Daily briefing · August 28, 2026

10 Actively Exploited CVEs Demand Immediate Action: Metabase, VMware, macOS, Cisco, and More Under Fire

Automated Vexday summary · sources: NVD, CISA KEV, EPSS
Verdict of the day — attention

While August 28, 2026 registered no new CVE disclosures, the threat landscape remains under significant pressure: all 10 featured vulnerabilities carry active exploitation confirmation from both CISA KEV and VulnCheck, spanning critical infrastructure, enterprise collaboration tools, AI platforms, and endpoint management systems. Several were weaponized within days of disclosure, underscoring the relentless pace at which attackers are operationalizing known flaws. Defenders should treat this ATTENTION-level day as a clear signal to prioritize patch validation across affected product families.

Today’s brief
  • 10 CVEs in active exploitation (CISA KEV + VulnCheck confirmed) — no new disclosures today, but the backlog demands urgent attention
  • Metabase SQL injection (CVSS 10.0) and MLflow SSRF bypass (weaponized in 1 day) top the functional-exploit tier
  • macOS Screen Sharing auth bypass, TrueConf RCE pair, and Zimbra command injection all carry functional or PoC exploits already in the wild
  • N-central authentication bypass (CVE-2026-18556) was incompletely patched — CVE-2026-18577 exploits that failed fix, weaponized in 2 days
Critical highlights
1
CVE-2026-72898KEVCVSS 10Functional exploit2 daysaffects Metabase
A CVSS 10.0 unauthenticated SQL injection in Metabase's '/reset_password' endpoint grants full administrator access to the connected database instance — weaponized with a functional exploit just 2 days after disclosure and confirmed in active exploitation by both CISA and VulnCheck, making this the highest-priority patch of the day.
2
CVE-2026-59310KEVCVSS 9.8PoC18 daysaffects Cloud Foundation
A directory traversal flaw in VMware vCenter's Syslog server (CVSS 9.8) allows unauthenticated remote code execution for any attacker with network access to vCenter — its PoC exploit and confirmed active exploitation place it at the top of the critical remediation queue for all VMware Cloud Foundation environments.
3
CVE-2026-65400KEVCVSS 9.8PoC12 daysaffects macOS
An authentication state management failure in macOS (Sequoia, Sonoma, and Tahoe) lets a network-adjacent attacker bypass Screen Sharing credentials entirely — weaponized 12 days after disclosure and actively exploited, any Mac running pre-patched versions accessible over the network is at immediate risk.
4
CVE-2026-72530KEVCVSS 9.5PoC6 daysaffects TrueConf Server
This CVSS 9.5 RCE in TrueConf Server (versions up to 5.5.5) allows an unauthenticated attacker via port 4307/TCP to break out of the isolated environment and execute arbitrary code on the host — weaponized in 6 days, it is the more severe of two sibling TrueConf CVEs confirmed in active exploitation today.
5
CVE-2026-64849KEVCVSS 9.3Functional exploit1 daysaffects mlflow
An SSRF-via-redirect vulnerability in MLflow's unauthenticated webhook test endpoint bypasses URL validation by following redirects to a different resolved host — weaponized with a functional exploit in just 1 day after disclosure, this is a critical risk for any organization running MLflow prior to 3.15.0 exposed to the network.
6
CVE-2026-72529KEVCVSS 9.3affects TrueConf Server
A companion flaw to CVE-2026-72530, this TrueConf Server vulnerability allows unauthenticated remote attackers to invoke undocumented internal functions via port 4307/TCP and execute arbitrary scripts — actively exploited and confirmed by both CISA KEV and VulnCheck, TrueConf environments should be treated as fully compromised until patched.
7
CVE-2026-73570KEVHIGH 8.9Functional exploit8 daysaffects Collaboration
Zimbra Collaboration (pre-10.1.20) is vulnerable to unauthenticated OS command injection via SNMP notification processing when the zimbra-snmp package is installed — armed with a functional exploit 8 days after disclosure and actively exploited, any Zimbra instance with SNMP notifications enabled should be considered a high-priority target.
8
CVE-2026-20349KEVHIGH 8.6affects Cisco Secure Firewall Adaptive Security Appliance (ASA) Software
An insufficient error-checking flaw in Cisco ASA and FTD's Remote Access SSL VPN service allows unauthenticated remote attackers to trigger unexpected device reloads, causing denial of service — with confirmed active exploitation and a CVSS of 8.6, this is particularly dangerous for organizations relying on these devices for perimeter security continuity.
9
CVE-2026-18577KEVHIGH 8.2Functional exploit2 daysaffects N-central
This CVE documents an incomplete patch for CVE-2026-18556 in N-able N-central (through version 2026.3.1) that still allows authentication bypass and full account takeover — weaponized in only 2 days with a functional exploit, it serves as a stark reminder that partial patches can create a false sense of security.
10
CVE-2026-18556KEVHIGH 8.2PoC5 daysaffects N-central
The original authentication bypass vulnerability in N-able N-central (through 2026.1) allows attackers to use alternate paths or channels to circumvent authentication controls — weaponized in 5 days with an existing PoC and confirmed in active exploitation, it forms a critical remediation pair with CVE-2026-18577 that must be addressed together.
Ransomware today

