August 2026 CVE Landscape

In August 2026, Insikt Group® identified 73 high-impact vulnerabilities that should be prioritized for remediation, 43 of which had a Very Critical Recorded Future Risk Score. This represents a 14% decrease from last month. 31 of these vulnerabilities were surfaced through the US Cybersecurity and Infrastructure Security Agency (CISA)’s Known Exploited Vulnerabilities (KEV) catalog, 32 were reported in open sources and validated by Insikt Group, seven were sourced through security vendor telemetry, and three were exclusively surfaced through honeypot data.

Introduction to Malware Binary Triage (IMBT) Course

Looking to level up your skills? Get 10% off using coupon code: MWNEWS10 for any flavor.

Enroll Now and Save 10%: Coupon Code MWNEWS10

Note: Affiliate link – your enrollment helps support this platform at no extra cost to you.

    <p>The 73 vulnerabilities in this blog affected products from 45 vendors, with Microsoft accounting for approximately 11% of the vulnerabilities. The remaining exposure spanned remote monitoring and management, virtualization, application delivery, collaboration, artificial intelligence, developer, analytics, identity, operational technology, content management, network edge, video surveillance, and endpoint technologies.</p>
    <p>In August, Insikt Group created Nuclei templates to detect CVE-2025-62593 (Ray), CVE-2026-72898 (Metabase), and CVE-2026-9198 (IBM Langflow). Each of these vulnerabilities is featured in this blog. Additionally, Insikt Group had previously created templates to detect CVE-2026-3395 (MaxSite CMS) and CVE-2026-59800 (decolua 9Router), but their exploitation was reported in July, so they are not listed in the August 2026 Vulnerability Table. Additionally, Insikt Group created a Nuclei template to detect GitHub Issue #4255 affecting Apache Log4j, a deserialization allowlist bypass that Apache classified as a hardening gap rather than a Log4j vulnerability; as such, it was not assigned a CVE. These Nuclei templates are available to customers via the Recorded Future Intelligence Platform.</p>
    <h2>Quick reference: August 2026 vulnerability table</h2>
    <p><em>All 70 vulnerabilities below were actively exploited or operationally weaponized in August 2026.</em> <em><strong>This table does not include the three CVEs that were primarily surfaced through honeypot data, which are available to Recorded Future Intelligence Platform customers via the CVE Monthly report.</strong></em> <em>The table below also provides examples of public PoCs identified by Insikt Group. These PoCs were not tested for accuracy or efficacy. Vulnerability management teams should exercise caution and verify the validity of PoCs before testing.</em></p>
    <div>
      <div>
        <div><strong>#</strong></div>
        <div><strong>Vulnerability</strong></div>
        <div><strong>Risk</strong><br /><strong>Score</strong></div>
        <div><strong>Vendor/Product</strong></div>
        <div><strong>KEV</strong></div>
        <div><strong>RCE</strong></div>
        <div><strong>PoC</strong></div>
      </div>
      <div>
        <div>1</div>
        <div>CVE-2026-81578</div>
        <div>99</div>
        <div>PaperCut NG/MF</div>
        <div>✓</div>
        <div></div>
        <div><a href="https://github.com/yora1928/PaperCut-CVE-2026-81578-82078" rel="noreferrer" target="_blank">Link ✓</a></div>
      </div>
      <div>
        <div>2</div>
        <div>CVE-2026-82078</div>
        <div>99</div>
        <div>PaperCut NG/MF</div>
        <div>✓</div>
        <div>✓</div>
        <div><a href="https://github.com/yora1928/PaperCut-CVE-2026-81578-82078" rel="noreferrer" target="_blank">Link ✓</a></div>
      </div>
      <div>
        <div>3</div>
