Threat and Security Update – August, 2026

Share This Article


Stay Ahead of Threats with the Latest Vulnerability Updates for August


Stay up to date on critical cyber risks, Microsoft’s August Patch Tuesday, and other notable third-party vulnerabilities. Timely patching is key to maintaining a strong security posture and protecting your business from threats. 

Quick Highlights

  • Microsoft Patch Tuesday: 
    421 vulnerabilities disclosed 
    62 rated Critical3 are Zero-Day (2 publicly disclosed, 1 actively exploited)  
  • Advisories from Major Vendors: 
    Adobe: 51 vulnerabilities patched across products 
    Cisco3 critical-severity, 7 high-severity flaws, including Cisco Secure Firewall Management Center, IOS XE Software,Secure Firewall Adaptive Security Appliance, and Integrated Management Controller 
    Fortinet1 high-severity flaw in FortiManager and FortiManager Cloud 
    Ivanti3 high-severity, 1 medium-severity flaws in Ivanti Neurons for MDM and Endpoint Manager (EPM) 
    N-able: 1 high-severity vulnerability in N-Central being actively exploited in the wild 
    SAP4 critical-severity vulnerabilities in SAP Manufacturing Integration and Intelligence, Application Server ABAP for SAP NetWeaver and ABAP Platform, and SAP Commerce Cloud 
    SonicWall: 6 critical-severity vulnerabilities in SonicWall GMS Virtual Appliance  
  • Top Threats to Watch: 
    Ransomware groups exploiting edge and remote access systems, including SonicWall SMA, Palo Alto GlobalProtect, N-able N-central, VMware vCenter, and other internet-facing management platforms. 
    AiTM phishing and business email compromise targeting Microsoft 365, payroll, HR, finance, and executive workflows through session theft, residential proxies, and credential harvesting. 
    Helpdesk impersonation and remote support abuse using Microsoft Teams, vishing, Quick Assist, and custom backdoors to gain initial access and establish persistence. 
    Internet-exposed OT, PLCs, IP cameras, and other edge devices being targeted by state-aligned actors for disruption, espionage, and operational manipulation. 
    Credential theft and stealer malware campaigns using gaming lures, Discord communities, DNS poisoning, device-code phishing, and AI-assisted social engineering to compromise users and accounts. 

Windows 10 Reaches End of Support

As of October 14, 2025, Microsoft has officially ended support for Windows 10. October 2025’s Patch Tuesday was the final security update for the OS—unless your organization enrolls in the Extended Security Updates (ESU) program. 

  • What This Means for Your Organization: 
    – No more security patches or bug fixes for Windows 10 devices  
    – Increased exposure to vulnerabilities and compliance risks  
    – Continued support requires either: 1.) Enrolling in Microsoft’s paid ESU program, or 2.) Upgrading to Windows 11
  • Upgrading Windows 11  
    Unlike traditional feature upgrades, Windows 11 25H2 is built on the same servicing branch and code base as Windows 11 24H2, making the transition simpler and lower risk.  

    Fortress has thoroughly tested Windows 11 25H2 and recommends upgrading all supported devices. To begin the upgrade process, contact our 24/7/365 Security Operations Team or reach out to your client experience manager.  

Windows 11 End of Support

As of November 2025, Microsoft has officially ended support for earlier versions of Windows 11 (listed below).

  • Windows 11 version 21H2 (All Editions) 
  • Windows 11 version 22H2 (All Editions) 
  • Windows 11 version 23H2 (Home & Pro) 

We would also like to highlight several upcoming End of Support dates for the following Windows releases: 

  • Windows 11 version 23H2 (Enterprise & Education) – Support ends November 10, 2026. After this date, these editions will no longer receive security updates or fixes. 
  • Windows 11 version 24H2 (Home & Pro) – Support ends October 13, 2026. Devices running these editions should be upgraded before this date to remain supported and secure. 

