Skip to content
Threat Feed

August 2026 (30)

high advisory

Adversary-in-the-Middle Phishing via Legitimate Cloud Platforms

Threat actors are increasingly abusing reputable PaaS providers to host multi-stage AitM phishing campaigns that use browser service workers and the Ultraviolet library to intercept credentials and MFA tokens.

Cloudflare Workers +4 phishing aitm cloud credential-harvesting
2t 1i
high advisory

Shai-Hulud Campaign Activity

Tracking brief for the Shai-Hulud campaign; individual sightings are folded in as reported.

jscrambler 8.14.0 +90 campaign shai-hulud
25i updated
high advisory

Multiple Vulnerabilities in Red Hat Enterprise Linux Perl Modules

Multiple vulnerabilities in Red Hat Enterprise Linux within DBI and perl-GD components allow local or remote attackers to execute arbitrary code, manipulate data, or trigger denial-of-service conditions.

Enterprise Linux +1 linux vulnerability perl rhel
1t
medium advisory

Remote Code Execution Vulnerability in Zyxel Firewalls

A vulnerability in Zyxel firewall firmware allows a remote, authenticated attacker to achieve arbitrary code execution on the device.

Zyxel Firewall vulnerability remote-code-execution firewall
1t
high advisory

Local Code Execution Vulnerability in Red Hat Enterprise Linux AI

A local vulnerability in Red Hat Enterprise Linux AI enables attackers to execute arbitrary code, potentially resulting in full system compromise or denial-of-service.

Enterprise Linux AI
1t
high advisory

Google Security Updates — August 2026

Roundup of Google security advisories published in August 2026.

Google Kubernetes Engine +13 roundup
2c updated
medium advisory

Multiple Denial of Service Vulnerabilities in IBM Tivoli Netcool/OMNIbus

Multiple Denial of Service vulnerabilities in IBM Tivoli Netcool/OMNIbus, potentially involving vulnerable Immutable.js libraries, allow unauthenticated remote attackers to disrupt service availability.

Tivoli Netcool/OMNIbus denial-of-service vulnerability enterprise-monitoring
1t
medium advisory

Multiple Denial of Service Vulnerabilities in PJSIP pjmedia

Multiple vulnerabilities in the PJSIP pjmedia library can be exploited by a remote, unauthenticated attacker to trigger a denial of service condition, potentially disrupting telecommunications services.

pjmedia denial-of-service voip infrastructure
1t
high advisory

Multiple Vulnerabilities in LibreNMS

LibreNMS versions prior to 26.5.0 are affected by multiple vulnerabilities including RCE, SSRF, and XSS, posing a significant risk for unauthorized system access and network reconnaissance.

LibreNMS web-application vulnerability rce ssrf xss
1t
high advisory

Prevalence of Direct-to-IP Malware Command and Control

Nearly half of malware samples with command-and-control activity bypass DNS resolution by connecting directly to hardcoded IP addresses, rendering traditional DNS-based defenses ineffective.

Phorpiex +3
2t 6i
high advisory

Heap-based Buffer Overflows in GIMP APNG and DDS Loaders

GIMP contains multiple heap-buffer-overflow vulnerabilities in its APNG and DDS file format loaders, which can lead to arbitrary code execution when a victim opens a specially crafted image file.

GIMP
1t 1c
high advisory

Path Traversal Vulnerability in Zyxel Network Appliance CLI

An authenticated path traversal vulnerability in Zyxel ATP and USG series firmware allows administrators to execute arbitrary configuration files, potentially leading to command execution.

ATP series +3 path-traversal network-security firmware
1t 1c
high advisory

Command Injection in Zyxel WAX650S export-cgi

An authenticated administrator can exploit a command injection vulnerability in the export-cgi program of Zyxel WAX650S firmware versions through 7.10(ABRM.4)C0 to execute arbitrary OS commands.

WAX650S firmware cve command-injection zyxel network-infrastructure
1r 1t 1c
high advisory

Adobe Security Updates — August 2026

Roundup of Adobe security advisories published in August 2026.

