-
A 2019 SQL Server bug is on a federal clock that runs out Saturday, and it needs a login to work
CVE-2019-1068 was published in July 2019 and patched the same month; CISA added it to the Known Exploited Vulnerabilities catalog on 26 August 2026 with a 29 August…
-
CISA gave two of this week’s KEV additions three days and four of them fourteen. The required-action text is identical on all of them
Across the nine CVEs CISA added to the Known Exploited Vulnerabilities catalog on 26 and 27 August, the “required action” text is the same on a three-day deadline…
-
A 2023 ownCloud auth bypass is on a three-day federal clock ending Sunday, and the evidence is the attacker’s own open directory
CVE-2023-49105 went into the federal Known Exploited Vulnerabilities catalog on 27 August with a 30 August due date — and the exploitation record behind it comes from one…
-
BOD 22-01 has been dead since June. Its replacement ships the deadline matrix as a screenshot, and the first compliance date passed unremarked.
If your vulnerability management policy says “patch KEV entries within 14 days,” it cites a directive that CISA revoked eleven weeks ago. BOD 26-04 replaced it on 10…
-
A medium-severity Artifactory flaw is on a federal clock, and the version everyone patched to in July does not cover it
CVE-2026-66384 is a CVSS 5.3 medium-severity path traversal that requires an authenticated user and specific remote-repository conditions. It is now on the federal Known Exploited Vulnerabilities clock, because…
-
CISA put a Linux kernel container escape on a three-day clock. The only documented exploitation is OpenAI’s own agents
CISA added CVE-2026-53362 to the Known Exploited Vulnerabilities catalog on 27 August with a 30 August deadline, and the only documented exploitation of it anywhere is OpenAI’s own…
-
Citrix calls CVE-2026-8452 a denial of service. Researchers used it to get root, and the federal deadline is Saturday
Citrix’s own advisory still describes CVE-2026-8452 as a denial-of-service bug. Two research teams have demonstrated it is a pre-authentication heap overflow that ends in a root shell, CISA…
-
Microsoft flagged a CVSS 10.0 Entra ID flaw as exploited, then retracted it a day later. Much of the coverage never followed.
On 20 August, Microsoft published an advisory for a maximum-severity remote code execution flaw in Entra ID and marked it as exploited in the wild. On 21 August,…
-
The GitLab flaw under “active exploitation” is one firm’s honeypot data — GitLab hasn’t said a word about it
A critical GitLab flaw is being reported as under active exploitation within days of disclosure. The vulnerability is real, the patch is real, and self-managed instances should install…
-
N-able says attackers used N-central’s own remote control to reach managed endpoints and plant Cloudflare tunnels
If you are an MSP running N-central on premises, or a company whose MSP does, this is the most consequential item of the week. N-able has stated in…
-
GPUThor beats NVIDIA’s ECC for a root shell in about a minute — on four workstation cards, not the AI fleet
University of Toronto researchers have shown that non-uniform Rowhammer patterns defeat NVIDIA’s sideband ECC on GDDR6 workstation GPUs, yielding a root shell on the host in under two…
-
Carhartt’s breach is 12.9 million records, not 25 — and the gap is benchmark data someone left in production
Every headline today puts the Carhartt breach at 12.9 million accounts. That number did not come from Carhartt, which has said nothing publicly, and it did not come…
-
vCenter servers are being backdoored five days after the patch, and Broadcom still hasn’t mentioned exploitation
CISA gave federal agencies three days to fix a vCenter directory traversal flaw. A German incident response firm has since mapped 361 victim IP addresses across 47 countries,…
-
PaperCut is under active attack with no CVE, and the emergency patch skipped its own release process
PaperCut has confirmed that customers are being attacked through an unpatched flaw in its NG and MF print management servers. There is no CVE. There is no entry…