Linux Kernel IPv6 Flaw Exploited; CISA Adds to KEV
Today's cybersecurity digest — CVEs, headline news, quantum computing, and something weird. August 31, 2026
cybr.cx — Daily Intelligence Digest | August 31, 2026
Critical Vulnerabilities
⚠️ Actively exploited — CVE-2026-53362 | Linux Kernel | IPv6 Privilege Escalation
The Linux kernel's IPv6 networking subsystem contains an unspecified flaw enabling local privilege escalation, now confirmed actively exploited in the wild and added to the CISA KEV catalog. RHEL, SUSE, and any distribution shipping a vulnerable kernel build is affected. Patch or mitigate immediately — this class of flaw is a staple of post-exploitation toolkits targeting cloud and container environments.
⚠️ Actively exploited — CVE-2022-0995 | Linux Kernel | Out-of-Bounds Memory Write
A second Linux kernel flaw, this one an out-of-bounds memory write, is also being actively exploited, allowing local users to escalate privileges or cause a denial of service. With two Linux kernel CVEs simultaneously on the KEV list, teams running self-managed Linux infrastructure should treat kernel patching as an emergency change this week.
⚠️ Actively exploited — CVE-2023-49105 | ownCloud | Authentication Bypass
ownCloud's improper authentication flaw allows unauthenticated attackers to read, modify, or delete any file — provided they know a valid username and the victim has no signing-key configured. CISA's remediation deadline has already passed (August 30). Any internet-facing ownCloud instance should be treated as compromised until patched and audited.
⚠️ Actively exploited — CVE-2026-66384 | JFrog Artifactory | Path Traversal
An authenticated path traversal in JFrog Artifactory allows writes outside the intended Docker cache directory under specific remote-repository conditions. Given Artifactory's role as a central artifact store in CI/CD pipelines, exploitation here is a direct route to supply chain compromise. Remediation due September 10 — don't wait.
⚠️ Actively exploited — CVE-2026-60004 | Gitea | Code Injection via Git Hook
Any user with repository write access in Gitea can send a malicious patch to the diffpatch API endpoint, plant an executable Git hook, and run arbitrary shell commands as the Gitea service account. Self-hosted Gitea deployments are a common blind spot for patching cadences — treat this as critical if you run one.
⚠️ Actively exploited — CVE-2021-23758 | Ajax.NET Professional (AjaxPro) | Remote Code Execution
A deserialization vulnerability in AjaxPro allows remote code execution via arbitrary .NET class instantiation. The product is likely end-of-life for most users, but CISA's active-exploitation flag confirms someone is actively hunting for it. If AjaxPro is anywhere in your estate, remove or isolate it now.
⚠️ Actively exploited — CVE-2019-1068 | Microsoft SQL Server | Remote Code Execution
A 2019-vintage RCE in Microsoft SQL Server is back on the radar, allowing code execution under the Database Engine service account context. Threat actors continue to weaponise old SQL Server vulnerabilities against unpatched or legacy deployments. Check your SQL Server versions and confirm patch status.
⚠️ Actively exploited — CVE-2026-8452 | Citrix NetScaler ADC / Gateway | Memory Buffer DoS
Citrix NetScaler ADC and Gateway contain an out-of-bounds memory buffer issue enabling denial of service. With CISA's remediation deadline already past (August 29), any unpatched appliance should be prioritised for emergency patching given how frequently NetScaler edge devices are targeted.
CVE-2026-82641 | keploy 3.1.0–3.6.25 | CVSS 8.6 — TLS Key Exposure
Keploy's agent control-plane HTTP server binds to all interfaces with no authentication, exposing /agent/pcap/keylog — an endpoint that streams NSS keylog lines in real time. Any attacker with network access can pull TLS session keys and decrypt captured traffic. Operators running keploy in shared or multi-tenant environments are exposed; upgrade to 3.6.26 or later and firewall the agent port.
