15 newly exploited CVEs: how to find, fix and verify them
A field guide to the fifteen newest entries in CISA’s Known Exploited Vulnerabilities catalogue—because “we probably do not run that” is not an asset register, and a successful patch job is not automatically a successful incident response.
Scope
This edition covers the 15 most recently added entries in CISA’s Known Exploited Vulnerabilities catalogue at review time, ordered by CISA date added. It is for authorised owners and administrators. The examples identify versions, exposure and evidence; they do not exploit the flaws.
What “latest serious CVEs” means
A list sorted by CVSS alone is a handsome way to spend Tuesday patching theoretical dragons while somebody walks through the door actually being used. This list uses the newest rows in CISA’s official KEV data mirror. A KEV entry means CISA has evidence of exploitation in the wild. It does not mean every installation is compromised, or that CVSS tells the whole operational story.
The snapshot was checked on 18 August 2026. Vendor advisories are living documents. Before making a change, open the linked primary advisory and map your exact product train, deployment model and support contract. Where no universal fixed build exists, this guide says so rather than inventing a pleasing number.
The queue
The fifteen at a glance
Before the product notes
A reusable first-hour workflow
- Search the inventory. Include containers, test systems, standby nodes and product aliases. Abandoned appliances have a remarkable instinct for remaining online.
- Record the exact build. Save authoritative command or UI evidence. A banner is a lead, not package truth.
- Establish reachability. Record interfaces, proxies, VPNs and firewall rules. Do not test reachability with an exploit.
- Preserve volatile evidence. Save application, identity, EDR, proxy, DNS and firewall logs before rotation or upgrade.
- Contain, update, investigate, verify. Isolation blocks fresh attempts; updating removes this flaw; investigation handles prior use.
# General Linux/container evidence; no exploitation
date -u
hostname
whoami
sudo ss -lntup
docker ps --format 'table {{.Names}}\t{{.Image}}\t{{.Ports}}'
docker inspect --format '{{.Name}} {{.Config.Image}} {{.Image}}' $(docker ps -q)
# Hash collected evidence
find evidence -type f -print0 | sort -z | xargs -0 sha256sum > evidence.sha256
01 · Added 17 Aug 2026
CVE-2025-62593 — Ray dashboard code injection
Affected: Ray releases before 2.52.0. A malicious website opened in Firefox or Safari may use DNS rebinding to reach a local/private Ray dashboard. Once an untrusted origin operates a powerful dashboard, “dashboard” becomes a rather optimistic noun.
python -c "import ray; print(ray.__version__)"
python -m pip show ray
sudo ss -lntp | grep ':8265'
docker exec ray-head python -c "import ray; print(ray.__version__)"
Detect: find every notebook, workstation, container and cluster head. A result below 2.52.0 is vulnerable. A listener on all interfaces deserves immediate containment, but “private” is not automatically safe in a browser-assisted attack. Review Ray job/dashboard logs for unknown jobs, runtime environments, actors, child processes and outbound traffic.
Fix and verify: upgrade to 2.52.0 or later, configure dashboard token authentication where appropriate, restrict the dashboard to trusted administration paths, restart and repeat the version/listener checks. If unknown code ran, isolate the host and rotate cloud, model-registry and data-store secrets available to Ray.
02 · Added 11 Aug 2026
CVE-2026-20349 — Cisco ASA/FTD denial of service
Affected: Cisco Secure Firewall ASA/FTD builds and web/VPN features identified by Cisco. CISA describes unauthenticated remote denial of service resulting in device reload.
show version
show uptime
show asp table socket | include SSL
show logging
dir crashinfo:
Detect: map the complete version and enabled listener to Cisco’s live tables. Preserve crashinfo, syslog, uptime transitions, VPN history and monitoring around unexplained reloads. Cisco release trains differ, so there is no responsible universal build number.
Fix and verify: install Cisco’s fixed release for your train, verify deployment, VPN function and stable uptime. Restrict exposure where possible, but do not call a firewall rule the patch. Suspected exploitation warrants TAC involvement and incident review.
03 · Added 11 Aug 2026
CVE-2026-68820 — Windows AFD privilege escalation
Affected: Windows products in MSRC before their applicable August 2026 security update. The local authenticated use-after-free can elevate privileges, which means the attacker already has a foothold.
