CISA warned that attackers are exploiting a critical flaw in Gitea, the popular self-hosted Git service, and added it to its exploited-vulnerabilities catalog. Tracked as CVE-2026-60004 and scored 9.8, the code-injection bug lets a user with repository write access send a malicious patch to the diffpatch API endpoint, planting an executable Git hook that runs shell commands as the Gitea service account. Crucially, default installations have open self-registration, so an unauthenticated attacker can simply register, create a repository, and gain code execution. It affects versions 1.17 through 1.27.0 and was fixed in July, and reports describe attackers dropping cryptocurrency miners, with one intrusion taking about eleven seconds.
Researchers disclosed a flaw in NVIDIA NemoClaw, a stack for running AI agents like OpenClaw with local inference through Ollama, that lets a single malicious webpage hijack the agent. Tracked as CVE-2026-65105, the issue is that NemoClaw starts Ollama bound to all network interfaces, so a DNS-rebinding attack from a page the user simply visits reaches the local model server and takes unauthenticated control. The attacker can then rewrite the model's chat template to plant hidden instructions that run on every later inference, beneath the agent's own guardrails and persisting across conversations. A fix landed in version 0.0.35 for macOS and Linux, but the Windows path remains exposed.
CERT/CC disclosed two unpatched flaws in Kaltura's HTML5 video player library that let a remote, unauthenticated attacker read files from a server and run code, with only network access to the endpoint required. Both stem from the same unsafe deserialization in the mwEmbedLoader.php endpoint, which takes a user-controlled ServiceUrl parameter and passes fetched data to PHP's unserialize without validating it. Supplying a file path lets an attacker read any file the web server can access, including credentials and API keys, while the deserialization also enables code execution. CERT/CC could not reach the vendor, and because the endpoint is exposed on Kaltura's shared multi-tenant infrastructure, the flaws can affect many tenants at once.
Attackers are exploiting two critical authentication-bypass flaws in the miniOrange SAML 2.0 Single Sign On plugin for WordPress, chaining them to forge login responses and sign in as an administrator. The first flaw, CVE-2026-61979, lets the plugin accept an attacker-chosen signature algorithm, so the identity provider's public key can be abused as a shared secret to forge a valid signature; the second, CVE-2026-15981, makes the plugin treat a signature-verification error as success. Both were fixed in July, but the vendor only alerted free-edition users, leaving paid editions unpatched. Security firm Patchstack traced an attack in mid-August where the two were chained to steal an administrator session cookie.
A critical flaw in Keycloak, the widely used open-source identity and access management server, lets an unauthenticated attacker take over any account through its password-reset flow. Tracked as CVE-2026-18963, the bug is improper state validation in the reset-credentials flow: a crafted request to the reset endpoint pushes the authentication session straight to the password-update step, so the action token Keycloak normally emails is never required, and the attacker sets new credentials for a chosen user. It needs no user interaction and works against any account, including administrators. Red Hat fixed it in Keycloak 26.7.2 and related releases; there is no confirmed exploitation yet.
An unpatched flaw in Calix residential routers used by several US broadband providers lets a remote, unauthenticated attacker create port-forwarding rules that expose devices on the local network to the internet. Tracked as CVE-2026-75501, the missing-authentication issue affects the Calix GS7 XGS model on a specific firmware version, and Calix supplies gear to large providers including Cox and Brightspeed. The researcher who found it reported it to the vendor in June, got no response, and disclosed through CERT/CC after further attempts failed. Because it lets an attacker punch holes through the router's network address translation, internal devices that were never meant to be reachable can be exposed. No fix is available.
Cisco released fixes for nine vulnerabilities across its Crosswork network-automation platforms and Secure Workload software, five of them rated 10.0. Four affect Crosswork Data Gateway, Network Controller, and Planning regardless of configuration, and include a SQL injection flaw, a missing-authentication flaw, and external control of the file system, each scored 10.0, plus an insufficiently protected credentials issue at 9.9. Five more affect Secure Workload in both cloud and on-premises deployments, led by a 10.0 improper access control flaw and a 9.9 command-injection flaw. Cisco found them in internal testing using AI models and says none are exploited yet, but there are no workarounds, so patching is the only fix.
Microsoft disclosed that a critical flaw in Entra ID, its cloud identity and access service formerly known as Azure Active Directory, was exploited in the wild, though it says the issue is fully mitigated on its side and customers need take no action. Tracked as CVE-2026-69836 and scored 10.0, it is an unsafe-deserialization bug that let an unauthenticated attacker run code over the network in the identity service. Because Entra ID underpins sign-in to Microsoft 365, Azure, and many third-party apps, a code execution flaw there is unusually serious. Microsoft has not shared how it was exploited, so the practical step is reviewing identity logs for suspicious activity before the disclosure.
Poland's national CERT warned that attackers are exploiting a now-patched flaw in Zimbra Collaboration to run commands on mail servers without authentication. Tracked as CVE-2026-73570 and scored 8.9, it is an OS command injection bug in Zimbra's SNMP monitoring feature: when the optional SNMP package is installed and notification traps are enabled, improper input handling lets an unauthenticated attacker send crafted requests that execute commands as the Zimbra user. The monitoring service involved is on by default where SNMP is used, widening exposure. Zimbra fixed it in version 10.1.20 in July, and Zimbra servers are a long-standing target, so unpatched instances should be treated as urgent.
Citrix patched a critical flaw in NetScaler ADC and Gateway that lets a remote, unauthenticated attacker bypass authentication on appliances used for remote access. Tracked as CVE-2026-19490 and scored 9.3, it is an authentication-bypass issue affecting devices configured as a gateway for SSL VPN, ICA proxy, clientless VPN, or RDP proxy, or as an AAA authentication server. On newer builds it requires a SAML configuration, but on older builds any gateway or AAA configuration is exposed. There is no confirmed exploitation yet, but NetScaler appliances sit at the network edge and have repeatedly been attacked soon after disclosure, so patching is urgent.