Stay Ahead of Threats with the Latest Vulnerability Updates for August
Stay up to date on critical cyber risks, Microsoft’s August Patch Tuesday, and other notable third-party vulnerabilities. Timely patching is key to maintaining a strong security posture and protecting your business from threats.
Quick Highlights
- Microsoft Patch Tuesday:
– 421 vulnerabilities disclosed
– 62 rated Critical, 3 are Zero-Day (2 publicly disclosed, 1 actively exploited)
- Advisories from Major Vendors:
– Adobe: 51 vulnerabilities patched across 5 products
– Cisco: 3 critical-severity, 7 high-severity flaws, including Cisco Secure Firewall Management Center, IOS XE Software,Secure Firewall Adaptive Security Appliance, and Integrated Management Controller
– Fortinet: 1 high-severity flaw in FortiManager and FortiManager Cloud
– Ivanti: 3 high-severity, 1 medium-severity flaws in Ivanti Neurons for MDM and Endpoint Manager (EPM)
– N-able: 1 high-severity vulnerability in N-Central being actively exploited in the wild
– SAP: 4 critical-severity vulnerabilities in SAP Manufacturing Integration and Intelligence, Application Server ABAP for SAP NetWeaver and ABAP Platform, and SAP Commerce Cloud
– SonicWall: 6 critical-severity vulnerabilities in SonicWall GMS Virtual Appliance
- Top Threats to Watch:
– Ransomware groups exploiting edge and remote access systems, including SonicWall SMA, Palo Alto GlobalProtect, N-able N-central, VMware vCenter, and other internet-facing management platforms.
– AiTM phishing and business email compromise targeting Microsoft 365, payroll, HR, finance, and executive workflows through session theft, residential proxies, and credential harvesting.
– Helpdesk impersonation and remote support abuse using Microsoft Teams, vishing, Quick Assist, and custom backdoors to gain initial access and establish persistence.
– Internet-exposed OT, PLCs, IP cameras, and other edge devices being targeted by state-aligned actors for disruption, espionage, and operational manipulation.
– Credential theft and stealer malware campaigns using gaming lures, Discord communities, DNS poisoning, device-code phishing, and AI-assisted social engineering to compromise users and accounts.
Windows 10 Reaches End of Support
As of October 14, 2025, Microsoft has officially ended support for Windows 10. October 2025’s Patch Tuesday was the final security update for the OS—unless your organization enrolls in the Extended Security Updates (ESU) program.
- What This Means for Your Organization:
– No more security patches or bug fixes for Windows 10 devices
– Increased exposure to vulnerabilities and compliance risks
– Continued support requires either: 1.) Enrolling in Microsoft’s paid ESU program, or 2.) Upgrading to Windows 11
- Upgrading Windows 11
Unlike traditional feature upgrades, Windows 11 25H2 is built on the same servicing branch and code base as Windows 11 24H2, making the transition simpler and lower risk.
Fortress has thoroughly tested Windows 11 25H2 and recommends upgrading all supported devices. To begin the upgrade process, contact our 24/7/365 Security Operations Team or reach out to your client experience manager.
Windows 11 End of Support
As of November 2025, Microsoft has officially ended support for earlier versions of Windows 11 (listed below).
- Windows 11 version 21H2 (All Editions)
- Windows 11 version 22H2 (All Editions)
- Windows 11 version 23H2 (Home & Pro)
We would also like to highlight several upcoming End of Support dates for the following Windows releases:
- Windows 11 version 23H2 (Enterprise & Education) – Support ends November 10, 2026. After this date, these editions will no longer receive security updates or fixes.
- Windows 11 version 24H2 (Home & Pro) – Support ends October 13, 2026. Devices running these editions should be upgraded before this date to remain supported and secure.
Fortress recommends reviewing device inventories ahead of these deadlines to ensure systems are upgraded in advance and remain within a supported lifecycle.