# Elevated PowerShell
Get-ComputerInfo |
Select-Object WindowsProductName, WindowsVersion, OsBuildNumber
Get-HotFix |
Sort-Object InstalledOn -Descending |
Select-Object -First 20 HotFixID, InstalledOn
Detect: compare OS build and KB compliance with MSRC using Intune, Configuration Manager, WSUS or EDR inventory. Do not test a kernel exploit. Hunt for unusual processes becoming SYSTEM, new services/tasks, security-tool tampering, credential access and lateral movement.
Fix and verify: deploy the applicable cumulative update, restart if required and prove the resulting build centrally. Isolate and investigate endpoints with post-exploitation evidence; patching does not evict an attacker who already obtained SYSTEM.
04 · Added 11 Aug 2026
CVE-2026-72898 — Metabase unauthenticated SQL injection
Affected: x.58.0–x.58.23, x.59.0–x.59.20, x.60.0–x.60.16, x.61.0–x.61.10, x.62.0–x.62.8 and x.63.0–x.63.2. The vendor confirms active exploitation; impact includes admin access, stored database credentials and data export.
docker ps --filter name=metabase --format '{{.Names}} {{.Image}} {{.Ports}}'
docker inspect --format '{{.Config.Image}} {{.Image}}' metabase
# Temporary reverse-proxy workaround; verify before relying on it
location = /api/session/reset_password {
return 403;
}
Fix: upgrade to x.58.24, x.59.21, x.60.17, x.61.11, x.62.9 or x.63.5 for the matching branch. Afterwards revoke active sessions, review API keys/admins, rotate connected-database credentials, and inspect Metabase/query and warehouse logs. Verify the patched version and a normal saved query.
05 · Added 7 Aug 2026
CVE-2026-8037 — Progress LoadMaster command injection
Affected: LoadMaster builds in Progress’s critical bulletin. Unauthenticated command injection on a reachable appliance is potential compromise, not merely a compliance exception.
# Record version/build in:
# System Configuration > System Administration > System Information
# Confirm expected management exposure only
nmap -Pn -sT -p 22,443 --reason loadmaster-admin.example.net
Detect: compare the authoritative UI build with the live bulletin. Export system/security/audit logs and inspect unknown admin actions, configuration changes, new destinations and vendor IoCs. Nmap proves a listener answered, not that the CVE exists.
Fix and verify: restrict management, preserve a supported evidence snapshot and install the fixed build for your branch. Follow the vendor HA sequence. Confirm both nodes, synchronisation and application health; contact Progress and rotate appliance-reachable secrets if suspicious.
06 · Added 5 Aug 2026
CVE-2026-63077 — TeamCity unauthenticated RCE
Affected: all TeamCity On-Premises versions before 2025.11.7 and 2026.1.3. TeamCity Cloud was patched by JetBrains. The agent-polling path can execute OS commands as the TeamCity server process, threatening repositories, tokens, signing material and build artefacts.
# Administration > Updates shows the supported build.
grep -E 'version|build' \
"$TEAMCITY_HOME/webapps/ROOT/META-INF/buildServerVersion.properties"
grep -Ei 'agent|token|user|plugin|error' \
"$TEAMCITY_DATA_PATH/logs/teamcity-server.log" | tail -n 200
Fix: upgrade to 2025.11.7 or 2026.1.3. JetBrains also supplies a security patch plugin for 2017.1+ if a full update cannot happen immediately.
Investigate: preserve server, activities, identity and proxy logs; inspect unknown agents, users, tokens, plugins, builds, child processes and outbound traffic. Rotate repository, registry, cloud and signing credentials if exposed. Verify the build, run one controlled build and put the interface behind trusted access.
07 and 10 · Added 4 and 3 Aug 2026
CVE-2026-18556 and CVE-2026-18577 — N-central’s patch chain
CVE-2026-18556 is an authentication bypass; CVE-2026-18577 is an incomplete fix that may allow account takeover. Checking only the earlier ticket is the sort of historical re-enactment patch management should avoid.
# Record the exact build from the N-central administration UI.
# Vendor release notes identify:
# N-central 2026.3.1 HF1 — build 2026.3.1.7
# Export supported audit reports for:
# sign-ins, source IPs, MFA resets, account/role changes,
# API tokens, automation policies and scripts sent to endpoints.
Fix and verify: install 2026.3 HF1 build 2026.3.1.7 or a later approved build, restrict the console to trusted networks and invalidate sessions. Inspect unknown users, automation and downstream endpoint actions; rotate privileged integrations if exposure is plausible. Verify build, administrator access and agent communication after restart.
