██████╗██╗   ██╗██████╗ ██████╗     ██████╗██╗  ██╗
 ██╔════╝╚██╗ ██╔╝██╔══██╗██╔══██╗   ██╔════╝╚██╗██╔╝
 ██║      ╚████╔╝ ██████╔╝██████╔╝ ● ██║      ╚███╔╝ 
 ██║       ╚██╔╝  ██╔══██╗██╔══██╗   ██║      ██╔██╗ 
 ╚██████╗   ██║   ██████╔╝██║  ██║   ╚██████╗██╔╝ ██╗
  ╚═════╝   ╚═╝   ╚═════╝ ╚═╝  ╚═╝    ╚═════╝╚═╝  ╚═╝
────────────────────────────────── STAY SHARP ───

CISA Orders ownCloud Patch by Saturday — Exploit Active Now

Today's cybersecurity digest — CVEs, headline news, quantum computing, and something weird. August 28, 2026

Share

cybr.cx | Daily Digest — August 28, 2026


Critical Vulnerabilities

⚠️ Actively exploited — CVE-2023-49105 | ownCloud | No CVSS in KEV data
CISA added this to the KEV catalogue yesterday with a remediation deadline of August 30 — patch or isolate immediately. The flaw allows completely unauthenticated access to any file if an attacker knows a valid username and the account has no signing-key configured, meaning read, write, and delete are all on the table. Any internet-exposed ownCloud instance should be treated as compromised until patched.

⚠️ Actively exploited — CVE-2026-53362 | Linux Kernel (IPv6 subsystem)
Also KEV-listed yesterday with a 72-hour remediation window ending August 30. The vulnerability enables privilege escalation via the IPv6 networking stack and affects downstream distributions including SUSE and Red Hat. The breadth of exposure across Linux-based infrastructure — servers, containers, network appliances — makes this a top-priority patch regardless of your distribution.

⚠️ Actively exploited — CVE-2022-0995 | Linux Kernel
An out-of-bounds memory write that gives local users a path to full privilege escalation or denial of service. KEV deadline is September 9, but active exploitation means that timeline should be treated as a ceiling, not a target. Kernel updates addressing this should be expedited through your patching pipeline.

⚠️ Actively exploited — CVE-2026-66384 | JFrog Artifactory
An authenticated path traversal flaw allowing data to be written outside the intended Docker cache directory under certain remote-repository configurations. KEV deadline is September 10, but authenticated-only doesn't mean low risk — supply chain attack scenarios where a threat actor already holds low-privilege credentials make this particularly dangerous in CI/CD-heavy environments.

⚠️ Actively exploited — CVE-2021-23758 | Ajax.NET Professional (AjaxPro)
A deserialization vulnerability enabling remote code execution via arbitrary .NET class instantiation. The product is effectively end-of-life, which is likely why exploitation has resurfaced — legacy .NET web applications are rarely monitored closely. If AjaxPro is anywhere in your estate, the answer is removal, not patching.

⚠️ Actively exploited — CVE-2026-60004 | Gitea
Any user with repository write access can send a crafted patch to the diffpatch API endpoint, plant an executable Git hook, and achieve shell execution as the Gitea service account. This is a significant risk for self-hosted Gitea instances in development environments, where the service account often carries elevated permissions. KEV deadline was today — treat this as urgent.

CVE-2026-76639 | Unitree G1 EDU Robot Firmware ≤ 1.5.2 | CVSS 8.8
Three weaknesses chain into unauthenticated root-level RCE on the Unitree G1 humanoid robot: an open WebRTC-to-DDS bridge on TCP 9991, a world-readable hardcoded AES-128 key, and a path traversal in the knowledge-upload API. Network-adjacent attackers — think same Wi-Fi, same lab network — get full root. Research and educational robotics environments should apply the firmware update and firewall port 9991 immediately.

CVE-2026-10036 | SpeechBrain < 1.1.1 | CVSS 8.8
PyYAML's unsafe loader is used when parsing CKPT.yaml checkpoint metadata files, meaning any attacker who can supply a crafted checkpoint can embed !!python/object/apply tags and execute arbitrary code in the context of the training process. ML pipelines that load checkpoints from external or untrusted sources — model hubs, shared storage — are directly at risk. Upgrade to 1.1.1, which enforces the safe loader.

