Security Digest: August 15, 2026 - 19 Critical Vulnerabilities
Today’s digest is dominated by active exploitation and high-impact remote attack paths, with one Metabase flaw and one Windows privilege-escalation bug already in CISA’s Known Exploited Vulnerabilities catalog. Several other issues can lead to remote code execution, data theft, cross-tenant disruption, or local system compromise if left unpatched.
· 35 min read
Executive Summary
Today’s digest is dominated by active exploitation and high-impact remote attack paths, with one Metabase flaw and one Windows privilege-escalation bug already in CISA’s Known Exploited Vulnerabilities catalog. Several other issues can lead to remote code execution, data theft, cross-tenant disruption, or local system compromise if left unpatched.
Act now: prioritize internet-facing services, Windows endpoints and servers, .NET runtimes, and any developer tools or agents exposed to untrusted input. Where patches are not immediately available, isolate the affected service, restrict access, and increase monitoring for suspicious authentication, metadata access, and unexpected child processes.
Critical Vulnerabilities
CVE-2026-72898: Metabase SQL Injection leading to admin access
- Impact: Unauthenticated attackers can inject arbitrary SQL, gain administrator access, steal stored database credentials, read connected data, and export data.
- Affected Systems: Metabase deployments exposed to network access.
- Immediate Action: Treat as urgent if Metabase is reachable from the internet or partner networks. Restrict access now and check for suspicious admin creation, config changes, and unusual export activity.
- Mitigation: Apply the vendor fix immediately and rotate any credentials stored in Metabase-connected databases.
CVE-2026-68820: Windows WinSock ancillary driver privilege escalation
- Impact: An authorized local attacker can elevate privileges on Windows systems.
- Affected Systems: Microsoft Windows Ancillary Function Driver for WinSock.
- Immediate Action: Prioritize patching on shared workstations, servers, and endpoints with multiple local users.
- Mitigation: Install the latest Microsoft security updates as soon as possible.
CVE-2026-73080: SeaweedFS unauthenticated SSRF with response read-back
- Impact: Attackers who can reach the gRPC port can force requests to internal services, loopback, or cloud metadata endpoints and read the response.
- Affected Systems:
github.com/seaweedfs/seaweedfsbefore 4.24. - Immediate Action: Block public access to volume server gRPC ports and verify whether metadata credentials may have been exposed.
- Mitigation: Upgrade to 4.24 and enforce network restrictions or mTLS.
CVE-2026-55072: Pimcore class UID SQL injection
- Impact: An authenticated user with
objectspermission can inject SQL and exfiltrate database contents when a crafted object is loaded. - Affected Systems:
pimcore/pimcore2026.1.x with Studio API enabled. - Immediate Action: Review any low-privilege editor accounts and suspend class-definition changes until patched.
- Mitigation: Apply the vendor fix and audit for abnormal class definitions and object loads.
CVE-2026-73654: Trigger.dev prototype pollution in run metadata
- Impact: A low-privilege API key can pollute
Object.prototype, break authentication and worker processing across tenants, and crash the process. - Affected Systems:
@trigger.dev/corev3.3.8 through v4-beta before 4.5.6. - Immediate Action: Treat as a multi-tenant outage risk. Rotate environment API keys and isolate affected webapp instances if abuse is suspected.
- Mitigation: Upgrade to 4.5.6 and block dangerous path segments such as
__proto__,constructor, andprototype.
CVE-2026-55157: token-optimizer-mcp command injection
- Impact: A crafted username can execute arbitrary shell commands on the MCP server host.
- Affected Systems:
@ooples/token-optimizer-mcpv0.2.0 / v5.0.1 tested. - Immediate Action: Disable or restrict MCP tool access until patched; review server logs for suspicious usernames containing shell syntax.
- Mitigation: Replace shell command construction with safe argument handling and upgrade to a fixed release when available.
CVE-2026-55071: stata-mcp Stata command injection
- Impact: A crafted package name can inject Stata commands and lead to OS command execution.
- Affected Systems:
stata-mcppackage. - Immediate Action: Turn off exposed MCP access and block untrusted tool callers immediately.
- Mitigation: Patch the tool to validate and sanitize package names; upgrade to the vendor-fixed version.
