Gitea Zero-Day Exploited: CISA Demands Patch by Tomorrow
Today's cybersecurity digest — CVEs, headline news, quantum computing, and something weird. August 27, 2026
cybr.cx Daily Digest — August 27, 2026
Critical Vulnerabilities
⚠️ Actively exploited — CVE-2026-60004 | Gitea | CVSS 9.x (KEV)
Attackers with repository write access can send a malicious patch to Gitea's diffpatch API endpoint to plant an executable Git hook, achieving shell command execution as the Gitea service account. With CISA's remediation deadline of August 28, if you're running Gitea, this is a today problem — check for unexpected hook files and update immediately.
⚠️ Actively exploited — CVE-2026-8452 | Citrix NetScaler ADC & Gateway (KEV)
An out-of-bounds memory buffer vulnerability in NetScaler ADC and Gateway is being actively exploited, leading to denial of service. Remediation due August 29 — NetScaler appliances sitting at the perimeter need to be patched or mitigated before the weekend.
⚠️ Actively exploited — CVE-2019-1068 | Microsoft SQL Server (KEV)
A seven-year-old remote code execution flaw in SQL Server is seeing active exploitation, allowing attackers to execute arbitrary code under the Database Engine service account context. The fact this is being actively weaponised in 2026 suggests opportunistic scanning for unpatched legacy instances. Remediation deadline: August 29.
⚠️ Actively exploited — CVE-2022-0995 | Linux Kernel (KEV)
An out-of-bounds memory write in the Linux Kernel allows a local user to escalate privileges or trigger denial of service. Active exploitation makes this particularly relevant in shared hosting, container breakout, and insider threat scenarios — audit your kernel versions across your fleet now.
⚠️ Actively exploited — CVE-2021-23758 | Ajax.NET Professional (AjaxPro) (KEV)
A deserialization of untrusted data vulnerability in the AjaxPro library allows remote code execution via arbitrary .NET class instantiation. This product is likely end-of-life in most environments — if it's still present, it needs to go. Deadline: September 9.
⚠️ Actively exploited — CVE-2015-3246 & CVE-2015-5287 | Red Hat libuser / ABRT (KEV)
Two decade-old Red Hat local privilege escalation flaws — a race condition in libuser that can corrupt /etc/passwd, and a symlink attack in the Automatic Bug Reporting Tool — are being actively exploited. Their presence on the 2026 KEV list is a pointed reminder that legacy RHEL systems in long-running enterprise environments remain active targets.
CVE-2026-80193 | Kimai | CVSS 8.8
An authorisation bypass in Kimai's QuickEntry controller allows authenticated users with timesheet view/edit permissions to create timesheet records for other team members. The missing create_other_timesheet permission check could be abused for time fraud or attendance manipulation. Upgrade to 2.62.0.
CVE-2026-81036 | Stalwart Mail Server | CVSS 8.1
Stalwart's OAuth implementation skips redirect URI validation entirely when client authentication is disabled — which is the default shipped configuration. An attacker can supply an arbitrary redirect target and intercept authorization codes. If you're running Stalwart Mail Server with OAuth enabled, treat this as critical until patched.
CVE-2026-80186 | BlueZ (Linux Bluetooth) | CVSS 7.6
A stack-based buffer overflow in BlueZ can be triggered by a malicious Extended Inquiry Response (EIR) packet sent by any device within Bluetooth radio range during discovery. At minimum this crashes bluetoothd; code execution is not ruled out. Disable Bluetooth discovery on exposed systems and monitor for upstream patches.
CVE-2026-73108 | RustDesk | CVSS 7.5
Before authentication completes, RustDesk's BytesCodec trusts a four-byte frame header and will attempt to reserve up to ~1GB of memory per connection. Concurrent TCP connections can exhaust system memory, causing denial of service without any credentials. Upgrade to 1.4.7 — particularly important for organisations using RustDesk as a remote support tool.
CVE-2026-15990 | Formidable Charts (WordPress) | CVSS 7.5
Unauthenticated directory traversal via the frm_graph parameter allows arbitrary file reads on the server. Requires Formidable Forms Lite, Pro, and Charts to all be installed, but that's a common combination. Any WordPress instance running all three up to version 2.0.1 is exposing server files to the internet — patch or remove the plugin.
