Critical Vulnerabilities and Active Exploitation, Aug 2026
August closed with 344 verified incidents in LATAM, 83 critical CVEs, and 281 vulnerability events, with Brazil and Argentina in focus.
Key findings
- August showed high pressure from actively exploited vulnerabilities, with 344 verified incidents and 83 critical CVEs mentioned in the analyzed material.
- The dominant theme was vulnerabilities, with 281 of 344 incidents, far ahead of ransomware or extortion, which recorded no primary classified cases.
- Windows AFD.sys, Progress LoadMaster, Apache Tomcat, Zimbra, and Spring Security concentrated the most urgent cases for the region due to active exploitation or critical risk.
- Brazil was the country with the highest density of official alerts, with several CTIR Gov.br advisories on software widely deployed in public and private infrastructure.
- Attribution of campaigns to APTs linked to Russia against targets in Brazil and Argentina raises the risk assessment beyond opportunistic exploitation.
- The increase in fraud and phishing, from 2 to 30 cases versus July, reinforces the need to protect initial access and not focus only on patching.
- The gap between disclosure and remediation remained decisive, with several cases in the KEV weeks or months after fixed versions were available.
Monthly reference modules
These modules are filled automatically with verified dated facts within the period. Each one states its basis and counting criterion, so the figures reconcile across modules. They are the recurring month-by-month reading; the later analysis develops the cases without repeating this summary.
Indicator window: 346 dated facts in August 2026 · 16 from prior months (comparative frame, not monthly volume) · 23 without confirmed date (excluded from indicators). Facts from prior months are used only as a comparative frame in the analysis, never as volume for this period.
Executive monthly summary
August 2026 sent a strong signal across Latin America toward the exploitation of critical vulnerabilities, with 344 verified incidents, 83 critical CVEs mentioned, and 281 incidents classified in the vulnerabilities track. The month was dominated by software widely used in corporate and government environments, with notable alerts for Brazil, Argentina, Chile, Paraguay, and other countries in the region.
The defining pattern was not ransomware or extortion. The most sensitive exposure surfaced in collaboration servers, gateways, firewalls, Windows drivers, load-balancing appliances, and widely deployed management platforms. At the same time, regional CERTs, especially CTIR Gov.br and INCIBE-CERT, issued multiple advisories on products with active exploitation risk or urgent mitigation needs, reinforcing the month’s bias toward patching and immediate containment.
The clearest case of active exploitation was CVE-2026-68820 in Windows AFD.sys, treated as a zero-day exploited in the wild by Microsoft and several analysts. It was joined by CVE-2026-8037 in Progress LoadMaster, CVE-2026-34486 in Apache Tomcat, and CVE-2026-73570 in Zimbra Collaboration Suite, all classified as actively exploited in different technical and threat intelligence sources. The common pattern was a very short window between disclosure, KEV inclusion, and remediation requirements.
At the regional level, Brazil concentrated the highest density of official alerts, with CTIR Gov.br publishing advisories on FortiOS, Windows AFD, and Apache Tomcat, while Argentina appeared in the attribution of campaigns tied to CVE-2026-73570 against government agencies and universities. Chile added a different angle, more tied to the AI supply chain and preventive measures around LiteLLM. Paraguay, for its part, was linked to alerts on Ubiquiti and Joomla in contextual material, although without a confirmed date, so it is not included in the month’s indicators.
The operational readout is high risk. Not because of sheer volume alone, but because of the mix of real exploitation, cross-cutting products, and ever tighter mitigation timelines. August also showed added pressure on hybrid environments and public-sector systems, with campaigns affecting email, collaboration, authentication, load balancing, VPNs, firewalls, and development platforms, in other words, the logical perimeter that now supports much of the region’s operations.
Regional snapshot for the month
August saw an unusual concentration of alerts across the region about critical vulnerabilities that were either already being exploited or were ready for immediate exploitation, with Brazil as the documentary epicenter and Argentina, Chile, and Paraguay affected either directly or through preventive analysis of the campaigns. The month’s qualitative risk is high because most of the verified incidents pointed to internet-facing systems, collaboration services, security products, and administrative tools that often carry broad privileges.
The most important figure is not just that 344 verified incidents were recorded. It is that 281 of them fell into the vulnerability category, showing that the month’s main pressure came from the exploitation of known flaws, not from mass malware or extortion campaigns. For Latin American teams, that matters twice over. It confirms that attackers still find value in delayed patching, and it also makes inventory, external exposure, and response time top priorities.
Brazil concentrated CTIR Gov.br alerts on FortiOS, Windows AFD, and Apache Tomcat, three surfaces that often coexist in the public sector, financial services, and enterprise environments. The fact that the Brazilian agency issued repeated advisories about widely used software suggests a mature reading of risk, but also an ecosystem where vulnerability exploitation is significant enough to justify specific warnings. Argentina appeared less often in the alert count, but not in impact. The campaign attributed to actors linked to Russia against state institutions, universities, and public agencies places the country on the map of high-value targets.
Chile faced a different, no less serious focus. The material on the LiteLLM supply chain and the preventive response from ANCI and other entities shows how a vulnerability or compromise in the AI tooling layer can end up affecting hundreds of organizations and thousands of pipelines. Although that episode does not strictly belong to the core of critical CVEs, it reinforces the view of a month in which entry points expanded into automation and development infrastructure.
Period indicators
August’s statistical snapshot confirms a clear dominance of the vulnerability axis over the rest of the verified signals, with 344 base events, 83 critical CVEs, and a total drop to zero in ransomware or extortion cases as the primary focus. The regional reading should be handled carefully: the count reflects the material analyzed, not all activity observed in the region.
| Indicator | August 2026 | Previous month | Change |
|---|---|---|---|
| Verified events for the period (base for all indicators) | 344 | 187 | +157 |
| Indicator time window | 346 events dated in August 2026 · 16 from previous months (comparative frame, not monthly volume) · 23 with unconfirmed date (excluded from the indicators) | Same | N/A |
| Unclassified incidents (breaches or disruptions) | 14 | 3 | +11 |
| Cases with ransomware or extortion as primary focus | 0 | 4 | -4 |
| Ransomware breakdown by impact type | No typifiable ransomware cases in the period | No typifiable ransomware cases in the period | N/A |
| Documented fraud or phishing cases | 30 | 2 | +28 |
| Documented regulatory moves | 0 | 0 | No change |
| Critical CVEs mentioned | 83 | 48 | +35 |
| Sectors with at least one documented event | 8 | 5 | +3 |
| Dominant threat of the month | Vulnerabilities (281 of 344 events) | Vulnerabilities (143 of 187 events) | Change in intensity |
| Events with direct source confirmation | 97% | Not reported | N/A |
| Aggregated telemetry figures excluded from volume | 2 (aggregated attempts or blocks, not incidents with confirmed impact) | 0 | +2 |
The base of 344 verified events should not be read as a simple sum of categories, because the editorial attribution axes are exclusive and a single event can affect more than one sector. The time window also matters: 346 events fell within August 2026, 16 corresponded to previous months, and 23 had no confirmed date, so they are not included in the indicators.