        <div>CVE-2015-3246</div>
        <div>99</div>
        <div>Red Hat Libuser</div>
        <div>✓</div>
        <div></div>
        <div><a href="https://www.qualys.com/2015/07/23/cve-2015-3245-cve-2015-3246/cve-2015-3245-cve-2015-3246.txt" rel="noreferrer" target="_blank">Link ✓</a></div>
      </div>
      <div>
        <div>4</div>
        <div>CVE-2015-5287</div>
        <div>99</div>
        <div>Red Hat Automatic Bug Reporting Tool</div>
        <div>✓</div>
        <div></div>
        <div><a href="https://www.exploit-db.com/exploits/38832" rel="noreferrer" target="_blank">Link ✓</a></div>
      </div>
      <div>
        <div>5</div>
        <div>CVE-2017-0199</div>
        <div>99</div>
        <div>Microsoft Office and WordPad</div>
        <div></div>
        <div>✓</div>
        <div><a href="https://www.exploit-db.com/exploits/41934/" rel="noreferrer" target="_blank">Link ✓</a></div>
      </div>
      <div>
        <div>6</div>
        <div>CVE-2017-5753</div>
        <div>99</div>
        <div>Intel</div>
        <div></div>
        <div></div>
        <div><a href="https://www.exploit-db.com/exploits/43427/" rel="noreferrer" target="_blank">Link ✓</a></div>
      </div>
      <div>
        <div>7</div>
        <div>CVE-2019-1068</div>
        <div>99</div>
        <div>Microsoft SQL Server</div>
        <div>✓</div>
        <div>✓</div>
        <div><a href="https://github.com/Vulnerability-Playground/CVE-2019-1068" rel="noreferrer" target="_blank">Link ✓</a></div>
      </div>
      <div>
        <div>8</div>
        <div>CVE-2019-18935</div>
        <div>99</div>
        <div>Progress Telerik UI for ASP.NET AJAX</div>
        <div></div>
        <div>✓</div>
        <div><a href="https://github.com/noperator/CVE-2019-18935" rel="noreferrer" target="_blank">Link ✓</a></div>
      </div>
      <div>
        <div>9</div>
        <div>CVE-2020-0796</div>
        <div>99</div>
        <div>Microsoft Windows 10 and Windows Server</div>
        <div></div>
        <div>✓</div>
        <div><a href="https://github.com/jamf/CVE-2020-0796-RCE-POC" rel="noreferrer" target="_blank">Link ✓</a></div>
      </div>
      <div>
        <div>10</div>
        <div>CVE-2020-1472</div>
        <div>99</div>
        <div>Microsoft Windows Server</div>
        <div></div>
        <div></div>
        <div><a href="https://github.com/dirkjanm/CVE-2020-1472" rel="noreferrer" target="_blank">Link ✓</a></div>
      </div>
      <div>
        <div>11</div>
        <div>CVE-2021-23758</div>
        <div>99</div>
        <div>Ajax.NET Professional</div>
        <div>✓</div>
        <div>✓</div>
        <div><a href="https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/http/ajaxpro_deserialization_rce.rb" rel="noreferrer" target="_blank">Link ✓</a></div>
      </div>
      <div>
        <div>12</div>
        <div>CVE-2021-3156</div>
        <div>99</div>
        <div>sudo</div>
        <div></div>
        <div></div>
        <div><a href="https://github.com/worawit/CVE-2021-3156" rel="noreferrer" target="_blank">Link ✓</a></div>
      </div>
      <div>
        <div>13</div>
        <div>CVE-2022-0847</div>
        <div>99</div>
        <div>Linux kernel</div>
        <div></div>
        <div></div>
        <div><a href="https://github.com/AlexisAhmed/CVE-2022-0847-DirtyPipe-Exploits" rel="noreferrer" target="_blank">Link ✓</a></div>
      </div>
      <div>
        <div>14</div>
        <div>CVE-2022-0995</div>
        <div>99</div>
        <div>Linux kernel</div>
        <div>✓</div>
        <div></div>
        <div><a href="https://github.com/Bonfee/CVE-2022-0995" rel="noreferrer" target="_blank">Link ✓</a></div>
      </div>
      <div>
        <div>15</div>
        <div>CVE-2023-49105</div>
        <div>99</div>