CVE-2026-82653 & CVE-2026-82654 | SiYuan < v3.8.1 | CVSS 8.9 — Stored XSS
Two stored XSS vulnerabilities in the SiYuan note-taking application allow attackers to inject script payloads via malicious bazaar package names (CVE-2026-82653) or block name/alias/memo fields (CVE-2026-82654). Both execute in victims' browsers during normal application use — installing a package or viewing a document referencing a poisoned block. Upgrade to v3.8.1.
CVE-2026-82639 | NextChat 2.15.8–2.16.1 | CVSS 7.5 — API Key Theft
NextChat validates the x-base-url header using substring matching rather than proper hostname parsing, meaning any URL containing the string api.openai.com passes validation. Attackers can point the proxy at an attacker-controlled server and receive the victim server's OpenAI API key in the Authorization header. If you self-host NextChat, rotate your API keys and patch immediately.
Headline News
The HuggingFace Breach: A Postmortem Worth Reading Closely
A detailed postmortem from the organizations involved in responding to the HuggingFace platform compromise has surfaced, and it's one of the more technically candid incident reviews the ML security community has produced. The breach — which targeted one of the most widely used repositories for open-weight AI models and datasets — has significant supply chain implications, given that researchers and developers pull model weights directly from HuggingFace into production and research pipelines with relatively little verification. The postmortem examines how the attackers gained initial access, moved laterally within the platform's infrastructure, and the detection gaps that allowed dwell time to extend. For security practitioners, the incident is a timely reminder that AI/ML infrastructure now sits firmly in scope for supply chain threat modelling: a poisoned or backdoored model uploaded to a trusted repository is functionally equivalent to a compromised package registry. Teams consuming HuggingFace-hosted assets should review their model provenance practices and consider hash verification or signed model manifests as baseline hygiene.
European Commission Renews Push for Encryption Backdoors
The European Commission has resurrected its campaign for mandated law enforcement access to encrypted communications, this time under the banner of its ProtectEU security strategy. The proposal follows years of failed attempts to legislate so-called "client-side scanning" and lawful-access mechanisms, all of which have faced sustained technical and legal opposition from cryptographers, civil liberties organisations, and the security research community. The core problem remains unchanged: any mechanism that allows a third party to access encrypted communications at scale fundamentally weakens the encryption for everyone, including against the criminal actors the policy aims to target. For practitioners, the concern is practical as well as principled — if such legislation passed and was implemented in widely deployed communications libraries or platforms, it would represent a systemic vulnerability affecting European infrastructure that adversarial nation-states would immediately attempt to exploit. The debate is expected to intensify through autumn legislative sessions.
Schrödinger's Feed
Researchers have demonstrated that freezing optical fiber to cryogenic temperatures causes light and sound to interact approximately 1,000 times more strongly than at room temperature — a result with meaningful implications for quantum sensing and quantum memory architectures. Stronger light-sound coupling enables more precise manipulation of quantum states, which is directly relevant to building the low-noise, high-fidelity quantum hardware that future cryptographically relevant quantum computers will depend on. The work doesn't break any encryption today, but advances like this are precisely the kind of incremental hardware progress that closes the gap between current noisy intermediate-scale quantum (NISQ) devices and the fault-tolerant systems that could threaten RSA and ECC at scale. Practitioners tracking post-quantum migration timelines should note that hardware improvements often arrive faster than policy and procurement cycles — another reason not to treat PQC adoption as a problem for the next decade.
/dev/random
Haiku OS — the open-source spiritual successor to BeOS, a operating system that last had mainstream relevance sometime around the second Bush administration — has released R1/beta6, and people are genuinely excited about it. The release ships with a range of driver updates, performance improvements, and compatibility fixes for an OS whose entire userbase could probably fit in a mid-sized conference room, yet somehow keeps producing polished, well-documented releases. There's something quietly remarkable about a volunteer-driven project maintaining a complete, independent OS kernel, GUI stack, and package ecosystem in 2026 purely out of love for an interface philosophy that commercial vendors abandoned twenty years ago. Security professionals who've ever maintained a legacy system nobody else remembers will feel a deep, specific kinship with everyone who just downloaded beta6.