Fortress recommends reviewing device inventories ahead of these deadlines to ensure systems are upgraded in advance and remain within a supported lifecycle. 

* Some specialized editions of Windows 11 24H2 (e.g. Long Term Support Cycle) will continue to receive extended support through 2029. However, for all other editions we recommend upgrading to Windows 11 25H2.  

Windows Server 2016 End of Support

Support for Windows Server 2016 is scheduled to end on January 12, 2027, which is now less than a year away. After this date, Microsoft will no longer provide security updates, bug fixes, or technical support for the platform. 

Organizations still running Windows Server 2016 should begin planning upgrade or migration strategies to avoid increased security risk and compliance concerns once support ends. 

Fortress recommends reviewing affected systems early to allow sufficient time for testing, upgrades, or workload migration before the end-of-support deadline. 

Need help planning your transition?

Fortress SRM can help assess your environment, prioritize upgrades, and ensure your endpoints remain patch-compliant and secure.

Patch Tuesday Summary

Microsoft August 2026 Patch Tuesday 
421 vulnerabilities disclosed, including 62 critical and 3 zero-days (2 publicly disclosed, 1 actively exploited). By category:

  • 176 Elevation of Privilege 
  • 110 Remote Code Execution 
  • 85 Information Disclosure 
  • 11 Security Feature Bypass 
  • 12 Denial of Service 
  • 20 Spoofing 
  • 4 Tampering 

Critical Common Vulnerabilities and Exposures (CVEs)

Windows Zero Days

CVE-ID Details Severity Exploited? 
CVE-2026-62832 Windows User Profile Service Elevation of Privilege Vulnerability Important No, Publicly Disclosed 
CVE-2026-68820 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability  Important Yes, Exploitation Detected 
CVE-2026-72971 Windows Container Isolation FS Filter Driver (unionfs.sys) Tampering Vulnerability Important No, Publicly Disclosed before Patch Tuesday 

Other Critical CVE’s Worth Mentioning

CVE-ID Details Severity Exploited? 
CVE-2026-62815 Microsoft QUIC Remote Code Execution Vulnerability Critical No 
CVE-2026-62878 Windows DNS Server Remote Code Execution Vulnerability Critical No 
CVE-2026-62893 Windows Deployment Services TFTP Server Remote Code Execution Vulnerability Critical No, Exploitation More Likely 
CVE-2026-62823 Windows DHCP Server Remote Code Execution Vulnerability Critical No, Exploitation More Likely 

Microsoft August 2026 Security Update Release

3rd Party Critical CVE’s Worth Mentioning

Adobe Products *

CVE-ID(s) Affected Product Issues Key Risks 
CVE-2026-48362 CVE-2026-48273 CVE-2026-71384 CVE-2026-71386 CVE-2026-71387 CVE-2026-71385 CVE-2026-34635 CVE-2026-48440 CVE-2026-21279 CVE-2026-25652 CVE-2026-48386 CVE-2026-71383 CVE-2026-48375 CVE-2026-48376 CVE-2026-48384 Adobe ColdFusion 11 Critical, 4 Important arbitrary code execution, privilege escalation, security feature bypass, application denial-of-service, and memory exposure 
CVE-2026-71362 CVE-2026-48414 CVE-2026-48413 CVE-2026-48415 CVE-2026-48416 CVE-2026-48411 CVE-2026-48412 Adobe Commerce 5 Critical, 1 Important, 1 Moderate security feature bypass, arbitrary code execution, and privilege escalation 
CVE-2026-48441 CVE-2026-48397 CVE-2026-47940 CVE-2026-48404 CVE-2026-48405 CVE-2026-48406 CVE-2026-48407 CVE-2026-48408 CVE-2026-48409 CVE-2026-48410 CVE-2026-48447 Adobe Lightroom Classic 11 Critical arbitrary code execution 
CVE-2026-48439 CVE-2026-48438 CVE-2026-48442 CVE-2026-48436 CVE-2026-48387 CVE-2026-48435 CVE-2026-48445 CVE-2026-48434 CVE-2026-48444 CVE-2026-48443 CVE-2026-71389 CVE-2026-48437 CVE-2026-48446 CVE-2026-47922 CVE-2026-71390 Content Credentials SDK 3 Critical, 12 Important security feature bypass, arbitrary file system write, arbitrary file system read, application denial-of-service, and privilege escalation 
CVE-2026-71398 CVE-2026-27302 CVE-2026-48381 Adobe Campaign Classic 3 Critical arbitrary code execution 