        <div>ownCloud</div>
        <div>✓</div>
        <div></div>
        <div></div>
      </div>
      <div>
        <div>16</div>
        <div>CVE-2025-62593</div>
        <div>99</div>
        <div>Ray-Project Ray</div>
        <div>✓</div>
        <div>✓</div>
        <div><a href="https://github.com/ray-project/ray/security/advisories/GHSA-q279-jhrf-cc6v" rel="noreferrer" target="_blank">Link ✓</a></div>
      </div>
      <div>
        <div>17</div>
        <div>CVE-2026-18556</div>
        <div>99</div>
        <div>N-able N-central</div>
        <div>✓</div>
        <div></div>
        <div></div>
      </div>
      <div>
        <div>18</div>
        <div>CVE-2026-18577</div>
        <div>99</div>
        <div>N-able N-central</div>
        <div>✓</div>
        <div></div>
        <div></div>
      </div>
      <div>
        <div>19</div>
        <div>CVE-2026-20349</div>
        <div>99</div>
        <div>Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD)</div>
        <div>✓</div>
        <div></div>
        <div></div>
      </div>
      <div>
        <div>20</div>
        <div>CVE-2026-21962</div>
        <div>99</div>
        <div>Oracle HTTP Server and Oracle WebLogic Server Proxy Plug-in</div>
        <div>✓</div>
        <div></div>
        <div></div>
      </div>
      <div>
        <div>21</div>
        <div>CVE-2026-33824</div>
        <div>99</div>
        <div>Microsoft Internet Key Exchange (IKE) Service Extensions</div>
        <div>✓</div>
        <div>✓</div>
        <div></div>
      </div>
      <div>
        <div>22</div>
        <div>CVE-2026-34486</div>
        <div>99</div>
        <div>Apache Tomcat</div>
        <div>✓</div>
        <div></div>
        <div><a href="https://github.com/striga-ai/CVE-2026-34486" rel="noreferrer" target="_blank">Link ✓</a></div>
      </div>
      <div>
        <div>23</div>
        <div>CVE-2026-39987</div>
        <div>99</div>
        <div>Marimo</div>
        <div></div>
        <div>✓</div>
        <div><a href="https://github.com/marimo-team/marimo/security/advisories/GHSA-2679-6mx9-h9xc" rel="noreferrer" target="_blank">Link ✓</a></div>
      </div>
      <div>
        <div>24</div>
        <div>CVE-2026-53362</div>
        <div>99</div>
        <div>Linux kernel</div>
        <div>✓</div>
        <div></div>
        <div></div>
      </div>
      <div>
        <div>25</div>
        <div>CVE-2026-55040</div>
        <div>99</div>
        <div>Microsoft SharePoint</div>
        <div>✓</div>
        <div></div>
        <div><a href="https://github.com/sfewer-r7/CVE-2026-55040" rel="noreferrer" target="_blank">Link ✓</a></div>
      </div>
      <div>
        <div>26</div>
        <div>CVE-2026-59310</div>
        <div>99</div>
        <div>Broadcom VMware vCenter</div>
        <div>✓</div>
        <div>✓</div>
        <div><a href="https://github.com/fankh/vulnerability-poc/tree/main/2026/CVE-2026-59310" rel="noreferrer" target="_blank">Link ✓</a></div>
      </div>
      <div>
        <div>27</div>
        <div>CVE-2026-60004</div>
        <div>99</div>
        <div>Gitea</div>
        <div>✓</div>
        <div>✓</div>
        <div><a href="https://github.com/go-gitea/gitea/security/advisories/GHSA-rcr6-4jqh-j84m" rel="noreferrer" target="_blank">Link ✓</a></div>
      </div>
      <div>
        <div>28</div>
        <div>CVE-2026-63030</div>
        <div>99</div>
        <div>WordPress</div>
        <div></div>
        <div>✓</div>
        <div><a href="https://github.com/vulhub/vulhub/tree/master/wordpress/CVE-2026-63030" rel="noreferrer" target="_blank">Link ✓</a></div>
      </div>
      <div>
        <div>29</div>
        <div>CVE-2026-63077</div>
        <div>99</div>
        <div>JetBrains TeamCity</div>
        <div>✓</div>