Relevant incidents
The month’s most actionable signal was not a single breach, but the convergence of several critical vulnerabilities under active exploitation across products widely used in the region. The most relevant cases are grouped by platform, because that makes the operational risk clearer for Latin American environments exposed to the internet, clusters, gateways, and remote administration services.
CVE-2026-68820 in Windows AFD.sys
Microsoft treated CVE-2026-68820 as a vulnerability exploited in the wild and the only explicitly acknowledged zero-day in its August 2026 Patch Tuesday. The flaw, a use-after-free in the Ancillary Function Driver for WinSock, allows privilege escalation from a limited account to SYSTEM, with CVSS 7.0 and a consistent reading across several technical write-ups and regional advisories.
For Latin America, the issue is not abstract. Windows remains the operating base for many public administrations, universities, service companies, and corporate desktop environments, and this vulnerability acts as an intermediate link in exploitation chains. That makes it especially valuable to attackers who already have an initial foothold through phishing, exposed services, or compromised credentials.
CTIR Gov.br published alert 72/2026 on August 25, describing the flaw and aligning it with international notices about active exploitation. That overlap between a local alert and an international classification reinforced the need to prioritize updates in Brazil. Moncloa.com, citing INCIBE-CERT, also reported that the vulnerability was being exploited in real campaigns, confirming that the exposure was not theoretical.
From an operational standpoint, CVE-2026-68820 fits a classic pattern, initial access through one path and local escalation through another. UpGuard explained that it is used as an intermediate component within compromise chains in desktop and server infrastructure, which means teams need to look not only at the Windows version, but also at privilege hygiene and internal segmentation.
CVE-2026-8037 in Progress LoadMaster
Progress LoadMaster was one of the most sensitive names of the month. CVE-2026-8037, an unauthenticated command injection with CVSS 9.8, was marked as actively exploited in CISA’s KEV catalog and was accompanied by multiple technical analyses that stress the risk when the appliance API is exposed to the internet.
The response window was short. Decryption Digest reported at least 792 attempts from 65 unique IPs before the flaw was added to KEV on August 7, 2026. That figure reflects attempt telemetry, not confirmed impact incidents, but it helps size the pressure before the regulatory alert. It is a useful signal because it shows the attacker was already operating before the defense loop reacted.
The case matters in Latin America because of the presence of load balancers and application delivery appliances in banks, telecoms, universities, and government agencies. The exposure model is dangerous: if the API was left open and the device was not updated with the corrected versions released in June, the risk of remote command execution with root privileges is immediate. The problem is not limited to the version, but also to the appliance’s access design.
DFT Informática and SecurityOnline.info placed the vulnerability in active real-world exploitation, while SecurityArsenal emphasized that the first control is to inventory appliances and restrict external access to the API. That approach matches the type of asset involved. This is not just another server, but a traffic control point that, if it fails, usually compromises several downstream services.
CVE-2026-34486 in Apache Tomcat
Apache Tomcat reappeared as a critical vector in August, this time because of CVE-2026-34486. The flaw affects the EncryptInterceptor component in Tomcat Tribes, with confidentiality impact due to the lack of encryption in the cluster channel. CISA added it to KEV on August 4 and set a remediation deadline of August 7 for US federal agencies.
The relevant regional detail comes from CTIR Gov.br. Alert 67/2026, published on August 5, linked the vulnerability to Tomcat and stressed its criticality for infrastructure used in Brazil. At the same time, Cybersecurity News underscored the urgency of applying Apache mitigations in clusters and environments with Apache Tribes enabled, a very common setup in institutional portals and business applications.
Barr Cyber added an important nuance, KEV appeared four months after corrected versions had already been available in April. That gap between patch release and active exploitation is one of the month’s constants. There was no shortage of technical fixes, only delay in applying them, and attackers took advantage of that delay.
In impact terms, the flaw does not break integrity or availability according to the cited analysis, but it does expose sensitive traffic between cluster nodes. In environments where Tomcat supports authentication flows, portals, or internal backends, reading that traffic in cleartext can open the door to later movement, session theft, or mapping the internal architecture.
CVE-2026-73570 in Zimbra Collaboration Suite
Zimbra was another major focus in August. CVE-2026-73570, an OS command injection classified as high severity by NVD and actively exploited in the wild, affected versions earlier than 10.1.20 when the zimbra-snmp package is installed and SNMP is enabled. The sources agree that there was confirmed exploitation and proof-of-concept testing.
The publication sequence shows growing urgency. CERT Polska confirmed active exploitation, CISA added the flaw to KEV and set a correction deadline, and SecurityWeek reported that actors were targeting Zimbra servers in active campaigns. CERT Santé in France also issued an advisory that precisely defined the vulnerable configurations. The picture is clear: only part of Zimbra deployments were exposed, but that subset was enough to make the vulnerability a priority.
For Latin America, Zimbra remains relevant in email and collaboration across public-sector organizations, universities, and mid-sized businesses. SCWorld attributed campaigns linked to Russian APT groups against targets in Brazil and Argentina, raising the profile of the case beyond a simple technical flaw. The technical pattern described by Dev.to shows that exploitation relies on a manipulated SMTP request that ends up executing commands with the privileges of the zimbra user.
The most delicate operational detail is that the vulnerability does not necessarily require prior credentials. If the optional package is present and SNMP notifications are enabled, the attacker can reach remote code execution through an entry point that appears unrelated to email. That mix of auxiliary surface and main effect is exactly the kind of issue that takes time to detect in production.
CVE-2026-59270 in Spring Security
Spring Security appeared with a critical vulnerability in its embedded UnboundID LDAP server. CVE-2026-59270 has CVSS 9.4, requires only remote access to the exposed LDAP port, and needs neither prior credentials nor user interaction. HeroDevs, HunCERT/NKI, Mallory, and Berigo all agreed on the exposure of the administrative DN and the possibility of authenticating with a known account.
The operational risk is high because the flaw affects CI/CD, testing, and deployment environments where the embedded LDAP is often left accessible by mistake. On August 21 and 22, INCIBE-CERT published its critical advisories, and Moncloa detailed the affected branches along with the patched versions. The response was quick and useful, but it also exposed an uncomfortable reality: a flaw in a widely used security component can spread across multiple applications and pipelines without the owner team noticing right away.
The technical material adds a second layer of interest. The Russian source 1275.ru said the flaw could bypass WebAuthn mechanisms when that embedded LDAP is trusted for authentication. That is not a regional campaign detail, but it is a design warning, if a test server ends up exposed in production, a vulnerability in an internal layer can become a break in strong authentication.
HeroDevs also noted that Spring’s August release batch delivered 91 CVEs in a single day, but CVE-2026-59270 was the only critical one. That helps prioritize, because it keeps the noise from the volume from hiding the flaw that actually demands immediate attention.