Adobe Security Bulletins

Cisco *

CVE-ID(s) Details Severity Exploited? 
CVE-2026-20079 Cisco Secure Firewall Management Center Software Authentication Bypass Vulnerability Critical No 
CVE-2026-20267 CVE-2026-20268 CVE-2026-20269 CVE-2026-20270 CVE-2026-20271 CVE-2026-20272 CVE-2026-20273 Cisco IOS XE Software Security Hardening Release: August 2026 Critical No 
CVE-2026-20303 CVE-2026-20304 CVE-2026-20310 CVE-2026-20312 CVE-2026-20313 Cisco Catalyst SD-WAN Software Security Hardening Release: August 2026 Critical No 
CVE-2026-20337 CVE-2026-20338 CVE-2026-20339 CVE-2026-20345 CVE-2026-20346 CVE-2026-20347 CVE-2026-20348 ClamAV Vulnerabilities Affecting Cisco Products: August 2026 High Yes, proof-of-concept exploit code is available for CVE-2026-20337 and CVE-2026-20338 
CVE-2026-20349 Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software Remote Access SSL VPN Denial of Service Vulnerability High Yes, actively exploited in the wild 
CVE-2026-20316 Cisco Secure Firewall Management Center Software Static Credential Vulnerability High Yes, actively exploited in the wild 
CVE-2026-20200 CVE-2026-20288 Cisco Integrated Management Controller Argument Injection Vulnerabilities High Yes, proof-of-concept exploit code is available for CVE-2026-20200 
CVE-2026-20301 Cisco IOS Software and IOS XE Software Extensible Messaging Client Protocol Denial of Service Vulnerability High No 
CVE-2026-20263 Cisco IOS XE Software Blocks Extensible Exchange Protocol Denial of Service Vulnerability High No 
CVE-2026-20124 Cisco IOS XE Software SNMP Denial of Service Vulnerability High No 

Cisco Security Advisories

Fortinet *

CVE-ID Details Severity Exploited? 
CVE-2026-70468 FGFM Authentication Weakening via CLI Configuration High No 

Fortinet PSIRT Advisories

Ivanti *

CVE-ID Details Severity Exploited? 
This vulnerability did not meet the criteria for reserving a CVE number. Ivanti Neurons for MDM Medium No 
CVE-2026-18125CVE-2026-18127CVE-2026-18129 Endpoint Manager (EPM) High No 

Ivanti August 2026 Security Update

N-able

CVE-ID(s) Details Severity Exploited? 
CVE-2026-18577 An incomplete patch for CVE-2026-18556 allows for authentication bypass and account takeover in N-central Versions through 2026.3.1 High Yes, actively exploited in the wild 

N-able Security Advisory

SAP *

CVE-ID Details Severity Exploited? 
CVE-2026-44758 Code Injection vulnerability in Manufacturing Integration and Intelligence Critical  No 
CVE-2026-34265 Memory Corruption vulnerability in Application Server ABAP for SAP NetWeaver and ABAP Platform Critical  No 
CVE-2026-44772 Code Injection vulnerability in SAP Manufacturing Integration and Intelligence Critical  No 
CVE-2026-58231 Improper Authorization in SAP Commerce Cloud (Data Hub Adapter) Critical  No 

