VMware vCenter CVE-2026-59310: Germany Hit Hardest

VMware vCenter CVE-2026-59310, a CVSS 9.8 flaw, is under active exploitation in 47 countries — Germany is hit hardest. What to do now.

VMware vCenter CVE-2026-59310, a maximum-severity path-traversal vulnerability scoring 9.8 on CVSS, is being actively exploited across 47 countries — and Germany is the single most-affected country of all of them. German incident-response firm QUIRSO uncovered the campaign live during an IR engagement, tracing 361 distinct victim IP addresses back to a directory-traversal flaw in vCenter’s…

Read More

SAP Commerce Cloud CVE-2026-58231: CVSS 10.0 RCE

SAP Commerce Cloud CVE-2026-58231 (CVSS 10.0) lets unauthenticated attackers hit the Data Hub import endpoint for code execution. Patch and mitigation steps.

SAP Commerce Cloud CVE-2026-58231, a maximum-severity (CVSS 10.0) flaw disclosed on SAP’s August 2026 Security Patch Day, lets an unauthenticated attacker with network access reach the Data Hub import endpoint and potentially execute arbitrary code — no login, no user interaction, just a crafted request to a component many DACH e-commerce and manufacturing storefronts run…

Read More

CVE-2026-68820 WinSock Zero-Day: Lazarus Deploys Rootkit

CVE-2026-68820 WinSock zero-day

The CVE-2026-68820 WinSock zero-day was already being used by North Korea’s Lazarus Group to plant a kernel-mode rootkit weeks before Microsoft shipped a fix in its August 2026 Patch Tuesday. Any Windows endpoint that processes network sockets — which is to say, essentially every Windows machine on your network — was exposed until this month’s…

Read More

Metabase CVSS 10 SQL Injection Zero-Day Hits Admin Access

The Metabase CVSS 10 SQL injection zero-day gives attackers admin access and every connected database credential. Framework and Tally already hit.

The Metabase CVSS 10 SQL injection zero-day lets an unauthenticated attacker turn a self-hosted analytics dashboard into a master key for every database it touches. Active exploitation began August 3, 2026, and two named victims — Framework and Tally — have already confirmed customer data theft. If your organization runs Metabase for internal reporting, this…

Read More

TeamCity CVE-2026-63077 RCE: Unauthenticated CI/CD Takeover

TeamCity CVE-2026-63077 RCE

TeamCity CVE-2026-63077 RCE lets an unauthenticated attacker send a single crafted request to a TeamCity On-Premises server and execute operating system commands — no login, no valid session, no user interaction. CISA added it to the Known Exploited Vulnerabilities catalog on August 5 with a three-day remediation deadline, and exploitation is now active in the…

Read More