has been confirmed. Treat as unverified pending corroboration. AnQuanKe
Other
-
Over 9,300 publicly leaked AWS access keys are still active: Exposed between August 2022 and August 2026, giving full control over the affected corporate accounts. Bleeping Computer
-
Suspected Russian hackers abuse Google OAuth and WhatsApp device linking to hijack accounts: Three distinct suspected Russian espionage clusters abused legitimate authentication flows to target individuals in academia, aerospace and defense, government, and think tanks across Europe and beyond. The Hacker News
-
New "Manic" Android malware exfiltrates data from offline phones via nearby infected devices: Targeting Ukrainian banks, government and identity services, and messaging apps, as well as Russian and European financial institutions, fintech, and crypto services. The Hacker News · Bleeping Computer