CVE-2026-19586 in TP-Link Omada
TP-Link Omada entered the radar through CVE-2026-19586, a pre-auth command injection in gateways configured as an OpenVPN server. Technical material from CTI Pilot and Blogspan describes a scenario in which data sent during connection setup reaches command execution before authentication is completed, affecting 18 models and carrying CVSS 9.3 severity.
The regional relevance is obvious. Remote access gateways are part of hybrid work and distributed administration in Latin America, and many organizations rely on network equipment that can be managed from the internet. When a flaw like this appears in an access device, the impact can be greater than on an application server because the entire perimeter becomes compromised.
CTI Pilot dated the advisory to August 20 and stressed that the vulnerability is truly pre-authentication. That distinction matters because it removes the false sense of security often provided by user or credential controls: the attacker does not need an account to reach the vulnerable point. In an environment with an exposed VPN, the problem shifts to the network edge, exactly where many organizations reduce monitoring.
CVE-2026-16812 in VMware VeloCloud Orchestrator
VMware VeloCloud Orchestrator appeared as another confirmed real-world exploitation case. SecurityOnline.info reported that CVE-2026-16812 affects privileged internal functions and is listed in KEV, with active exploitation. Although the regional material does not break out a specific country for this flaw, its presence helps explain why network infrastructure and virtualization segments remained under pressure throughout August.
The case adds to the July VMware comparison baseline, where the regional ecosystem had already shown sensitivity to flaws in vCenter and other products from the vendor. That continuity confirms a broader reading, administration and orchestration platforms remain preferred targets because they concentrate privileges and because a single breach affects multiple assets.
Active Threats and Campaigns
The month was not dominated by ransomware, but by active exploitation campaigns and by fraud or phishing at a higher volume than the previous month. The most consistent threat signal was the combination of vulnerabilities and initial access, with APTs and opportunistic actors taking advantage of exposed services, collaboration products, and management platforms.
APT and targeted exploitation
The most sensitive campaign from an attribution standpoint was the one tied to CVE-2026-73570. SCWorld said that Russia-linked APT groups were among the actors exploiting the flaw, with campaigns aimed at government agencies, universities, and state institutions in Brazil and Argentina. That detail does not redefine the whole month on its own, but it does establish an intelligence priority: this was not just indiscriminate exploitation.
Targeted exploitation also appeared in the Tomcat and Windows reporting. In Tomcat, regulatory urgency and cluster exposure make it an attractive piece for quiet access to internal traffic. In Windows, the AFD.sys driver serves as a stepping stone for consolidating privileges. In both cases, the technique matches intrusion operations that seek persistence and lateral movement more than immediate noise.
At the same time, reporting on VMware VeloCloud Orchestrator and other management assets suggests that the region's logical perimeter remains highly attractive. When orchestration or remote access platforms fail, attackers do not need to multiply their efforts. They only need one point that opens multiple internal routes.
Fraud and phishing
August recorded 30 documented fraud or phishing cases, far above the 2 seen the previous month. Not all of the material supports attribution to a single campaign, but the increase clearly signals more pressure on users and initial-access chains. The most likely reading is that, alongside CVE exploitation, there were more attempts to harvest credentials and lure victims.
That figure aligns with what the exploited vulnerabilities show. When an adversary is building a full chain, phishing is often the first layer and a critical vulnerability is the second. CVE-2026-68820, for example, is useful for local privilege escalation after initial entry. CVE-2026-59270 and CVE-2026-19586, by contrast, reduce the need for credentials. The combination of both paths keeps fraud relevant even if it is not the month's main focus.
Ransomware and extortion
There were no ransomware or extortion cases classified as the primary focus in August. That does not mean there was no pressure, only that the material analyzed did not record incidents of that type under the required taxonomy. The absence of this axis gave more room to examine vulnerability exploitation and initial-access campaigns more closely.
Critical Vulnerabilities
August saw a dense run of critical CVEs, spanning Windows, Tomcat, Zimbra, Spring Security, LoadMaster, TP-Link Omada, and VMware. The table below summarizes the most relevant cases for Latin America and their exploitation status, based on the material reviewed.
| CVE | Software | Exploitation | Source |
|---|---|---|---|
| CVE-2026-68820 | Windows Ancillary Function Driver for WinSock, afd.sys | Actively exploited, zero-day acknowledged by Microsoft | CTIR Gov.br, SecurityWeek, Tenable, Moncloa.com |
| CVE-2026-8037 | Progress LoadMaster | Actively exploited, included in CISA KEV | DFT INFORMATICA, Decryption Digest, SecurityOnline.info, SecurityArsenal, WindowsForum |
| CVE-2026-34486 | Apache Tomcat | Actively exploited, included in CISA KEV | CTIR Gov.br, Barr Cyber, f4n6, Cybersecurity News |
| CVE-2026-73570 | Zimbra Collaboration Suite | Real-world exploitation confirmed, included in CISA KEV | NVD, SecurityWeek, f4n6, CERT Santé, Redlegg Security, AhnLab ASEC, SCWorld |
| CVE-2026-59270 | Spring Security embedded LDAP server | Active exploitation, disclosed as critical with CVSS 9.4 | HeroDevs, HunCERT/NKI, Mallory, Berigo, INCIBE-CERT |
| CVE-2026-19586 | TP-Link Omada gateways with OpenVPN | Pre-auth, exploitation possible and treated as critical by technical sources | CTI Pilot, Blogspan |
| CVE-2026-16812 | VMware VeloCloud Orchestrator | Actively exploited, included in KEV | SecurityOnline.info |
| CVE-2026-60004 | Gitea | Added to KEV, material available with active exploitation mentioned | Canadian Centre for Cyber Security |
The concentration in collaboration, remote access, and load balancing products points to a clear preference for systems that function as control nodes. These flaws do not just expose data, they can also open access to entire networks. In a regional environment with heavy reliance on shared infrastructure, that helps explain why patch management became the month’s focal point.
Regulation and compliance
No regulatory moves were documented as events during August. That absence did not lessen the severity of the month, because regulatory pressure showed up in another form, through KEV, official alerts, and remediation deadlines driven by CISA and mirrored by agencies such as CTIR Gov.br and INCIBE-CERT.
The most visible case was CISA’s handling of CVE-2026-8037, CVE-2026-34486 and CVE-2026-73570, where KEV inclusion came with short correction deadlines. In Brazil, CTIR Gov.br issued alerts 67/2026, 68/2026, 71/2026 and 72/2026, showing a highly granular monitoring posture for the global catalog of exploited vulnerabilities.
INCIBE-CERT, for its part, was the main responder in the August 20 to 25 window, with advisories on Spring Security, Citrix NetScaler, Frauscher FDS102, TAO 2.0, TP-Link Omada, Zimbra, HP Easy Start, MagicAI for WordPress and other products. The regulatory value of these advisories does not lie in imposing sanctions, but in turning active exploitation into an immediate operational signal for defense teams.
