National Cyber Warfare Foundation (NCWF)

August 2026 CVE Landscape


0 user ratings
2026-09-09 13:17:14
milo
Blue Team (CND)
In August 2026, Insikt Group® identified 73 high-impact vulnerabilities that should be prioritized for remediation, 43 of which had a Very Critical Recorded Future Risk Score. This represents a 14% decrease from last month.

In August 2026, Insikt Group® identified 73 high-impact vulnerabilities that should be prioritized for remediation, 43 of which had a Very Critical Recorded Future Risk Score. This represents a 14% decrease from last month. 31 of these vulnerabilities were surfaced through the US Cybersecurity and Infrastructure Security Agency (CISA)’s Known Exploited Vulnerabilities (KEV) catalog, 32 were reported in open sources and validated by Insikt Group, seven were sourced through security vendor telemetry, and three were exclusively surfaced through honeypot data.


The 73 vulnerabilities in this blog affected products from 45 vendors, with Microsoft accounting for approximately 11% of the vulnerabilities. The remaining exposure spanned remote monitoring and management, virtualization, application delivery, collaboration, artificial intelligence, developer, analytics, identity, operational technology, content management, network edge, video surveillance, and endpoint technologies.


In August, Insikt Group created Nuclei templates to detect CVE-2025-62593 (Ray), CVE-2026-72898 (Metabase), and CVE-2026-9198 (IBM Langflow). Each of these vulnerabilities is featured in this blog. Additionally, Insikt Group had previously created templates to detect CVE-2026-3395 (MaxSite CMS) and CVE-2026-59800 (decolua 9Router), but their exploitation was reported in July, so they are not listed in the August 2026 Vulnerability Table. Additionally, Insikt Group created a Nuclei template to detect GitHub Issue #4255 affecting Apache Log4j, a deserialization allowlist bypass that Apache classified as a hardening gap rather than a Log4j vulnerability; as such, it was not assigned a CVE. These Nuclei templates are available to customers via the Recorded Future Intelligence Platform.


Quick reference: August 2026 vulnerability table


All 70 vulnerabilities below were actively exploited or operationally weaponized in August 2026. This table does not include the three CVEs that were primarily surfaced through honeypot data, which are available to Recorded Future Intelligence Platform customers via the CVE Monthly report. The table below also provides examples of public PoCs identified by Insikt Group. These PoCs were not tested for accuracy or efficacy. Vulnerability management teams should exercise caution and verify the validity of PoCs before testing.




#

Vulnerability

Risk
Score

Vendor/Product

KEV

RCE

PoC



1

CVE-2026-81578

99

PaperCut NG/MF

✓





2

CVE-2026-82078

99

PaperCut NG/MF

✓

✓




3

CVE-2015-3246

99

Red Hat Libuser

✓





4

CVE-2015-5287

99

Red Hat Automatic Bug Reporting Tool

✓





5

CVE-2017-0199

99

Microsoft Office and WordPad


✓




6

CVE-2017-5753

99

Intel






7

CVE-2019-1068

99

Microsoft SQL Server

✓

✓




8

CVE-2019-18935

99

Progress Telerik UI for ASP.NET AJAX


✓




9

CVE-2020-0796

99

Microsoft Windows 10 and Windows Server


✓




10

CVE-2020-1472

99

Microsoft Windows Server






11

CVE-2021-23758

99

Ajax.NET Professional

✓

✓




12

CVE-2021-3156

99

sudo






13

CVE-2022-0847

99

Linux kernel






14

CVE-2022-0995

99

Linux kernel

✓





15

CVE-2023-49105

99

ownCloud

✓





16

CVE-2025-62593

99

Ray-Project Ray

✓

✓




17

CVE-2026-18556

99

N-able N-central

✓





18

CVE-2026-18577

99

N-able N-central

✓





19

CVE-2026-20349

99

Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD)

✓





20

CVE-2026-21962

99

Oracle HTTP Server and Oracle WebLogic Server Proxy Plug-in

✓





21

CVE-2026-33824

99

Microsoft Internet Key Exchange (IKE) Service Extensions

✓

✓




22

CVE-2026-34486

99

Apache Tomcat

✓





23

CVE-2026-39987

99

Marimo


✓




24

CVE-2026-53362

99

Linux kernel

✓





25

CVE-2026-55040

99

Microsoft SharePoint

✓





26

CVE-2026-59310

99

Broadcom VMware vCenter

✓

✓




27

CVE-2026-60004

99

Gitea

✓

✓




28

CVE-2026-63030

99

WordPress


✓




29

CVE-2026-63077

99

JetBrains TeamCity

✓

✓




30

CVE-2026-64849

99

MLflow

✓





31

CVE-2026-65400

99

Apple macOS

✓





32

CVE-2026-68820

99

Microsoft Windows Ancillary Function Driver for WinSock

✓





33

CVE-2026-72529

99

TrueConf Server

✓





34

CVE-2026-72530

99

TrueConf Server

✓

✓




35

CVE-2026-72898

99

Metabase

✓





36

CVE-2026-73570

99

Synacor Zimbra Collaboration Suite (ZCS)

