——
Act nowVULNERABILITIES

15 newly exploited CVEs: how to find, fix and verify them

A field guide to the fifteen newest entries in CISA’s Known Exploited Vulnerabilities catalogue—because “we probably do not run that” is not an asset register, and a successful patch job is not automatically a successful incident response.

This edition covers the 15 most recently added entries in CISA’s Known Exploited Vulnerabilities catalogue at review time, ordered by CISA date added. It is for authorised owners and administrators. The examples identify versions, exposure and evidence; they do not exploit the flaws.

Known exploitedSafe detectionRemediationIncident triage

What “latest serious CVEs” means

A list sorted by CVSS alone is a handsome way to spend Tuesday patching theoretical dragons while somebody walks through the door actually being used. This list uses the newest rows in CISA’s official KEV data mirror. A KEV entry means CISA has evidence of exploitation in the wild. It does not mean every installation is compromised, or that CVSS tells the whole operational story.

The snapshot was checked on 18 August 2026. Vendor advisories are living documents. Before making a change, open the linked primary advisory and map your exact product train, deployment model and support contract. Where no universal fixed build exists, this guide says so rather than inventing a pleasing number.

Three separate findingsVulnerable: the build and feature match the advisory. Exposed: an attacker could reach the affected path. Compromised: evidence shows or strongly suggests exploitation. Do not collapse these into one checkbox.

The fifteen at a glance

CVE and productImpactFirst action
CVE-2025-62593 · RayBrowser-assisted remote code execution.Find Ray below 2.52.0; isolate dashboard port 8265.
CVE-2026-20349 · Cisco ASA/FTDUnauthenticated remote denial of service.Inventory releases/VPN listeners; preserve reload evidence.
CVE-2026-68820 · Windows AFDLocal privilege escalation.Verify OS build and August security-update compliance.
CVE-2026-72898 · MetabaseSQL injection, admin access and data theft.Upgrade to the fixed patch for the installed branch.
CVE-2026-8037 · LoadMasterUnauthenticated command injection.Restrict management and apply the vendor-fixed build.
CVE-2026-63077 · TeamCityUnauthenticated OS command execution.Upgrade to 2025.11.7/2026.1.3 or install the patch plugin.
CVE-2026-18556 · N-centralAuthentication bypass.Treat with CVE-2026-18577; update and inspect identity activity.
CVE-2026-34486 · TomcatEncryptInterceptor bypass.Check branch and cluster interceptor configuration.
CVE-2026-9198 · LangflowUnauthenticated remote code execution.Upgrade to at least 1.10.1; remove public access.
CVE-2026-18577 · N-centralAccount takeover; incomplete earlier fix.Install 2026.3 HF1 build 2026.3.1.7 or later.
CVE-2026-20316 · Cisco FMCStatic credential allows unauthorised login.Upgrade; no workaround. Check unknown sessions.
CVE-2025-68686 · FortiOSSSL-VPN persistence patch bypass.Patch and investigate the prerequisite compromise.
CVE-2026-16812 · VeloCloudUnauthenticated command injection.Restrict VCO, preserve logs, install a fixed release.
CVE-2026-16232 · SmartConsoleLogin token exposure and full administration.Apply Check Point’s fix; review admin sessions.
CVE-2026-50522 · SharePointUnauthenticated remote code execution.Patch the whole farm, run PSConfig and hunt.

A reusable first-hour workflow

  1. Search the inventory. Include containers, test systems, standby nodes and product aliases. Abandoned appliances have a remarkable instinct for remaining online.
  2. Record the exact build. Save authoritative command or UI evidence. A banner is a lead, not package truth.
  3. Establish reachability. Record interfaces, proxies, VPNs and firewall rules. Do not test reachability with an exploit.
  4. Preserve volatile evidence. Save application, identity, EDR, proxy, DNS and firewall logs before rotation or upgrade.
  5. Contain, update, investigate, verify. Isolation blocks fresh attempts; updating removes this flaw; investigation handles prior use.
# General Linux/container evidence; no exploitation
date -u
hostname
whoami
sudo ss -lntup
docker ps --format 'table {{.Names}}\t{{.Image}}\t{{.Ports}}'
docker inspect --format '{{.Name}} {{.Config.Image}} {{.Image}}' $(docker ps -q)