Latin America’s most affected countries
Country-level reading shows uneven concentration. Brazil had the highest density of official alerts and direct links to exploited vulnerabilities. Argentina appeared in the attribution of campaigns against state institutions and universities. Chile stood out for the preventive side of the AI supply chain. Paraguay and Colombia appear more faintly in the material, with less temporal support or no dated facts from the period.
Brazil
Brazil was the most affected country in terms of verifiable material and official response. CTIR Gov.br issued alerts 67/2026, 68/2026, 71/2026 and 72/2026 on Apache Tomcat, a KEV vulnerability with elevated EPSS, FortiOS and Windows AFD.sys. The pattern is no accident, these are components that often support critical digital infrastructure in the public and private sectors.
Brazil’s presence is also significant because of the attribution of APT campaigns against government agencies, universities and state institutions. Although SCWorld also mentioned targets in Europe, Brazil’s inclusion in the campaign places the country among the short list of top regional targets. Operationally, that requires monitoring email, authentication, Tomcat clusters and network edges at the same time.
Argentina
Argentina appeared in coverage of CVE-2026-73570 as one of the countries targeted by campaigns linked to Russian APT groups. The detail matters because the material does not frame it as an isolated exposure, but as part of a campaign aimed at state institutions and universities. That points to priority targeting of high-value organizations and environments with public visibility.
The Argentine signal does not include a local notice equivalent to Brazil’s, but it does include an attribution that calls for closer scrutiny of collaborative email, Zimbra servers and authentication services in academic and government environments. In those segments, a mail server vulnerability can quickly become a credentials, persistence and exfiltration issue.
Chile
Chile was tied mainly to the AI supply chain and to preventive steps related to LiteLLM. The available material refers to a preventive alert at Chilean institutions after the LiteLLM hack and to a scenario with thousands of potentially exposed CI/CD pipelines. Although that case is not part of the critical CVE track, it does broaden the country’s attack surface.
For Chilean teams, the lesson is twofold. First, exploitation is no longer limited to traditional servers. Second, exposure in development or integration tools can have a regional blast radius, especially when a supply chain compromise affects keys, secrets and pipelines. Defense has to treat infrastructure and development as one surface.
Paraguay
Paraguay appears with useful material but without a confirmed date in several CERT-PY notices on Ubiquiti, Samba and Joomla. By editorial rule, those facts do not count toward the period indicators, but they do show sustained interest by Paraguay’s CERT in widely used critical vulnerabilities. In the dated August material, the country appears more as a recipient of alerts than as the focus of a specific campaign.
Colombia
Colombia is mentioned secondarily in undated material and in a COLCERT context note on Windows privileges, but there is not enough basis to count August as a month with relevant dated facts in this vertical. That does not mean no risk, only a lack of dateable material in the provided archive.
Mexico, Peru, Bolivia and the USA
There were not enough dated facts in the period material to develop a specific August section on Mexico, Peru or Bolivia. The United States appears as a regulatory and technical reference, mainly through CISA, Microsoft and remediation deadlines, but not as a direct Latin American focal point in the month’s facts.
Trends and signals to watch
The comparison with July shows a sharp shift in volume and mix. Verified incidents rose from 187 to 344, critical CVEs from 48 to 83, and fraud or phishing cases from 2 to 30. The dominant trend is not linear, but one of intensification, more alerts, more surface area, and more pressure on early remediation.
The most striking figure is that ransomware fell from 4 primary cases in July to 0 in August, while vulnerabilities rose from 143 of 187 incidents to 281 of 344. That points to a month less focused on extortion and more on technical intrusion. For defense teams, the signal is clear, time shifted to patching, segmentation, exposure reduction, and privilege control.
The risk profile also changed. In July, the region had already seen critical vulnerabilities in VMware and other platforms; in August, that pressure shifted to Windows AFD.sys, Tomcat, Zimbra, Spring Security, LoadMaster, and TP-Link Omada. These are different products, but they share one trait, they sit on the path of administration, collaboration, or remote access. If one is compromised, it can enable lateral movement or access consolidation.
Regional CERTs responded quickly, especially CTIR Gov.br and INCIBE-CERT. That speed is a positive sign, but also a reminder that the threat had already reached active exploitation. By the time an official advisory appears, the attacker usually has a time advantage. The difference comes down to inventory discipline and the ability to apply patches or mitigations without waiting for ideal windows.
Security team recommendations
This month’s operational priority is to reduce external exposure and close escalation paths that have already shown active exploitation. Latin American teams should start with the most Internet-exposed assets, remote access gateways, load balancer appliances, and collaboration servers. That is where the period’s most dangerous cases are concentrated.
First, Windows AFD.sys and the rest of the Windows platform need to be reviewed through a local privilege escalation lens. CVE-2026-68820 is not fixed by a standalone patch if excessive privileges remain in place, lateral movement is broad, or endpoints are not segmented. It is also worth prioritizing a secure minimum build, exploitation telemetry, and detection of chains where initial access ends in SYSTEM.
Second, network and load balancer appliances require strict inventory control. In LoadMaster and TP-Link Omada, the problem gets worse when the API or the OpenVPN service is left exposed. The concrete step is to verify external exposure, restrict administrative access, isolate management interfaces, and apply the corrected versions immediately. If the appliance cannot be patched in time, it must be removed from the public perimeter.
Third, Zimbra and Spring Security warrant emergency handling in organizations that rely on email, embedded LDAP, or development environments. In Zimbra, the presence of zimbra-snmp and enabled SNMP notifications changes the risk profile. In Spring Security, the simple fact that the LDAP port is accessible is enough to turn a test environment into a serious production problem.
Fourth, Tomcat and Apache Tribes clusters should be audited for traffic confidentiality, not just availability. The risk here is not necessarily visible outages, but internal data being read in transit. That requires reviewing configuration, encryption, cluster topology, and patch dates, especially in institutional portals and business applications deployed in Brazil and other countries in the region.
Fifth, the documented rise in phishing calls for stronger authentication, MFA, and email hardening. If the first point of entry is still a stolen user account, the critical vulnerabilities exploited afterward become much more dangerous. Phishing plus a local vulnerability was one of the month’s implicit attack paths.
Frequently Asked Questions
What was the key finding for Latin America in August?
August closed with a clear dominance of the vulnerability track, with 344 verified incidents, 83 critical CVEs, and 281 events of that type. The strongest signal was the active exploitation of flaws in Windows, Tomcat, Zimbra, Spring Security, and network appliances, with Brazil standing out as the most exposed country in official advisories.
Which CVEs should regional teams prioritize first?
The most urgent cases are CVE-2026-68820 in Windows AFD.sys, CVE-2026-8037 in Progress LoadMaster, CVE-2026-34486 in Apache Tomcat, CVE-2026-73570 in Zimbra, and CVE-2026-59270 in Spring Security. The material describes all of these flaws as actively exploited or treated as critical by CERTs and vendors.
Why does Brazil appear so often in the report?
Because CTIR Gov.br published several advisories on flaws affecting infrastructure used in Brazil, including Apache Tomcat, FortiOS, and Windows AFD.sys. The material also attributes direct targeting of Brazil to an APT campaign against state institutions, universities, and government agencies.