CVE-2026-81730 / CVE-2026-81728 | Dolibarr ERP ≤ 23.0.4 / < 24.0.0 | CVSS 8.2
Two distinct high-severity flaws in Dolibarr: a path traversal in email attachment handling that allows writing files to arbitrary server paths via malicious MIME Content-Disposition headers (8.2), and a SQL injection in the CSV/XLSX import wizard where the updatekeys parameter receives only superficial HTML-stripping rather than proper parameterisation (8.1). Either flaw alone warrants immediate patching; together they represent a serious exposure for any internet-facing Dolibarr deployment.

CVE-2026-5680 | Red Hat Undertow (WebSocket) | CVSS 7.5
Specially crafted WebSocket messages with permessage-deflate compression negotiated trigger exponential memory doubling in PerMessageDeflateFunction.largerBuffer(), enabling remote denial of service. Any application server using Undertow's WebSocket stack with permessage-deflate enabled should apply the vendor patch or disable the extension as a temporary mitigation.


Headline News

Boston Scientific Hit by Cyberattack, Global Operations Disrupted

Medical device giant Boston Scientific is dealing with significant global operational disruptions following a cyberattack, with impacts rippling through its manufacturing and supply chain infrastructure. The incident raises acute concerns about patient care continuity — Boston Scientific produces cardiac rhythm management devices, endoscopy equipment, and other life-critical hardware where supply interruptions carry real clinical consequences. For practitioners, this is a textbook illustration of why operational technology (OT) and medical device networks require isolation architecture: a breach that touches business systems shouldn't be able to halt production lines. The medtech sector has historically lagged on OT segmentation, and incidents like this are the inevitable result. Expect scrutiny of third-party supplier dependencies as the full scope becomes clearer in the coming days.

Kiewit Corporation Breach Exposes Employee and Contractor Data

Kiewit Corporation, one of North America's largest construction and engineering conglomerates, has disclosed a cybersecurity incident resulting in exposure of personal information belonging to employees and contractors. The breach is notable for its potential scale — Kiewit operates across hundreds of large infrastructure projects and maintains personnel records for a substantial workforce spanning multiple countries. For security teams, the contractor data angle is significant: third-party personnel records often include sensitive onboarding information, background check data, and financial details that provide rich material for follow-on phishing or identity fraud campaigns targeting critical infrastructure worksites. Construction and engineering firms have become increasingly attractive targets given their intersection with sensitive government and defence contracts. Affected individuals should treat any suspicious outreach referencing employment details as a potential spear-phishing attempt.


Schrödinger's Feed

NASA has awarded a $20 million follow-on contract for continued development of a Quantum Gravity Gradiometer, a sensing technology that uses quantum interference to measure gravitational field variations with extraordinary precision. While not a cryptography story, the security implications are real and underappreciated: quantum gravimeters of sufficient sensitivity can detect subsurface voids, tunnels, buried infrastructure, and even submarine movements through gravitational anomaly mapping — capabilities previously requiring extensive ground survey access. A spaceborne or airborne quantum gravity sensor at this maturity level would represent a significant shift in physical infrastructure intelligence gathering. Practitioners involved in critical infrastructure protection, especially facilities with classified or hardened underground components, should be tracking the maturation of quantum sensing alongside post-quantum cryptography.


/dev/random

The /dev/random slot is supposed to be light relief, but this week's most-discussed oddity is Nvidia registering a political action committee — officially entering the DC influence game alongside the chip fabs, defence primes, and Big Tech lobbyists it increasingly competes with. The move comes as export controls, AI compute restrictions, and national security reviews of semiconductor supply chains make Washington arguably as important a theatre as any data centre. There's a certain symmetry in the company whose GPUs train models that automate everything now needing humans to manually walk the halls of Congress. At least the PAC presumably can't be jailbroken with a clever system prompt. Yet.