08 · Added 4 Aug 2026
CVE-2026-34486 — Tomcat EncryptInterceptor bypass
Affected: vulnerable Tomcat clustering EncryptInterceptor builds. Apache lists fixes in 9.0.117, 10.1.55 and 11.0.21; consult the branch page for exact affected ranges. CISA notes potential chaining with CVE-2025-24813.
"$CATALINA_HOME/bin/version.sh"
java -cp "$CATALINA_HOME/lib/catalina.jar" \
org.apache.catalina.util.ServerInfo
grep -Rni 'EncryptInterceptor' \
"$CATALINA_BASE/conf" "$CATALINA_HOME/conf" 2>/dev/null
Detect: confirm branch, clustering configuration and which peers reach the cluster transport. Preserve Catalina, proxy and cluster logs; inspect unknown peers, deserialisation errors, changed content and child processes. Configuration may be templated, so one empty grep is not proof.
Fix and verify: upgrade to a fixed branch release, restrict cluster traffic to trusted peers, restart, repeat the version command and validate cluster membership. If compromise indicators exist, preserve evidence and use the web-server playbook.
09 · Added 4 Aug 2026
CVE-2026-9198 — Langflow unauthenticated RCE
Affected: Langflow OSS releases in IBM’s bulletin before 1.10.1. Auto-login bypass and unsafe code validation can yield unauthenticated code execution in default-style deployments.
python -m pip show langflow
python -c "import importlib.metadata as m; print(m.version('langflow'))"
docker ps --filter name=langflow --format '{{.Names}} {{.Image}} {{.Ports}}'
sudo ss -lntp
ps -ef --forest | grep -i '[l]angflow'
Detect: find pip, virtual-environment and container installs; check public reachability. Review proxy/application logs, new flows, unexpected code components, child processes, outbound connections and access to API keys.
Fix and verify: upgrade to at least 1.10.1—prefer the newest supported fixed release—disable auto-login, require authentication and keep the interface private. Run with minimal privileges and external secret storage. If unknown code ran, isolate and rotate every credential visible to the process.
11 · Added 29 Jul 2026
CVE-2026-20316 — Cisco FMC static credential
Affected: FMC releases in Cisco’s advisory, regardless of configuration. A static low-privilege credential permits unauthenticated login and sensitive-data access. Cisco reports active exploitation and no workaround.
# Record version via Help > About.
# Preserve supported exports of:
# authentication/audit history, sessions, source addresses,
# policy deployments, API activity and integration changes.
Detect and fix: compare the exact release with Cisco’s fixed-software table and upgrade. Immediately reduce public management access, but do not call that permanent remediation. Use Cisco’s current IoC command from the live advisory; its revision history shows the command was corrected, so an old copied version is unsafe. Review unknown low-privilege sessions and chained elevation. If suspicious, preserve evidence, revoke sessions, rotate credentials and contact TAC.
12 · Added 27 Jul 2026
CVE-2025-68686 — FortiOS SSL-VPN persistence bypass
The attacker must first compromise the FortiGate at filesystem level through another flaw. This CVE then bypasses a fix for symbolic-link persistence. Finding the version asks both “must we update?” and “was the appliance already owned?”
get system status
show system interface
show vpn ssl settings
execute log filter category event
execute log display
Affected/fixed: 7.6.0–7.6.1 → 7.6.2+; 7.4.0–7.4.6 → 7.4.7+. FortiOS 7.2, 7.0 and 6.4 must migrate to a fixed supported release. Products that never had SSL-VPN enabled are not affected by this issue.
Response: preserve config, audit, FortiAnalyzer/SIEM and integrity evidence; use Fortinet’s upgrade path. Review historical SSL-VPN exposure, admin logins, changes, unexpected files and outbound connections. Persistence evidence requires vendor-guided recovery/rebuild and appropriate secret rotation, not merely an in-place update.
13 · Added 27 Jul 2026
CVE-2026-16812 — VeloCloud Orchestrator command injection
Affected: VCO on-premises releases identified by Arista. Hosted and dedicated versions were patched by the provider. The on-prem flaw exposes privileged internal functionality; Arista rates it 10.0.
