π‘οΈ Cyber Pulse Weekly | 17β23 August 2026 β Threats, CVEs, Attacks & AI Innovations
π CVE Watch: Top 10 CVEs β Severity, Impact & Patch Status
-
CVE-2026-33824 β Windows IKE Extension
Severity: Critical; CVSS: not quoted in the cited report; impact: unauthenticated RCE over UDP 500/4500; exploitation: confirmed by CISA. Patch status: fixed by Microsoft in April 2026, with firewall restrictions documented as interim mitigation.
Source: BleepingComputer β https://www.bleepingcomputer.com/news/security/cisa-critical-windows-ike-extension-flaw-now-exploited-in-attacks/
-
CVE-2026-64849 β MLflow webhook SSRF
Severity: Critical; CVSS: not quoted in the cited report; impact: unauthenticated access to internal services and cloud metadata with possible credential theft; exploitation: confirmed by CISA. Patch status: fixed in MLflow 3.15.0.
Source: BleepingComputer β https://www.bleepingcomputer.com/news/security/cisa-warns-of-hackers-exploiting-critical-mlflow-vulnerability/
-
CVE-2026-73570 β Zimbra Collaboration Suite
Severity: Critical; CVSS: not quoted in the cited report; impact: unauthenticated OS-command execution when SNMP notifications are enabled; exploitation: confirmed by CERT Polska. Patch status: fixed in Zimbra 10.1.20.
Source: BleepingComputer β https://www.bleepingcomputer.com/news/security/critical-zimbra-rce-flaw-now-actively-exploited-in-attacks/
-
CVE-2026-72529 β TrueConf Server
Severity: Critical; CVSS: not quoted in the cited report; impact: unauthenticated arbitrary script execution through TCP 4307; exploitation: listed by CISA as active. Patch status: vendor fixes are available and CISA set a remediation deadline.
Source: BleepingComputer β https://www.bleepingcomputer.com/news/security/cisa-orders-feds-to-patch-actively-exploited-trueconf-server-flaws/
-
CVE-2026-72530 β TrueConf Server
Severity: Critical; CVSS: not quoted in the cited report; impact: code injection and escape from the isolated environment to the host OS; exploitation: listed by CISA as active. Patch status: vendor remediation is available.
Source: BleepingComputer β https://www.bleepingcomputer.com/news/security/cisa-orders-feds-to-patch-actively-exploited-trueconf-server-flaws/
-
CVE-2025-60710 β Windows Task Host
Severity: High; CVSS: not quoted in the cited report; impact: a local basic user can reach SYSTEM on Windows 11 and Server 2025; exploitation: CISA says ransomware gangs use it. Patch status: fixed in Microsoftβs November 2025 updates.
Source: BleepingComputer β https://www.bleepingcomputer.com/news/security/cisa-windows-task-host-flaw-now-exploited-by-ransomware-gangs/
-
CVE-2026-19490 β NetScaler Gateway and ADC
Severity and CVSS: not quoted in the cited report; impact: remote unauthenticated authentication bypass under specified AAA, Gateway or SAML configurations; exploitation: not reported. Patch status: fixed builds include 14.1-73.32 and 13.1-63.21 or later, with listed FIPS/NDcPP equivalents.
Source: BleepingComputer β https://www.bleepingcomputer.com/news/security/citrix-urges-admins-to-patch-new-netscaler-flaws-as-soon-as-possible/
-
CVE-2026-19489 β NetScaler ADC
Severity: High; CVSS: not quoted in the cited report; impact: remote unauthenticated denial of service where SIP ALG is enabled in a large-scale NAT group; exploitation: not reported. Patch status: Citrix published fixed releases and configuration checks.
Source: BleepingComputer β https://www.bleepingcomputer.com/news/security/citrix-urges-admins-to-patch-new-netscaler-flaws-as-soon-as-possible/
-
CVE-2026-32475 β Elementor Pro
Severity: Critical; CVSS: not quoted in the cited report; impact: executable-file upload leading to RCE on qualifying forms; exploitation: none observed at publication. Patch status: fixed in Elementor Pro 4.2.2.
Source: BleepingComputer β https://www.bleepingcomputer.com/news/security/critical-elementor-pro-bug-exposes-wordpress-sites-to-rce-attacks/
-
CVE-2026-69836 β Microsoft Entra ID
Severity: Maximum severity according to the cited report; CVSS: not quoted; impact: unauthorized RCE through unsafe deserialization; exploitation: Microsoft said the initial exploited flag was erroneous. Patch status: Microsoft reported the flaw as patched.
Source: BleepingComputer β https://www.bleepingcomputer.com/news/microsoft/microsoft-warns-of-max-severity-entra-id-flaw-exploited-in-attacks/