🛡️ Cyber Pulse Weekly | 17–23 August 2026 — Threats, CVEs, Attacks & AI Innovations

🛡️ Patch Priority: Top 10 Critical Vulnerabilities to Watch

  1. CVE-2026-33824 — Windows IKE Extension RCE

    CISA confirmed exploitation of this critical unauthenticated network RCE affecting supported Windows clients and servers. Apply Microsoft’s April update; where delayed, restrict UDP 500/4500 to known peers or block it when IKE is unused.

    Source: BleepingComputer — https://www.bleepingcomputer.com/news/security/cisa-critical-windows-ike-extension-flaw-now-exploited-in-attacks/

  2. CVE-2026-64849 — MLflow SSRF exposing cloud metadata

    Attackers exploit this critical unauthenticated SSRF bypass to reach internal services and cloud metadata, potentially stealing IAM credentials. Upgrade MLflow to 3.15.0 or later, review logs and rotate credentials that may have been exposed.

    Source: BleepingComputer — https://www.bleepingcomputer.com/news/security/cisa-warns-of-hackers-exploiting-critical-mlflow-vulnerability/

  3. CVE-2026-73570 — Zimbra command injection

    CERT Polska confirmed exploitation of this unauthenticated OS-command injection when SNMP notifications are enabled. Upgrade to Zimbra 10.1.20 and inspect web-application and temporary directories for attacker-created files.

    Source: BleepingComputer — https://www.bleepingcomputer.com/news/security/critical-zimbra-rce-flaw-now-actively-exploited-in-attacks/

  4. CVE-2026-72529 — TrueConf missing authentication

    CISA added this critical unauthenticated script-execution flaw to KEV after active exploitation. Apply TrueConf’s fixed release and investigate server-side installer changes or backdoors associated with Head Mare.

    Source: BleepingComputer — https://www.bleepingcomputer.com/news/security/cisa-orders-feds-to-patch-actively-exploited-trueconf-server-flaws/

  5. CVE-2026-72530 — TrueConf sandbox escape

    This companion critical flaw can let an unauthenticated attacker progress from isolated code execution to commands on the host OS. CISA confirmed active exploitation, making vendor remediation and compromise assessment urgent.

    Source: BleepingComputer — https://www.bleepingcomputer.com/news/security/cisa-orders-feds-to-patch-actively-exploited-trueconf-server-flaws/

  6. CVE-2025-60710 — Windows Task Host privilege escalation

    CISA updated the KEV entry to state that ransomware gangs exploit this high-severity local elevation-of-privilege flaw. Microsoft patched it in November 2025; Windows 11 and Server 2025 systems should be checked for update coverage.

    Source: BleepingComputer — https://www.bleepingcomputer.com/news/security/cisa-windows-task-host-flaw-now-exploited-by-ransomware-gangs/

  7. CVE-2026-19490 — NetScaler authentication bypass

    Citrix warned that specified NetScaler Gateway and ADC configurations permit remote unauthenticated authentication bypass. No exploitation was reported, but internet exposure and the product’s history justify rapid upgrade to Citrix’s fixed builds.

    Source: BleepingComputer — https://www.bleepingcomputer.com/news/security/citrix-urges-admins-to-patch-new-netscaler-flaws-as-soon-as-possible/

  8. CVE-2026-19489 — NetScaler denial of service

    This high-severity memory-overflow flaw affects appliances using SIP ALG in large-scale NAT configurations. Citrix reported no exploitation but urged customers to assess configuration preconditions and install fixed releases.

    Source: BleepingComputer — https://www.bleepingcomputer.com/news/security/citrix-urges-admins-to-patch-new-netscaler-flaws-as-soon-as-possible/

  9. CVE-2026-32475 — Elementor Pro arbitrary PHP upload

    The critical flaw can allow unauthenticated RCE when a published Elementor form has file upload and multiple-file upload enabled. Update Elementor Pro to 4.2.2 or later and inspect the forms upload directory because patching does not remove prior payloads.

    Source: BleepingComputer — https://www.bleepingcomputer.com/news/security/critical-elementor-pro-bug-exposes-wordpress-sites-to-rce-attacks/

  10. CVE-2026-69836 — Microsoft Entra ID RCE

    Microsoft patched a maximum-severity deserialization flaw that permitted unauthorized network attackers to execute code in Entra ID. Microsoft later said the advisory mistakenly marked it as exploited, so verify remediation without misreporting exploitation.

    Source: BleepingComputer — https://www.bleepingcomputer.com/news/microsoft/microsoft-warns-of-max-severity-entra-id-flaw-exploited-in-attacks/