-
Berlin confirms it is being extorted, eleven days after announcing a network compromise without mentioning it
The State of Berlin acknowledged a compromise of its administrative network on 17 August without mentioning extortion. On 28 August it confirmed the extortion and rejected the ultimatum…
-
Gitea’s federal deadline expired with 8,393 servers still vulnerable, and the exploitation record is one CPU alert
CISA gave federal agencies three days to fix a critical Gitea remote code execution flaw. The clock ran out on 28 August; the day before, Shadowserver counted 8,393…
-
ServiceNow scored three of its own AI Platform flaws at a flat 10.0, and a fourth record contradicts itself on authentication
ServiceNow’s PSIRT published four CVEs on 27 August and scored three of them at a flat CVSS v4.0 10.0 with byte-identical vectors — while the fourth record describes…
-
PaperCut’s zero-day is now two chained CVEs, and the first emergency patch does not stop the chain
PaperCut’s unnamed zero-day now has two CVE numbers, a confirmed chain, and a second emergency patch — because researchers bypassed the first one. Anyone who patched on 27…
-
The vendor record understated the day, and a federal clock runs out tomorrow
Citrix still calls CVE-2026-8452 a denial of service. It is a pre-auth root shell with a federal deadline of Saturday, and it outranks the two breaches that sound…
-
UI-TARS-desktop’s MCP servers listened on every interface with no authentication, and the fix is a commit, not a release
CVE-2026-81735 scores 10.0 because the MCP command server had no authentication and listened on every interface — and the remediation is identified by a commit hash, not a…
-
Langflow 1.11.2 fixes three code-execution flaws, one of them unauthenticated, with no workaround offered
Three code-execution CVEs against Langflow OSS 1.0.0 through 1.11.1 reached NVD late Friday; one needs no credentials, IBM lists no workaround, and the fix is 1.11.2. What happened…
-
McKesson confirms a cybersecurity incident and files it under Item 7.01, not the SEC’s cybersecurity item
McKesson told the SEC on Friday that it discovered a cybersecurity incident on 25 August. The filing does not say whether any data left the company — the…
-
A 2019 SQL Server bug is on a federal clock that runs out Saturday, and it needs a login to work
CVE-2019-1068 was published in July 2019 and patched the same month; CISA added it to the Known Exploited Vulnerabilities catalog on 26 August 2026 with a 29 August…
-
CISA gave two of this week’s KEV additions three days and four of them fourteen. The required-action text is identical on all of them
Across the nine CVEs CISA added to the Known Exploited Vulnerabilities catalog on 26 and 27 August, the “required action” text is the same on a three-day deadline…
-
A 2023 ownCloud auth bypass is on a three-day federal clock ending Sunday, and the evidence is the attacker’s own open directory
CVE-2023-49105 went into the federal Known Exploited Vulnerabilities catalog on 27 August with a 30 August due date — and the exploitation record behind it comes from one…
-
BOD 22-01 has been dead since June. Its replacement ships the deadline matrix as a screenshot, and the first compliance date passed unremarked.
If your vulnerability management policy says “patch KEV entries within 14 days,” it cites a directive that CISA revoked eleven weeks ago. BOD 26-04 replaced it on 10…
-
A medium-severity Artifactory flaw is on a federal clock, and the version everyone patched to in July does not cover it
CVE-2026-66384 is a CVSS 5.3 medium-severity path traversal that requires an authenticated user and specific remote-repository conditions. It is now on the federal Known Exploited Vulnerabilities clock, because…
-
CISA put a Linux kernel container escape on a three-day clock. The only documented exploitation is OpenAI’s own agents
CISA added CVE-2026-53362 to the Known Exploited Vulnerabilities catalog on 27 August with a 30 August deadline, and the only documented exploitation of it anywhere is OpenAI’s own…
-
Citrix calls CVE-2026-8452 a denial of service. Researchers used it to get root, and the federal deadline is Saturday
Citrix’s own advisory still describes CVE-2026-8452 as a denial-of-service bug. Two research teams have demonstrated it is a pre-authentication heap overflow that ends in a root shell, CISA…