Security Digest: August 25, 2026 - 12 Critical Vulnerabilities

Today’s highest-risk issues include one actively exploited Oracle flaw, a critical SQL injection in GeoTools, and multiple high-severity vulnerabilities that can lead to stored XSS, denial of service, path traversal, or arbitrary file write. If you run affected Oracle, Java, Go, Python, PHP, Node, or CMS stacks, patch now and restrict exposure immediately.

· 11 min read

Critical Security Digest for August 25, 2026

Executive Summary

Today’s highest-risk issues include one actively exploited Oracle flaw, a critical SQL injection in GeoTools, and multiple high-severity vulnerabilities that can lead to stored XSS, denial of service, path traversal, or arbitrary file write. If you run affected Oracle, Java, Go, Python, PHP, Node, or CMS stacks, patch now and restrict exposure immediately.

The most urgent action is to treat CVE-2026-21962 as a live intrusion risk, then move through the rest of this list by internet exposure and privilege level. Where patches are not yet deployed, isolate the service, reduce privileges, and disable risky features until fixed builds are in place.

Critical Vulnerabilities

  • CVE-2026-21962: Oracle HTTP Server / WebLogic Proxy Plug-in access control bypass
    • Impact: Attackers can read, change, delete, or fully access critical Oracle HTTP Server and WebLogic Proxy Plug-in data.
    • Affected Systems: Oracle HTTP Server and Oracle WebLogic Server Proxy Plug-in.
    • Immediate Action: Patch immediately and assume exposed systems may already be targeted.
    • Mitigation: Apply Oracle’s fix as soon as available; restrict access to management and proxy interfaces now.
  • CVE-2026-76904: GeoTools PostGIS SQL injection
    • Impact: Remote attackers can execute arbitrary SQL against the database.
    • Affected Systems: org.geotools.jdbc:gt-jdbc-postgis using PostGIS 12+ with the vulnerable jsonArrayContains path.
    • Immediate Action: Upgrade to GeoTools 35.1, 34.4, or 33.5 depending on branch.
    • Mitigation: If patching is delayed, lock the PostGIS connection pool down to the least-privilege database account.
  • CVE-2026-54049: Sakai Conversations stored XSS
    • Impact: Authenticated users can inject script that runs in other users’ browsers.
    • Affected Systems: Sakai Conversations, kernel, and rubrics implementations.
    • Immediate Action: Remove or disable Conversations where possible and deploy the fix before reopening collaborative sites.
    • Mitigation: Update to the release containing the committed fix; verify that user content is sanitized before render.
  • CVE-2026-61824: defuddle site extractor XSS
    • Impact: Malicious content can trigger script execution in downstream viewers.
    • Affected Systems: npm defuddle through 0.19.0.
    • Immediate Action: Upgrade to 0.19.1 immediately.
    • Mitigation: Do not render parsed output as HTML until patched.
  • CVE-2026-63135: YOURLS referrer-based stored XSS
    • Impact: An attacker can poison stats pages and run JavaScript in an admin’s browser.
    • Affected Systems: Composer package yourls/yourls.
    • Immediate Action: Patch now and review any public or admin stats pages.
    • Mitigation: Restrict stats access, and treat referrer data as untrusted until fixed.
  • CVE-2026-64679: Atlantis workspace path traversal
    • Impact: Crafted workspace values can push filesystem operations outside the intended workspace root.
    • Affected Systems: github.com/runatlantis/atlantis versions >= 0.19.8 and < 0.45.0.
    • Immediate Action: Upgrade to 0.45.0 and audit any repository-controlled atlantis.yaml.
    • Mitigation: Limit who can submit Atlantis config and restrict filesystem permissions on mounted volumes.
  • CVE-2026-68508: Hydra instantiate arbitrary code execution risk
    • Impact: Untrusted config can cause code execution inside the consuming process.
    • Affected Systems: hydra-core in applications that pass attacker-controlled config to hydra.utils.instantiate().
    • Immediate Action: Stop feeding untrusted configs into instantiate paths and upgrade to 1.3.4+.
    • Mitigation: Enforce a trusted allowlist for targets; do not rely on config blacklists alone.
  • CVE-2026-63462: Unleash server crash via deeply nested JSON
    • Impact: A single unauthenticated request can crash the server and keep it offline.
    • Affected Systems: Unleash OSS server, confirmed on v8.0.0.
    • Immediate Action: Patch urgently and put rate limits / edge filtering in front of public endpoints.
    • Mitigation: Add request-depth controls and process supervision; do not rely on body-size limits alone.
  • CVE-2026-63421: Keystone GraphQL maxTake bypass
    • Impact: Attackers can request more records than intended, increasing data exposure and load.
    • Affected Systems: npm @keystone-6/core.
    • Immediate Action: Upgrade to 6.5.3 and block negative take values immediately.
    • Mitigation: Validate query inputs server-side even if client controls are present.
  • CVE-2026-76905: kin-openapi multipart validation crash
    • Impact: An unauthenticated multipart request can trigger a nil-pointer panic and deny service.
    • Affected Systems: Go projects using github.com/getkin/kin-openapi error helpers with multipart validation.
    • Immediate Action: Patch the library and add a recovery boundary around request validation.
    • Mitigation: If you cannot patch yet, avoid multipart endpoints or stop using the library’s error encoder on those routes.
  • CVE-2026-55477: 3X-UI / Xray arbitrary file write
    • Impact: An authenticated admin can write attacker-controlled content to arbitrary files and potentially gain code execution.
    • Affected Systems: github.com/mhsanaei/3x-ui/v2 and /v3.
    • Immediate Action: Upgrade to v3.3.1 and review all administrator access.
    • Mitigation: Restrict panel admins to trusted operators only; verify Xray log paths are confined to the expected folder.
  • CVE-2026-54623: django-cms plugin tree cycle denial of service
    • Impact: Authenticated staff can corrupt plugin trees and cause recursive queries to hang workers.
    • Affected Systems: django-cms before 5.0.8.
    • Immediate Action: Upgrade to 5.0.8 and review staff permissions on placeholder/plugin management.
    • Mitigation: Block self-parenting and descendant reparenting attempts at the application layer.

