Critical VMware vCenter RCE Exploited by APT Across 47 Countries. A directory traversal flaw in VMware vCenter Syslog Server (CVE-2026-59310) is being actively exploited by an APT actor to deploy reverse_ssh for persistent remote access, with confirmed hits across 361 IP addresses in 47 countries. Broadcom patched the flaw on July 29, but researchers warn that patching alone may be insufficient if the actor has already established footholds. Learn more
Adobe Commerce Auth Bypass (CVE-2026-71362) Exploited Immediately After Disclosure. A critical incorrect authorization vulnerability (CVSS 9.1) in Adobe Commerce and Magento allows unauthenticated attackers to hijack customer accounts and access private data via session switching. Exploitation attempts were detected by Sansec within hours of Adobe's patch release. Learn more
SAP Commerce Cloud RCE (CVE-2026-58231) Targeted Within Three Days of Patch. An improper authorization flaw enabling unauthenticated RCE in SAP Commerce Cloud was confirmed exploited in the wild just three days after SAP released a fix, with honeypot data from Defused confirming active attempts. SAP has not yet formally flagged it as exploited, underscoring the gap between vendor timelines and real-world attacker speed.
Windows Zero-Day 'ShieldBreak' Bypasses Defender, Grants SYSTEM Privileges. Researcher Nightmare Eclipse publicly dropped a new exploit targeting a Windows User Profile Service flaw (CVE-2026-62832, now patched as LegacyHive) that allows any authenticated local user to escalate to SYSTEM. The researcher released it publicly to protest Microsoft's vulnerability disclosure practices, making weaponized code immediately available to threat actors. Learn more
Key Takeaway
Patch VMware vCenter, Adobe Commerce, and SAP Commerce Cloud immediately and conduct post-compromise threat hunts on all three, as exploitation preceded or matched patch timelines.
