A concise view of the activity, vulnerabilities, and campaigns that deserve a defender’s attention.
Current reporting from trusted threat-research teams, refreshed at most once per hour.
CISA KEV · VulnerabilityAug 27, 2026
CVE-2026-53362: Linux Kernel Unspecified Vulnerability
Linux Kernel contains an unspecified vulnerability that can allow for privilege escalation via IPv6 networking subsystem. This vulnerability can impact multiple products, including but not limited to Suse, Red Hat, and other products using Linux.
CVE-2026-53362LinuxLinux
Brief overview
CISA added this Linux Kernel vulnerability to the Known Exploited Vulnerabilities catalogue on Aug 27, 2026, confirming evidence of exploitation in the wild. The federal remediation due date listed by CISA is Aug 30, 2026.
Defender next steps
•Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
•Inventory Linux Kernel deployments and prioritize exposed or high-value systems.
CVE-2026-65400: Apple macOS Improper Authentication Vulnerability
Apple macOS contains an improper authentication vulnerability that could allow an attacker on the network to authenticate to Screen Sharing without valid credentials.
CVE-2026-65400macOSApple
Brief overview
CISA added this Apple macOS vulnerability to the Known Exploited Vulnerabilities catalogue on Aug 18, 2026, confirming evidence of exploitation in the wild. The federal remediation due date listed by CISA is Aug 21, 2026.
Defender next steps
•Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
•Inventory Apple macOS deployments and prioritize exposed or high-value systems.
CVE-2019-1068: Microsoft SQL Server Remote Code Execution Vulnerability
Microsoft SQL Server contains a remote code execution vulnerability that could allow an attacker to execute code in the context of the SQL Server Database Engine service account.
CVE-2019-1068MicrosoftMicrosoft
Brief overview
CISA added this Microsoft SQL Server vulnerability to the Known Exploited Vulnerabilities catalogue on Aug 26, 2026, confirming evidence of exploitation in the wild. The federal remediation due date listed by CISA is Aug 29, 2026.
Defender next steps
•Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
•Inventory Microsoft SQL Server deployments and prioritize exposed or high-value systems.
Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) contain a heap inspection vulnerability that could allow an unauthenticated, remote attacker to cause the device to reload unexpectedly, resulting in a denial of service (DoS) condition.
CVE-2026-20349CiscoCisco
Brief overview
CISA added this Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) vulnerability to the Known Exploited Vulnerabilities catalogue on Aug 11, 2026, confirming evidence of exploitation in the wild. The federal remediation due date listed by CISA is Aug 14, 2026.
Defender next steps
•Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
•Inventory Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) deployments and prioritize exposed or high-value systems.
Mikrotik released a patch late last week for an already-exploited vulnerability. The vulnerability allows an SSH authentication bypass and is already being exploited. At this point, assume compromise. Attackers have been adding new accounts to affected devices to maintain access after a patch is…
SANS ISCVulnerability
Brief overview
This item was published by SANS ISC. Read the source report for its complete evidence, indicators, scope, and caveats.
Defender next steps
•Confirm whether the affected product is present and internet-facing.
•Review vendor guidance, patch status, and signs of exploitation before closing the item.
Enterprises face an unmanaged crisis of AI agent and MCP server sprawl, characterized by rapid, decentralized proliferation of autonomous agents, protocol connections operating with excessive privilege, opaque execution paths, and identity blind spots. Absent agent-aware governance, modern…
SANS ISCVulnerability
Brief overview
This item was published by SANS ISC. Read the source report for its complete evidence, indicators, scope, and caveats.
Defender next steps
•Confirm whether the affected product is present and internet-facing.
•Review vendor guidance, patch status, and signs of exploitation before closing the item.
Welcome to this week’s edition of the Threat Source newsletter. Our goal is to get accurate threat intelligence to our audience as quickly as possible, with all the context you need to ask the right questions of your own environment: How at risk are we from this threat? Are we prepared for it? And…
Cisco TalosVulnerability
Brief overview
This item was published by Cisco Talos. Read the source report for its complete evidence, indicators, scope, and caveats.
Defender next steps
•Confirm whether the affected product is present and internet-facing.
•Review vendor guidance, patch status, and signs of exploitation before closing the item.
Honeypot-Omaha and batch.py [Guest Diary], (Wed, Sep 2nd)
[This is a Guest Diary by Frank Igbokwe, an ISC intern as part of the SANS.edu BACS program] Honeypot-Omaha is a DShied Sensor located at the Internet Storm Center (ISC) that is set up as a decoy for the original target and deployed over the internet. It is a flawed and very vulnerable system that…
SANS ISCVulnerability
Brief overview
This item was published by SANS ISC. Read the source report for its complete evidence, indicators, scope, and caveats.
Defender next steps
•Confirm whether the affected product is present and internet-facing.
•Review vendor guidance, patch status, and signs of exploitation before closing the item.