✓

✓




37

CVE-2026-8037

99

Progress LoadMaster

✓

✓




38

CVE-2026-8452

99

Citrix NetScaler ADC and NetScaler Gateway

✓





39

CVE-2026-9198

99

IBM Langflow

✓

✓




40

CVE-2026-66384

92

JFrog Artifactory

✓





41

CVE-2017-7921

89

Hikvision cameras






42

CVE-2021-29441

89

Alibaba Nacos






43

CVE-2024-4577

89

PHP


✓




44

CVE-2025-24813

89

Apache Tomcat


✓




45

CVE-2025-43529

89

Apple Safari, iOS, iPadOS, macOS, tvOS, visionOS, and watchOS


✓




46

CVE-2025-49113

89

Roundcube Webmail


✓




47

CVE-2025-68613

89

n8n


✓




48

CVE-2026-0300

89

Palo Alto Networks PAN-OS


✓




49

CVE-2026-12569

89

PTC Windchill and FlexPLM


✓




50

CVE-2026-21858

89

n8n






51

CVE-2026-3055

89

Citrix NetScaler ADC and NetScaler Gateway






52

CVE-2026-33017

89

Langflow


✓




53

CVE-2010-3904

79

Linux kernel






54

CVE-2020-1013

79

Microsoft Windows






55

CVE-2021-29442

79

Alibaba Nacos






56

CVE-2021-33044

79

Dahua cameras and video devices






57

CVE-2021-33045

79

Dahua cameras and video devices






58

CVE-2022-1040

79

Sophos Firewall


✓




59

CVE-2022-27925

79

Synacor Zimbra Collaboration Suite


✓




60

CVE-2022-47986

79

IBM Aspera Faspex


✓




61

CVE-2023-22527

79

Atlassian Confluence Data Center and Server


✓




62

CVE-2023-46747

79

F5 BIG-IP


✓




63

CVE-2024-55591

79

Fortinet FortiOS and FortiProxy






64

CVE-2025-24472

79

Fortinet FortiOS and FortiProxy






65

CVE-2025-31324

79

SAP NetWeaver Visual Composer


✓




66

CVE-2026-15981

79

miniOrange SAML SSO Login






67

CVE-2026-19478

79

GitLab CE and EE






68

CVE-2026-25895

79

FUXA


✓




69

CVE-2026-61979

79

miniOrange SAML SP SSO






70

CVE-2022-36883

76

Jenkins Git Plugin






Table 1: List of vulnerabilities that were actively exploited in August, 2026 based on Recorded Future data (excluding honeypot-sourced CVEs).


Key trends: August 2026



  • August reporting showed two AI-assisted operations: UAT-10147 exploited Zimbra, AjaxPro, Nacos, and Telerik servers before using DeepAudit and PentestGPT after compromise, while a separate Chinese-speaking actor weaponized Hermes Agent and DeepSeek in failed attempts against Langflow and n8n.

  • 34 of the 73 vulnerabilities enabled remote code execution (RCE). They affected Microsoft productivity, database, server, and endpoint software; network edge and application delivery appliances; webmail, collaboration, content management, and web server platforms; AI, analytics, developer, and CI/CD services; and operational technology, product lifecycle management, file transfer, videoconferencing, and enterprise integration software.

  • We identified public proof-of-concept (PoC) exploits and scanners for 53 of the 73 vulnerabilities.

  • The most common weakness classes were CWE-94 (Code Injection) and CWE-502 (Deserialization of Untrusted Data) with seven each, followed by CWE-287 (Improper Authentication) and CWE-306 (Missing Authentication for Critical Function) with six each.

  • 17 vulnerabilities were at least five years old, and the oldest was approximately 16 years old.


Trend analysis: AI-assisted workflows scale exploitation and target selection


Insikt Group detailed how Chinese-speaking threat group, UAT-10147, combined conventional exploitation with agentic artificial intelligence (AI) during post-compromise operations against internet-facing Windows and Linux web servers. Cisco Talos observed the threat actor exploiting or weaponizing CVE-2019-18935 in Telerik UI for ASP.NET AJAX, CVE-2021-23758 in AjaxPro, CVE-2021-29441 and CVE-2021-29442 in Nacos, and CVE-2022-27925 in Zimbra for initial access. After compromise, UAT-10147 used CVE-2010-3904, CVE-2015-3246, CVE-2015-5287, CVE-2021-3156, CVE-2022-0847, and CVE-2022-0995 for local privilege escalation on Linux.









Figure 1: Risk Rules history on the Vulnerability Intelligence Card® for CVE-2021-23758 in Recorded Future (Source: Recorded Future)




Source: RecordedFuture
Source Link: https://www.recordedfuture.com/blog/august-2026-cve-landscape


Comments
new comment
Nobody has commented yet. Will you be the first?
 
Forum
Blue Team (CND)



Copyright 2012 through 2026 - National Cyber Warfare Foundation - All rights reserved worldwide.