Last updated: August 19, 2026 at 1:47 AM UTC
All 741 Vulnerability 286 Breach 129 Threat 319 Defense 7

Adobe Commerce session flaw lets unauthenticated attackers take over customer accounts

Adobe patched a critical flaw in its Commerce and Magento e-commerce platforms that lets an unauthenticated attacker hijack customer accounts, and security firm Sansec reports its web application firewall is already blocking exploitation attempts. Tracked as CVE-2026-71362 and scored 9.1, the incorrect-authorization bug stems from the platform failing to bind a customer identity to an account session, so an attacker with only network access to the public storefront can switch an active session to another customer and read their private data. It needs no account, administrator rights, or user interaction. Adobe ships the fix as isolated patch files, so administrators must be on the latest point release first.

Check
Apply Adobe's August isolated patch for Commerce, Commerce B2B, and Magento after confirming you are on the latest point release for your branch, and treat exploitation traffic as already present.
Affected
Merchants running Adobe Commerce 2.4.4 to 2.4.9 or Magento Open Source 2.4.6 to 2.4.9 (CVE-2026-71362); an unauthenticated visitor can switch into another customer's session and access their account data.
Fix
Patch promptly, put a web application firewall in front of the storefront, review privileged account activity and unexpected configuration changes, and validate extension integrity on internet-facing Commerce instances.

Adobe patches ColdFusion command injection flaw scored a perfect ten

Adobe released Priority 1 updates for ColdFusion and Campaign Classic, led by a critical operating-system command injection flaw in ColdFusion scored 10.0 that could give an attacker arbitrary code execution. Tracked as CVE-2026-48362, it is accompanied by an eval-injection flaw scored 9.9 and an authorization flaw that can cause a denial of service. ColdFusion application servers are a long-standing target for attackers because they are widely internet-exposed and often run with broad access. Adobe is not aware of exploitation yet but urges installation within 72 hours given the priority rating. The Campaign Classic updates apply only to on-premises and hybrid on-premises deployments.

Check
Update ColdFusion to the fixed 2025 and 2023 releases within Adobe's 72-hour window, and confirm internet-facing ColdFusion servers are not running with unnecessary privileges or exposure.
Affected
Organizations running affected Adobe ColdFusion (CVE-2026-48362); an attacker could achieve arbitrary code execution through operating-system command injection, and ColdFusion servers are frequently exposed and targeted.
Fix
Apply the Priority 1 updates quickly, restrict and monitor ColdFusion server access, run it with least privilege, and watch for unexpected process execution, since command-injection flaws are attractive and often weaponized fast.

Red Hat cluster management flaw lets a namespace editor become cluster admin

Red Hat disclosed a critical flaw in its Advanced Cluster Management for Kubernetes that lets a user with only namespace-level edit rights escalate to full cluster administrator. Tracked as CVE-2026-10090 and scored 9.9, the bug is in the application subscription controller: a low-privileged user can create a channel pointing to a Helm repository they control, then a subscription referencing it, and the controller deploys the chart using its own elevated permissions without checking the requester's authorization. It is a confused-deputy problem that crosses the namespace-to-cluster boundary. Because namespace edit access is often granted broadly to developers, many multi-tenant clusters could be exposed, and no fix was available at disclosure.

Check
Identify Advanced Cluster Management hub namespaces where non-administrators hold edit rights, restrict those permissions, and monitor for unexpected channel and subscription objects pointing to external Helm repositories.
Affected
Organizations running Red Hat Advanced Cluster Management for Kubernetes (CVE-2026-10090); a user with namespace edit rights on the hub can reach full cluster-admin and access secrets, with no fix yet.
Fix
Tighten who holds namespace edit access on ACM hubs, watch for suspicious channel and subscription resources, and apply Red Hat's fix as soon as it ships, since no mitigation fully substitutes.

