Microsoft’s August Patch Tuesday includes fixes for 421 vulnerabilities, among them three zero-days and 62 marked critical. Multiple issues also touch Office remote code execution paths, raising the urgency for organizations that rely on Office-centric workflows. If you haven’t already, prioritize patching systems with Internet exposure and machines used to open Office documents.
Source: Malwarebytes
CVE-2026-68820: Windows AFD.sys use-after-free is under active exploitation
A use-after-free flaw in the Windows Ancillary Function Driver for WinSock (AFD.sys), tracked as CVE-2026-68820, is being exploited in the wild. The vulnerability is described as enabling low-privileged local attackers to escalate privileges to SYSTEM. Given the confirmed activity, incident-response teams should check for related indicators (and confirm patch status) immediately.
Source: Help Net Security
VMware vCenter CVE-2026-59310: exploitation confirmed, threat actors gain persistent remote access
Broadcom VMware vCenter’s critical directory traversal vulnerability (CVE-2026-59310) is reportedly being actively exploited. Public reporting notes attackers leveraging it for arbitrary code execution and persistence, which can quickly turn a “patchable issue” into a fully compromised management-plane incident. Organizations using vCenter should treat this as a priority remediation, and validate compensating controls where patching is delayed.
Source: The Record
SharePoint CVE-2026-55040: attackers move fast after PoC release
After a proof-of-concept was made public, researchers report that threat actors began exploiting the SharePoint authentication bypass vulnerability CVE-2026-55040 (CVSS 9.1). The issue is tied to weak authentication checks that can allow an unauthenticated attacker to impersonate administrators. This is a clear example of “time-to-exploit” shrinking—patch quickly after disclosure and monitor for abnormal authentication and session behavior.
Source: Security Affairs
Lazarus “Operation Dream Job”: fake recruiting lures now tied to Windows zero-days
Multiple reports detail Lazarus campaigns that weaponize fake job offers, trojanized documents, and at least one Windows zero-day to target defense and aerospace organizations. These intrusions emphasize operational stealth—using believable social engineering and then escalating impact once execution is gained. Security teams should review recruitment-themed lures, tighten control over document execution paths, and validate endpoint protections against zero-day activity.
Source: The Record
“City-Forum” exposure: Salesforce and ServiceNow portals reportedly read for 17 months
Researchers describe a long-running campaign they call “City-Forum” that accessed Salesforce and ServiceNow portal data globally. The activity allegedly originated from a domain abandoned years ago but repointed to a generic rented server, enabling sustained collection without immediate detection. The key takeaway: even when breaches don’t look like “loud hacking,” misconfigurations or exposed guest access can yield prolonged data harvesting.
Source: Help Net Security
You May Also Be Interested In...
Four corporate investigation mistakes organizations make under pressure
Wireshark 4.6.8 patches 28 security bugs (including file-parser issues)
Over 2,500 organizations impacted by LiteLLM supply-chain attack