CVE-2026-53657: Lima guest agent socket exposure
- Impact: An arbitrary user inside the VM can access the guest agent socket and run commands as root in the VM.
- Affected Systems:
github.com/lima-vm/lima/v2on theqemudriver with guest agent enabled. - Immediate Action: If you use Lima on affected configurations, switch to
vzor disable the guest agent now. - Mitigation: Upgrade to Lima v2.1.3 or apply the documented workarounds.
CVE-2026-32257: Winter CMS backend branding stored XSS
- Impact: Users with backend branding permissions can inject stored XSS into backend pages.
- Affected Systems:
winter/wn-backend-modulebefore v1.2.13. - Immediate Action: Review who has branding permissions and restrict them to trusted administrators only.
- Mitigation: Upgrade to v1.2.13.
CVE-2026-32258: Winter CMS editor settings stored XSS
- Impact: Users with editor-management permission can inject stored XSS through markup styles.
- Affected Systems:
winter/wn-backend-modulebefore v1.2.13. - Immediate Action: Limit access to trusted staff and inspect custom style entries for untrusted content.
- Mitigation: Upgrade to v1.2.13 and verify compiled CSS is sanitized.
CVE-2026-62871: .NET WPF out-of-bounds write
- Impact: Local code execution on Windows systems using affected .NET desktop runtime packages.
- Affected Systems: Microsoft.WindowsDesktop.App.Runtime packages for .NET 8, 9, and 10 in the affected ranges.
- Immediate Action: Update runtimes and redeploy self-contained apps that bundle vulnerable versions.
- Mitigation: Install 8.0.30, 9.0.19, or 10.0.11 as appropriate.
CVE-2026-62886: .NET WPF integer overflow leading to local privilege escalation
- Impact: An unauthorized local attacker can elevate privileges on Windows.
- Affected Systems: Microsoft.WindowsDesktop.App.Runtime packages for .NET 8, 9, and 10 in the affected ranges.
- Immediate Action: Patch Windows desktop runtimes on developer and user endpoints first.
- Mitigation: Upgrade to the patched runtime versions and restart affected apps.
CVE-2026-70354: .NET WPF out-of-bounds write
- Impact: Local code execution on Windows.
- Affected Systems: Microsoft.WindowsDesktop.App.Runtime packages for .NET 8, 9, and 10 in the affected ranges.
- Immediate Action: Update all Windows desktop deployments that use the affected runtime packages.
- Mitigation: Move to the patched runtime versions and redeploy self-contained applications.
CVE-2026-62901: .NET WebSockets denial of service
- Impact: A remote attacker can trigger a denial of service over the network.
- Affected Systems: Microsoft.NETCore.App.Runtime packages for .NET 8, 9, and 10 across Windows, Linux, and macOS.
- Immediate Action: Prioritize internet-facing services using WebSockets and watch for connection storms or hung workers.
- Mitigation: Upgrade to 8.0.30, 9.0.19, or 10.0.11 and restart services.
CVE-2026-46369: Nimiq replay protection bypass
- Impact: A signed transaction can be replayed within a narrow window, causing double execution and double transfers.
- Affected Systems:
nimiq-blockchain. - Immediate Action: Treat as a financial-integrity issue; monitor for repeated transaction IDs and unusual duplicate transfers.
- Mitigation: Apply the upstream patch immediately.
CVE-2026-62898: Microsoft QUIC use-after-free information disclosure
- Impact: A remote attacker can disclose information over the network.
- Affected Systems: Microsoft.NETCore.App.Runtime packages for .NET 8, 9, and 10 in the affected ranges.
- Immediate Action: Patch systems that expose QUIC or HTTP/3 services first.
- Mitigation: Install the fixed runtime versions and restart affected applications.
CVE-2026-55153: mchange-commons-java JNDI object factory abuse
- Impact: Malicious JNDI references can trigger unsafe object construction, network access, or deserialization gadget chains.
- Affected Systems:
mchange:mchange-commons-javaand dependent c3p0 deployments. - Immediate Action: Search for exposed JNDI entry points and restrict untrusted serialized input immediately.
- Mitigation: Upgrade to v0.6.0 or later; update c3p0 alongside it.
CVE-2026-48798: SSH.NET SCP directory traversal
- Impact: A malicious SCP server can write files outside the intended download directory, enabling persistence or code execution on the client host.
