25 August 2026
9 vulnerabilities added to CISA's exploited-in-the-wild catalog this week.
CVE-2026-21962: HTTP Server and Oracle Weblogic Server Proxy Plug-in
Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in contain an improper access control vulnerability that can result in unauthorized creation, deletion or modification access to critical data as well as unauthorized access to critical data or complete access to all Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in accessible data.
CISA KEV · 25 August 2026 · Read the original →
CVE-2026-64849: MLflow
MLflow contains a server-side request forgery vulnerability that can allow attackers to reach internal or cloud metadata services and receive response_status and response_body.
CISA KEV · 25 August 2026 · Read the original →
CVE-2026-33824: Microsoft Internet Key Exchange (IKE) Service Extensions
Microsoft Internet Key Exchange (IKE) Service Extensions contains a double free vulnerability that could enable remote code execution.
CISA KEV · 25 August 2026 · Read the original →
CVE-2026-59310: Broadcom VMware vCenter
Broadcom VMware vCenter contains a path traversal vulnerability which could allow a threat actor with network access to vCenter to execute arbitrary code.
CISA KEV · 25 August 2026 · Read the original →
CVE-2026-65400: Apple macOS
Apple macOS contains an improper authentication vulnerability that could allow an attacker on the network to authenticate to Screen Sharing without valid credentials.
CISA KEV · 25 August 2026 · Read the original →
CISA Updates Medusa Ransomware Advisory
CISA, FBI, and HHS updated their joint advisory on Medusa ransomware on August 18, 2026, detailing expanded techniques and tooling, including faster exploitation of unpatched vulnerabilities and improved post-exploitation capabilities. Medusa actors have impacted over 500 critical infrastructure organizations.
CISA · 25 August 2026 · Read the original →
CISA Adds Actively Exploited Vulnerabilities to KEV
On August 18, 2026, CISA added four vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog: VMware vCenter (CVE-2026-59310), Microsoft SharePoint (CVE-2026-55040), Windows IKE Service Extensions (CVE-2026-33824), and Apple macOS (CVE-2026-65400), indicating active exploitation in the wild.
CISA · 25 August 2026 · Read the original →
Ransom Busters Impersonates Incident Responders
A ransomware affiliate, 'Ransom Busters,' is contacting victims of ransomware attacks, claiming to have infiltrated the attackers' servers and offering to delete stolen data and provide encryption keys for a fee between $20,000 and $60,000.
The Hacker News · 25 August 2026 · Read the original →
Doubloon Dredger Abuses Notion for Token Harvesting
The financially motivated threat actor 'Doubloon Dredger' is abusing free Notion accounts, malicious PDFs, and device code phishing to harvest authentication tokens from targeted organizations. The attacks involve impersonating senior executives to send document-sharing notifications.
Infosecurity Magazine · 25 August 2026 · Read the original →
Go ahead and clear your calendar; the backlog has already been decided.
9 stories, every Tuesday
Published here every week. Follow by RSS to get it as it lands.