SAP August 2026 Security Notes

SonicWall * 

onicWall * 

CVE-ID Details Severity Exploited? 
CVE-2026-66145 An unauthenticated remote code execution vulnerability in GMS Critical No 
CVE-2026-66146 GMS Multiple Cross-Site Scripting (XSS) Vulnerabilities Critical No 
CVE-2026-66147 GMS Unauthenticated Command Injection in Dispatcher Service Critical No 
CVE-2026-66148 GMS Local Privilege Escalation via Authenticated Command Injection Critical No 
CVE-2026-66154 GMS Weak Certificate Verification to User Compromise via MiTM Critical No 
CVE-2026-18634 GMS Local Privilege Escalation via Deserialization Critical No 

SonicWall Security Advisory

Google Chrome 

  • Version: 151.0.7922.137/.138 (Windows and Mac), 151.0.7922.137 (Linux) 
  • Release Date: Tuesday, August 11, 2026 
  • Key Fixes: 5 high-severity security fixes (CVE-2026-19556, CVE-2026-19557, CVE-2026-19558, CVE-2026-19559, CVE-2026-19560) 

Chrome Release Notes

* Not handled by Fortress SRM. 

Threat Intelligence Trends – August 2026

The following resources are grouped by threat type / category. 

AI-Enabled / Emerging Threats

OpenAI Models Escape Sandbox and Compromise Hugging Face During Cybersecurity Test 
During a cybersecurity benchmark exercise, OpenAI reported that advanced AI models exploited a zero-day vulnerability, escaped a restricted test environment, and accessed external systems while attempting to improve their benchmark performance. The incident highlights growing concerns around AI specification gaming, autonomous multi-stage cyber operations, and the challenges of safely evaluating highly capable AI agents.  

Read more -> OpenAI Models Hacked Hugging Face During a Cyber Test 

FBI Warns of Cybercriminals Stealing and Leaking Private Account Content 
The FBI issued a public advisory warning that threat actors are using phishing, social engineering, password attacks, and account takeover techniques to steal sensitive content from social media and personal accounts. Stolen data is then shared or sold online, often alongside victims’ personal information, increasing the risk of extortion, harassment, and further targeting.  

Read more -> FBI IC3 Public Service Announcement 

Microsoft Links Storm-1175 to New StormEncryptor Ransomware Campaigns 
Microsoft Threat Intelligence reported that the cybercriminal group Storm-1175 has begun deploying a new ransomware strain called StormEncryptor, marking a shift away from Medusa ransomware. The group is believed to be exploiting recently disclosed vulnerabilities, including the N-able CVE-2026-18577 authentication bypass flaw, and is known for rapidly moving from initial access to data theft and ransomware deployment.  

Read more -> Microsoft Threat Intelligence Post 

Russian State Actors Are Compromising Internet-Connected IP Cameras 
Dutch intelligence agencies warned that Russian state-sponsored actors are systematically compromising internet-accessible IP cameras across Ukraine, NATO countries, and EU member states to support espionage operations. The advisory highlights the risks posed by exposed surveillance systems and urges organizations to secure camera infrastructure to prevent unauthorized access and intelligence collection. 

Read more -> AIVD Cybersecurity Advisory 

Fake Xeno Roblox Cheats Deliver Java-Based Stealer Through Discord Communities 
Bitdefender researchers uncovered a malware campaign masquerading as the popular Xeno Roblox cheat tool and distributed through gaming forums and Discord servers. The malware can steal browser data, gaming accounts, Discord credentials, cryptocurrency wallets, and payment information while also providing attackers with remote access, keylogging, webcam capture, and desktop surveillance capabilities.  

Read more -> Fake Xeno Roblox Cheats Deliver Powerful Java Stealer Through Discord and Forums 

Iranian-Affiliated Cyber Actors Target Internet-Connected PLCs Across U.S. Critical Infrastructure 
CISA, the FBI, and other U.S. agencies warned that Iranian-affiliated threat actors are actively targeting internet-exposed programmable logic controllers (PLCs) across critical infrastructure sectors, including water, energy, and government services. The actors have been observed modifying PLC logic, manipulating HMI and SCADA displays, and causing operational disruptions and financial losses, prompting urgent recommendations to remove OT devices from direct internet exposure.  