        <div>✓</div>
        <div></div>
      </div>
      <div>
        <div>30</div>
        <div>CVE-2026-64849</div>
        <div>99</div>
        <div>MLflow</div>
        <div>✓</div>
        <div></div>
        <div><a href="https://github.com/mlflow/mlflow/security/advisories/GHSA-7gwp-5pfp-969j" rel="noreferrer" target="_blank">Link ✓</a></div>
      </div>
      <div>
        <div>31</div>
        <div>CVE-2026-65400</div>
        <div>99</div>
        <div>Apple macOS</div>
        <div>✓</div>
        <div></div>
        <div><a href="https://github.com/HORKimhab/CVE-2026-65400" rel="noreferrer" target="_blank">Link ✓</a></div>
      </div>
      <div>
        <div>32</div>
        <div>CVE-2026-68820</div>
        <div>99</div>
        <div>Microsoft Windows Ancillary Function Driver for WinSock</div>
        <div>✓</div>
        <div></div>
        <div></div>
      </div>
      <div>
        <div>33</div>
        <div>CVE-2026-72529</div>
        <div>99</div>
        <div>TrueConf Server</div>
        <div>✓</div>
        <div></div>
        <div></div>
      </div>
      <div>
        <div>34</div>
        <div>CVE-2026-72530</div>
        <div>99</div>
        <div>TrueConf Server</div>
        <div>✓</div>
        <div>✓</div>
        <div></div>
      </div>
      <div>
        <div>35</div>
        <div>CVE-2026-72898</div>
        <div>99</div>
        <div>Metabase</div>
        <div>✓</div>
        <div></div>
        <div></div>
      </div>
      <div>
        <div>36</div>
        <div>CVE-2026-73570</div>
        <div>99</div>
        <div>Synacor Zimbra Collaboration Suite (ZCS)</div>
        <div>✓</div>
        <div>✓</div>
        <div></div>
      </div>
      <div>
        <div>37</div>
        <div>CVE-2026-8037</div>
        <div>99</div>
        <div>Progress LoadMaster</div>
        <div>✓</div>
        <div>✓</div>
        <div><a href="https://labs.watchtowr.com/enterprise-tech-in-shell-out-progress-kemp-loadmaster-uninitialized-heap-to-pre-auth-rce-cve-2026-8037/" rel="noreferrer" target="_blank">Link ✓</a></div>
      </div>
      <div>
        <div>38</div>
        <div>CVE-2026-8452</div>
        <div>99</div>
        <div>Citrix NetScaler ADC and NetScaler Gateway</div>
        <div>✓</div>
        <div></div>
        <div><a href="https://github.com/watchtowrlabs/watchTowr-vs-Citrix-Netscaler-PreAuth-RCE-CVE-2026-8452" rel="noreferrer" target="_blank">Link ✓</a></div>
      </div>
      <div>
        <div>39</div>
        <div>CVE-2026-9198</div>
        <div>99</div>
        <div>IBM Langflow</div>
        <div>✓</div>
        <div>✓</div>
        <div><a href="https://github.com/0xgh057r3c0n/CVE-2026-9198" rel="noreferrer" target="_blank">Link ✓</a></div>
      </div>
      <div>
        <div>40</div>
        <div>CVE-2026-66384</div>
        <div>92</div>
        <div>JFrog Artifactory</div>
        <div>✓</div>
        <div></div>
        <div></div>
      </div>
      <div>
        <div>41</div>
        <div>CVE-2017-7921</div>
        <div>89</div>
        <div>Hikvision cameras</div>
        <div></div>
        <div></div>
        <div><a href="https://github.com/rapid7/metasploit-framework/blob/master/modules/auxiliary/gather/hikvision_info_disclosure_cve_2017_7921.rb" rel="noreferrer" target="_blank">Link ✓</a></div>
      </div>
      <div>
        <div>42</div>
        <div>CVE-2021-29441</div>
        <div>89</div>
        <div>Alibaba Nacos</div>
        <div></div>
        <div></div>
        <div><a href="https://github.com/alibaba/nacos/issues/4701" rel="noreferrer" target="_blank">Link ✓</a></div>
      </div>
      <div>
        <div>43</div>
        <div>CVE-2024-4577</div>
        <div>89</div>
        <div>PHP</div>
        <div></div>