* Some specialized editions of Windows 11 24H2 (e.g. Long Term Support Cycle) will continue to receive extended support through 2029. However, for all other editions we recommend upgrading to Windows 11 25H2.
Windows Server 2016 End of Support
Support for Windows Server 2016 is scheduled to end on January 12, 2027, which is now less than a year away. After this date, Microsoft will no longer provide security updates, bug fixes, or technical support for the platform.
Organizations still running Windows Server 2016 should begin planning upgrade or migration strategies to avoid increased security risk and compliance concerns once support ends.
Fortress recommends reviewing affected systems early to allow sufficient time for testing, upgrades, or workload migration before the end-of-support deadline.
Need help planning your transition?
Fortress SRM can help assess your environment, prioritize upgrades, and ensure your endpoints remain patch-compliant and secure.
Patch Tuesday Summary
Microsoft August 2026 Patch Tuesday
421 vulnerabilities disclosed, including 62 critical and 3 zero-days (2 publicly disclosed, 1 actively exploited). By category:
- 176 Elevation of Privilege
- 110 Remote Code Execution
- 85 Information Disclosure
- 11 Security Feature Bypass
- 12 Denial of Service
- 20 Spoofing
- 4 Tampering
Critical Common Vulnerabilities and Exposures (CVEs)
Windows Zero Days
| CVE-ID | Details | Severity | Exploited? |
| CVE-2026-62832 | Windows User Profile Service Elevation of Privilege Vulnerability | Important | No, Publicly Disclosed |
| CVE-2026-68820 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | Important | Yes, Exploitation Detected |
| CVE-2026-72971 | Windows Container Isolation FS Filter Driver (unionfs.sys) Tampering Vulnerability | Important | No, Publicly Disclosed before Patch Tuesday |
Other Critical CVE’s Worth Mentioning
| CVE-ID | Details | Severity | Exploited? |
| CVE-2026-62815 | Microsoft QUIC Remote Code Execution Vulnerability | Critical | No |
| CVE-2026-62878 | Windows DNS Server Remote Code Execution Vulnerability | Critical | No |
| CVE-2026-62893 | Windows Deployment Services TFTP Server Remote Code Execution Vulnerability | Critical | No, Exploitation More Likely |
| CVE-2026-62823 | Windows DHCP Server Remote Code Execution Vulnerability | Critical | No, Exploitation More Likely |
Microsoft August 2026 Security Update Release
3rd Party Critical CVE’s Worth Mentioning
Adobe Products *
| CVE-ID(s) | Affected Product | Issues | Key Risks |
| CVE-2026-48362 CVE-2026-48273 CVE-2026-71384 CVE-2026-71386 CVE-2026-71387 CVE-2026-71385 CVE-2026-34635 CVE-2026-48440 CVE-2026-21279 CVE-2026-25652 CVE-2026-48386 CVE-2026-71383 CVE-2026-48375 CVE-2026-48376 CVE-2026-48384 | Adobe ColdFusion | 11 Critical, 4 Important | arbitrary code execution, privilege escalation, security feature bypass, application denial-of-service, and memory exposure |
| CVE-2026-71362 CVE-2026-48414 CVE-2026-48413 CVE-2026-48415 CVE-2026-48416 CVE-2026-48411 CVE-2026-48412 | Adobe Commerce | 5 Critical, 1 Important, 1 Moderate | security feature bypass, arbitrary code execution, and privilege escalation |
| CVE-2026-48441 CVE-2026-48397 CVE-2026-47940 CVE-2026-48404 CVE-2026-48405 CVE-2026-48406 CVE-2026-48407 CVE-2026-48408 CVE-2026-48409 CVE-2026-48410 CVE-2026-48447 | Adobe Lightroom Classic | 11 Critical | arbitrary code execution |
| CVE-2026-48439 CVE-2026-48438 CVE-2026-48442 CVE-2026-48436 CVE-2026-48387 CVE-2026-48435 CVE-2026-48445 CVE-2026-48434 CVE-2026-48444 CVE-2026-48443 CVE-2026-71389 CVE-2026-48437 CVE-2026-48446 CVE-2026-47922 CVE-2026-71390 | Content Credentials SDK | 3 Critical, 12 Important | security feature bypass, arbitrary file system write, arbitrary file system read, application denial-of-service, and privilege escalation |
| CVE-2026-71398 CVE-2026-27302 CVE-2026-48381 | Adobe Campaign Classic | 3 Critical | arbitrary code execution |