Was phishing on the rise, or just secondary noise?
It did rise in the material analyzed, with 30 documented cases compared with 2 in July. It did not displace the vulnerability track, but it does point to more pressure on the initial access layer. That combination with active exploitation increases the urgency of MFA, training, and email controls.
Does the absence of ransomware mean there were no serious incidents?
No. It means the August material did not record ransomware or extortion cases as the primary focus. The month’s severity was elsewhere, especially in active CVE exploitation and campaigns aimed at high-value assets. The absence of that category does not reduce regional risk.
Material limitations
This report was built exclusively from the facts provided for August 2026 and from the comparative framework for prior months included in the file itself. No internet access or sources outside the authorized list were used. Facts without a confirmed date were left out of the indicators, although some were used as qualitative context without being counted.
A zero value in an indicator, especially ransomware or regulatory activity, means it did not appear in the analyzed material for the period, not that it did not exist in the region. The same applies to any thematic absence: the report reflects the available documentary snapshot, not the full Latin American ecosystem.
The declared time window included 346 dated facts in August 2026, 16 from prior months used only as comparative context, and 23 without a confirmed date excluded from the indicators. Aggregated telemetry data, such as attempts or blocks, were not added to incidents and were mentioned only when the material made it explicit that they were not confirmed intrusions.
Sponsored content, consumer social media, and sources not explicitly listed in the block of available sources to cite were also excluded as evidence. When the material offered commercial or third-party claims without sufficient technical confirmation, they were treated as source attributions and not as established trends.
Sources
- CISA adds Zimbra Collaboration Suite bug to exploited vulnerabilities listSCWorld
- ALERTA 71/2026Gabinete de Segurança Institucional da Presidência da República (CTIR Gov.br)
- ALERTA 72/2026Gabinete de Segurança Institucional da Presidência da República (CTIR Gov.br)
- Weekly Threat Intelligence Report: Late August 2026SecurityOnline.info
- ALERTA 68/2026Gabinete de Segurança Institucional da Presidência da República (CTIR Gov.br)
- BCY-ADV-2026-021 — Apache Tomcat CVE-2026-34486Barr Cyber
- El INCIBE-CERT alerta de 421 vulnerabilidades Microsoft; una ya está siendo explotada de forma activaMoncloa.com / INCIBE-CERT
- August 2026 Patch Tuesday: Microsoft Fixes 421 CVEs, One Exploited Zero-DaySecurityWeek
- August 2026 Microsoft Patch TuesdayTenable
- Expert CVE Analysis: Patch Tuesday August 2026Automox
- CVE-2026-8037: Injeção Crítica no LoadMaster — Exploração AtivaDFT INFORMATICA
- CVE-2026-8037 LoadMaster: CISA KEV Root RCE, Patch ...Decryption Digest
- Weekly CISA KEV Updates: 10 August 2026HackerStorm
- Weekly CVE Report: 6 Actively Exploited Flaws and 1877 New CVEsSecurityOnline.info
- CVE-2026-68820 — CVSS 7.0, HIGHCVE Security
- CVE-2026-8037 Progress LoadMaster Command Injection Under Active ExploitationSecurityArsenal
- CVE-2026-68820 | Microsoft Windows AFD.sys VulnerabilityUpGuard
- Apache Tomcat Encryption Vulnerability Actively ExploitedCybersecurity News
- CVE-2026-8037: Patch Progress LoadMaster After CISA KEVWindowsForum
- ALERTA 67/2026Gabinete de Segurança Institucional da Presidência da República (CTIR Gov.br)
- CVE-2026-34486 Apache Tomcatf4n6
- CVE Weekly Roundup: July 27 – August 2, 2026SecurityOnline.info
- CVE-2026-59270 - Exploits & SeverityFeedly
- Gitea security advisory (AV26-845)Canadian Centre for Cyber Security
- CVE-2026-59270HunCERT / NKI
- Administrative Access Exposure in Spring Security Embedded LDAP Server (CVE-2026-59270)Mallory
- TP-Link Omada: Kritische VPN-Lücke betrifft 18 Gateway-ModelleBlogspan
- Security Bulletin: OS Command Injection in Zimbra Collaboration Suite SNMP Notification ProcessingRedlegg Security
- Spring: 91 vulnerabilities patched, one criticalBerigo
- CVE-2026-12556 | INCIBE-CERTINCIBE-CERT
- CVE-2026-73570 — Synacor Zimbra Collaboration Suite (ZCS) OS Command Injection Vulnerabilityf4n6 security feed
- CVE-2026-73570 DetailNVD (NIST)
- Обход WebAuthn в Spring Security и выполнение кода в Spring Integration1275.ru
- CVE-2026-32560 | INCIBE-CERTINCIBE-CERT
- Zimbra Product Security Update Advisory (CVE-2026-73570)AhnLab ASEC
- Hackers Target Zimbra Servers in Active Exploitation CampaignSecurityWeek
- 91 Spring CVEs in a Single Day: Inside the August 2026 BatchHeroDevs
- El INCIBE-CERT alerta de una vulnerabilidad Spring Security ...Moncloa
- CTI Daily Brief · 2026-08-22CTI Pilot
- El INCIBE-CERT alerta de múltiples vulnerabilidades en productos Cisco como Crosswork Data Gateway y Secure WorkloadMoncloa.com
- Zimbra CVE-2026-73570: Unauthenticated Command Injection via SMTPDev.to
- CISA Warns of Zimbra OS Command Injection Vulnerability Active Exploitation (CVE-2026-73570)Qualys ThreatProtect
- CVE-2026-9244 | INCIBE-CERTINCIBE-CERT
- El INCIBE-CERT alerta de ocho vulnerabilidades en el sensor ferroviario Frauscher FDS102, una crítica y cinco altasMoncloa.com
- El INCIBE-CERT alerta de una vulnerabilidad Citrix NetScaler crítica y otra altaMoncloa.com
- CVE-2026-59270: Spring Security Embedded LDAP Admin DN ExposureHeroDevs
- CVE-2026-19586 — TP-Link Omada gateways: attacker-supplied data during OpenVPN connection establishment reaches command execution before authentication completes (CVSS 4.0 9.3)CTI Pilot