# Hash collected evidence
find evidence -type f -print0 | sort -z | xargs -0 sha256sum > evidence.sha256

CVE-2025-62593 — Ray dashboard code injection

Affected: Ray releases before 2.52.0. A malicious website opened in Firefox or Safari may use DNS rebinding to reach a local/private Ray dashboard. Once an untrusted origin operates a powerful dashboard, “dashboard” becomes a rather optimistic noun.

python -c "import ray; print(ray.__version__)"
python -m pip show ray
sudo ss -lntp | grep ':8265'
docker exec ray-head python -c "import ray; print(ray.__version__)"

Detect: find every notebook, workstation, container and cluster head. A result below 2.52.0 is vulnerable. A listener on all interfaces deserves immediate containment, but “private” is not automatically safe in a browser-assisted attack. Review Ray job/dashboard logs for unknown jobs, runtime environments, actors, child processes and outbound traffic.

Fix and verify: upgrade to 2.52.0 or later, configure dashboard token authentication where appropriate, restrict the dashboard to trusted administration paths, restart and repeat the version/listener checks. If unknown code ran, isolate the host and rotate cloud, model-registry and data-store secrets available to Ray.

Ray advisory GHSA-q279-jhrf-cc6v

CVE-2026-20349 — Cisco ASA/FTD denial of service

Affected: Cisco Secure Firewall ASA/FTD builds and web/VPN features identified by Cisco. CISA describes unauthenticated remote denial of service resulting in device reload.

show version
show uptime
show asp table socket | include SSL
show logging
dir crashinfo:

Detect: map the complete version and enabled listener to Cisco’s live tables. Preserve crashinfo, syslog, uptime transitions, VPN history and monitoring around unexplained reloads. Cisco release trains differ, so there is no responsible universal build number.

Fix and verify: install Cisco’s fixed release for your train, verify deployment, VPN function and stable uptime. Restrict exposure where possible, but do not call a firewall rule the patch. Suspected exploitation warrants TAC involvement and incident review.

Cisco advisory

CVE-2026-68820 — Windows AFD privilege escalation

Affected: Windows products in MSRC before their applicable August 2026 security update. The local authenticated use-after-free can elevate privileges, which means the attacker already has a foothold.

# Elevated PowerShell
Get-ComputerInfo |
  Select-Object WindowsProductName, WindowsVersion, OsBuildNumber

Get-HotFix |
  Sort-Object InstalledOn -Descending |
  Select-Object -First 20 HotFixID, InstalledOn

Detect: compare OS build and KB compliance with MSRC using Intune, Configuration Manager, WSUS or EDR inventory. Do not test a kernel exploit. Hunt for unusual processes becoming SYSTEM, new services/tasks, security-tool tampering, credential access and lateral movement.

Fix and verify: deploy the applicable cumulative update, restart if required and prove the resulting build centrally. Isolate and investigate endpoints with post-exploitation evidence; patching does not evict an attacker who already obtained SYSTEM.

Microsoft advisory

CVE-2026-72898 — Metabase unauthenticated SQL injection

Affected: x.58.0–x.58.23, x.59.0–x.59.20, x.60.0–x.60.16, x.61.0–x.61.10, x.62.0–x.62.8 and x.63.0–x.63.2. The vendor confirms active exploitation; impact includes admin access, stored database credentials and data export.

docker ps --filter name=metabase --format '{{.Names}} {{.Image}} {{.Ports}}'
docker inspect --format '{{.Config.Image}} {{.Image}}' metabase

# Temporary reverse-proxy workaround; verify before relying on it
location = /api/session/reset_password {
    return 403;
}

Fix: upgrade to x.58.24, x.59.21, x.60.17, x.61.11, x.62.9 or x.63.5 for the matching branch. Afterwards revoke active sessions, review API keys/admins, rotate connected-database credentials, and inspect Metabase/query and warehouse logs. Verify the patched version and a normal saved query.

Metabase advisory

CVE-2026-8037 — Progress LoadMaster command injection

Affected: LoadMaster builds in Progress’s critical bulletin. Unauthenticated command injection on a reachable appliance is potential compromise, not merely a compliance exception.