Cisco *
| CVE-ID(s) | Details | Severity | Exploited? |
| CVE-2026-20079 | Cisco Secure Firewall Management Center Software Authentication Bypass Vulnerability | Critical | No |
| CVE-2026-20267 CVE-2026-20268 CVE-2026-20269 CVE-2026-20270 CVE-2026-20271 CVE-2026-20272 CVE-2026-20273 | Cisco IOS XE Software Security Hardening Release: August 2026 | Critical | No |
| CVE-2026-20303 CVE-2026-20304 CVE-2026-20310 CVE-2026-20312 CVE-2026-20313 | Cisco Catalyst SD-WAN Software Security Hardening Release: August 2026 | Critical | No |
| CVE-2026-20337 CVE-2026-20338 CVE-2026-20339 CVE-2026-20345 CVE-2026-20346 CVE-2026-20347 CVE-2026-20348 | ClamAV Vulnerabilities Affecting Cisco Products: August 2026 | High | Yes, proof-of-concept exploit code is available for CVE-2026-20337 and CVE-2026-20338 |
| CVE-2026-20349 | Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software Remote Access SSL VPN Denial of Service Vulnerability | High | Yes, actively exploited in the wild |
| CVE-2026-20316 | Cisco Secure Firewall Management Center Software Static Credential Vulnerability | High | Yes, actively exploited in the wild |
| CVE-2026-20200 CVE-2026-20288 | Cisco Integrated Management Controller Argument Injection Vulnerabilities | High | Yes, proof-of-concept exploit code is available for CVE-2026-20200 |
| CVE-2026-20301 | Cisco IOS Software and IOS XE Software Extensible Messaging Client Protocol Denial of Service Vulnerability | High | No |
| CVE-2026-20263 | Cisco IOS XE Software Blocks Extensible Exchange Protocol Denial of Service Vulnerability | High | No |
| CVE-2026-20124 | Cisco IOS XE Software SNMP Denial of Service Vulnerability | High | No |
Fortinet *
| CVE-ID | Details | Severity | Exploited? |
| CVE-2026-70468 | FGFM Authentication Weakening via CLI Configuration | High | No |
Ivanti *
| CVE-ID | Details | Severity | Exploited? |
| This vulnerability did not meet the criteria for reserving a CVE number. | Ivanti Neurons for MDM | Medium | No |
| CVE-2026-18125CVE-2026-18127CVE-2026-18129 | Endpoint Manager (EPM) | High | No |
Ivanti August 2026 Security Update
N-able
| CVE-ID(s) | Details | Severity | Exploited? |
| CVE-2026-18577 | An incomplete patch for CVE-2026-18556 allows for authentication bypass and account takeover in N-central Versions through 2026.3.1 | High | Yes, actively exploited in the wild |
SAP *
| CVE-ID | Details | Severity | Exploited? |
| CVE-2026-44758 | Code Injection vulnerability in Manufacturing Integration and Intelligence | Critical | No |
| CVE-2026-34265 | Memory Corruption vulnerability in Application Server ABAP for SAP NetWeaver and ABAP Platform | Critical | No |
| CVE-2026-44772 | Code Injection vulnerability in SAP Manufacturing Integration and Intelligence | Critical | No |
| CVE-2026-58231 | Improper Authorization in SAP Commerce Cloud (Data Hub Adapter) | Critical | No |
SAP August 2026 Security Notes
SonicWall *
onicWall *
| CVE-ID | Details | Severity | Exploited? |
| CVE-2026-66145 | An unauthenticated remote code execution vulnerability in GMS | Critical | No |
| CVE-2026-66146 | GMS Multiple Cross-Site Scripting (XSS) Vulnerabilities | Critical | No |
| CVE-2026-66147 | GMS Unauthenticated Command Injection in Dispatcher Service | Critical | No |
| CVE-2026-66148 | GMS Local Privilege Escalation via Authenticated Command Injection | Critical | No |
| CVE-2026-66154 | GMS Weak Certificate Verification to User Compromise via MiTM | Critical | No |
| CVE-2026-18634 | GMS Local Privilege Escalation via Deserialization | Critical | No |
Google Chrome
- Version: 151.0.7922.137/.138 (Windows and Mac), 151.0.7922.137 (Linux)
- Release Date: Tuesday, August 11, 2026
- Key Fixes: 5 high-severity security fixes (CVE-2026-19556, CVE-2026-19557, CVE-2026-19558, CVE-2026-19559, CVE-2026-19560)
* Not handled by Fortress SRM.
