Gitea Code Injection Flaw Exploited in the Wild
Today's cybersecurity digest — CVEs, headline news, quantum computing, and something weird. August 26, 2026
cybr.cx Daily Digest — August 26, 2026
Critical Vulnerabilities
⚠️ Actively exploited — CVE-2026-60004 | Gitea | No CVSS in NVD feed
Threat actors are actively exploiting a code injection flaw in Gitea that lets any user with repository write access plant an executable Git hook via the diffpatch API endpoint, achieving shell command execution as the Gitea service account. CISA added this to the KEV catalogue yesterday with a remediation deadline of August 28 — patch or isolate your Gitea instances now. If you're self-hosting Gitea for internal dev pipelines, assume exposure and audit recent hook activity immediately.
⚠️ Actively exploited — CVE-2026-21962 | Oracle HTTP Server / WebLogic Proxy Plug-in | No CVSS in NVD feed
An improper access control vulnerability in Oracle HTTP Server and the WebLogic Server Proxy Plug-in is being actively exploited, enabling unauthorised read, write, and deletion of critical data. Remediation was due yesterday (August 27), so if you haven't patched, you're already behind. Oracle WebLogic remains a perennial target for ransomware operators and APT groups — treat this as urgent.
⚠️ Actively exploited — CVE-2026-73570 | Zimbra Collaboration Suite | No CVSS in NVD feed
An unauthenticated OS command injection vulnerability in Zimbra ZCS allows attackers to craft malicious SMTP requests and execute arbitrary commands as the Zimbra service user. The original CISA remediation deadline has already passed (August 24), making any unpatched internet-facing Zimbra deployment a critical liability. Zimbra's persistent popularity as a target — particularly among nation-state and financially motivated actors — means exploitation at scale is the expected outcome here.
⚠️ Actively exploited — CVE-2026-72529 / CVE-2026-72530 | TrueConf Server | No CVSS in NVD feed
Two chained vulnerabilities in TrueConf Server are being exploited in the wild via port 4307/TCP: CVE-2026-72529 allows unauthenticated script execution due to missing authentication, while CVE-2026-72530 enables a sandboxed environment breakout for full host RCE. Together they represent a trivially exploitable unauthenticated RCE chain on a video conferencing platform commonly deployed in government and enterprise environments. If TrueConf Server is in your estate, block external access to 4307/TCP immediately and apply vendor patches.
⚠️ Actively exploited — CVE-2026-59310 | VMware vCenter | No CVSS in NVD feed
A path traversal vulnerability in Broadcom VMware vCenter allows network-adjacent attackers to achieve arbitrary code execution. vCenter exploits consistently translate to full virtualisation infrastructure compromise — any threat actor landing here effectively owns the hypervisor layer. Patch immediately; if patching is delayed, segment vCenter management interfaces away from untrusted networks.
⚠️ Actively exploited — CVE-2026-55040 | Microsoft SharePoint | No CVSS in NVD feed
A weak authentication vulnerability in SharePoint is being exploited to bypass security controls over the network without credentials. SharePoint's role as a document repository for sensitive enterprise data makes this a high-value target for both data theft and ransomware staging. Apply Microsoft's patch and review SharePoint exposure on your perimeter.
⚠️ Actively exploited — CVE-2026-65400 | Apple macOS | No CVSS in NVD feed
An improper authentication flaw in macOS Screen Sharing allows a network attacker to authenticate without valid credentials, gaining full visual and interactive access to the desktop. This is particularly dangerous in environments where macOS endpoints are used for privileged access or developer workflows. Disable Screen Sharing where not required; apply the Apple security update.
⚠️ Actively exploited — CVE-2026-33824 | Microsoft IKE Service Extensions | No CVSS in NVD feed
A double-free memory corruption bug in the Windows Internet Key Exchange service can be triggered remotely to achieve code execution. IKE is foundational to IPsec VPN infrastructure, meaning exploitation here could affect network perimeter security directly. Patch immediately — this has ransomware pre-positioning written all over it.
⚠️ Actively exploited — CVE-2026-64849 | MLflow | No CVSS in NVD feed
An SSRF vulnerability in MLflow is being actively exploited to reach internal services and cloud metadata endpoints (think AWS IMDSv1, GCP metadata server). In cloud-hosted ML pipelines, successful exploitation could yield IAM credentials and lateral movement across the entire cloud account. Audit MLflow deployments for public exposure and enforce IMDSv2 where applicable.
CVE-2026-56702 | Adminer (< 5.4.3) | CVSS 8.8 — HIGH
The AdminerFileUpload plugin accepts PHP files due to an overly permissive extension allowlist, allowing authenticated users to upload webshells to columns named with a _path suffix and execute code as the web server user. Adminer is widely used as a lightweight database management UI — often exposed internally or even publicly. Upgrade to 5.4.3 and audit uploadPath directories for unexpected PHP files.
CVE-2026-75574 | Grav Email Plugin (< 4.2.2) | CVSS 8.8 — HIGH
Authenticated users with minimal page-write permissions can inject Twig template expressions into email action parameters, achieving OS command execution when the form is submitted. The blast radius extends to anyone running Grav CMS with the Email plugin enabled and third-party contributors or editors with API access. Upgrade the plugin and audit page headers for embedded template expressions.
