Microsoft Entra ID Flaw (CVSS 10.0) Exploited in Wild, Allows Remote Code Execution. CVE-2026-69836, a maximum-severity RCE vulnerability in Microsoft Entra ID, has been actively exploited in the wild. Microsoft states the vulnerability is fully server-side mitigated and no customer action is required, but the absence of technical detail and the identity-layer targeting make this worth validating in your environment.
CISA Orders Feds to Patch Actively Exploited TrueConf Server Flaws. Two critical TrueConf Server vulnerabilities, CVE-2026-72529 (missing authentication) and CVE-2026-72530 (code injection), are being actively exploited by the Head Mare hacktivist group to deploy PhantomCore backdoor malware via trojanized client installers. CISA has added both to its KEV catalog and mandated federal remediation.
Attackers Exploit Zimbra SNMP Flaw for Unauthenticated RCE. CVE-2026-73570, an OS command injection flaw in Zimbra Collaboration, is being actively exploited in the wild when the optional zimbra-snmp package is installed. CERT Polska has issued alerts and the flaw is now on the CISA KEV catalog; patch to version 10.1.20 immediately. Learn more
ShieldBreak Zero-Day: No Patch, CISA BOD Gives 14 Days. CVE-2026-69414 (ShieldBreak) is an unpatched local privilege escalation to SYSTEM in Microsoft's Malware Protection Engine. A public PoC dropped August 12 and no patch exists yet, making detection and compensating controls the only option for defenders right now. Learn more
Critical NetScaler Flaw Can Bypass Authentication on Gateway and AAA Servers. Citrix patched CVE-2026-19490 (CVSS 9.3), an authentication bypass affecting NetScaler ADC and Gateway appliances configured with SAML actions, alongside a memory overflow DoS flaw. Citrix is urging immediate upgrades given the sensitivity of these perimeter devices to credential theft and lateral movement. Learn more
MLflow SSRF Vulnerability Actively Exploited for Cloud Credential Theft. CVE-2026-64849 (CVSS 9.3) in MLflow's unauthenticated model-registry webhooks API is being exploited to steal cloud credentials and secrets from hosted AI/ML instances. CISA added it to the KEV catalog; all MLflow versions before 3.15.0 are affected. Learn more
Key Takeaway
Prioritize patching Entra ID, TrueConf, Zimbra, NetScaler, and MLflow this week; all have confirmed exploitation and at least one carries a CVSS 10.0 score.