Adobe Campaign Classic roundup
5c
high advisory

Out-of-Bounds Heap Read Vulnerability in AIOHTTP C Parser

An out-of-bounds heap read vulnerability (CVE-2026-69244) in the AIOHTTP C-based HTTP response parser allows a malicious server to trigger a denial-of-service condition via malformed chunked responses.

aiohttp
1c
high threat

Guzzle Hostname Validation Bypass via Transport Discrepancy

Guzzle versions before 7.15.2 and 8.0.1 are vulnerable to a host-based security check bypass where transport handlers interpret non-canonical URI hostnames differently than application-level validation, potentially enabling SSRF.

exploited Guzzle +1 ssrf php vulnerability web-security
1t 1c
high advisory

Bleichenbacher Oracle Vulnerability in cryptography Library

The cryptography library fails to perform constant-time operations during PKCS#7 EnvelopedData decryption, creating a Bleichenbacher oracle that allows attackers to recover content-encryption keys via error and timing analysis (CVE-2026-69247).

cryptography
1t 1c
high advisory

Resource Exhaustion in Python cryptography Certificate Chain Validation

An exponential complexity vulnerability in the certificate chain validation logic of the Python cryptography library allows for denial-of-service attacks via resource exhaustion using crafted, redundant certificate chains.

cryptography
1t 1c
high advisory

DLL Hijacking in FirmaCheck for Windows via Unvalidated OpenSSL Configuration

FirmaCheck for Windows versions prior to 1.3.16 are susceptible to local privilege escalation and arbitrary code execution due to an unvalidated OpenSSL configuration file path.

FirmaCheck vulnerability dll-hijacking local-privilege-escalation
1r 2t 1c
high threat

SSRF Vulnerability in Jina AI Reader Crawler

An unauthenticated server-side request forgery (SSRF) vulnerability in the Jina AI Reader crawler allows remote attackers to perform unauthorized requests, with public exploit code currently available.

exploited Reader
1c
high advisory

OS Command Injection in ClearOS Log Viewer

ClearOS 7.9 contains an OS command injection vulnerability in the Log Viewer component that allows authenticated attackers to execute arbitrary commands as the webconfig user, with subsequent escalation to root.

ClearOS vulnerability remote-code-execution privilege-escalation webserver
1r 2t 1c
high advisory

Emlog Pro TLS Certificate Validation Bypass

Emlog Pro versions up to 2.6.23 contain a vulnerability in the AI service component that disables TLS certificate verification, allowing attackers to perform man-in-the-middle interception of LLM API keys and manipulate AI responses.

Emlog Pro vulnerability mitm ai-security
2t 1c
high advisory

Remote Command Injection in Sangfor Operation and Maintenance Security Management System

An unauthenticated remote OS command injection vulnerability in the Sangfor Operation and Maintenance Security Management System allows attackers to execute arbitrary system commands via the /fort/portal_login endpoint.

Operation and Maintenance Security Management System cve-2026-18641 remote-code-execution command-injection sangfor
1r 2t 1c
low advisory

Memory Exhaustion in Socket.IO Parser

A memory exhaustion vulnerability in socket.io-parser (CVE-2026-69185) allows remote attackers to trigger denial-of-service by sending specially crafted packets containing a large number of binary attachments.

socket.io-parser +2 denial-of-service vulnerability javascript npm supply-chain
1t 1c
high advisory

CVE-2026-18446 Host Confusion in fast-uri

The fast-uri package exhibits a URI parsing discrepancy compared to the native Node.js WHATWG URL parser, allowing attackers to bypass host-based security policies through malicious backslash-encoded authorities.

fast-uri
1c
high advisory

Information Disclosure and Denial of Service in Undici Cache Interceptor

The undici library is susceptible to cache poisoning leading to information disclosure and application crashes due to improper handling of malformed Cache-Control directives in the cache interceptor.

undici +1 vulnerability npm nodejs webserver
1c
high advisory

SSRF via Ambiguous IPv4 Parsing in ip-address Library

The ip-address library versions 10.3.0 and below incorrectly parse IPv4 addresses with leading zeros, leading to trust-boundary bypasses and SSRF when used to filter internal network access.

ip-address ssrf library-vulnerability supply-chain
1t 1c
high advisory

GitPython Argument Injection in IndexFile and TagReference

GitPython fails to sanitize keyword arguments passed to git commands, allowing attackers to perform arbitrary file overwrites and unauthorized file reads.

GitPython injection python supply-chain
1t
critical advisory

SQL Injection in Sequelize Oracle Dialect

Sequelize v6.37.3 and earlier versions contain a critical SQL injection vulnerability in the Oracle dialect implementation, allowing unauthenticated attackers to bypass input sanitization and execute arbitrary SQL.

Sequelize web-vulnerability sqli npm cve-2026-69240
1t
high advisory

Remote Code Execution in OpenEMR Document Category Tree

OpenEMR versions 8.2.0 and earlier are vulnerable to authenticated remote code execution via SQL injection and unsafe eval() calls in the document category tree component.

OpenEMR +1 web-application-vulnerability remote-code-execution healthcare cve-2026-39931 sql-injection web-application vulnerability authentication-bypass +1
8t 1c