Security Operations Blog
Technical articles on vulnerability management, threat detection, compliance automation, and building a security program that works.
CVE-2026-76460 (CVSS 10.0) is an unauthenticated privileged API bypass in Cisco ISE's ise-kong gateway, the Kong based reverse proxy that fronts the ISE management surface. One route was left unbound to the auth plugin, so a crafted request on TCP 443 reaches management code as a trusted internal caller and detonates as root. Exploited in the wild before the patch, CISA KEV deadline September 19. Mechanism, the ise-kong/access.log hunt, and how to prove the patch actually held.
CVE-2026-76461 (CVSS 9.8) is an unauthenticated SQL injection in Cisco AsyncOS email parsing that reaches PostgreSQL's COPY ... TO PROGRAM primitive, so a single crafted message on port 25 lands a root shell on the appliance you count on to filter attacks. Exploited in the wild before the patch, on CISA's KEV with a September 17 federal deadline. The mechanism, the mail_logs hunt, and how to prove the fix actually held.
CVE-2026-75650 (CVSS 10.0), Sansec's StyleSmuggler, is an unauthenticated RCE in Adobe Commerce and Magento Open Source 2.4.4 through 2.4.9. A styles GraphQL input smuggles Magento template directives ({{block}}, {{template}}, {{layout}}) past the filter, and a gadget factory calls objectManager->create() before its instanceof check, so a chosen class runs its constructor when the async job queue renders a Payment Transaction Failed Reminder email. Mechanism, the [kworker/u:8:0] Rust implant, and how to prove APSB26-146 actually took.
CVE-2026-86218 (CVSS 10.0) is a pre-auth static code injection (CWE-96) at /remoteControlAction.do?method=getPierDetails in N-able N-central. Huntress confirmed live exploitation from September 4, N-able shipped Hotfix 4 (build 2026.3.1.14) on September 6, CISA KEV deadline was today. The chain from unauth POST to Java shell, the downstream hunt across your managed fleet, and why patching the console alone is not enough.
CVE-2026-82329 (CVSS 9.8) is an unauthenticated auth bypass in JFrog Artifactory: default installs seed JFrog Access with a signing key derived from the empty string, so anyone can forge a join JWT with kid=SHA256(""), exchange it at /access/api/v1/registry/join for a SERVICE token, and mint a platform admin token at /access/api/v1/tokens. Mechanism, the phantom-KID startup-log hunt, and how to prove the patched build actually rejects the forgery.
CVE-2026-82222 (CVSS 10.0) chains three flaws in the WordPress GiveWP plugin into unauthenticated remote code execution: a give_action=user_register path that ignores WordPress's own users_can_register option, a safeUnserialize helper that isn't, and a bundled PHP gadget chain that triggers on any front-end pageload. Patched in 4.16.7.2. The chain, the payload that sleeps in the database, and the hunts to run tonight in WordPress access logs and PHP-FPM parent-of-shell alerts.
CVE-2026-8452 (CVSS 8.8) is an unauthenticated heap overflow in NetScaler's SAML signature canonicalization: an oversized PrefixList inside <ds:SignedInfo> corrupts adjacent nsb chunk metadata, hands the attacker a write-what-where primitive, and lands root code execution inside nsppe. CISA KEV since August 26 with active exploitation dropping x.php and z.php webshells. Mechanism, the file drops to hunt tonight, and Bishop Fox's no-crash patch verification.
CVE-2026-59310 (CVSS 9.8) is a directory traversal in vCenter's syslog collector: a crafted UDP 514 message resolves outside the log root and lands as a crontab fragment in /etc/cron.d/, giving unauthenticated attackers root, a reverse_ssh tunnel, and a documented pivot to Babuk-derived ESXi ransomware. 361 vCenter hosts across 47 countries compromised, CISA KEV since August 18. Mechanism, the two-line IOC pattern, and how to prove your patched build actually rejects the payload.