# Record version/build in:
# System Configuration > System Administration > System Information

# Confirm expected management exposure only
nmap -Pn -sT -p 22,443 --reason loadmaster-admin.example.net

Detect: compare the authoritative UI build with the live bulletin. Export system/security/audit logs and inspect unknown admin actions, configuration changes, new destinations and vendor IoCs. Nmap proves a listener answered, not that the CVE exists.

Fix and verify: restrict management, preserve a supported evidence snapshot and install the fixed build for your branch. Follow the vendor HA sequence. Confirm both nodes, synchronisation and application health; contact Progress and rotate appliance-reachable secrets if suspicious.

Progress bulletin

CVE-2026-63077 — TeamCity unauthenticated RCE

Affected: all TeamCity On-Premises versions before 2025.11.7 and 2026.1.3. TeamCity Cloud was patched by JetBrains. The agent-polling path can execute OS commands as the TeamCity server process, threatening repositories, tokens, signing material and build artefacts.

# Administration > Updates shows the supported build.
grep -E 'version|build' \
  "$TEAMCITY_HOME/webapps/ROOT/META-INF/buildServerVersion.properties"

grep -Ei 'agent|token|user|plugin|error' \
  "$TEAMCITY_DATA_PATH/logs/teamcity-server.log" | tail -n 200

Fix: upgrade to 2025.11.7 or 2026.1.3. JetBrains also supplies a security patch plugin for 2017.1+ if a full update cannot happen immediately.

Investigate: preserve server, activities, identity and proxy logs; inspect unknown agents, users, tokens, plugins, builds, child processes and outbound traffic. Rotate repository, registry, cloud and signing credentials if exposed. Verify the build, run one controlled build and put the interface behind trusted access.

JetBrains advisory

CVE-2026-18556 and CVE-2026-18577 — N-central’s patch chain

CVE-2026-18556 is an authentication bypass; CVE-2026-18577 is an incomplete fix that may allow account takeover. Checking only the earlier ticket is the sort of historical re-enactment patch management should avoid.

# Record the exact build from the N-central administration UI.
# Vendor release notes identify:
# N-central 2026.3.1 HF1 — build 2026.3.1.7

# Export supported audit reports for:
# sign-ins, source IPs, MFA resets, account/role changes,
# API tokens, automation policies and scripts sent to endpoints.

Fix and verify: install 2026.3 HF1 build 2026.3.1.7 or a later approved build, restrict the console to trusted networks and invalidate sessions. Inspect unknown users, automation and downstream endpoint actions; rotate privileged integrations if exposure is plausible. Verify build, administrator access and agent communication after restart.

N-able 2026.3 HF1 release notes

CVE-2026-34486 — Tomcat EncryptInterceptor bypass

Affected: vulnerable Tomcat clustering EncryptInterceptor builds. Apache lists fixes in 9.0.117, 10.1.55 and 11.0.21; consult the branch page for exact affected ranges. CISA notes potential chaining with CVE-2025-24813.

"$CATALINA_HOME/bin/version.sh"
java -cp "$CATALINA_HOME/lib/catalina.jar" \
  org.apache.catalina.util.ServerInfo
grep -Rni 'EncryptInterceptor' \
  "$CATALINA_BASE/conf" "$CATALINA_HOME/conf" 2>/dev/null

Detect: confirm branch, clustering configuration and which peers reach the cluster transport. Preserve Catalina, proxy and cluster logs; inspect unknown peers, deserialisation errors, changed content and child processes. Configuration may be templated, so one empty grep is not proof.

Fix and verify: upgrade to a fixed branch release, restrict cluster traffic to trusted peers, restart, repeat the version command and validate cluster membership. If compromise indicators exist, preserve evidence and use the web-server playbook.

Apache Tomcat security updates

CVE-2026-9198 — Langflow unauthenticated RCE

Affected: Langflow OSS releases in IBM’s bulletin before 1.10.1. Auto-login bypass and unsafe code validation can yield unauthenticated code execution in default-style deployments.

python -m pip show langflow
python -c "import importlib.metadata as m; print(m.version('langflow'))"
docker ps --filter name=langflow --format '{{.Names}} {{.Image}} {{.Ports}}'
sudo ss -lntp
ps -ef --forest | grep -i '[l]angflow'

Detect: find pip, virtual-environment and container installs; check public reachability. Review proxy/application logs, new flows, unexpected code components, child processes, outbound connections and access to API keys.

