Continue reading the full briefing.
A flaw was found in the managedcluster-import-controller. The Certificate Signing Request (CSR) auto-approval logic improperly validates incoming CSRs, specifically by not inspecting the signer name or decoding the PEM-encoded x509 CSR. This vulnerability allows a privileged service account on a spoke cluster to submit a malicious CSR. Successful exploitation can lead to privilege escalation, enabling the attacker to obtain administrative credentials on the hub cluster.
Why it matters: A flaw was found in the managedcluster-import-controller. The Certificate Signing Request (CSR)… belongs in an exploit-led queue only after the affected product is matched to a reachable asset and accountable owner.
What to verify: Separate confirmed applicability from broad advisory language, assign the remediation decision, and keep any exception visible with an expiry date.
Open the original source record
CVE-2026-71472: A flaw was found in acm-search-v2-rhel9. This vulnerability allows an authenticated attacker,…
A flaw was found in acm-search-v2-rhel9. This vulnerability allows an authenticated attacker, such as a hub administrator or a Search Custom Resource (CR) editor, to inject malicious shell commands or SQL statements. This occurs because the WORK_MEM string provided in the Search CR is not properly validated before being used in a bash script and an SQL query. Successful exploitation could lead to arbitrary code execution within the privileged postgres pod, potentially compromising the system.
Why it matters: A flaw was found in acm-search-v2-rhel9. This vulnerability allows an authenticated attacker,… belongs in an exploit-led queue only after the affected product is matched to a reachable asset and accountable owner.
What to verify: Confirm the affected version and reachable component, preserve useful telemetry, apply the publisher guidance, and record the evidence used to close the item.
CVE-2026-66792: A flaw was found in the multicloud-operators-subscription component. This vulnerability allows a…
A flaw was found in the multicloud-operators-subscription component. This vulnerability allows a user on a managed cluster to escalate their privileges by creating a Subscription with specific, crafted annotations. Successful exploitation grants the attacker the ability to deploy resources into any namespace with the elevated permissions of the controller's Service Account, potentially leading to unauthorized access and control over cluster resources.
Why it matters: A flaw was found in the multicloud-operators-subscription component. This vulnerability allows a… belongs in an exploit-led queue only after the affected product is matched to a reachable asset and accountable owner.
What to verify: Start with asset ownership and exposure, compare the fixed release with the deployed build, and validate both security behavior and service health afterward.
CVE-2026-74899: Openssl_encrypt versions before 1.4.0 contain a sandbox escape vulnerability in IsolatedPluginExecutor that…
openssl_encrypt versions before 1.4.0 contain a sandbox escape vulnerability in IsolatedPluginExecutor that exposes Python type objects in restricted exec() builtins. Attackers can traverse the Python class hierarchy via __class__.__mro__.__subclasses__() to access system functions and execute arbitrary OS commands.
Why it matters: Openssl_encrypt versions before 1.4.0 contain a sandbox escape vulnerability in IsolatedPluginExecutor that… belongs in an exploit-led queue only after the affected product is matched to a reachable asset and accountable owner.
What to verify: Separate confirmed applicability from broad advisory language, assign the remediation decision, and keep any exception visible with an expiry date.
CVE-2026-74872: Openssl_encrypt versions before 1.4.0 contain an arbitrary code execution vulnerability in the…
openssl_encrypt versions before 1.4.0 contain an arbitrary code execution vulnerability in the Whirlpool hash implementation that uses broad glob patterns to load .so modules without integrity verification. Attackers can place malicious .so files matching the whirlpool*py313*.so pattern in site-packages directories to achieve native code execution when the module is loaded.
Why it matters: Openssl_encrypt versions before 1.4.0 contain an arbitrary code execution vulnerability in the… belongs in an exploit-led queue only after the affected product is matched to a reachable asset and accountable owner.
What to verify: Confirm the affected version and reachable component, preserve useful telemetry, apply the publisher guidance, and record the evidence used to close the item.