- El INCIBE coordina la publicación de cuatro vulnerabilidades de T-Systems TAO 2.0, dos de ellas de severidad altaMoncloa.com
- Zimbra - CVE-2026-73570CERT Santé (Francia)
- CVE-2026-62289 | INCIBE-CERTINCIBE-CERT
- CVE-2026-73570: Zimbra Collaboration Suite (ZCS) ...Makriva
- FBI FLASH-20260702-01 Explained: The AI Supply Chain ...CloudSEK
- CVE-2026-55674INCIBE-CERT
- Cyber Security Week in Review: August 21, 2026Cyber Security Help
- Hackers Target Zimbra Servers in Active Exploitation Campaign via CVE-2026-73570 SNMP Command Injection — Threadlinqs IntelligenceThreadlinqs Intelligence
- CVE-2026-55674 - Vulnerability DetailsOpenCVE
- CVE-2025-41770: Allocation of Resources Without Limits or Throttling in Phoenix Contact AXC F 1152OffSeq Threat Radar
- ANCI activa alerta preventiva en Chile tras el mayor hackeo a la cadena de suministro de IA del añoRadio Siglo 25
- ANCI activa protocolo preventivo y notifica a veintena de instituciones chilenas por hackeo a LiteLLMBioBioChile
- CVE-2026-19188 - Vulnerability DetailsOpenCVE
- El INCIBE-CERT alerta de una vulnerabilidad crítica en ...Moncloa
- Palo Alto Networks PAN-OS 10.2.x < 10.2.8 / 11.1.x < 11.1.16-h1 vulnerability pluginTenable
- An information disclosure vulnerability in the URL Filtering feature of Palo Alto Networks PAN-OS software enables an unauthenticated user with network access to obtain sensitive information (CVE-2026-0301)OffSeq
- CVE-2026-0301: CWE-908 Use of Uninitialized Resource in Palo Alto Networks Cloud NGFWOffSeq
- CVE-2026-19188: Haiwell IoT Cloud HMI Gateway OS Command Injectionexploit.cc
- CISA Flags Maximum-Severity Command Injection Flaw in Haiwell IoT Gateway Deployed Across Energy, Water SectorsCVETodo
- Johnson Controls C·CURE 9000 RCE Vulnerability: ICSA-26-204-01 Advisory and MitigationOT/ICS Monitor
- El INCIBE-CERT alerta de tres vulnerabilidades en ... - MoncloaMoncloa
- Filtración LiteLLM credenciales: un ataque a la cadena de suministro de IA expone credenciales de grandes empresasMoncloa.com
- CVE-2026-0301 | Information Disclosure in Palo Alto PAN-OS URL FilteringBaseFortify
- CVE-2026-0301 | TenableTenable
- CVE-2026-0301: Palo Alto Networks: An information disclosure vulnerability in URL FilteringRapid7
- CSIRT Panamá Aviso 2026-ago-13: PAN-OS ...CSIRT Panamá
- Alerta de seguridad: Supply chain attack compromete LiteLLM y expone potencialmente 434.000 pipelines CI/CDCronUp Ciberseguridad
- Palo Alto Networks corrige 11 vulnerabilidades en PAN-OS, GlobalProtect y PrismaDevel Group
- El INCIBE-CERT alerta de tres vulnerabilidades Johnson ...Moncloa
- CVE-2026-0301 PAN-OS: Information Disclosure Vulnerability in URL FilteringPalo Alto Networks
- INCIBE-CERT alerta de vulnerabilidades en CPDLC que ...Moncloa
- Vulnerabilidad Crítica en Check Point – CVE-2026-18574CSIRT Panamá
- sk185222 - CVE-2026-18574Check Point
- Check Point Security Management Server vulnerability flagged by CERT-In: What users need to knowMoneycontrol
- CVE-2026-18574 | INCIBE-CERTINCIBE-CERT
- INCIBE-CERT alerta de tres vulnerabilidades críticas VMwareMoncloa.com
- Avisos | INCIBE-CERTINCIBE-CERT
- CERT-PY – CERT-PYCERT-PY
- Known Exploited Vulnerabilities (KEV) CatalogCISA
- COLCERT AL – 20260820 - 114 Alerta: Operation Dream Job utilizada para escalar privilegios en WindowsCOLCERT
- Microsoft Patches Nearly 400 Flaws, Including Exploited afd.sys ...Mallory.ai
- CISO Application Risk Intel Briefing for Week of August 19Veracode
- Weekly Recap: VMware Exploits, Windows 0-Day, MCP ...The Hacker News
- DPRK's Lazarus Group exploits Windows zero-day in ...SC World
- Lazarus Kernel Zero-Day Hits Defense ContractorsCloud Security Alliance
- Lazarus Windows Exploit Fuels New Espionage CampaignGreenbone
- Microsoft Patches 398 Flaws Including a Windows Driver Zero ...Zerodayroom
- CVE-2025-62593 and the CISA KEV listing: what Ray users need to knowAnyscale
- CVE-2025-62593 Detail - NVD - NISTNVD / NIST
- Ray Framework RCE Under Active Exploitation Joins CISA KEVCloud Security Alliance
- CVE-2025-62593: Ray let Firefox and Safari drive dashboard job RCECorgea
- CVE-2025-62593: Vulnerabilidad de Inyección de Código en Ray-Project Ray con Explotación ActivaCiberPlaneta
- CISA Flags Actively Exploited Ray Flaw That Can Trigger Browser RCEThe Hacker News
- Brīdinājums Ubiquiti iekārtu lietotājiemCERT.LV
- Samba Security AdvisoriesSamba Project
- Ubiquiti Patches Three Simultaneous Maximum-Severity UniFi Flaws in Cameras, OS, and VoIPTechTimes
- Ubiquiti Patches Three Critical Remote Flaws in UniFi ProductsMallory.ai
- UniFi OS CRLF Injection Authentication Bypass (CVE-2026-77550)Mallory.ai
- Ubiquiti security advisory (AV26-850)Canadian Centre for Cyber Security
- Bulletin de sécurité Ubiquiti (AV26-850)Canadian Centre for Cyber Security
- CVE-2026-77554 - Vulnerability DetailsOpenCVE
- CVE-2026-77532 - Ubiquiti EdgeMAX EdgeSwitch Buffer OverflowCVEfeed.io
- Popping Root on UniFi OS Server: Unauthenticated RCEBishop Fox (via Daily.dev)
- Ubiquiti patches 3 critical remote code execution vulnerabilitiesSCWorld
- CVE-2026-74803 - Zoo extension for Joomla Unauthenticated arbitrary file upload (CVSS 10)Strix
- CVE-2026-73337 - Joomla! CMS Authentication Bypass (details and affected versions)Strix
- CVE-2026-71574 - Inconsistent ACL checks for mutating webservice endpoints in Joomla! 4.x/6.xRapid7
- UniFi OS -- Unauthenticated Command Injection RCE (CVE-2026-34910) · PoC ArchivePoC Archive / IntelSecLab
- CVE-2026-73327 - Path Traversal in Joomla! extract.php enabling persistent RCEOffSeq Threat Radar
- CVE-2026-72382 - ksmbd integer underflow in parse_dacl (critical, remote)Feedly (agregador CVE)