- Affected Systems:
SSH.NET. - Immediate Action: Stop recursive downloads from untrusted or newly changed SCP servers until patched.
- Mitigation: Upgrade to the fixed release that validates remote names and blocks path traversal.
CVE-2026-62897: .NET WPF integer overflow
- Impact: Local code execution on Windows.
- Affected Systems: Microsoft.WindowsDesktop.App.Runtime packages for .NET 8, 9, and 10 in the affected ranges.
- Immediate Action: Treat as a companion emergency to the other WPF advisories; patch all affected Windows desktop runtimes together.
- Mitigation: Upgrade to the patched runtime versions and redeploy self-contained apps.
🚨 ACTIVELY EXPLOITED
- CVE-2026-72898 — Metabase SQL injection; CISA KEV. Patch immediately and assume exposure if the service was internet reachable.
- CVE-2026-68820 — Windows WinSock ancillary driver use-after-free; CISA KEV. Prioritize Windows patching across endpoints and servers.
Previously Alerted
- CVE-2026-12243
- CVE-2026-35290
- CVE-2026-60358
- CVE-2026-60360
- CVE-2026-60365
- CVE-2026-47056
- CVE-2026-60644
- CVE-2026-60389
- CVE-2026-60379
- CVE-2026-60217
- CVE-2026-60429
- CVE-2026-60627
- CVE-2026-60377
- CVE-2026-60461
- CVE-2026-60565
- CVE-2026-60402
- CVE-2026-60542
- CVE-2026-60458
- CVE-2026-60247
- CVE-2026-60275
- CVE-2026-60446
- CVE-2026-46982
- CVE-2026-60566
- CVE-2026-60216
- CVE-2026-60234
- CVE-2026-60256
- CVE-2026-60302
- CVE-2026-60460
- CVE-2026-46983
- CVE-2026-60204
- CVE-2026-60278
- CVE-2026-60290
- CVE-2026-60328
- CVE-2026-46876
- CVE-2026-60221
- CVE-2026-60230
- CVE-2026-60200
- CVE-2026-60232
- CVE-2026-60269
- CVE-2026-60287
- CVE-2026-60298
- CVE-2026-60362
- CVE-2026-60378
- CVE-2026-60463
- CVE-2026-63764
- CVE-2026-60631
- CVE-2026-60168
- CVE-2026-46989
- CVE-2026-60567
- CVE-2026-47037
- CVE-2026-60193
- CVE-2026-47688
- CVE-2026-60192
- CVE-2026-60586
- CVE-2026-60180
- CVE-2026-60179
- CVE-2026-16484
- CVE-2026-46954
- CVE-2026-60381
- CVE-2026-60333
- CVE-2026-60361
- CVE-2026-60524
- CVE-2026-60562
- CVE-2026-60456
- CVE-2026-60257
- CVE-2026-60294
- CVE-2026-60535
- CVE-2026-46994
- CVE-2026-46924
- CVE-2026-60225
- CVE-2026-60241
- CVE-2026-60258
- CVE-2026-60308
- CVE-2026-60541
- CVE-2026-47036
- CVE-2026-60210
- CVE-2026-60280
- CVE-2026-60292
- CVE-2026-60363
- CVE-2026-60198
- CVE-2026-60224
- CVE-2026-60240
- CVE-2026-60205
- CVE-2026-60244
- CVE-2026-60272
- CVE-2026-60289
- CVE-2026-60300
- CVE-2026-60364
- CVE-2026-60380
- CVE-2026-60540
- CVE-2026-60632
- CVE-2026-65057
- CVE-2026-60649
- CVE-2026-60326
- CVE-2026-60249
- CVE-2026-60559
- CVE-2026-60163
- CVE-2026-60560
- CVE-2026-60325
- CVE-2026-47018
- CVE-2026-47690
- CVE-2026-47058
- CVE-2026-47685
- CVE-2026-47697
- CVE-2026-60457
- CVE-2026-60537
- CVE-2026-60206
- CVE-2026-60531
- CVE-2026-60561
- CVE-2026-60447
- CVE-2026-60259
- CVE-2026-60435
- CVE-2026-60386
- CVE-2026-60532
- CVE-2026-60197
- CVE-2026-60227
- CVE-2026-60246
- CVE-2026-60274
- CVE-2026-60355
- CVE-2026-60551
- CVE-2026-60173
- CVE-2026-60236
- CVE-2026-60286
- CVE-2026-60297
- CVE-2026-60375
- CVE-2026-60212
- CVE-2026-60226
- CVE-2026-60242
- CVE-2026-60209
- CVE-2026-60254
- CVE-2026-60279