Coverage by security desk
Exploited and critical vulnerabilities
- CVE-2025-62593: Ray-Project Ray Code Injection Vulnerability – Ray-Project Ray contains a code injection vulnerability that could allow remote code execution. Developers using Ray as a development tool may be exposed to this vulnerability exploitable through…
- CVE-2026-15748: The Forminator Forms plugin for WordPress is vulnerable to Arbitrary File Upload… – The Forminator Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.56.1 via the handle_file_upload function. This is due to…
- CVE-2026-75094: A flaw has been found in COMFAST CF-N1-S 2.6.0.1. This impacts the… – A flaw has been found in COMFAST CF-N1-S 2.6.0.1. This impacts the function sub_44B438 of the file /cgi-bin/mbox-config?method=SET§ion=ptest_ssid of the component CGI Interface. This manipulation of the argument…
Linux and open-source operations
- USN-8631-4: Linux kernel (Azure CVM) vulnerabilities – Siebe Devroe, Héloïse Gollier, and Mathy Vanhoef discovered that the WiFi implementation in the Linux kernel did not properly handle aggregated frames in mesh networks, due to an…
Network, VPN, firewall, and edge security
- SonicWall GMS Security Affected By Multiple Vulnerabilities – SonicWall GMS (Virtual Appliance, Windows) – 9.5.1 and earlier versions are vulnerable to the following security issues.1) CVE-2026-66145 – An unauthenticated remote code execution vulnerabilityAn unauthenticated remote code…
- Cisco Advance Notification for Publication of August 19, 2026, Security Advisories – On August 19, 2026, the Cisco Product Security Incident Response Team (PSIRT) will publish advisories to disclose security vulnerability information along with fixed software releases for the following…
Web applications, APIs, and WordPress
- CVE-2026-15748: The Forminator Forms plugin for WordPress is vulnerable to Arbitrary File Upload… – The Forminator Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.56.1 via the handle_file_upload function. This is due to…
- WordPress 7.0.4 Release – WordPress 7.0.4 is now available WordPress 7.0.4 is now available which features a security fix. Because this is a security release, it is recommended that you update your…
DevOps and software supply chain
- What 50 open source projects taught us about security in the AI era – See how the open source projects in Session 4 of the GitHub Secure Open Source Fund combined AI-assisted workflows, maintainer expertise, GitHub security tools, expert guidance, and funding…
AI and agent security
- CVE-2026-75110: MemOS is a memory operating system for LLMs and AI agents. In… – MemOS is a memory operating system for LLMs and AI agents. In deployments where authentication is enabled (AUTH_ENABLED=true) but the undocumented, defaultless INTERNAL_SERVICE_SECRET environment variable is unset, the…
- What 50 open source projects taught us about security in the AI era – See how the open source projects in Session 4 of the GitHub Secure Open Source Fund combined AI-assisted workflows, maintainer expertise, GitHub security tools, expert guidance, and funding…
Cloud and identity controls
- USN-8631-4: Linux kernel (Azure CVM) vulnerabilities – Siebe Devroe, Héloïse Gollier, and Mathy Vanhoef discovered that the WiFi implementation in the Linux kernel did not properly handle aggregated frames in mesh networks, due to an…
Priority actions for today
- Confirm exposure: match CVEs and vendor advisories to exact products, versions, internet reachability, and business-critical roles.
- Move exploited items first: patch, isolate, or disable affected paths for confirmed known-exploited technology before routine CVSS-only work.
- Preserve evidence: review authentication, process, endpoint, network, and management-plane telemetry before rebooting or replacing an affected system.
- Validate remediation: prove that the fixed version is running, required restarts are complete, controls still report healthy, and exceptions have owners and deadlines.
Primary sources and references
- CISA Known Exploited Vulnerabilities: CVE-2025-62593: Ray-Project Ray Code Injection Vulnerability
- CISA Cybersecurity Advisories: CVE-2025-62593: Ray-Project Ray Code Injection Vulnerability
- NIST National Vulnerability Database: CVE-2026-15748: The Forminator Forms plugin for WordPress is vulnerable to Arbitrary File Upload…
- NIST National Vulnerability Database: CVE-2026-75094: A flaw has been found in COMFAST CF-N1-S 2.6.0.1. This impacts the…
- NIST National Vulnerability Database: CVE-2026-75110: MemOS is a memory operating system for LLMs and AI agents. In…
- NIST National Vulnerability Database: CVE-2026-75106: OpnForm derives editable-submission secrets from sequential row identifiers using Hashids with an…
- NIST National Vulnerability Database: CVE-2026-66795: A flaw was found in the managedcluster-import-controller. The Certificate Signing Request (CSR)…
- NIST National Vulnerability Database: CVE-2026-71472: A flaw was found in acm-search-v2-rhel9. This vulnerability allows an authenticated attacker,…
- NIST National Vulnerability Database: CVE-2026-66792: A flaw was found in the multicloud-operators-subscription component. This vulnerability allows a…
- NIST National Vulnerability Database: CVE-2026-74899: Openssl_encrypt versions before 1.4.0 contain a sandbox escape vulnerability in IsolatedPluginExecutor that…
- NIST National Vulnerability Database: CVE-2026-74872: Openssl_encrypt versions before 1.4.0 contain an arbitrary code execution vulnerability in the…
- SonicWall PSIRT: SonicWall GMS Security Affected By Multiple Vulnerabilities
- Palo Alto Networks Security Advisories: CVE-2026-0301 PAN-OS: Information Disclosure Vulnerability in URL Filtering (Severity: LOW)
- Cisco Security Advisories: Cisco Advance Notification for Publication of August 19, 2026, Security Advisories
- WordPress Security Releases: WordPress 7.0.4 Release
- Ubuntu Security Notices: USN-8631-4: Linux kernel (Azure CVM) vulnerabilities
- Ubuntu Security Notices: USN-8631-3: Linux kernel (NVIDIA Tegra IGX) vulnerabilities
- Ubuntu Security Notices: USN-8633-2: Linux kernel vulnerabilities
- GitHub Security Blog: What 50 open source projects taught us about security in the AI era
Need to add context to this briefing?
Send corrections, security tips, source updates, or collaboration notes through the contact page so the editorial team can review them properly.