CVE-2026-81031 | IDURAR ERP CRM | CVSS 7.2
A broken access control flaw means the password update handler targets whichever account ID appears in the URL path rather than the authenticated session. Any authenticated user can reset another account's password by simply changing the identifier in the request. Privilege escalation to admin is trivial.
Headline News
Norway's Government Hit by Its Largest DDoS Yet — 30 Hours of Disruption
Norway's shared government digital infrastructure sustained its third significant DDoS campaign, this time two to three times larger in volume than previous incidents, knocking ten public services offline or unstable for over 30 consecutive hours. Casualties included ID-porten, MinID, Altinn, and national e-signing infrastructure — systems that underpin citizen identity verification and public service delivery across the country. The pattern of repeated, escalating attacks against the same shared infrastructure reveals a deliberate campaign rather than opportunistic noise, and the 30-hour duration suggests the attackers were either well-resourced or the mitigation playbook needed updating after prior incidents. For practitioners, the case reinforces that shared government platforms — attractive for their breadth of impact — need layered, rehearsed DDoS resilience, not just volume thresholds.
Omarchy's Development Practices Expose a Familiar Problem
A detailed technical post examining Omarchy — a Linux distribution and dotfile framework — found that its development and distribution practices introduce predictable, structural security risks rather than accidental one-off bugs. The analysis surfaces issues around how software is fetched, verified (or not), and executed during setup, making supply chain compromise an accessible attack path for anyone who can influence upstream sources. The story resonated broadly in practitioner circles because it illustrates a pattern common far beyond Omarchy: projects that prioritise developer convenience during bootstrapping routinely skip integrity checks, signature verification, and sandboxing at precisely the moment when trust should be highest. It's a useful case study for teams auditing their own internal tooling and onboarding scripts.
AI Is Compressing the Window Between Disclosure and Exploit
Analysis from Microsoft confirms what practitioners have been sensing: AI-assisted vulnerability research is materially shrinking the time between public disclosure and weaponised exploit development, in some cases collapsing a window that once spanned weeks into a matter of hours. The implication for enterprise patch management is serious — change control cycles built around a "reasonable" 30-day patch window are increasingly misaligned with actual attacker timelines. Microsoft's suggested mitigations lean heavily on network-enforced, continuous controls rather than patch velocity alone, acknowledging that patching speed has a practical ceiling. For security teams, this is a prompt to revisit compensating controls — default-deny network segmentation, runtime behavioural detection, and exploitation telemetry — that can hold the line when patches can't land fast enough.
Schrödinger's Feed
IBM's completed acquisition of HRL Laboratories brings silicon-spin qubit expertise, cryogenic engineering, and advanced materials research directly into IBM's quantum programme — a meaningful expansion beyond IBM's existing superconducting qubit roadmap. Silicon-spin qubits are interesting to the security community because their potential for high-qubit-density integration on conventional CMOS processes could accelerate the timeline to fault-tolerant quantum systems capable of threatening current public-key cryptography. Separately, QuantumX Labs has launched Qatacomb, a research initiative explicitly focused on quantum-native approaches to protecting sensitive data — a sign that the industry is beginning to treat post-quantum security as a design constraint rather than a future consideration. Practitioners not yet tracking their organisation's cryptographic inventory against NIST's finalised PQC standards should treat consolidation moves like this as a signal that the clock is running faster than the headlines suggest.
/dev/random
Tailscale has released tailcat — a spiritual successor to netcat, but tunnelled entirely over Tailscale's encrypted WireGuard-based data plane rather than raw TCP. The practical upshot: you can pipe arbitrary data between nodes on your tailnet without opening firewall ports, spinning up a listener on a public address, or explaining to your CISO why there's a netcat binary in production. It inherits Tailscale's existing authentication and ACL model, which is either reassuring or a reminder to double-check your tailnet ACLs depending on how that conversation went last time. Raw networking primitives wrapped in a zero-trust mesh: genuinely useful, and almost certainly about to appear in a pentest toolkit near you.