CVE-2026-64849 (CVSS 9.3) is an unauthenticated SSRF in MLflow's /api/2.0/mlflow/webhooks/{id}/test endpoint: _validate_webhook_url checks the URL, but the delivery adapter follows a 302 to 169.254.169.254 and reflects the metadata response back to the caller. CISA KEV since August 19 with a 14-day BOD 26-04 clock. Mechanism, the two-line IOC pattern, and how to prove your 3.15.0 upgrade actually held.
CVE-2026-58231 (CVSS 10.0) is an unauth improper-authorization bug in SAP Commerce Cloud's Data Hub Adapter: a default authentication client plus loose input validation on /datahubadapter/import/** lets attackers push ImpEx that Commerce's own Groovy hooks then execute. Patched Aug 11, honeypot hits from AS11402 by Aug 14. Mechanism, the log lines and process trees that catch it, and how to prove your patched build actually rejects the payload.
CVE-2026-8037 is a pre-auth root RCE in Progress Kemp LoadMaster's /accessv2 API driven by an uninitialized heap buffer inside the escape_quotes() sanitizer itself. CISA KEV since August 7 with 792 attempts logged across 65 IPs. Mechanism, the log lines and process trees that catch it, and how to prove your patched build actually rejects the payload.
GHSA-vwf4-m7j8-wcjf is an unauthenticated CVSS 10.0 SQL injection in Metabase's /api/session/reset_password. Because Metabase's app database is also its auth store, one HTTP request mints an admin session and every stored data source credential leaks with it. Mechanism, the two-log-line IOC pattern, and how to prove your patch actually held.
On August 4 a compromised maintainer account pushed keyv@6.0.0 and ten sibling packages carrying a self-propagating worm whose C2 address lives on the Ethereum mainnet. Mechanism, IoCs on developer laptops and CI runners, and the order to rotate credentials in.
CVE-2026-15409 is a pre-auth /wsproxy WebSocket bypass in SonicWall SMA 1000; chained with CVE-2026-15410's ctrl-service remove_hotfix path traversal it hands INC Ransomware root on a VPN appliance in one unauthenticated request. Mechanism, defender hunts on extraweb_access.log and /var/lib/unit/conf.json, and how to prove firmware 12.4.3-03453 or 12.5.0-02835 actually held.
CVE-2026-18577 is an unauthenticated auth bypass in N-able N-central that survives the vendor's first hotfix, actively exploited to pivot into every endpoint an MSP manages via Take Control and Cloudflared tunnels. Mechanism, defender hunts on ui_access_control.log and BASupSrvc log gzips, and how to prove the 2026.3.1.7 hotfix actually held.
CVE-2026-20316 is a hardcoded low-privilege account in Cisco Secure FMC's web tier, actively exploited before the July 29 hotfix and chainable through the package_info.pl diagnostic wrapper to root. Mechanism, the /var/log/messages IoC Cisco is telling you to grep for, defender hunts, and how to prove the hotfix actually took.
CVE-2026-16812 is a CVSS 10.0 unauthenticated OS command injection in Arista VeloCloud Orchestrator on-prem, exploited as a zero-day and added to CISA KEV on July 27, 2026 with a July 30 federal deadline. The mechanism, why SD-WAN monitoring walks it past, defender hunts against the orchestrator host, and how to prove the patch actually held.
CVE-2026-16723 is an unpatched RCE in Fastjson 1.2.68 to 1.2.83 under active exploitation since July 21, 2026. The parser's own type validator fetches attacker-hosted JARs through getResourceAsStream, and the @JSONType annotation short-circuits the safety gate. Mechanism, defender hunts, and how to prove SafeMode actually took effect.
Check Point's SmartConsole login accepted an application token from unauthenticated callers, handing full firewall-management admin to anyone who could reach the Management Server. The mechanism, why no signature tooling catches it, defender hunts against the audit log, and how to prove the patch actually held before the July 25 CISA KEV deadline.
CVE-2026-6875 chains an unauthenticated POST to /assessment_thanks.do with a mutable Object.clone override that turns gs.include into Function(payload) inside ServiceNow's less restricted Rhino context. The mechanism, why signature tooling walks it past, defender hunts, and how to prove the fix held.