Cisco warns of ClamAV flaws with public exploit code and no workaround

Cisco warned that public proof-of-concept code exists for two vulnerabilities in ClamAV, the widely used open-source antivirus engine, that a remote unauthenticated attacker can use to crash the scanning process and disrupt protection. Tracked as CVE-2026-20337 and CVE-2026-20338, the flaws are rated high severity on Windows because ClamAV runs there in a privileged security context, and medium on macOS and Linux where it runs with lower privileges. There are no workarounds, and Cisco is rolling out fixes in August across its Secure Endpoint Connector products, which embed ClamAV. Because ClamAV is bundled into many mail and file-scanning products, exposure extends well beyond Cisco.

Check
Update ClamAV and any products that embed it, including Cisco Secure Endpoint Connector, and prioritize Windows systems where the scanning process runs in a privileged context.
Affected
Systems running unpatched ClamAV or products that bundle it (CVE-2026-20337, CVE-2026-20338); a remote attacker can crash scanning to disable protection, with the highest risk on Windows and public exploit code available.
Fix
Apply the ClamAV updates as they ship, since there is no workaround, inventory the mail and file-scanning products that embed the engine, and monitor for scanning processes crashing unexpectedly.

Exploited Metabase zero-day gives unauthenticated attackers admin and database credentials

Metabase warned that a critical zero-day in its open-source business intelligence platform was exploited in the wild for data theft. Scored 10.0 and tracked only as GHSA-vwf4-m7j8-wcjf with no CVE assigned, so scanners relying on the national database will not flag it, the flaw is an unauthenticated SQL injection in the password-reset endpoint. A remote attacker with no credentials injects SQL into the application database, gains administrator access, and can steal the stored credentials for every database the instance connects to, then read and export their data. Metabase Cloud was attacked from around August 3 and is already patched; self-hosted versions 1.58 and later must upgrade.

Check
Upgrade self-hosted Metabase to the fixed release for your branch immediately, and if the reset-password endpoint was internet-reachable, treat the instance and all connected database credentials as compromised.
Affected
Organizations running self-hosted Metabase 1.58 or later; an unauthenticated attacker can gain admin access and steal credentials for every connected database, and it is exploited with no CVE for scanners to catch.
Fix
Patch to the safe release, clear the session table to revoke sessions, rotate credentials for all connected databases, audit API keys and admin accounts, and block the reset-password endpoint if unpatched.

Progress Kemp LoadMaster command injection flaw added to KEV after active exploitation

CISA added a critical Progress Kemp LoadMaster flaw to its Known Exploited Vulnerabilities catalog after reports of active exploitation. Tracked as CVE-2026-8037 and scored 9.6, it is a command injection bug that lets an unauthenticated attacker run arbitrary commands on the load balancer appliance through unsanitized input in several command endpoints. watchTowr traced it to improper handling of user input in a quote-escaping function. Telemetry recorded 792 exploitation attempts over 41 days from 65 addresses across 18 countries, with activity as recent as early August. Federal agencies were directed to patch by August 10, a useful signal of urgency for everyone else.

Check
Patch Progress Kemp LoadMaster appliances to the fixed release now, and because the appliance sits inline with traffic, review it for signs of command execution and unexpected configuration changes.
Affected
Organizations running unpatched Progress Kemp LoadMaster (CVE-2026-8037); an unauthenticated attacker can execute arbitrary commands on an appliance that sits inline with network traffic, and exploitation is ongoing.
Fix
Apply the vendor patch, restrict management access to the appliance, hunt for unauthorized commands and configuration changes, and rotate any credentials the load balancer stored or handled.

Cisco patches critical SD-WAN and IOS XE flaws with no available workarounds

Cisco released fixes for twelve flaws in Catalyst SD-WAN and IOS XE software, including three rated 9.9 and a command-injection issue rated 9.8. The three critical SD-WAN flaws, CVE-2026-20303, CVE-2026-20304, and CVE-2026-20310, stem from improper input validation, access control, and file-path handling in software that centrally controls a network. Cisco found them through internal testing that included frontier AI models and is not aware of exploitation, but there are no workarounds, so patching is the only remediation. Cisco also patched a management-controller flaw with public exploit code that lets a low-privileged user reach root.

