Weekly Exploit Roundup 2026-08-18
Weekly Exploit Roundup
Generated 2026-08-18T08:00:09.425896+00:00 (UTC)
- Patch Tuesday – August 2026
Source: Rapid7 Cybersecurity Blog | Published: 2026-08-11T21:10:55+00:00 | Score: 26.492Microsoft is publishing 421 vulnerabilities on August 2026 Patch Tuesday , including 236 vulnerabilities in Windows. This is lower volume than last month’s record-breaking behemoth, but still one of the largest Patch Tuesday totals ever. There is no reason to suppose that Patch Tuesday will ever return to the lower volumes we saw prior to 2026. Microsoft is aware of exploitation in the wild for one of the vulnerabilities published today, as well as public disclosure for two others, although the Notable CVEs section of the Security Update Guide omits one of these. As usual, browser vulns are not included in the Patch Tuesday count above, but unusually, Microsoft does not appear to have published any desktop browser security patches so far this month. SharePoint: critical RCE chain by Rapid7 Today sees the publication of CVE-2026-63520 , a high-severity remote code execution in Microsoft SharePoint. Discovered by Rapid7 Senior Principal Security Researcher Stephen Fewer , and published t
- CVE-2026-63520: Microsoft SharePoint Remote Code Execution (FIXED)
Source: Rapid7 Cybersecurity Blog | Published: 2026-08-11T13:00:00+00:00 | Score: 24.449Overview Rapid7 Labs conducted a zero-day research project against Microsoft SharePoint, resulting in the discovery of two new vulnerabilities that, when chained together, achieve unauthenticated remote code execution (RCE) against a vulnerable SharePoint server. Today, both Rapid7 and Microsoft are disclosing the second vulnerability in this chain, the RCE vulnerability CVE-2026-63520. The first vulnerability in the chain, CVE-2026-55040, was disclosed by Rapid7 and Microsoft last month. Our full disclosure timeline for the exploit chain can be seen below in Figure 1. Figure 1: The road to disclosure. ⠀ CVE-2026-63520 affects all supported versions of Microsoft SharePoint. An attacker can leverage CVE-2026-63520 to execute arbitrary code on a vulnerable SharePoint server with the privileges of the SharePoint Site’s service account. The vulnerability is due to an unsafe .NET type instantiation issue within the Business Connectivity Services . CVE-2026-63520 has a CVSSv3.1 score of 8.1
- Metasploit Wrap Up: Lot of summer shells and fit http profiles
Source: Rapid7 Cybersecurity Blog | Published: 2026-08-14T21:27:45+00:00 | Score: 23.043This wrap-up brings a full-on shell parade. Thirteen shiny new modules landed, starting with a buffet of RCEs. WordPress WP2Shell, Ghost CMS, Joomla JCE, Langflow, OpenCATS, Pterodactyl Panel, SonicWall SMA1000, Ray Dashboard, a Pix-for-WooCommerce, and for those who like their exploits closer to the bare-metal, the Fragnesia Linux kernel LPE (CVE-2026-46300). Metasploit also got the glow-up of the summer with the new http malleable profiles, MCP functionality and linux multi fetch payloads (more details on the [official 6.5 release blog post](https://www.rapid7.com/blog/post/pt-metasploit-framework-6-5-released/)!). Windows on ARM confirm to be the new first-class citizenship thanks to brand-new AArch64 reverse-TCP shells (both inline and staged), so your Snapdragon boxes can join the party too. Last but not least, an important message: *Nyan Nyan Nyan Nyan Nyan Nyan.* New module content (13) Ray Dashboard Logs API Path Traversal Author: Richard Howe <rhowe425> Type: Auxiliary Pull re
- GeoServer Zero-Day Targeted in Active Exploitation Attempts, Can Lead to RCE
Source: The Hacker News | Published: 2026-08-13T18:45:12+00:00 | Score: 21.849A newly disclosed zero-day flaw in GeoServer is seeing active exploitation efforts, per watchTowr.
The vulnerability, which has yet to be assigned a CVE identifier, is an SQL injection vulnerability in the open-source platform that can lead to remote code execution (RCE). The security defect remains unpatched.
It was first disclosed on August 12, 2026, at 10:46 UTC, by a researcher named @
- Adobe Patches Three CVSS 10.0 ColdFusion and Campaign Classic Flaws
Source: The Hacker News | Published: 2026-08-12T11:13:03+00:00 | Score: 21.41Adobe has shipped updates to address multiple critical security vulnerabilities impacting ColdFusion, Commerce, and Campaign Classic that, if successfully exploited, could result in arbitrary code execution and privilege escalation.
The most severe of the flaws are listed below –
CVE-2026-48362 (CVSS score: 10.0) – An operating system command injection vulnerability in ColdFusion that could
- Forminator WordPress Flaw Can Enable Unauthenticated RCE via Malicious PHP Uploads
Source: The Hacker News | Published: 2026-08-17T18:22:09+00:00 | Score: 20.194A critical security flaw has been disclosed in Forminator Forms, a WordPress plugin with more than 600,000 active installations, that could be exploited to achieve arbitrary code execution on susceptible sites.
The vulnerability, tracked as CVE-2026-15748, is rated 9.8 out of 10.0 on the CVSS scoring system. It was discovered and reported by a security researcher who goes by the online alias "
- Apple macOS Screen Sharing Flaw Exploited on Internet-Exposed Macs to Install Monero Miner
Source: The Hacker News | Published: 2026-08-15T07:24:04+00:00 | Score: 19.439A recently patched security flaw in Apple macOS has come under active exploitation in the wild to deploy a cryptocurrency miner, the Netherlands National Cyber Security Centre (NCSC-NL) has warned.
The vulnerability in question is CVE-2026-65400 (CVSS score: 9.8), a critical authentication issue impacting the Screen Sharing component that could allow an attacker already on the network to
- Critical SAP Commerce Cloud Vulnerability Exploited 3 Days After Disclosure
Source: SecurityWeek | Published: 2026-08-17T08:13:07+00:00 | Score: 19.292The vulnerability tracked as CVE-2026-58231 can be exploited to execute arbitrary code and compromise internal components. The post Critical SAP Commerce Cloud Vulnerability Exploited 3 Days After Disclosure appeared first on SecurityWeek .
- CISA Flags Actively Exploited Ray Flaw That Can Trigger Browser-Based RCE
Source: The Hacker News | Published: 2026-08-18T06:34:20+00:00 | Score: 19.057The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a critical flaw impacting Ray to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation.
Ray is an open-source, Python-native distributed computing framework designed to scale artificial intelligence and machine learning workloads. As of writing, the GitHub project has more than
- CISA Adds One Known Exploited Vulnerability to Catalog
Source: Alerts | Published: 2026-08-17T12:00:00+00:00 | Score: 17.405CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2025-62593 Ray-Project Ray Code Injection Vulnerability This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise. Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in CISA’s KEV Catalog on publicly exposed assets that grant total control of the asset post-exploitation, while deferring action for lower-risk vulnerabilities. BOD 26-04 further establishes basic expectations for when agencies must check whether
End of report.