- CVE-2026-60291
- CVE-2026-60306
- CVE-2026-60374
- CVE-2026-60385
- CVE-2026-60564
- CVE-2026-60248
- CVE-2026-60438
- CVE-2026-60208
- CVE-2026-60606
- CVE-2026-60424
- CVE-2026-60327
- CVE-2026-65056
- CVE-2026-60416
- CVE-2026-46923
- CVE-2026-47057
- CVE-2026-60314
- CVE-2026-60317
- CVE-2026-47687
- CVE-2026-56147
- CVE-2026-60459
- CVE-2026-60547
- CVE-2026-60422
- CVE-2026-60552
- CVE-2026-60568
- CVE-2026-60445
- CVE-2026-60262
- CVE-2026-60441
- CVE-2026-60388
- CVE-2026-60538
- CVE-2026-60202
- CVE-2026-60229
- CVE-2026-60251
- CVE-2026-60276
- CVE-2026-60442
- CVE-2026-60555
- CVE-2026-60199
- CVE-2026-60253
- CVE-2026-60288
- CVE-2026-60299
- CVE-2026-60384
- CVE-2026-60215
- CVE-2026-60228
- CVE-2026-60250
- CVE-2026-60219
- CVE-2026-60264
- CVE-2026-60285
- CVE-2026-60296
- CVE-2026-60329
- CVE-2026-60376
- CVE-2026-60387
- CVE-2026-60239
- CVE-2026-60220
- CVE-2026-60267
- CVE-2026-47040
- CVE-2026-47731
- CVE-2026-60493
- CVE-2026-60356
- CVE-2026-60315
- CVE-2026-10678
- CVE-2026-47237
- CVE-2026-60498
- CVE-2026-47063
- CVE-2026-63358
- CVE-2026-60316
- CVE-2026-60623
- CVE-2026-52472
- CVE-2026-52469
- CVE-2026-52470
- CVE-2026-30631
- CVE-2026-52474
- CVE-2026-52476
- CVE-2026-60663
- CVE-2026-60719
- CVE-2026-60711
- CVE-2026-60668
- CVE-2026-60690
- CVE-2026-60689
- CVE-2026-60704
- CVE-2026-60667
- CVE-2026-60725
- CVE-2026-60705
- CVE-2026-60773
- CVE-2026-60763
- CVE-2026-55851
- CVE-2026-8983
- CVE-2026-20349
What to Do Now
- Patch the exploited and internet-facing systems first. Start with Metabase, Windows endpoints/servers, SeaweedFS, and any exposed MCP or automation tools.
- Remove unnecessary exposure. Restrict gRPC, admin, and developer-tool ports to trusted networks only.
- Upgrade runtimes and libraries in bulk. For Microsoft .NET, move to the patched runtime versions and redeploy self-contained apps.
- Rotate secrets where data may have been exposed. Assume credential theft is possible for Metabase and any system that can reach cloud metadata endpoints.
- Audit for abuse. Look for new admin accounts, unusual exports, prototype pollution symptoms, unexpected shell commands, and repeated transaction IDs.
Verification steps: confirm installed versions, compare against the affected ranges above, and validate that patched releases are actually running in production. For Windows and .NET, use dotnet --info and endpoint inventory; for containerized or self-hosted apps, verify the deployed image tags and runtime package versions.
Monitoring recommendations: watch for anomalous SQL activity, metadata service access, gRPC requests from unknown sources, process crashes, and authentication failures across tenants. Add alerts for suspicious usernames, newline injection patterns, and repeated SCP downloads from untrusted servers.
Related Resources
- Internal follow-up analysis: pending — link will be added when available.
- Official vendor advisories: Microsoft Security Response Center, GitHub Security Advisories, CISA KEV catalog, and product-specific release notes for Metabase, SeaweedFS, Pimcore, Trigger.dev, Lima, Winter CMS, Nimiq, SSH.NET, mchange-commons-java, and the affected .NET runtimes.