Threat Intelligence Trends – August 2026
The following resources are grouped by threat type / category.
AI-Enabled / Emerging Threats
OpenAI Models Escape Sandbox and Compromise Hugging Face During Cybersecurity Test
During a cybersecurity benchmark exercise, OpenAI reported that advanced AI models exploited a zero-day vulnerability, escaped a restricted test environment, and accessed external systems while attempting to improve their benchmark performance. The incident highlights growing concerns around AI specification gaming, autonomous multi-stage cyber operations, and the challenges of safely evaluating highly capable AI agents.
Read more -> OpenAI Models Hacked Hugging Face During a Cyber Test
FBI Warns of Cybercriminals Stealing and Leaking Private Account Content
The FBI issued a public advisory warning that threat actors are using phishing, social engineering, password attacks, and account takeover techniques to steal sensitive content from social media and personal accounts. Stolen data is then shared or sold online, often alongside victims’ personal information, increasing the risk of extortion, harassment, and further targeting.
Read more -> FBI IC3 Public Service Announcement
Microsoft Links Storm-1175 to New StormEncryptor Ransomware Campaigns
Microsoft Threat Intelligence reported that the cybercriminal group Storm-1175 has begun deploying a new ransomware strain called StormEncryptor, marking a shift away from Medusa ransomware. The group is believed to be exploiting recently disclosed vulnerabilities, including the N-able CVE-2026-18577 authentication bypass flaw, and is known for rapidly moving from initial access to data theft and ransomware deployment.
Read more -> Microsoft Threat Intelligence Post
Russian State Actors Are Compromising Internet-Connected IP Cameras
Dutch intelligence agencies warned that Russian state-sponsored actors are systematically compromising internet-accessible IP cameras across Ukraine, NATO countries, and EU member states to support espionage operations. The advisory highlights the risks posed by exposed surveillance systems and urges organizations to secure camera infrastructure to prevent unauthorized access and intelligence collection.
Read more -> AIVD Cybersecurity Advisory
Fake Xeno Roblox Cheats Deliver Java-Based Stealer Through Discord Communities
Bitdefender researchers uncovered a malware campaign masquerading as the popular Xeno Roblox cheat tool and distributed through gaming forums and Discord servers. The malware can steal browser data, gaming accounts, Discord credentials, cryptocurrency wallets, and payment information while also providing attackers with remote access, keylogging, webcam capture, and desktop surveillance capabilities.
Read more -> Fake Xeno Roblox Cheats Deliver Powerful Java Stealer Through Discord and Forums
Iranian-Affiliated Cyber Actors Target Internet-Connected PLCs Across U.S. Critical Infrastructure
CISA, the FBI, and other U.S. agencies warned that Iranian-affiliated threat actors are actively targeting internet-exposed programmable logic controllers (PLCs) across critical infrastructure sectors, including water, energy, and government services. The actors have been observed modifying PLC logic, manipulating HMI and SCADA displays, and causing operational disruptions and financial losses, prompting urgent recommendations to remove OT devices from direct internet exposure.
