Security Digest: August 20, 2026 - 30 Critical Vulnerabilities

Today’s patch load is heavy, but the risk is concentrated: six actively exploited CVEs are already in CISA KEV, and several others enable full sandbox escape, credential theft, SSRF, or remote code execution. Treat exposed macOS, MLflow, Ray, vCenter, SharePoint, and any internet-facing Java, Python, Ruby, Node, or PHP service as patch-now items.

Β· 16 min read

Executive Summary

Today’s patch load is heavy, but the risk is concentrated: six actively exploited CVEs are already in CISA KEV, and several others enable full sandbox escape, credential theft, SSRF, or remote code execution. Treat exposed macOS, MLflow, Ray, vCenter, SharePoint, and any internet-facing Java, Python, Ruby, Node, or PHP service as patch-now items.

Immediate action: prioritize KEV entries first, then any systems parsing untrusted files or exposing admin/API endpoints. If you cannot patch today, isolate, disable vulnerable features, and rotate secrets where credential exposure is possible.

🚨 ACTIVELY EXPLOITED

  • CVE-2026-65400: Apple macOS Screen Sharing auth bypass β€” Impact: network attacker can authenticate to Screen Sharing without credentials. Affected Systems: Apple macOS. Immediate Action: patch macOS fleet now; restrict Screen Sharing exposure. Mitigation: install Apple security update; disable Screen Sharing where not required.
    https://cyberlensai.com/news/security-digest-2026-08-20
  • CVE-2026-64849: MLflow SSRF to internal/cloud metadata services β€” Impact: attackers can reach internal services and metadata endpoints. Affected Systems: MLflow. Immediate Action: update MLflow immediately; block outbound metadata access from MLflow hosts. Mitigation: apply vendor fix and egress controls.
  • CVE-2025-62593: Ray sandbox code injection / RCE β€” Impact: remote code execution via sandbox breakout. Affected Systems: Ray. Immediate Action: upgrade Ray and stop running untrusted notebooks/scripts. Mitigation: patch to fixed release; isolate developer environments.
  • CVE-2026-33824: Microsoft IKE Service Extensions double free β€” Impact: remote code execution. Affected Systems: Microsoft Internet Key Exchange (IKE) Service Extensions. Immediate Action: deploy Microsoft update to VPN/edge systems now. Mitigation: patch and restrict inbound management/VPN exposure.
  • CVE-2026-59310: VMware vCenter path traversal to code execution β€” Impact: arbitrary code execution on vCenter. Affected Systems: Broadcom VMware vCenter. Immediate Action: patch vCenter urgently; isolate admin access. Mitigation: vendor update and tight network ACLs.
  • CVE-2026-55040: SharePoint weak authentication bypass β€” Impact: unauthorized network attacker can bypass a security feature. Affected Systems: Microsoft SharePoint. Immediate Action: patch SharePoint and review exposed portals. Mitigation: apply Microsoft guidance and limit external access.