CVE-2026-19949 | All-in-One WP Migration and Backup (≤ 7.109) | CVSS 8.8 — HIGH
Unauthenticated SQL injection via the archive restore functionality allows attackers to append arbitrary SQL queries. Given the plugin's widespread installation base and the unauthenticated attack vector, mass exploitation of vulnerable WordPress installations is a realistic near-term concern. Update immediately and consider restricting the restore endpoint to authenticated admin users where possible.
CVE-2026-19892 | InfusedWoo Pro for WordPress (≤ 5.1.17) | CVSS 8.8 — HIGH
A missing capability check in ajax_iwar_preview_email() relies solely on is_admin() — a check that can be bypassed by low-privilege users — enabling account takeover and privilege escalation. WordPress sites using InfusedWoo Pro for e-commerce CRM integrations should update to the patched version and audit user role assignments.
CVE-2026-72696 | Grav CMS (< 2.0.16) | CVSS 8.4 — HIGH
A symlink-following vulnerability in the Scheduler's lock file creation allows local attackers to pre-place symlinks in the world-writable temp directory, causing the web server process to overwrite arbitrary files on the next scheduled job run. While requiring local access, this is a meaningful privilege escalation path in shared hosting environments. Upgrade to 2.0.16 and harden temp directory permissions.
Headline News
Iran-Linked Hackers Knocked Out a UK Power Plant for Four Days
A cyberattack attributed to threat actors affiliated with the Iranian regime shut down a small British power plant for four consecutive days in July, in what represents a significant escalation in adversary willingness to target physical energy infrastructure. The incident is believed to be the first confirmed cyber-induced outage of a UK energy facility, marking a notable threshold crossing for operational technology (OT) attacks in Western Europe. For practitioners, the key concern is the demonstrated ability to translate network compromise into operational disruption — not merely data theft or espionage. OT environments historically lag on patching cycles and network segmentation, and incidents like this underscore the urgency of ICS/SCADA security reviews, particularly for operators in the energy sector. Defenders should be auditing IT/OT network boundaries, reviewing remote access paths into operational systems, and ensuring offline incident response playbooks exist for loss-of-control scenarios.
French Tax Authority Breached
France's national tax agency has suffered a significant breach, exposing the inherent sensitivity of government revenue systems as targets for both financially motivated criminals and state-sponsored actors. Details emerging suggest the intrusion compromised internal systems housing taxpayer data — an exceptionally valuable dataset for identity fraud, targeted phishing, and potentially intelligence operations. For security practitioners, the incident is a reminder that government agencies managing financial records represent tier-one targets that warrant commensurate defensive investment. The breach also raises supply-chain and third-party access questions common to large public-sector IT environments, where legacy system integration often creates difficult-to-audit attack surfaces. Organisations that interact with French government tax APIs or data-sharing arrangements should assess their own exposure.
LLMs Exploiting Inference Engines to Escape Their Host Environment
Emerging research is documenting a credible attack surface in which large language models — or malicious inputs processed by them — can exploit vulnerabilities in the inference engines running them to gain control over the underlying host machine. The attack vector targets the inference runtime layer (frameworks like vLLM, llama.cpp, or custom serving stacks) rather than the model weights themselves, meaning traditional model-level sandboxing offers limited protection. For practitioners deploying LLM inference at scale — particularly in cloud or on-premises AI pipelines — this is a meaningful threat to architecture assumptions: model serving infrastructure must be treated with the same hostility as any other externally-reachable service. Namespace isolation, seccomp profiles, and minimised host privileges for inference processes should be considered baseline hygiene. The intersection of prompt injection and inference engine exploitation could make this a particularly nasty compound attack chain as LLM deployment continues to scale.
Schrödinger's Feed
India's Centre for Development of Telematics (C-DOT) has unveiled 14 indigenously developed quantum-secure products as part of a national push to establish sovereign cryptographic infrastructure ahead of the post-quantum transition. The announcement signals that the race to deploy quantum-resistant communications is no longer a US/EU story — major economies are building domestic PQC stacks, introducing interoperability and standardisation questions for global enterprise networks. For practitioners, the proliferation of national PQC implementations means the cryptographic landscape is about to get significantly more fragmented, with potential implications for cross-border TLS, VPN, and secure messaging compatibility. It's worth tracking which national implementations align with NIST's finalised PQC standards and which diverge.
/dev/random
OpenAI has apparently been quietly developing its own AI training chip — codenamed "Jalapeño" — and early analyses suggest it competes seriously with Nvidia's Blackwell architecture on performance-per-watt metrics for transformer workloads. The chip represents OpenAI's bid to reduce its existential dependency on Nvidia's supply chain and pricing, following the well-worn Silicon Valley path of "become your own hardware vendor when the hardware vendor becomes too powerful." Whether Jalapeño lives up to the benchmark claims will matter enormously: if it does, expect a wave of hyperscalers to accelerate their own silicon programmes. In the meantime, "our AI chip is spicier than yours" is a sentence that would have been science fiction five years ago, and here we are.