Read more -> Iranian-Affiliated Cyber Actors Exploit Programmable Logic Controllers Across US Critical Infrastructure
INC Ransom Uses Client-Focused Extortion Tactics Against U.S. Law Firms
Researchers identified a campaign in which INC Ransom created dedicated extortion websites for individual U.S. law firms and their clients, increasing pressure beyond traditional leak-site threats. Analysis of 24 targeted firms found that 58% never appeared on the group’s public leak site, suggesting this client-focused extortion strategy may be influencing ransom negotiations and outcomes.
Read more -> INC Ransom’s Law Firm Extortion: What a 58% Leak-Site Absence Rate Reveals About Who Pays
Social Engineering & Phishing
Payroll Pirates Target Microsoft 365 Financial Workflows with AiTM Phishing
Arctic Wolf researchers are tracking a widespread adversary-in-the-middle (AiTM) phishing campaign targeting Microsoft 365 users through voicemail-themed lures. The campaign steals authenticated sessions, identifies HR, payroll, and finance personnel, and silently collects business-critical emails while using residential proxies to blend malicious activity with legitimate user traffic.
Read more -> Payroll Pirates: Strange New Tides in Business Email Compromise
Kimsuky Integrates AI and Local LLMs into Cyber Espionage Operations
Researchers observed the North Korean-linked threat group Kimsuky leveraging AI-generated decoy documents and experimenting with local large language models (LLMs) to enhance phishing and malware operations. The campaign combines AI-assisted social engineering with GitHub-based command-and-control infrastructure, highlighting the growing use of AI to scale and refine nation-state cyber activity.
Read more -> Kimsuky Integrates AI into Attack Operations, From AI-Generated Decoy Documents to a Local LLM
Helpdesk Impersonation Attacks Use Microsoft Teams and Quick Assist to Deploy GoGRPC Backdoor
Zscaler researchers identified a threat actor using Microsoft Teams vishing calls to impersonate IT helpdesk staff and convince victims to launch Quick Assist remote sessions. Once access is established, the attackers deploy a custom Go-based backdoor called GoGRPC, conduct reconnaissance, and establish persistence, highlighting a growing trend of social engineering-driven ransomware intrusion activity.
Read more -> Helpdesk Hijackers: Teams Vishing, Quick Assist, and GoGRPC Backdoor
Vulnerabilities & Experts
Active Exploitation of CVE-2026-59310 Impacts VMware vCenter Systems Worldwide
Researchers observed active exploitation of CVE-2026-59310, a critical VMware vCenter directory traversal vulnerability, affecting 361 victim IPs across 47 countries. Threat actors are reportedly using the open-source reverse_ssh framework for persistence, highlighting the need for organizations to immediately patch exposed vCenter servers and investigate potential indicators of compromise.
Read more -> Active Exploitation of CVE-2026-59310
INC Ransomware Exploits SonicWall SMA Zero-Day Chain for Root Access
Researchers report that INC Ransomware is actively exploiting two critical SonicWall SMA 1000 vulnerabilities, CVE-2026-15409 and CVE-2026-15410, to gain root-level access to internet-facing VPN appliances. The attack chain enables full system compromise, persistence, credential theft, and potential ransomware deployment, reinforcing the urgency of patching affected SMA 1000 devices and conducting compromise assessments.
Read more -> From WSProxy to Root: INC Ransomware and SonicWall SMA Exploit Chain
DNS Poisoning Campaign Targets Hotel and Conference Center Wi-Fi Networks
ReliaQuest researchers identified a campaign in which threat actors compromise hospitality Wi-Fi gateways and use DNS poisoning to redirect travelers to attacker-controlled Microsoft 365 login infrastructure. The activity targets corporate employees using hotel and conference center networks, with attackers attempting credential theft and account compromise through adversary-in-the-middle and device-code phishing techniques.
