Days after disclosure, attackers are exploiting a critical authentication-bypass flaw in JFrog Artifactory, the widely used repository manager for binaries, packages, containers, and build artifacts. Tracked as CVE-2026-82329 and scored 9.8, the flaw lets an unauthenticated attacker with network access gain administrative privileges under Artifactory's default configuration. Researchers at watchTowr observed exploitation beginning September 1, with attackers minting admin tokens for themselves and enumerating users, groups, and credentials. Because Artifactory sits at the center of software supply chains and CI/CD pipelines, admin access lets attackers tamper with build pipelines, poison trusted dependencies, and push malicious code downstream to customers. JFrog patched it in version 7.161.20 on August 28.
VulnCheck reported active exploitation of two critical flaws, one in the AI workflow builder Langflow and one in Ruby on Rails. The Langflow bug, CVE-2026-0768, scored 9.8, lets an attacker run arbitrary Python code as root through improper input validation. The Rails bug, CVE-2026-66066 and nicknamed KindaRails2Shell at 9.5, lets an unauthenticated attacker read arbitrary files by uploading a crafted image that exploits a mismatch between Active Storage and the libvips image library, leaking secrets like the Rails master key and cloud credentials and ultimately enabling code execution. Detections jumped from about 50 to 360 within a day, with attackers querying environment variables for OpenAI and AWS keys and probing SSH access.
PaperCut warned that attackers are actively exploiting vulnerabilities in all versions of its widely deployed NG and MF print-management software, and confirmed real customer incidents. Two flaws are involved: CVE-2026-82078, unsafe dynamic class loading in the database connection utilities that lets an attacker run arbitrary Java bytecode, and CVE-2026-81578, an access-control flaw in the web management interface that lets an unauthenticated attacker change system configuration. PaperCut released emergency out-of-cycle patches for its version 25 and 26 branches, with a version 24 build still in progress, and later issued a hardened second release. PaperCut servers have a history of being targeted by ransomware crews.
CISA warned that attackers are exploiting a critical flaw in Gitea, the popular self-hosted Git service, and added it to its exploited-vulnerabilities catalog. Tracked as CVE-2026-60004 and scored 9.8, the code-injection bug lets a user with repository write access send a malicious patch to the diffpatch API endpoint, planting an executable Git hook that runs shell commands as the Gitea service account. Crucially, default installations have open self-registration, so an unauthenticated attacker can simply register, create a repository, and gain code execution. It affects versions 1.17 through 1.27.0 and was fixed in July, and reports describe attackers dropping cryptocurrency miners, with one intrusion taking about eleven seconds.
Attackers are exploiting two critical authentication-bypass flaws in the miniOrange SAML 2.0 Single Sign On plugin for WordPress, chaining them to forge login responses and sign in as an administrator. The first flaw, CVE-2026-61979, lets the plugin accept an attacker-chosen signature algorithm, so the identity provider's public key can be abused as a shared secret to forge a valid signature; the second, CVE-2026-15981, makes the plugin treat a signature-verification error as success. Both were fixed in July, but the vendor only alerted free-edition users, leaving paid editions unpatched. Security firm Patchstack traced an attack in mid-August where the two were chained to steal an administrator session cookie.
Poland's national CERT warned that attackers are exploiting a now-patched flaw in Zimbra Collaboration to run commands on mail servers without authentication. Tracked as CVE-2026-73570 and scored 8.9, it is an OS command injection bug in Zimbra's SNMP monitoring feature: when the optional SNMP package is installed and notification traps are enabled, improper input handling lets an unauthenticated attacker send crafted requests that execute commands as the Zimbra user. The monitoring service involved is on by default where SNMP is used, widening exposure. Zimbra fixed it in version 10.1.20 in July, and Zimbra servers are a long-standing target, so unpatched instances should be treated as urgent.
CISA added a critical flaw in Ray, the open-source framework for scaling AI and machine-learning workloads, to its exploited-vulnerabilities catalog and gave federal agencies just three days to fix it. Tracked as CVE-2025-62593 and scored 9.4, the bug stems from Ray leaving key dashboard and job endpoints unauthenticated; its only browser defense checked that the request's user-agent began with Mozilla, which attackers can forge. Combined with a DNS rebinding attack, a malicious website or advertisement viewed while running Ray can execute code on the developer's machine. A DDoS botnet adopted it before public disclosure, and a separate campaign has been turning unpatched Ray clusters with GPUs into cryptocurrency miners.
Attackers began exploiting a critical unauthenticated flaw in MLflow, the popular open-source machine-learning platform, within hours of its disclosure. Tracked as CVE-2026-64849 and scored 9.3, the server-side request forgery bug lives in the model-registry webhook testing feature: an attacker hosts an endpoint that passes validation, then redirects MLflow to internal targets such as the cloud metadata service or loopback addresses, and MLflow returns their responses. That exposes cloud credentials, API tokens, and secrets. Because MLflow sits close to training data, artifacts, object storage, CI/CD, and inference pipelines, a compromise offers both credentials and a foothold for lateral movement. watchTowr's honeypots saw exploitation attempts almost immediately.
Attackers began exploiting a critical SAP Commerce Cloud flaw within days of its patch, even though no public proof-of-concept exists. Tracked as CVE-2026-58231 and scored 10.0, the improper-authorization bug in the Data Hub Adapter lets an unauthenticated attacker abuse a default authentication client and send crafted input to reach arbitrary code execution. Threat intelligence firm Defused saw the first exploitation attempts hit its honeypots three days after SAP's August patch, classified as automated mass scanning of internet-facing deployments. Shadowserver tracks more than 4,200 exposed SAP Commerce Cloud systems, mostly in Europe and North America. Prior critical SAP flaws have been used by state actors and ransomware crews.
The Netherlands cyber agency warned that attackers are exploiting a recently patched macOS flaw to gain root on internet-exposed Macs and install cryptocurrency miners. Tracked as CVE-2026-65400 and scored 9.8, the authentication flaw in the Screen Sharing component lets a network attacker authenticate to the built-in remote desktop service, which uses VNC on port 5900, without valid credentials due to flawed state management. Apple fixed it in emergency updates on August 6 for macOS Tahoe, Sequoia, and Sonoma. Screen Sharing is off by default, but any Mac with it enabled and reachable from the internet is at high risk, and several have already been compromised to run Monero miners.