CVE-2026-63030 and CVE-2026-60137 chain a REST batch route confusion with a WP_Query author__not_in SQL injection into unauthenticated RCE on WordPress 6.9 and 7.0. The mechanism, why signature WAFs walk it past, defender hunts, and how to prove the patch actually held.
On July 14 an attacker used a pull_request_target misconfiguration in asyncapi/generator to steal the asyncapi-bot PAT, then pushed a module-load Miasma RAT through @asyncapi/specs, @asyncapi/generator, generator-components, and generator-helpers with valid SLSA provenance. Mechanism, defender hunts, and how to prove the fix actually held.
Microsoft's record July 14 Patch Tuesday hides three identity-forgery bugs. CVE-2026-56164 lets an unauthenticated caller reach a critical SharePoint function; CVE-2026-56155 hands the ADFS token signing keys to any low-privilege reader; CVE-2026-55040 chains a JWT bypass into the Pwn2Own SharePoint RCE. Mechanism, defender hunts, and how to prove the patch actually held.
CVE-2026-20896 is an authentication bypass in the official Gitea Docker image. A REVERSE_PROXY_TRUSTED_PROXIES=* default lets any network client set X-WEBAUTH-USER and log in as any account, admin included. Mechanism, Sysdig's ProtonVPN-scanner observation, defender hunts, and how to prove the patch actually held.
CVE-2026-48282 is an unauthenticated path traversal in ColdFusion's RDS FILEIO handler. One POST to /CFIDE/main/ide.cfm writes a CFML webshell anywhere the service account can reach, and CISA set today as the deadline. Mechanism, defender hunts, and how to prove the patch actually held.
CVE-2026-8451 is a pre-auth memory overread in NetScaler's custom SAML XML parser. An unquoted attribute followed by whitespace runs past the buffer, and the leaked bytes come back inside the NSC_TASS cookie. The mechanism, the exploit request, defender hunts, and how to prove the patch actually held.
SOCRadar tied the FortiBleed credential-harvest campaign to INC Ransom and Lynx. The FortigateSniffer mechanism abusing FortiOS's diagnose sniffer packet command, the CVE-2026-35616 EMS accelerator dropping EKZ Infostealer, the detection gap, and a blue-team playbook.
CVE-2026-45659 turns any authenticated Site Member into a SharePoint RCE via LosFormatter deserialization inside Update(). The mechanism, why normal blue-team tooling waves it through, the hunting queries and ATT&CK mapping, and how to verify the patch actually held.
CVE-2026-48558 is a CVSS 10 authentication bypass in SimpleHelp's OIDC login: the server never verifies the id_token signature, so attackers forge Technician sessions, self-register MFA, and use the RMM channel to drop TaskWeaver and Djinn Stealer on developer fleets. The mechanism, the detection gap, and a blue-team response playbook.
Three FortiSandbox CVEs (CVE-2026-39813, CVE-2026-39808, CVE-2026-25089) chain unauthenticated path traversal and OS command injection into root code execution on the appliance that grades every other Fortinet product's malware verdicts. The mechanism, the detection gap, and a blue-team response playbook.
JFrog's PixelSmash is a heap out-of-bounds write in FFmpeg's MagicYUV decoder, with working RCE demonstrated against Jellyfin and Nextcloud through automatic library scans. The chroma-height rounding mismatch, the AVBuffer free-pointer hijack, the detection gap, and a blue-team response playbook.
CVE-2026-20253 is a CVSS 9.8 pre-authentication RCE in Splunk Enterprise's PostgreSQL sidecar, actively exploited and on CISA KEV with a June 21 deadline. The confused-deputy mechanism, the detection gap, and a blue-team response playbook.
The Hades sub-wave of the Mini Shai-Hulud cluster republished six PyPI bioinformatics packages in under sixty seconds on June 8, hiding a Bun JavaScript credential worm inside trojanized .abi3.so native extensions. Detection gaps, MITRE mapping, and a blue-team response playbook.
Attackers claimed 1,500+ orphan Arch User Repository packages through legitimate adoption, then chained a malicious atomic-lockfile npm dependency, an eBPF rootkit, and a credential sweep. Detection gaps, MITRE mapping, and a blue-team response playbook.