Fix and verify: upgrade to at least 1.10.1—prefer the newest supported fixed release—disable auto-login, require authentication and keep the interface private. Run with minimal privileges and external secret storage. If unknown code ran, isolate and rotate every credential visible to the process.

IBM Langflow bulletin

CVE-2026-20316 — Cisco FMC static credential

Affected: FMC releases in Cisco’s advisory, regardless of configuration. A static low-privilege credential permits unauthenticated login and sensitive-data access. Cisco reports active exploitation and no workaround.

# Record version via Help > About.
# Preserve supported exports of:
# authentication/audit history, sessions, source addresses,
# policy deployments, API activity and integration changes.

Detect and fix: compare the exact release with Cisco’s fixed-software table and upgrade. Immediately reduce public management access, but do not call that permanent remediation. Use Cisco’s current IoC command from the live advisory; its revision history shows the command was corrected, so an old copied version is unsafe. Review unknown low-privilege sessions and chained elevation. If suspicious, preserve evidence, revoke sessions, rotate credentials and contact TAC.

Cisco FMC advisory

CVE-2025-68686 — FortiOS SSL-VPN persistence bypass

The attacker must first compromise the FortiGate at filesystem level through another flaw. This CVE then bypasses a fix for symbolic-link persistence. Finding the version asks both “must we update?” and “was the appliance already owned?”

get system status
show system interface
show vpn ssl settings
execute log filter category event
execute log display

Affected/fixed: 7.6.0–7.6.1 → 7.6.2+; 7.4.0–7.4.6 → 7.4.7+. FortiOS 7.2, 7.0 and 6.4 must migrate to a fixed supported release. Products that never had SSL-VPN enabled are not affected by this issue.

Response: preserve config, audit, FortiAnalyzer/SIEM and integrity evidence; use Fortinet’s upgrade path. Review historical SSL-VPN exposure, admin logins, changes, unexpected files and outbound connections. Persistence evidence requires vendor-guided recovery/rebuild and appropriate secret rotation, not merely an in-place update.

Fortinet PSIRT FG-IR-25-934

CVE-2026-16812 — VeloCloud Orchestrator command injection

Affected: VCO on-premises releases identified by Arista. Hosted and dedicated versions were patched by the provider. The on-prem flaw exposes privileged internal functionality; Arista rates it 10.0.

# Record in VCO: exact build, deployment type,
# administrators and integrations.

# Preserve before remediation:
# web, backend application, system and database logs,
# plus relevant filesystem timestamps.

Detect: inspect unfamiliar source IPs, admin changes, outbound traffic and new files/commands. Use the current malicious-address list from Arista rather than a frozen copy.

Fix and verify: restrict the VCO web UI to trusted networks and install a fixed release from Arista’s live table. Unsupported trains require TAC. Verify build, administrators, orchestration health and outbound baseline; rebuild trust and rotate integrations if compromised.

Arista Advisory 0144

CVE-2026-16232 — Check Point SmartConsole token exposure

Affected: SmartConsole/management deployments in sk185169. CISA describes unauthenticated acquisition of a login token and full administrative access, placing firewall policy and management credentials in scope.

# SmartConsole: Help > About
# Management server supported inventory:
cpinfo -y all

# Export audit logs and review:
# admin sign-ins, sources, session publications, policy installs,
# object changes, new administrators and API activity.

Fix and verify: install the exact hotfix/fixed release in sk185169 across the relevant management server and clients. Preserve logs, terminate suspect sessions, revoke tokens, reset credentials and review MFA/IdP activity and unexpected policy installations. After fixing, record inventory and verify trusted-client access and gateway policy state.

Check Point sk185169

CVE-2026-50522 — SharePoint unauthenticated RCE

Affected: on-premises SharePoint builds in MSRC before their security update. CISA describes unauthenticated network deserialisation leading to code execution. SharePoint Online servicing does not patch a forgotten on-prem farm.