🚨 ACTIVELY EXPLOITED

  • CVE-2026-21962 — CISA KEV, actively exploited in the wild. Previously alerted example style applies here: treat this as a top-priority incident response item.

Previously Alerted

What to Do Now

  1. Patch the internet-facing and actively exploited items first: Oracle, Unleash, YOURLS, Atlantis, and any exposed Go multipart validation services.
  2. Reduce blast radius immediately: disable or restrict risky features such as stats pages, collaborative editors, admin import tools, and repository-controlled automation configs.
  3. Lock down privileges: use least-privilege database accounts, non-root service users, and limited admin roles for CMS and panel tools.
  4. Verify exposure: inventory versions against the affected ranges, then confirm whether the vulnerable endpoints are reachable from untrusted networks.
  5. Monitor for abuse: watch for unusual Oracle access, repeated crash-inducing requests, unexpected XSS payloads, path traversal attempts, and suspicious admin actions.

Verification steps: confirm package versions, check deployment manifests for pinned vulnerable releases, and review logs for repeated 400/500 spikes, validation failures, and abnormal admin activity. For Oracle and Unleash, assume active probing is already underway.

Monitoring recommendations: alert on new short-link referrers containing quotes or brackets, nested JSON spikes, multipart validation errors, plugin tree modifications, and any filesystem writes outside expected app directories.

Related Resources

  • Internal blog post: August 25, 2026 threat brief — pending publication.
  • Internal blog post: Emergency patch guidance for exposed enterprise services — pending publication.
  • Official vendor advisories: Oracle CPU advisory, GeoTools/OSGeo advisories, Sakai release notes, Unleash security advisory, Atlantis release notes, Keystone changelog, kin-openapi issue tracker, django-cms security release notes.

Keep reading