Critical Vulnerabilities

  • CVE-2026-55107: Kobako sandbox escape via mruby dispatch β€” Impact: complete host RCE from guest script. Affected Systems: rubygems kobako. Immediate Action: upgrade to 0.9.1; stop binding host services to untrusted scripts. Mitigation: no safe workaround in affected versions.
  • CVE-2026-55209: resdata GRDECL input validation failure β€” Impact: file-parsing crash and possible memory corruption in web services. Affected Systems: pip resdata. Immediate Action: upgrade to 6.2.9+; block untrusted GRDECL uploads. Mitigation: patch immediately.
  • CVE-2026-47698: vm2 sandbox breakout β€” Impact: host command execution from sandboxed code. Affected Systems: npm vm2. Immediate Action: remove vm2 from trust boundary; upgrade to fixed version. Mitigation: do not run attacker-controlled code in vm2 until patched.
  • CVE-2026-55211: surfio buffer overflow in irap parsing β€” Impact: crash or code execution risk via malformed files. Affected Systems: pip surfio. Immediate Action: update to 0.0.19+; quarantine file parsing services. Mitigation: patch and limit file uploads.
  • CVE-2026-62988: Froxlor API leaks password hashes and TOTP seeds β€” Impact: authenticated API users can steal password hashes and 2FA seeds, enabling account takeover. Affected Systems: composer froxlor/froxlor. Immediate Action: patch now; rotate exposed passwords and reset 2FA for affected accounts. Mitigation: remove/redact secret fields from API responses.
  • CVE-2026-55839: Kestra Markdown XSS via custom link syntax β€” Impact: stored XSS can hijack admin sessions. Affected Systems: maven io.kestra:kestra. Immediate Action: patch and review any user-authored Markdown content. Mitigation: sanitize custom attributes; remove raw HTML rendering.
  • CVE-2026-54347: Froxlor DNS editor stored XSS β€” Impact: customer input can execute in admin browsers and lead to takeover. Affected Systems: composer froxlor/froxlor. Immediate Action: patch; audit DNS records for malicious payloads. Mitigation: escape output and remove unsafe inline HTML paths.
  • CVE-2026-56677: 9Router unauthenticated OIDC SSRF β€” Impact: internal network probing and metadata access. Affected Systems: npm 9router. Immediate Action: restrict access to the dashboard API and patch immediately. Mitigation: authenticate the endpoint and block private IP targets.
  • CVE-2026-54148: http4k Digest auth replay across URLs β€” Impact: replayed Digest credentials can be reused on other URLs in the same realm. Affected Systems: maven org.http4k:http4k-security-digest. Immediate Action: upgrade to 6.50.0.0 or matching LTS fix. Mitigation: enforce URL binding at the proxy or app layer.
  • CVE-2026-71308: Lemur certificate replacement permission bypass β€” Impact: attacker can silently substitute their certificate onto production endpoints. Affected Systems: pip lemur. Immediate Action: review certificate workflows and patch; inspect recent certificate replacements. Mitigation: enforce per-certificate authorization on replacement lists.
  • CVE-2026-71303: Lemur ACME URL allowlist bypass on update β€” Impact: authority members can repoint ACME to internal/metadata URLs, causing SSRF. Affected Systems: pip lemur. Immediate Action: patch and audit ACME authorities. Mitigation: revalidate ACME URLs on every update.
  • CVE-2026-71307: Lemur destination secrets exposed to authenticated users β€” Impact: plaintext deployment credentials can be read by low-privilege users. Affected Systems: pip lemur. Immediate Action: rotate destination passwords/passphrases now; patch access control. Mitigation: gate reads and redact secret-bearing options.
  • CVE-2026-53957: Contentful MCP PAT exfiltration via host/proxy override β€” Impact: attacker can redirect API traffic and capture the management token. Affected Systems: npm @contentful/mcp-server, npm @contentful/mcp-tools. Immediate Action: disable the migration tools or patch immediately. Mitigation: pin host/proxy and remove attacker-controlled overrides.
  • CVE-2026-59902: Netty SCTP fragment memory exhaustion β€” Impact: unauthenticated OOM DoS. Affected Systems: maven io.netty:netty-transport-sctp. Immediate Action: disable SCTP transport if unused; patch Netty. Mitigation: add byte limits and ingress filtering.
  • CVE-2026-53659: http4k gzip decompression bomb β€” Impact: small requests expand to gigabytes and exhaust heap. Affected Systems: maven org.http4k:http4k-core. Immediate Action: upgrade to 6.49.0.0 or fixed LTS; block gzip at the edge if needed. Mitigation: enforce decompression size caps.
  • CVE-2026-59893: sqlparse ReDoS in dollar-quoted literals β€” Impact: CPU exhaustion from crafted SQL text. Affected Systems: pip sqlparse. Immediate Action: patch all services that parse user SQL; rate-limit and cap input size. Mitigation: upgrade and add request timeouts.
  • CVE-2026-53752: docx4j style recursion StackOverflow β€” Impact: upload-triggered denial of service. Affected Systems: maven org.docx4j:docx4j-core. Immediate Action: patch and block untrusted DOCX processing until updated. Mitigation: isolate document conversion workers.
  • CVE-2026-55178: GeoLens cross-dataset authorization failures β€” Impact: anonymous or low-privileged users can read private vector tiles, raster pixels, metadata, and rows. Affected Systems: npm @geolens/sdk, pip geolens-cli, pip geolens. Immediate Action: upgrade to 1.2.3 immediately. Mitigation: there is no complete workaround; restrict network exposure until patched.
  • CVE-2026-70666: Lemur ACME client SSRF via malicious directory responses β€” Impact: authority members can coerce signed outbound requests to internal URLs. Affected Systems: pip lemur. Immediate Action: patch and audit ACME authorities for unexpected directories. Mitigation: pin all ACME outbound hosts to the allowlist.
  • CVE-2026-71417: Lemur revocation via duplicate certificate row β€” Impact: attacker can revoke real production certificates at the CA. Affected Systems: pip lemur. Immediate Action: audit revocations and duplicate certificate uploads now. Mitigation: enforce authority checks and deduplicate CA identities.
  • CVE-2026-53964: document-merge-service XLSX SSTI β€” Impact: remote code execution in the document merge container. Affected Systems: pip document-merge-service. Immediate Action: upgrade to v9.1.0; disable XLSX templates until then. Mitigation: remove unsafe template execution paths.
  • CVE-2024-45747: GeoServer FreeMarker SSTI β€” Impact: authenticated admins can execute OS commands and read/write files. Affected Systems: maven org.geoserver:gs-main, gs-wms, gs-web-app. Immediate Action: upgrade to 2.27.0+ and set the new block/allow list properties. Mitigation: restrict template access and expose only safe getters.
  • CVE-2026-54348: Froxlor second-order SQL injection via admin IP field β€” Impact: malicious admins can dump credentials and arbitrary database data. Affected Systems: composer froxlor/froxlor. Immediate Action: patch and inspect admin IP metadata for injected payloads. Mitigation: integer-cast stored IDs before SQL use.
  • CVE-2026-69148: MLflow model-version artifact read bypass β€” Impact: authenticated users can read files from another user’s artifact directory. Affected Systems: npm mlflow. Immediate Action: patch MLflow and review model-version creation permissions. Mitigation: enforce READ checks on source runs/models before validation.