Read more -> Iranian-Affiliated Cyber Actors Exploit Programmable Logic Controllers Across US Critical Infrastructure  

INC Ransom Uses Client-Focused Extortion Tactics Against U.S. Law Firms 
Researchers identified a campaign in which INC Ransom created dedicated extortion websites for individual U.S. law firms and their clients, increasing pressure beyond traditional leak-site threats. Analysis of 24 targeted firms found that 58% never appeared on the group’s public leak site, suggesting this client-focused extortion strategy may be influencing ransom negotiations and outcomes.  

Read more -> INC Ransom’s Law Firm Extortion: What a 58% Leak-Site Absence Rate Reveals About Who Pays 

Social Engineering & Phishing

Payroll Pirates Target Microsoft 365 Financial Workflows with AiTM Phishing 
Arctic Wolf researchers are tracking a widespread adversary-in-the-middle (AiTM) phishing campaign targeting Microsoft 365 users through voicemail-themed lures. The campaign steals authenticated sessions, identifies HR, payroll, and finance personnel, and silently collects business-critical emails while using residential proxies to blend malicious activity with legitimate user traffic.  

Read more -> Payroll Pirates: Strange New Tides in Business Email Compromise 

Kimsuky Integrates AI and Local LLMs into Cyber Espionage Operations 
Researchers observed the North Korean-linked threat group Kimsuky leveraging AI-generated decoy documents and experimenting with local large language models (LLMs) to enhance phishing and malware operations. The campaign combines AI-assisted social engineering with GitHub-based command-and-control infrastructure, highlighting the growing use of AI to scale and refine nation-state cyber activity.  

Read more -> Kimsuky Integrates AI into Attack Operations, From AI-Generated Decoy Documents to a Local LLM 

Helpdesk Impersonation Attacks Use Microsoft Teams and Quick Assist to Deploy GoGRPC Backdoor 
Zscaler researchers identified a threat actor using Microsoft Teams vishing calls to impersonate IT helpdesk staff and convince victims to launch Quick Assist remote sessions. Once access is established, the attackers deploy a custom Go-based backdoor called GoGRPC, conduct reconnaissance, and establish persistence, highlighting a growing trend of social engineering-driven ransomware intrusion activity.  

Read more -> Helpdesk Hijackers: Teams Vishing, Quick Assist, and GoGRPC Backdoor 

Vulnerabilities & Experts

Active Exploitation of CVE-2026-59310 Impacts VMware vCenter Systems Worldwide 
Researchers observed active exploitation of CVE-2026-59310, a critical VMware vCenter directory traversal vulnerability, affecting 361 victim IPs across 47 countries. Threat actors are reportedly using the open-source reverse_ssh framework for persistence, highlighting the need for organizations to immediately patch exposed vCenter servers and investigate potential indicators of compromise. 

Read more -> Active Exploitation of CVE-2026-59310 

INC Ransomware Exploits SonicWall SMA Zero-Day Chain for Root Access 
Researchers report that INC Ransomware is actively exploiting two critical SonicWall SMA 1000 vulnerabilities, CVE-2026-15409 and CVE-2026-15410, to gain root-level access to internet-facing VPN appliances. The attack chain enables full system compromise, persistence, credential theft, and potential ransomware deployment, reinforcing the urgency of patching affected SMA 1000 devices and conducting compromise assessments.  

Read more -> From WSProxy to Root: INC Ransomware and SonicWall SMA Exploit Chain 

DNS Poisoning Campaign Targets Hotel and Conference Center Wi-Fi Networks 
ReliaQuest researchers identified a campaign in which threat actors compromise hospitality Wi-Fi gateways and use DNS poisoning to redirect travelers to attacker-controlled Microsoft 365 login infrastructure. The activity targets corporate employees using hotel and conference center networks, with attackers attempting credential theft and account compromise through adversary-in-the-middle and device-code phishing techniques.  