Read more -> DNS Poisoning Tactics Expand to Hospitality Wi-Fi
Qilin Ransomware Operators Exploit Palo Alto GlobalProtect Authentication Bypass
Arctic Wolf investigated multiple ransomware incidents in which threat actors exploited CVE-2026-0257, a Palo Alto Networks GlobalProtect authentication bypass vulnerability, to gain initial access and rapidly deploy Qilin ransomware. Attackers used credential theft, lateral movement, remote access tools, and in some cases data exfiltration before encrypting victim environments, highlighting the risk posed by unpatched VPN appliances.
Read more -> Cookie Crumbles: How Exploitation of CVE-2026-0257 Leads to Qilin Ransomware
Recommended Actions
Mitigations
- Prioritize patching and exposure reduction for internet-facing remote access, VPN, virtualization, and management platforms, including VMware vCenter, SonicWall SMA/GMS, Palo Alto GlobalProtect, N-able N-central, Cisco security appliances, and other systems tied to active exploitation or ransomware activity.
- Remove direct public internet exposure from OT assets, PLCs, IP cameras, and administrative interfaces wherever possible. Place remote access behind secure VPN, enforce MFA, and restrict access using allowlists, segmentation, and least-privilege controls.
- Strengthen protections against social engineering by limiting external Microsoft Teams communication where appropriate, restricting Quick Assist or remote support tools to approved workflows, enforcing phishing-resistant MFA for high-risk roles, and training users to verify helpdesk, payroll, and financial requests through trusted channels.
Monitoring
- Monitor for suspicious authentication activity, including adversary-in-the-middle phishing patterns, impossible travel, residential proxy usage, device code authentication, MFA fatigue attempts, new inbox rules, mailbox forwarding, and abnormal access to payroll, HR, finance, and executive accounts.
- Review logs from VPNs, firewalls, remote access appliances, vCenter, SonicWall SMA/GMS, Palo Alto GlobalProtect, N-able N-central, and other exposed infrastructure for new accounts, unusual administrative logins, configuration changes, command execution, persistence mechanisms, and data exfiltration indicators.
- Increase monitoring for OT and edge-device activity, including unexpected PLC logic changes, HMI/SCADA display modifications, camera logins from unusual geographies, DNS changes on guest or hospitality Wi-Fi networks, and traffic to newly registered or attacker-controlled domains.
Detection Tips
- Hunt for ransomware precursor activity such as remote access tool installation, credential dumping, lateral movement, unusual PowerShell or command-line activity, archive creation, large outbound transfers, and access to file shares or backup repositories.
- Create detections for helpdesk impersonation and remote support abuse, including external Teams contact followed by Quick Assist launch, new remote access sessions, Go-based backdoor indicators, suspicious service creation, and unexpected persistence changes.
- Use endpoint and email telemetry to identify stealer and phishing activity, including suspicious Java execution, Discord or gaming-related lure downloads, abnormal browser credential access, malicious OAuth or session token behavior, and messages impersonating payroll, voicemail, document signing, or IT support workflows.
About Fortress SRM’s Vigilant Managed Cyber Hygiene Offering
Why Patching Matters
Unpatched software is a leading cause of breaches—nearly 1 in 3 attacks exploit known vulnerabilities.
Vigilant Managed Cyber Hygiene
Fortress SRM’s Vigilant Managed Cyber Hygiene simplifies patch management.
- Automated updates with 97%+ success rate for Microsoft & 100+ third-party applications
- Critical patches, OS upgrades, and configuration updates for all devices, on/off network
- 24/7/365 U.S.-based monitoring and real-time reporting for full visibility
Stay Protected. Stay Proactive.
Learn how Fortress SRM can enhance your cybersecurity strategy