What to Do Now

  1. Patch the six KEV items first: macOS, MLflow, Ray, Microsoft IKE, VMware vCenter, and SharePoint.
  2. Rotate secrets where advisories expose passwords, TOTP seeds, PATs, or deployment credentials: Froxlor, Lemur, Contentful MCP.
  3. Disable or isolate risky features until patched: untrusted script sandboxes, DOCX/XLSX parsing, gzip request handling, SCTP, and public Markdown rendering.
  4. Review admin/API access for Froxlor, Lemur, Kestra, GeoLens, and 9Router; assume authenticated abuse is possible.
  5. Block outbound metadata access from MLflow, Lemur, and any SSRF-prone service.

Verification: inventory versions, compare against the fixed releases listed above, and confirm no exposed admin endpoints remain internet-facing. Hunt for recent certificate changes, unexpected ACME authorities, unusual outbound requests, and spikes in 4xx/5xx or CPU saturation.

Monitoring: alert on new admin accounts, certificate revocations/replacements, outbound traffic to private IP ranges, and repeated parsing failures from document, SQL, or gzip inputs.

Previously Alerted

Related Resources

  • Internal blog post on KEV prioritization and emergency patching β€” mention only, not published yet.
  • Internal blog post on SSRF containment and egress controls β€” mention only, not published yet.
  • Official vendor advisories for Apple, Microsoft, Broadcom, MLflow, Ray, Lemur, Froxlor, Kestra, GeoServer, Netty, http4k, sqlparse, and GeoLens.

Keep reading