Check
Upgrade Catalyst SD-WAN and IOS XE to the fixed releases Cisco lists, since there are no workarounds, and prioritize the management-controller flaw that already has public exploit code.
Affected
Organizations running affected Cisco Catalyst SD-WAN or IOS XE (CVE-2026-20303, CVE-2026-20304, CVE-2026-20310); the flaws affect software that centrally controls the network, and no workarounds exist.
Fix
Apply Cisco's fixed software, restrict access to network management interfaces, and treat the management-controller flaw with public proof-of-concept code as a priority since it reaches root.

18-year-old Linux SCTP flaw gives local root and can escape containers

Tencent researchers disclosed SCTPhantom, a use-after-free flaw in the Linux kernel's SCTP networking code that lets a local user gain root and, in some configurations, escape a container to the host. Tracked as CVE-2026-64564, the bug is in the protocol's dynamic address reconfiguration handling and traces to code introduced around 2008, making it roughly 18 years old. It is local rather than remote and needs SCTP reachable on the target, which limits exposure, but where those conditions hold the researchers gained root on several major distributions. It was found by an AI-assisted kernel research pipeline, the latest long-dormant kernel bug surfaced that way this year.

Check
Update to a fixed kernel, checking your distribution's tracker rather than the version string since vendors backport, and where SCTP is not needed, block the module to remove the attack surface.
Affected
Linux systems with SCTP reachable and an unpatched kernel (CVE-2026-64564); a local user can gain root, and in some container configurations escape to the host, though remote exploitation is not possible.
Fix
Apply the distribution kernel update and reboot, disable the SCTP module where unused, and tighten container policies that grant network and packet-socket capabilities to untrusted workloads.

WordPress pre-auth login XSS can chain to full server takeover

WordPress patched a pre-authentication reflected cross-site scripting flaw in the login screen that researchers showed can chain into PHP code execution and full server takeover, naming the chain XSS2Shell. Tracked as CVE-2026-64638 and scored 8.9, the cross-site scripting bug affects all WordPress versions and needs no login to trigger. On its own it runs script in a visitor's browser, but when a logged-in administrator is lured to an attacker-controlled page, the chain can reach code execution on the server. Because WordPress runs a large share of the web, a flaw affecting every version and needing no authentication has broad reach.

Check
Update WordPress to the patched release across every site, including forgotten and staging installs, and put a web application firewall in front of internet-facing sites.
Affected
All WordPress sites on versions before the fix (CVE-2026-64638); an unauthenticated attacker can run script in the login page, and luring an administrator to a crafted page can chain to code execution.
Fix
Apply the WordPress update, confirm automatic updates ran, use a web application firewall, and remind administrators to avoid unexpected links, since the chain to code execution runs through an admin's browser.

Critical Terraform MCP flaw lets one user's cloud token serve another's requests

HashiCorp, Veeam, and Django patched critical flaws the same week, led by a top-severity bug in HashiCorp's Terraform MCP Server, which connects AI assistants to Terraform. Tracked as CVE-2026-16498 and scored 10.0, it is a cross-tenant flaw in the server's multi-user HTTP mode: its cache looked up clients by session identifier alone, without binding a cached client to the token that created it, so anyone who obtained another user's session ID could run Terraform actions with that user's credential. Only the shared HTTP deployment is affected, not local single-user mode. Veeam separately fixed an unauthenticated console flaw exposing agent credentials, and Django a code-execution bug in spatial queries.

Check
Update Terraform MCP Server to 1.1.0 or later, Veeam Service Provider Console to 9.3.0.35057, and Django to 6.0.8 or 5.2.17, prioritizing multi-user Terraform MCP deployments.
Affected
Teams running Terraform MCP Server in shared HTTP mode (CVE-2026-16498), Veeam Service Provider Console, or affected Django; the Terraform flaw lets one tenant's token be reused for another's requests.
Fix
Patch all three, run MCP servers in single-user stdio mode where possible, bind sessions to their credentials, restrict access to shared MCP HTTP listeners, and rotate tokens that may have been reused.