ShinyHunters spent two weeks exploiting CVE-2026-35273, a CVSS 9.8 pre-authentication RCE in Oracle PeopleSoft PSEMHUB, breaching 100+ organizations before Oracle's emergency patch landed. Detection gaps, MITRE mapping, and a blue-team response playbook.
An IKEv1 certificate validation flaw lets an unauthenticated attacker complete a Check Point VPN session without a valid password, and a Qilin ransomware affiliate is already inside. Detection gaps, MITRE mapping, and a blue-team response playbook.
An authenticated netadmin can ride a crafted CLI input into full root on Cisco Catalyst SD-WAN Manager with no patch yet shipped. Detection gaps, MITRE mapping, and a blue-team response playbook.
A Mini Shai-Hulud variant abused GitHub Actions OIDC to republish 96 malicious versions across 32 official @redhat-cloud-services npm packages on June 1, sweeping AWS, GCP, Azure, and CI/CD secrets while self-replicating. Detection gaps, MITRE mapping, and a blue-team response playbook.
An authentication bypass in PAN-OS GlobalProtect lets attackers forge override cookies and pull unauthorized VPN tunnels into internal networks. Active exploitation, detection gaps, MITRE mapping, and a blue-team response playbook.
The Megalodon campaign pushed 5,718 malicious commits across 5,561 repositories, injecting GitHub Actions workflow files that exfiltrate CI/CD secrets with stolen tokens. CISA advisory, detection gaps, MITRE mapping, and a blue-team response playbook.
A malicious Nx Console VS Code extension (nrwl.angular-console v18.95.0) ran for 18 minutes, stealing developer credentials and breaching roughly 3,800 GitHub internal repos. CVE-2026-48027 detection gaps, MITRE mapping, and a blue-team response playbook.
A live supply-chain campaign planted 34 credential-stealing packages and 384+ versions across three ecosystems, even poisoning AI assistant context files. Detection gaps, MITRE mapping, and a blue-team response playbook.
A supply-chain attacker rewrote git tags across four Composer packages to deploy a cross-platform credential stealer via autoload.files. Detection gaps, MITRE mapping, and response playbook.
BAS safely simulates real cyberattacks to test your defenses. How it works, BAS vs pentesting, MITRE ATT&CK mapping, and why every security team needs continuous validation.
Cloud SaaS security tools send your most sensitive data to third-party servers. Local-first means your logs, source code, and credentials never leave your hardware.
Enterprise SIEMs cost a fortune and small teams fly blind without log correlation. What a SIEM actually does, why it matters, and how local-first detection and BAS validation close the gap.
What MITRE ATT&CK actually is, how to map your detections, coverage gaps most teams miss, and how to validate your coverage with BAS.
Manual compliance is killing small teams. How to automate evidence collection across SOC 2, ISO 27001, HIPAA, PCI DSS, and NIST frameworks.
Phase 1: Visibility. Phase 2: Protection. Phase 3: Validation. Phase 4: Governance. The complete playbook for going from zero to a working program.
CVSS was designed for a world that no longer exists. Multi-layer scoring models factor in exploit maturity, business context, and threat intelligence.
Combining EPSS probability with CISA KEV binary signals produces a prioritization model that outperforms CVSS Base Score in every measurable category.
What SOC 2 actually requires for vulnerability management, how to automate evidence collection, and common audit findings to avoid.
A step-by-step operational guide: asset discovery, scanning cadence, triage workflow, SLAs, and board reporting.
Practical patterns for embedding static analysis into build pipelines without slowing developers down.
How local AI models generate context-aware remediation guidance -- complete with code snippets, deployment steps, and rollback procedures.
The vulnerability management market charges enterprise prices for problems that can be solved with better tooling.
Cross-referencing KEV, ransomware campaign data, and EPSS to build a prioritization list focused on the CVEs ransomware operators actively weaponize.
Most organizations face multiple compliance frameworks. Cross-mapping controls reduces duplication and simplifies evidence collection.