# SharePoint Management Shell
(Get-SPFarm).BuildVersion
Get-SPServer | Select-Object Address, Role, Status

# Every farm server
Get-HotFix |
  Sort-Object InstalledOn -Descending |
  Select-Object -First 20 HotFixID, InstalledOn

# After approved updates on every node
PSConfig.exe -cmd upgrade -inplace b2b -wait -force

Detect: compare every node’s farm build and KBs with MSRC. Inspect IIS/ULS, Windows Security, PowerShell and EDR for new ASPX/assemblies, tasks, services, accounts, unusual w3wp.exe children and outbound connections. Preserve suspicious files before removal.

Fix and verify: follow Microsoft’s farm-aware sequence, patch all servers and run PSConfig as required. Confirm every node’s build and upgrade state, test a site collection and Central Administration health. If exposed while vulnerable, investigate and rotate keys, service credentials, certificates and sessions according to current Microsoft guidance and evidence.

Microsoft advisory

How to close a CVE without lying to the ticket

StatementEvidenceOwner
All assets foundCMDB, cloud/container, network and app owner reconciled.Asset owner
Vulnerable condition gonePost-change build plus feature/config evidence.Platform owner
Service worksHealth test, HA state and monitoring recovery.Service owner
Prior use consideredLog window, sources, queries, gaps and conclusion.Security/IR
Residual risk ownedException, isolation, deadline and approver.Risk owner
Asset: tc-prod-01
CVE: CVE-2026-63077
Before: TeamCity 2026.1.2; reachable through public proxy
Containment: allowlist applied 2026-08-18 09:20Z
Evidence: TeamCity, proxy, EDR and identity logs; hashes attached
Remediation: upgraded to 2026.1.3
Verification: version recorded; controlled build passed; route denied
Investigation: no unknown users/agents/tokens or abnormal child process
Limitation: application logs retained 30 days
Owner / reviewer / time: ...

For a reachable KEV item, absence of evidence is bounded by logging quality and retention. Write that limitation. It is more professional than quietly converting uncertainty into a green cell.

Common mistakes

  • Searching only public IPs and missing private dashboards, build systems, containers and standby appliances.
  • Using a banner as authoritative version evidence.
  • Running public PoC code on production to prove what the vendor version table already proves.
  • Patching before saving short-retention logs from a reachable KEV system.
  • Rotating one password while leaving API tokens, database credentials, signing keys and sessions untouched.
  • Updating one HA node, farm server, client or container tag and closing the entire estate.

Questions sensible people ask

Does a matching version prove compromise?

No. It proves a vulnerable state, not exploitation. Patch or isolate it, then investigate product, identity, endpoint and network evidence.

Should I run a public proof of concept to confirm a CVE?

Not on production. Confirm product, version, affected feature and exposure from vendor guidance. Use an authorised disposable lab only if exploit validation is genuinely required.

Is patching enough after known exploitation?

Not always. Preserve logs, contain exposed systems, rotate affected secrets and investigate persistence before returning a possibly compromised host to service.

Which item should come first?

Start with exposed unauthenticated RCE or admin bypass in your estate. Internet-reachable Metabase, TeamCity, Langflow, LoadMaster, FMC, VCO, SmartConsole or SharePoint normally outrank local elevation on an isolated endpoint, unless evidence or business impact changes the order.

Safety boundary

Use these checks only on systems you own or are authorised to administer. They collect version, configuration and evidence; they do not exploit the vulnerabilities. Do not paste public exploits into production, delete suspected persistence before preserving evidence, or return a patched host while credible compromise remains unresolved.

Primary references

  1. Known Exploited Vulnerabilities data mirrorCISA
  2. GHSA-q279-jhrf-cc6vRay Project
  3. CVE-2026-20349Cisco
  4. CVE-2026-68820Microsoft
  5. GHSA-vwf4-m7j8-wcjfMetabase
  6. LoadMaster critical bulletinProgress
  7. CVE-2026-63077JetBrains
  8. N-central 2026.3 HF1N-able
  9. Tomcat security updatesApache
  10. Langflow bulletinIBM
  11. CVE-2026-20316Cisco
  12. FG-IR-25-934Fortinet
  13. Advisory 0144Arista
  14. sk185169Check Point
  15. CVE-2026-50522Microsoft

First edition. Reviewed against CISA KEV data and the linked vendor material on 18 August 2026. Re-check every live advisory before operational use.