- CVE-2023-2377 - CVE Details, Severity, and AnalysisStrobes Security
- CVE-2026-0301 - Vulnerability DetailsOpenCVE
- Palo Alto Networks Discloses 11 Vulnerabilities Across PAN-OS, GlobalProtect and Prisma AccessEsentry
- Ubiquiti UniFi OS: Critical Security Flaws PatchedDiaDorn
- CISA KEV August 2026: 9 New Exploited CVEs to Patch NowSME Node Academy
- Security Incident Affecting JetBrains CadenceJetBrains
- Attackers Exploit MCP RCE, Blind Prompt Injection and ...GBHackers on Security
- Hackers Exploit AI Infrastructure to Steal API Keys, Gain Persistence and Mine CryptocurrencyCybersecurityNews
- AI Honeypot: Real Attacks on LiteLLM and MCP Servers Reveal Three PatternsDeafNews
- LiteLLM Jumps the Queue After MicrosoftCyber Roundtable
- Weekly CISA KEV Updates: 31 August 2026HackerStorm
- CVE-2023-49105 exploited: patch ownCloud nowSenserva
- When AI infrastructure becomes the target: Securing gateways and control pointsMicrosoft Security Blog
- Weekly CVE: 9 CISA KEV Additions: vCenter, Zimbra, ...FireCompass
- BadHost: Exposed AI agent endpoints – a security checklist forGonkarouter
- CISA KEV August 2026: four exploited flaws, one weekendSecure in Seconds
- Weekly CISA KEV Updates: 24 August 2026HackerStorm
- CVE-2026-59085: SSRF vulnerability in Apache CloudStack webhook moduleRapid7
- Security Fixes in Apache CloudStack 4.20.3.1 and 4.22.1.1Shapeblue
- CVE-2026-61422 – Authenticated pre-validation SSRF in Apache CloudStack template/ISO registrationTenable
- Phishing de vinculación de WhatsApp: el QR real es la ...TuCodigoDigital (citando GTIG)
- Container security and cloud identity: where the governance gap isNHIMG.org
- Intruder 2026 Cloud Security Index finds each major cloud provider carries distinct security risksGround News
- CISA KEV Adds 4 Critical CVEs, 3 Rated CVSS 9.8 [2026]Tech Insider
- Cyber Risk Brief: 10 - 16 August 2026Sovereign GRC
- Critical SQL Injection in Metabase via Password Reset: CVE-2026-72898Bishop Fox
- Weak IAM affects up to 98% of cloud environments - Help Net SecurityHelp Net Security
- CPAI-2026-10100Check Point
- Massive Supply Chain Attack Exposes Terabytes of CredentialsHitechub
- 40 Minute LiteLLM Hack Exposes Cloud Keys and CI/CD Secrets From 2,488 CompaniesCybersecuritynews
- CVE-2026-72898 Metabase SQL Injection Under Active ExploitationTerra Security
- CVE-2026-72898: Metabase's Password-Reset Endpoint Lets Anyone Become AdminCodercops
- 2,500+ Companies and 434,000 CI/CD Pipelines Exposed in the ...CloudSEK
- LiteLLM Breach Exposed 434,000 CI/CD Pipelines, 2,500 FirmsCyberKendra
- TeamPCP’s LiteLLM Backdoor: New Data Shows 2,100+ Orgs ExposedCloud Security Alliance Labs
- Metabase Instances Actively Exploited: Unauthenticated Admin Takeover via BI Layer Reset Password SQL Injection (CVE-2026-72898)Upwind
- CVE-2026-72898: Metabase SQL Injection and KEV Risk - Penligent (ES)Penligent
- Over 2,500 Organizations Impacted by LiteLLM Supply Chain AttackSecurityWeek
- CloudSEK vincula la filtración de marzo de LiteLLM a más de 2.500 organizacionesUnite.AI
- Metabase CVE-2026-72898: SQLi CVSS 10 sin auth ya explotadaDonweb Cloud
- CVE-2026-72898 – Unauthenticated SQL Injection / Admin ...Ionix
- CoreBreak: i Tool degli Agent AI Partono Senza il ModelloPasquale Pillitteri
- Customer Security Newsletter - August 2026MEDITECH
- Cyber Threat Intelligence Report | 8/10/2026PacketWatch
- CVE-2026-63077 Detail - NVD - NISTNVD (NIST)
- Rapid7 Analysis of CVE-2026-63077, an unauthenticated ...Rapid7
- CoreBreak: las herramientas de los agentes IA se ejecutan sin el modeloPasquale Pillitteri
- TeamCity CVE-2026-63077: Actively Exploited RCE, CISA Patch Deadline Aug 8ShieldGaps
- CVE-2026-63077: Additional Guidance Following Reports ...JetBrains
- Claves de Anthropic, OpenAI y Gemini se filtraron sin que nadie lo notara; hackers acceden a la infraestructura de IA de las empresasSecurityLab Latam
- Cloud IAM Misconfiguration Hits 98% of Accounts [2026]Shattered
- Google y Microsoft no pagaron por estas fallas de nubenext+
- agosto 2026CSIRT Telconet
- Vulnerabilidad de ejecución remota de código en Zimbra con explotación activaCentro Nacional de Respuesta a Incidentes de Seguridad Informática (Uruguay)
- Zimbra SNMP Flaw Under Active Exploitation (CVE-2026-73570)Cloud Security Alliance
- Resumen de Amenazas — Agosto 2026: 10 vulnerabilidades críticas | Boletín de Seguridad CiberPlanetaCiberPlaneta
- Zimbra vulnerability CVE-2026-73570: find impacted assetsrunZero
- NVD-CVE-2026-73570 - NISTNIST NVD
- Attackers Exploit Zimbra SNMP Flaw for Unauthenticated ...The Hacker News
- Zimbra security advisory (AV26-816) – Update 1Canadian Centre for Cyber Security
- Weekly Threat Intelligence Report – August 2026SecurityOnline.info
- CISA Flags Six Actively Exploited NetScaler, SQL Server, Linux, and Ajax.NET FlawsMallory.ai
- Citrix NetScaler: CISA warnt vor kritischer RCE-LückeBoerse Express
- Microsoft says AI gateways should be treated as Tier-0 assetsCisoVoice
- CISA Adds Six Exploited Flaws to KEV, Including NetScaler, Linux ...The Hacker News
- CISA orders feds to patch Citrix NetScaler RCE flaw by August 29, 2026BleepingComputer
- Memory Overflow Vulnerability in Citrix NetScaler ADC and NetScaler Gateway (CVE-2026-8452)RedLegg
- CVE-2026-8452 — Citrix NetScaler ADC and NetScaler Gateway Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability (known exploited)netVigilance
- CISA Flags Six Exploited Vulnerabilities in KEV CatalogSecurity Online
- CVE-2026-8452: Citrix NetScaler Exploited (KEV)OpenVPN Blog
- CISA KEV Adds 4 Critical CVEs, 3 Rated CVSS 9.8 [2026]Tech-Insider
- CISA додає чотири критичні вразливості до KEVCyberSecureFox