        <div>✓</div>
        <div><a href="https://github.com/xcanwin/CVE-2024-4577-PHP-RCE" rel="noreferrer" target="_blank">Link ✓</a></div>
      </div>
      <div>
        <div>44</div>
        <div>CVE-2025-24813</div>
        <div>89</div>
        <div>Apache Tomcat</div>
        <div></div>
        <div>✓</div>
        <div><a href="https://github.com/absholi7ly/POC-CVE-2025-24813/blob/main/README.md" rel="noreferrer" target="_blank">Link ✓</a></div>
      </div>
      <div>
        <div>45</div>
        <div>CVE-2025-43529</div>
        <div>89</div>
        <div>Apple Safari, iOS, iPadOS, macOS, tvOS, visionOS, and watchOS</div>
        <div></div>
        <div>✓</div>
        <div><a href="https://varik.dev/blog/jsc/pois0nsword-native-calls" rel="noreferrer" target="_blank">Link ✓</a></div>
      </div>
      <div>
        <div>46</div>
        <div>CVE-2025-49113</div>
        <div>89</div>
        <div>Roundcube Webmail</div>
        <div></div>
        <div>✓</div>
        <div><a href="https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2025/CVE-2025-49113.yaml" rel="noreferrer" target="_blank">Link ✓</a></div>
      </div>
      <div>
        <div>47</div>
        <div>CVE-2025-68613</div>
        <div>89</div>
        <div>n8n</div>
        <div></div>
        <div>✓</div>
        <div><a href="https://github.com/Chocapikk/CVE-2026-21858" rel="noreferrer" target="_blank">Link ✓</a></div>
      </div>
      <div>
        <div>48</div>
        <div>CVE-2026-0300</div>
        <div>89</div>
        <div>Palo Alto Networks PAN-OS</div>
        <div></div>
        <div>✓</div>
        <div></div>
      </div>
      <div>
        <div>49</div>
        <div>CVE-2026-12569</div>
        <div>89</div>
        <div>PTC Windchill and FlexPLM</div>
        <div></div>
        <div>✓</div>
        <div></div>
      </div>
      <div>
        <div>50</div>
        <div>CVE-2026-21858</div>
        <div>89</div>
        <div>n8n</div>
        <div></div>
        <div></div>
        <div><a href="https://github.com/Chocapikk/CVE-2026-21858" rel="noreferrer" target="_blank">Link ✓</a></div>
      </div>
      <div>
        <div>51</div>
        <div>CVE-2026-3055</div>
        <div>89</div>
        <div>Citrix NetScaler ADC and NetScaler Gateway</div>
        <div></div>
        <div></div>
        <div><a href="https://labs.watchtowr.com/please-we-beg-just-one-weekend-free-of-appliances-citrix-netscaler-cve-2026-3055-memory-overread-part-2/" rel="noreferrer" target="_blank">Link ✓</a></div>
      </div>
      <div>
        <div>52</div>
        <div>CVE-2026-33017</div>
        <div>89</div>
        <div>Langflow</div>
        <div></div>
        <div>✓</div>
        <div><a href="https://github.com/langflow-ai/langflow/security/advisories/GHSA-vwmf-pq79-vjvx" rel="noreferrer" target="_blank">Link ✓</a></div>
      </div>
      <div>
        <div>53</div>
        <div>CVE-2010-3904</div>
        <div>79</div>
        <div>Linux kernel</div>
        <div></div>
        <div></div>
        <div><a href="https://www.exploit-db.com/exploits/44677/" rel="noreferrer" target="_blank">Link ✓</a></div>
      </div>
      <div>
        <div>54</div>
        <div>CVE-2020-1013</div>
        <div>79</div>
        <div>Microsoft Windows</div>
        <div></div>
        <div></div>
        <div><a href="https://github.com/GoSecure/WSuspicious" rel="noreferrer" target="_blank">Link ✓</a></div>
      </div>
      <div>
        <div>55</div>
        <div>CVE-2021-29442</div>
        <div>79</div>
        <div>Alibaba Nacos</div>
        <div></div>
        <div></div>
        <div><a href="https://github.com/alibaba/nacos/issues/4463" rel="noreferrer" target="_blank">Link ✓</a></div>
      </div>
      <div>
        <div>56</div>