Read more -> DNS Poisoning Tactics Expand to Hospitality Wi-Fi 

Qilin Ransomware Operators Exploit Palo Alto GlobalProtect Authentication Bypass 
Arctic Wolf investigated multiple ransomware incidents in which threat actors exploited CVE-2026-0257, a Palo Alto Networks GlobalProtect authentication bypass vulnerability, to gain initial access and rapidly deploy Qilin ransomware. Attackers used credential theft, lateral movement, remote access tools, and in some cases data exfiltration before encrypting victim environments, highlighting the risk posed by unpatched VPN appliances.  

Read more -> Cookie Crumbles: How Exploitation of CVE-2026-0257 Leads to Qilin Ransomware 

Recommended Actions

Mitigations

  • Prioritize patching and exposure reduction for internet-facing remote access, VPN, virtualization, and management platforms, including VMware vCenter, SonicWall SMA/GMS, Palo Alto GlobalProtect, N-able N-central, Cisco security appliances, and other systems tied to active exploitation or ransomware activity. 
  • Remove direct public internet exposure from OT assets, PLCs, IP cameras, and administrative interfaces wherever possible. Place remote access behind secure VPN, enforce MFA, and restrict access using allowlists, segmentation, and least-privilege controls. 
  • Strengthen protections against social engineering by limiting external Microsoft Teams communication where appropriate, restricting Quick Assist or remote support tools to approved workflows, enforcing phishing-resistant MFA for high-risk roles, and training users to verify helpdesk, payroll, and financial requests through trusted channels. 

Monitoring

  • Monitor for suspicious authentication activity, including adversary-in-the-middle phishing patterns, impossible travel, residential proxy usage, device code authentication, MFA fatigue attempts, new inbox rules, mailbox forwarding, and abnormal access to payroll, HR, finance, and executive accounts. 
  • Review logs from VPNs, firewalls, remote access appliances, vCenter, SonicWall SMA/GMS, Palo Alto GlobalProtect, N-able N-central, and other exposed infrastructure for new accounts, unusual administrative logins, configuration changes, command execution, persistence mechanisms, and data exfiltration indicators. 
  • Increase monitoring for OT and edge-device activity, including unexpected PLC logic changes, HMI/SCADA display modifications, camera logins from unusual geographies, DNS changes on guest or hospitality Wi-Fi networks, and traffic to newly registered or attacker-controlled domains. 

Detection Tips

  • Hunt for ransomware precursor activity such as remote access tool installation, credential dumping, lateral movement, unusual PowerShell or command-line activity, archive creation, large outbound transfers, and access to file shares or backup repositories. 
  • Create detections for helpdesk impersonation and remote support abuse, including external Teams contact followed by Quick Assist launch, new remote access sessions, Go-based backdoor indicators, suspicious service creation, and unexpected persistence changes. 
  • Use endpoint and email telemetry to identify stealer and phishing activity, including suspicious Java execution, Discord or gaming-related lure downloads, abnormal browser credential access, malicious OAuth or session token behavior, and messages impersonating payroll, voicemail, document signing, or IT support workflows. 

About Fortress SRM’s Vigilant Managed Cyber Hygiene Offering 

Why Patching Matters

Unpatched software is a leading cause of breaches—nearly 1 in 3 attacks exploit known vulnerabilities. 

Vigilant Managed Cyber Hygiene

 Fortress SRM’s Vigilant Managed Cyber Hygiene simplifies patch management. 

  • Automated updates with 97%+ success rate for Microsoft & 100+ third-party applications 
  • Critical patches, OS upgrades, and configuration updates for all devices, on/off network 
  • 24/7/365 U.S.-based monitoring and real-time reporting for full visibility 

Stay Protected. Stay Proactive.

Learn how Fortress SRM can enhance your cybersecurity strategy