Microsoft Entra ID Deserialization of Untrusted Data Vulnerability

🚨SEVERITY: CRITICAL — CVSS 10.0Security Advisory

TL;DR 📌

  • Microsoft Entra ID formerly known as Azure Active Directory contains a deserialization of untrusted data vulnerability which could allow an unauthorized attacker to execute code over a network.
  • Highest CVSS: 10.0 (Critical).
  • Listed in CISA KEV (2026-08-21) — this is being exploited in the wild.
  • Check the advisory for fixed releases — remediation detail is in the vendor link below.
  • CVEs: CVE-2026-69836.

What it is

CVE-2026-69836 is a deserialization of untrusted data vulnerability in Microsoft Entra ID (formerly Azure Active Directory). Deserialization flaws of this type typically arise when an application reconstructs objects from attacker-supplied data without adequately validating it first, allowing crafted input to trigger unintended code execution.

[]

Zimbra Collaboration Suite (ZCS) OS Command Injection Vulnerability

🚨SEVERITY: HIGH — CVSS 8.9Security Advisory

TL;DR 📌

  • Zimbra Collaboration Suite (ZCS) contains an OS command injection vulnerability which could allow an unauthenticated attacker to send specially crafted SMTP requests that may result in execution of arbitrary operating system commands as the Zimbra user.
  • Highest CVSS: 8.9 (High).
  • Listed in CISA KEV (2026-08-21) — this is being exploited in the wild.
  • Check the advisory for fixed releases — remediation detail is in the vendor link below.
  • CVEs: CVE-2026-73570.

What it is

CVE-2026-73570 is an OS command injection vulnerability in Zimbra Collaboration Suite (ZCS), reported by Synacor. The flaw sits in how ZCS handles SMTP requests: a specially crafted SMTP request can trigger execution of arbitrary operating system commands, running as the Zimbra user.

[]

TrueConf Server Code Injection Vulnerability

🚨SEVERITY: CRITICAL — CVSS 9.0Security Advisory

TL;DR 📌

  • TrueConf Server contains a code injection vulnerability that could allow an unauthorized remote attacker with network access via port 4307/TCP to use a specially crafted script to break out of the isolated environment and execute arbitrary code on the host system.
  • Highest CVSS: 9.0 (Critical).
  • Listed in CISA KEV (2026-08-20) — this is being exploited in the wild.
  • Check the advisory for fixed releases — remediation detail is in the vendor link below.
  • CVEs: CVE-2026-72530.

What it is

CVE-2026-72530 is a code injection vulnerability in TrueConf Server. An attacker with network access to port 4307/TCP can submit a specially crafted script that breaks out of the server’s isolated execution environment and runs arbitrary code on the underlying host.

[]

TrueConf Server Missing Authentication for Critical Function Vulnerability

🚨SEVERITY: CRITICAL — CVSS 9.8Security Advisory

TL;DR 📌

  • TrueConf Server contains a missing authentication for critical function vulnerability which could allow a remote unauthorized attacker with network access via port 4307/TCP to execute an arbitrary script.
  • Highest CVSS: 9.8 (Critical).
  • Listed in CISA KEV (2026-08-20) — this is being exploited in the wild.
  • Check the advisory for fixed releases — remediation detail is in the vendor link below.
  • CVEs: CVE-2026-72529.

What it is

CVE-2026-72529 is a missing authentication for critical function vulnerability in TrueConf Server. A critical function is reachable over the network on port 4307/TCP without any authentication check.

[]

MLflow Server-Side Request Forgery Vulnerability

🚨SEVERITY: CRITICAL — CVSS 9.3Security Advisory

TL;DR 📌

  • MLflow contains a server-side request forgery vulnerability that can allow attackers to reach internal or cloud metadata services and receive response_status and response_body.
  • Highest CVSS: 9.3 (Critical).
  • Listed in CISA KEV (2026-08-19) — this is being exploited in the wild.
  • Check the advisory for fixed releases — remediation detail is in the vendor link below.
  • CVEs: CVE-2026-64849.