        <div>CVE-2021-33044</div>
        <div>79</div>
        <div>Dahua cameras and video devices</div>
        <div></div>
        <div></div>
        <div><a href="https://packetstormsecurity.com/files/164423/Dahua-Authentication-Bypass.html" rel="noreferrer" target="_blank">Link ✓</a></div>
      </div>
      <div>
        <div>57</div>
        <div>CVE-2021-33045</div>
        <div>79</div>
        <div>Dahua cameras and video devices</div>
        <div></div>
        <div></div>
        <div><a href="https://packetstormsecurity.com/files/164423/Dahua-Authentication-Bypass.html" rel="noreferrer" target="_blank">Link ✓</a></div>
      </div>
      <div>
        <div>58</div>
        <div>CVE-2022-1040</div>
        <div>79</div>
        <div>Sophos Firewall</div>
        <div></div>
        <div>✓</div>
        <div><a href="https://www.exploit-db.com/exploits/51006" rel="noreferrer" target="_blank">Link ✓</a></div>
      </div>
      <div>
        <div>59</div>
        <div>CVE-2022-27925</div>
        <div>79</div>
        <div>Synacor Zimbra Collaboration Suite</div>
        <div></div>
        <div>✓</div>
        <div><a href="https://github.com/Josexv1/CVE-2022-27925" rel="noreferrer" target="_blank">Link ✓</a></div>
      </div>
      <div>
        <div>60</div>
        <div>CVE-2022-47986</div>
        <div>79</div>
        <div>IBM Aspera Faspex</div>
        <div></div>
        <div>✓</div>
        <div><a href="https://packetstormsecurity.com/files/171772/IBM-Aspera-Faspex-4.4.1-YAML-Deserialization.html" rel="noreferrer" target="_blank">Link ✓</a></div>
      </div>
      <div>
        <div>61</div>
        <div>CVE-2023-22527</div>
        <div>79</div>
        <div>Atlassian Confluence Data Center and Server</div>
        <div></div>
        <div>✓</div>
        <div><a href="https://packetstormsecurity.com/files/176789/Atlassian-Confluence-SSTI-Injection.html" rel="noreferrer" target="_blank">Link ✓</a></div>
      </div>
      <div>
        <div>62</div>
        <div>CVE-2023-46747</div>
        <div>79</div>
        <div>F5 BIG-IP</div>
        <div></div>
        <div>✓</div>
        <div><a href="https://packetstormsecurity.com/files/175673/F5-BIG-IP-TMUI-AJP-Smuggling-Remote-Command-Execution.html" rel="noreferrer" target="_blank">Link ✓</a></div>
      </div>
      <div>
        <div>63</div>
        <div>CVE-2024-55591</div>
        <div>79</div>
        <div>Fortinet FortiOS and FortiProxy</div>
        <div></div>
        <div></div>
        <div><a href="https://github.com/sysirq/fortios-auth-bypass-poc-CVE-2024-55591" rel="noreferrer" target="_blank">Link ✓</a></div>
      </div>
      <div>
        <div>64</div>
        <div>CVE-2025-24472</div>
        <div>79</div>
        <div>Fortinet FortiOS and FortiProxy</div>
        <div></div>
        <div></div>
        <div><a href="https://github.com/razureink/cve-2025-24472-fortinet_authbypass_reproduction" rel="noreferrer" target="_blank">Link ✓</a></div>
      </div>
      <div>
        <div>65</div>
        <div>CVE-2025-31324</div>
        <div>79</div>
        <div>SAP NetWeaver Visual Composer</div>
        <div></div>
        <div>✓</div>
        <div><a href="https://github.com/Krishcalin/Exploit-PoC/tree/main/CVE-2025-31324-PoC" rel="noreferrer" target="_blank">Link ✓</a></div>
      </div>
      <div>
        <div>66</div>
        <div>CVE-2026-15981</div>
        <div>79</div>
        <div>miniOrange SAML SSO Login</div>
        <div></div>
        <div></div>
        <div></div>
      </div>
      <div>
        <div>67</div>
        <div>CVE-2026-19478</div>
        <div>79</div>
        <div>GitLab CE and EE</div>
        <div></div>
        <div></div>
        <div><a href="https://github.com/n0xdaemon/cve-2026-19478" rel="noreferrer" target="_blank">Link ✓</a></div>