- CVE-2026-59780 - Apache CloudStack LDAPNVD (NIST)
- VMware vCenter Zero-Day: CVE-2026-59310 Hits 47 NationsTech-Insider
- CaptiveCrunch: malware en Wi-Fi público para viajerosMicrosoft News Source LATAM
- MLflow SSRF Under Active Attack: A Platform Breach VectorCloud Security Alliance
- CISO Daily Briefing – August 23, 2026Cloud Security Alliance
- Cybersecurity Weekly News: 15–21 August 2026Boston Institute of Analytics
- Threats Tagged 'cve-2026-12710'Threat Radar
- CVE-2026-12710 - Missing Authorization in Application Integration QueryEngineTaskKENET-CERT
- Missing Authorization in Google Cloud Application Integration QueryEngineTask (CVE-2026-12710)Mallory Security Labs
- CVE-2026-12710 Detail - Google Cloud Application IntegrationNVD (NIST)
- CVE-2026-59085: Server-Side Request Forgery (SSRF) in Apache CloudStackOffSeq Threat Radar
- CVE-2026-59780: Apache CloudStack LDAP provider configuration disclosurecvefeed.io
- CVE-2026-71494 - Infracost: Terraform Cloud and registry token exposure via untrusted hostnamecvefeed.io
- [ADVISORY] Apache CloudStack LTS Security Releases 4.20.3.1 and 4.22.1.1Apache CloudStack Project
- CVE-2026-59780 — Apache CloudStack LDAP 提供商配置泄露漏洞cve.imfht.com
- CISA Known Exploited Vulnerabilities Alert – August 2026Xhack.io
- CVE-2026-49431INCIBE-CERT
- The Package Registry Layer: How Supply-Chain Attacks ...Yahoo News
- CISA Adds Four Critical Vulnerabilities to KEV CatalogCyberSecureFox
- The LiteLLM Breach: 153 GB of AI and Cloud Credentials ...CybelAngel
- IoT News Digest 2633IoT News Digest (Substack)
- CVE-2026-71567 DetailNVD (NIST)
- CVE-2026-71567INCIBE-CERT
- CVE-2026-71567 - Exploits & SeverityFeedly CVE / EUVD aggregator
- Added to CISA KEV (CVE-2026-42208)CERT Uganda
- Falla crítica en MLflow bajo explotación activa — CISA ...Ciberseguridad LATAM
- CVE-2025-62593: Fallo Crítico En Ray Explotado ActivamenteCyberSecureFox
- Suspected China-Nexus Actor Exploits VMware vCenter FlawThe Hacker News
- A 153GB Leak From the LiteLLM Breach Shows Supply-Chain Defense Still Runs on Voluntary Disclosure, Not LawPeople of Internet
- Weekly Cyber Threats & Breaches Report: 10-16 Aug 2026FireCompass
- Cyber Roundup — Week of August 10thCybelAngel
- CVE-2026-73047INCIBE-CERT
- Five months later, the LiteLLM supply chain attack hit 2,500 organizationsInfosec.ge
- Forty Minutes Was EnoughMedium
- The LiteLLM supply chain attack yields a 153GB dump: 433,909 files, 2,488 corporate domains, keys still live five months laterMindPattern.ai
- LiteLLM Supply Chain Hack Hit 2488 FirmsTechTimes
- CVE-2026-74243INCIBE-CERT
- CVE-2026-74244 - Vulnerability DetailsOpenCVE
- CVE-2026-74241 - Vulnerability DetailsOpenCVE
- CVE-2025-41770: PLCnext Engineer DoS VulnerabilitySentinelOne
- LiteLLM Supply Chain Breach Spreads Credential Stealer Across Thousands of Enterprise CI/CD EnvironmentsCyberpress
- LiteLLM's March PyPI compromise maps to 434,000 CI/CD pipelines | CorgeaCorgea
- LiteLLM Supply Chain Attack Exposes 153GB of Corporate CredentialsTech-Quire
- Microsoft Patch Tuesday for August 2026 Fixed a Zero-Day and Wormable RCESecurity Affairs
- CSIRT Panamá Aviso 2026-ago-12: Vulnerabilidad de Denegación de Servicio en Cisco Secure Firewall ASA y FTDCSIRT Panamá
- Attackers Exploit VMware vCenter Vulnerability to Gain Persistent AccessThe Hacker News
- CVE-2026-68820: Windows AFD.sys Use-After-Free Actively ExploitedSecurity Arsenal
- Cyber Intel Brief: CVE-2026-72898 in MetabaseDataminr
- CVE-2026-72898 entry in Vulnerability-LookupCIRCL
- TeamPCP Campaign Timeline: From the Trivy ...CloudSEK
- LiteLLM Supply-Chain Attack - Technology, Banking and ...Security Affairs
- CVE-2026-20349: Cisco ASA și FTD, exploatate activ | Awarely MonitorAwarely Monitor
- CVE-2026-20349 · Cisco · CVSS 9.5 · CISA KEV · CVE BriefCVE Brief
- CVE-2026-20349 Detail - NVDNVD
- CVE-2026-20349 — Cisco ASA and FTD VPN Heap Inspection Denial-of-Service Flaw0dayNews
- Heap Inspection in Cisco Firewall Threat Defense (FTD) ...Cybersecurity-help.cz
- Cisco ASA and FTD Flaw Exploited in the Wild Can Trigger ...The Hacker News
- CVE-2026-20349: Cisco ASA and FTD VPN DoS FlawSocPrime
- Metabase CVE-2026-72898 CISA KEV Patch GuideFixitPhill
- CVE-2026-72898 · Metabase · CVSS 10.0 · CISA KEVCVE Brief
- CVE-2026-72898 exploited: patch Metabase nowSenserva
- Metabase CVE-2026-72898 vulnerability listingUpGuard
- CVE-2026-72898 — CVSS 10.0, CRITICALCVE Security
- NVD entry for CVE-2026-72898NVD (NIST)
- Detectan intentos de explotación de una vulnerabilidad crítica en Progress Kemp LoadMasterAltonaSpain
- Known Exploited Vulnerabilities CatalogCVE Circl
- Progress security advisory (AV26-552) – Update 2CSIRTS.com
- Adobe Uses AI Agents to Virtual-Patch CVEs in Minutes (section on Metabase CVE-2026-72898)Cloud Security Newsletter
- CISA Añade Tres Vulnerabilidades Activamente ExplotadasCybersecurefox
- CISA KEV Catalog — Known Exploited Vulnerabilities TrackerCVETodo
- CVE Brief - July 30, 2026CVE Brief
- Boletín Semanal de Ciberseguridad, 25-31 de julioTelefónica Tech
- INCIBE alerta de una inyección SQL en ERPNext que permite ejecutar consultas arbitrariasMoncloa.com / INCIBE-CERT
- Alerta sobre nueva campaña de ciberataques que afecta a organizaciones de América LatinaEstamos en Línea
- A exploração de vulnerabilidades virou o vetor de acesso nº1: por que mais patches é apenas parte da respostaGetup Cloud
- CVE Tools — The CVE database that answers backCVE Tools
- CISA Alerta sobre Explotación Activa en Fortinet FortiOS (CVE-2025-68686) para PersistenciaDevel Group
- Vulnpedia — Vulnerability Reference, Triage & PoC FinderVulnpedia
- CVE-2026-71494INCIBE-CERT