What it is

CVE-2026-64849 is a server-side request forgery (SSRF) vulnerability in MLflow. The CVSS vector indicates the flaw is reachable over the network, requires no authentication and no user interaction, and can be exploited with low attack complexity.

[]

Apple macOS Improper Authentication Vulnerability

🚨SEVERITY: CRITICAL — CVSS 9.8Security Advisory

TL;DR 📌

  • Apple macOS contains an improper authentication vulnerability that could allow an attacker on the network to authenticate to Screen Sharing without valid credentials.
  • Highest CVSS: 9.8 (Critical).
  • Listed in CISA KEV (2026-08-18) — this is being exploited in the wild.
  • Check the advisory for fixed releases — remediation detail is in the vendor link below.
  • CVEs: CVE-2026-65400.

What it is

CVE-2026-65400 is an improper authentication flaw in macOS Screen Sharing. The vulnerability allows an attacker on the network to authenticate to Screen Sharing without supplying valid credentials.

[]

Broadcom VMware vCenter Path Traversal Vulnerability

🚨SEVERITY: CRITICAL — CVSS 9.8Security Advisory

TL;DR 📌

  • Broadcom VMware vCenter contains a path traversal vulnerability which could allow a threat actor with network access to vCenter to execute arbitrary code.
  • Highest CVSS: 9.8 (Critical).
  • Listed in CISA KEV (2026-08-18) — this is being exploited in the wild.
  • Check the advisory for fixed releases — remediation detail is in the vendor link below.
  • CVEs: CVE-2026-59310.

What it is

CVE-2026-59310 is a path traversal vulnerability in Broadcom VMware vCenter. It has a CVSS score of 9.8 (Critical), with a vector of AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H — meaning it is reachable over the network, requires low attack complexity, needs no privileges and no user interaction, and results in full compromise of confidentiality, integrity and availability.

[]

Microsoft Internet Key Exchange (IKE) Service Extensions Double Free Vulnerability

🚨SEVERITY: CRITICAL — CVSS 9.8Security Advisory

TL;DR 📌

  • Microsoft Internet Key Exchange (IKE) Service Extensions contains a double free vulnerability that could enable remote code execution.
  • Highest CVSS: 9.8 (Critical).
  • Listed in CISA KEV (2026-08-18) — this is being exploited in the wild.
  • Check the advisory for fixed releases — remediation detail is in the vendor link below.
  • CVEs: CVE-2026-33824.

What it is

CVE-2026-33824 is a double free vulnerability in Microsoft’s Internet Key Exchange (IKE) Service Extensions. The IKE service handles key negotiation for IPsec, and on Windows this typically runs as part of the IKE/AuthIP IPsec Keying Modules service, which listens on the network to negotiate security associations with peers.

[]

Microsoft SharePoint Weak Authentication Vulnerability

🚨SEVERITY: CRITICAL — CVSS 9.1Security Advisory

TL;DR 📌

  • Microsoft SharePoint contains a weak authentication vulnerability which allows an unauthorized attacker to bypass a security feature over a network.
  • Highest CVSS: 9.1 (Critical).
  • Listed in CISA KEV (2026-08-18) — this is being exploited in the wild.
  • Check the advisory for fixed releases — remediation detail is in the vendor link below.
  • CVEs: CVE-2026-55040.

What it is

Microsoft SharePoint contains a weak authentication vulnerability which allows an unauthorized attacker to bypass a security feature over a network.

[]

Ray-Project Ray Code Injection Vulnerability

🚨SEVERITY: CRITICAL — CVSS 9.4Security Advisory

TL;DR 📌

  • Ray-Project Ray contains a code injection vulnerability that could allow remote code execution. Developers using Ray as a development tool may be exposed to this vulnerability exploitable through Firefox and Safari.
  • Highest CVSS: 9.4 (Critical).
  • Listed in CISA KEV (2026-08-18) — this is being exploited in the wild.
  • Check the advisory for fixed releases — remediation detail is in the vendor link below.
  • CVEs: CVE-2025-62593.

What it is

Ray-Project Ray contains a code injection vulnerability that could allow remote code execution. Developers using Ray as a development tool may be exposed to this vulnerability exploitable through Firefox and Safari.

[]