      </div>
      <div>
        <div>68</div>
        <div>CVE-2026-25895</div>
        <div>79</div>
        <div>FUXA</div>
        <div></div>
        <div>✓</div>
        <div><a href="https://github.com/Hann1bl3L3ct3r/FUXAPWN" rel="noreferrer" target="_blank">Link ✓</a></div>
      </div>
      <div>
        <div>69</div>
        <div>CVE-2026-61979</div>
        <div>79</div>
        <div>miniOrange SAML SP SSO</div>
        <div></div>
        <div></div>
        <div></div>
      </div>
      <div>
        <div>70</div>
        <div>CVE-2022-36883</div>
        <div>76</div>
        <div>Jenkins Git Plugin</div>
        <div></div>
        <div></div>
        <div><a href="https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2022/CVE-2022-36883.yaml" rel="noreferrer" target="_blank">Link ✓</a></div>
      </div>
    </div>
    <p><em><strong>Table 1:</strong></em> <em>List of vulnerabilities that were actively exploited in August, 2026 based on Recorded Future data (excluding honeypot-sourced CVEs).</em></p>
    <h2>Key trends: August 2026</h2>
    <ul>
      <li>August reporting showed two AI-assisted operations: UAT-10147 exploited Zimbra, AjaxPro, Nacos, and Telerik servers before using DeepAudit and PentestGPT after compromise, while a separate Chinese-speaking actor weaponized Hermes Agent and DeepSeek in failed attempts against Langflow and n8n.</li>
      <li>34 of the 73 vulnerabilities enabled remote code execution (RCE). They affected Microsoft productivity, database, server, and endpoint software; network edge and application delivery appliances; webmail, collaboration, content management, and web server platforms; AI, analytics, developer, and CI/CD services; and operational technology, product lifecycle management, file transfer, videoconferencing, and enterprise integration software.</li>
      <li>We identified public proof-of-concept (PoC) exploits and scanners for 53 of the 73 vulnerabilities.</li>
      <li>The most common weakness classes were CWE-94 (Code Injection) and CWE-502 (Deserialization of Untrusted Data) with seven each, followed by CWE-287 (Improper Authentication) and CWE-306 (Missing Authentication for Critical Function) with six each.</li>
      <li>17 vulnerabilities were at least five years old, and the oldest was approximately 16 years old.</li>
    </ul>
    <h2>Trend analysis: AI-assisted workflows scale exploitation and target selection</h2>
    <p>Insikt Group detailed how Chinese-speaking threat group, UAT-10147, combined conventional exploitation with agentic artificial intelligence (AI) during post-compromise operations against internet-facing Windows and Linux web servers. Cisco Talos observed the threat actor exploiting or weaponizing CVE-2019-18935 in Telerik UI for ASP.NET AJAX, CVE-2021-23758 in AjaxPro, CVE-2021-29441 and CVE-2021-29442 in Nacos, and CVE-2022-27925 in Zimbra for initial access. After compromise, UAT-10147 used CVE-2010-3904, CVE-2015-3246, CVE-2015-5287, CVE-2021-3156, CVE-2022-0847, and CVE-2022-0995 for local privilege escalation on Linux.</p>
    <div>
      <div>
        <div>
          <img alt="" height="1000" src="https://www.recordedfuture.com/media_1c04063b649bea005ed0acc1d839fc4c7da9a37a7.png?width=750&amp;format=png&amp;optimize=medium" width="2048" />
        </div>
      </div>
      <div>
        <div><em><strong>Figure 1:</strong></em> <em>Risk Rules history on the</em> <em><a href="https://www.recordedfuture.com/use-case/vulnerability-prioritization" rel="noreferrer" target="_blank">Vulnerability Intelligence Card®</a></em> <em>for CVE-2021-23758 in Recorded Future (Source: Recorded Future)</em></div>
      </div>
    </div>

Article Link: August 2026 CVE Landscape