# Record in VCO: exact build, deployment type,
# administrators and integrations.
# Preserve before remediation:
# web, backend application, system and database logs,
# plus relevant filesystem timestamps.
Detect: inspect unfamiliar source IPs, admin changes, outbound traffic and new files/commands. Use the current malicious-address list from Arista rather than a frozen copy.
Fix and verify: restrict the VCO web UI to trusted networks and install a fixed release from Arista’s live table. Unsupported trains require TAC. Verify build, administrators, orchestration health and outbound baseline; rebuild trust and rotate integrations if compromised.
14 · Added 22 Jul 2026
CVE-2026-16232 — Check Point SmartConsole token exposure
Affected: SmartConsole/management deployments in sk185169. CISA describes unauthenticated acquisition of a login token and full administrative access, placing firewall policy and management credentials in scope.
# SmartConsole: Help > About
# Management server supported inventory:
cpinfo -y all
# Export audit logs and review:
# admin sign-ins, sources, session publications, policy installs,
# object changes, new administrators and API activity.
Fix and verify: install the exact hotfix/fixed release in sk185169 across the relevant management server and clients. Preserve logs, terminate suspect sessions, revoke tokens, reset credentials and review MFA/IdP activity and unexpected policy installations. After fixing, record inventory and verify trusted-client access and gateway policy state.
How to close a CVE without lying to the ticket
Asset: tc-prod-01
CVE: CVE-2026-63077
Before: TeamCity 2026.1.2; reachable through public proxy
Containment: allowlist applied 2026-08-18 09:20Z
Evidence: TeamCity, proxy, EDR and identity logs; hashes attached
Remediation: upgraded to 2026.1.3
Verification: version recorded; controlled build passed; route denied
Investigation: no unknown users/agents/tokens or abnormal child process
Limitation: application logs retained 30 days
Owner / reviewer / time: ...
For a reachable KEV item, absence of evidence is bounded by logging quality and retention. Write that limitation. It is more professional than quietly converting uncertainty into a green cell.
Common mistakes
- Searching only public IPs and missing private dashboards, build systems, containers and standby appliances.
- Using a banner as authoritative version evidence.
- Running public PoC code on production to prove what the vendor version table already proves.
- Patching before saving short-retention logs from a reachable KEV system.
- Rotating one password while leaving API tokens, database credentials, signing keys and sessions untouched.
- Updating one HA node, farm server, client or container tag and closing the entire estate.
Questions sensible people ask
Does a matching version prove compromise?
No. It proves a vulnerable state, not exploitation. Patch or isolate it, then investigate product, identity, endpoint and network evidence.
Should I run a public proof of concept to confirm a CVE?
Not on production. Confirm product, version, affected feature and exposure from vendor guidance. Use an authorised disposable lab only if exploit validation is genuinely required.
Is patching enough after known exploitation?
Not always. Preserve logs, contain exposed systems, rotate affected secrets and investigate persistence before returning a possibly compromised host to service.
Which item should come first?
Start with exposed unauthenticated RCE or admin bypass in your estate. Internet-reachable Metabase, TeamCity, Langflow, LoadMaster, FMC, VCO, SmartConsole or SharePoint normally outrank local elevation on an isolated endpoint, unless evidence or business impact changes the order.
Safety boundary
Use these checks only on systems you own or are authorised to administer. They collect version, configuration and evidence; they do not exploit the vulnerabilities. Do not paste public exploits into production, delete suspected persistence before preserving evidence, or return a patched host while credible compromise remains unresolved.
Primary references
- Known Exploited Vulnerabilities data mirrorCISA
- GHSA-q279-jhrf-cc6vRay Project
- CVE-2026-20349Cisco
- CVE-2026-68820Microsoft
- GHSA-vwf4-m7j8-wcjfMetabase
- LoadMaster critical bulletinProgress
- CVE-2026-63077JetBrains
- N-central 2026.3 HF1N-able
- Tomcat security updatesApache
- Langflow bulletinIBM
- CVE-2026-20316Cisco
- FG-IR-25-934Fortinet
- Advisory 0144Arista
- sk185169Check Point
- CVE-2026-50522Microsoft
First edition. Reviewed against CISA KEV data and the linked vendor material on 18 August 2026. Re-check every live advisory before operational use.