News

Vulnerability Roundup — August 2026

Louis Stowasser
Louis Stowasser
Tuesday 1 September 2026
Vulnerability Roundup — August 2026
Vulnerability Roundup — August 2026

August’s clearest warning came from Metabase: a request to a password-reset database endpoint could become administrator control of a business-intelligence deployment, with the credentials and data behind its connected databases in reach. CVE-2026-72898 was published on August 10 and added to CISA’s Known Exploited Vulnerabilities catalog the next day.

That was not an isolated fast-moving incident. By month’s end, confirmed exploitation also covered a core cloud identity service, mail collaboration servers, code-hosting software and enterprise print management. August was distinctive less for one new bug class than for how often a remotely reachable or lightly protected management path led directly to control.

Metabase SQL injection

Metabase is widely used to put dashboards and ad-hoc queries in front of company data. In CVE-2026-72898, an unauthenticated remote attacker can inject SQL through the /reset_password database endpoint and gain administrator access to the Metabase instance.

That is much more than a dashboard compromise. An administrator can alter application configuration, recover stored credentials for connected databases, read data reachable through those connections and export it. The flaw is KEV-listed and actively exploited, and a patch is available. Internet-exposed Metabase instances deserved immediate attention; even internal instances are a useful target once an attacker gets a foothold on the network.

Entra ID network code execution

Microsoft Entra ID, formerly Azure Active Directory, is the identity layer organisations use for users, applications and access policies. CVE-2026-69836 is deserialization of untrusted data that lets an unauthorized attacker execute code over the network, without needing credentials or user interaction.

The limited technical detail is frustrating, but the operational meaning is clear: this is code execution against a platform whose job is to decide who gets access to everything else. It was added to KEV on August 21 after publication the day before. Teams should follow Microsoft’s security guidance and treat any Entra exposure and related signs of compromise as an identity incident, not merely a routine server patch.

NetScaler remote-access exposure

Citrix NetScaler ADC and Gateway sit at the edge of many organisations, handling application delivery and remote access. CVE-2026-19490 affects supported 14.1 and 13.1 release ranges identified in Citrix’s bulletin, and reports cited for the advisory say it is being actively exploited.

The advisory’s impact profile is severe, and its location matters as much as its score. A vulnerable gateway is reachable before an attacker has an internal account, and compromise can put a device trusted to broker access in the attacker’s hands. Check the Citrix bulletin for the applicable fixed build and do not assume that a gateway’s role makes it less exposed; that role is exactly why it is attractive.

Zimbra and Gitea execution

Two server-side products demonstrated different routes from normal application inputs to shell commands. CVE-2026-73570 affects Zimbra Collaboration before 10.1.20, but only where the optional zimbra-snmp package is installed and SNMP notifications are enabled. An unauthenticated attacker can send crafted SMTP requests that reach insufficiently sanitised notification handling and execute operating-system commands as the Zimbra user. It is KEV-listed and exploited; Zimbra 10.1.20 contains the fix.

In Gitea, CVE-2026-60004 requires repository write access, a meaningful constraint but not much comfort for shared projects or compromised developer accounts. A malicious patch sent to the diffpatch API can install an executable Git hook and run commands as the Gitea service account. The issue affects versions before 1.27.1, is KEV-listed and exploited. Repository write permission should not be treated as permission to alter the host running the forge.

PaperCut administrative bypass

PaperCut MF and NG are enterprise print-management platforms, often with a web management interface that administrators may not regard as a major security boundary until it is one. CVE-2026-81578 lets unauthenticated remote requests to administrative functions trigger backend actions before access checks finish, allowing configuration changes.

It is KEV-listed, a patch is available, and public Metasploit development accompanied the disclosure. The vendor also identifies CVE-2026-82078 as chainable with it, making this a release to deploy as a unit rather than a vulnerability to triage in isolation. Restricting management-interface reachability while updating is especially sensible here.

Administrative paths became attack paths

The common thread was not simply “critical severity.” It was misplaced trust at the point software changes state: Metabase’s reset path, PaperCut’s administrative functions, macOS Screen Sharing authentication, and Entra’s handling of data that should never have been trusted. CVE-2026-65400, also KEV-listed, allows a network attacker to authenticate to macOS Screen Sharing without valid credentials; Apple fixed it in macOS Sequoia 15.7.9, Sonoma 14.8.9 and Tahoe 26.6.1. These are paths built to establish identity or administer systems, so failure often bypasses the usual need for a stolen password.

The broader candidate pool reinforced the same concern across gateways, routers, cameras, conferencing and security infrastructure. It also contained repeated SQL, command-execution, template and deserialization mistakes, alongside AI and agent deployments that trusted attacker-controlled prompts, tools or listeners. Those are different implementation failures, but they converge on a practical question: can an untrusted network input make a trusted service perform an action with more authority than the sender has?

Mozilla’s CVE-2026-75874 is a useful counterpoint. The Remote Settings Client flaw is a sandbox escape fixed in Firefox 154 and Thunderbird 154: not another exposed administration panel, but a failure of a boundary meant to contain risky content. August’s list was full of products that had such boundaries and, in several cases, put too much trust on the wrong side of them.

The month added up to an unusually actionable set of exploited routes into systems that store data, broker access or run collaboration work. Prioritise externally reachable Metabase, gateways, Zimbra and PaperCut management surfaces, then make sure the versions actually match the fixes. SecAlerts monitors an organisation’s actual software stack and alerts on new vulnerabilities affecting the products it runs, helping teams focus on the exposures that apply rather than sift the month’s full list.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203