Ransomware activity targeting Brazil remains intense, with five Brazilian organizations identified as recent victims across multiple groups. The krybit group claimed three Brazilian targets — www.neooftalmo.com.br (Healthcare), sysconth.com (Technology), and vascara.com (Retail & E-Commerce) — while thegentlemen hit TEC Container (Manufacturing) and unsafe targeted amzur.com. Over the past 30 days, thegentlemen leads Brazilian activity with 7 confirmed victims, followed by krybit with 4, and groups such as dragonforce, Global Secret Group, L Group, and direwolf each accounting for 2 Brazilian victims.

amzur.com BRunsafe
www.neooftalmo.com.br BRkrybit · Healthcare
sysconth.com BRkrybit · Technology
vascara.com BRkrybit · Retail & E-Commerce
TEC Container BRthegentlemen · Manufacturing
thegentlemen 7krybit 4Global Secret Group 2dragonforce 2L Group 2direwolf 2
Active groups & APTs

Several threat actor groups are being tracked as active or recently updated in this cycle, including dragonforce, funksec, kairos, karakurt, kazu, and Iran-linked blackshadow, though no specific new victim disclosures are attributed to them in the current data window. The presence of kazu is notable in the Brazilian healthcare sector, where Brazil Mobilemed's Cloud PACS Platform and Meducar's Telemedicine platform appear among recent victims. The continued tracking of blackshadow — an Iranian-origin group — signals that geopolitically motivated actors remain part of the broader threat landscape alongside financially motivated ransomware operators.

Brazil focus

Brazil is facing concentrated ransomware pressure across multiple sectors, with at least eight Brazilian organizations identified as victims in recent weeks, spanning healthcare, technology, retail, manufacturing, and others. Healthcare is particularly exposed, with www.neooftalmo.com.br, Brazil Mobilemed, and Meducar all appearing as victims of krybit and kazu respectively — a sector that handles sensitive patient data and whose operational disruption carries direct public safety implications. The diversity of active groups targeting Brazil — krybit, thegentlemen, dragonforce, kazu, and unsafe — indicates that Brazilian organizations are being actively targeted by multiple independent ransomware ecosystems simultaneously.

amzur.comunsafe
www.neooftalmo.com.brkrybit · Healthcare
sysconth.comkrybit · Technology
vascara.comkrybit · Retail & E-Commerce
TEC Containerthegentlemen · Manufacturing
Fratodragonforce · Other
Brazil Mobilemed: Cloud PACS Platformkazu · Healthcare
Meducar: Telemedicine and Patient Management Systemkazu · Healthcare
Today’s recommendation: All organizations should immediately prioritize patching CVE-2026-72898 (Metabase), CVE-2026-59310 (VMware vCenter), and CVE-2026-64849 (MLflow), and validate that N-central deployments have applied both CVE-2026-18556 and CVE-2026-18577 fixes together — incomplete remediation of the N-central pair leaves systems fully exposed despite patching efforts.
Given the breadth and speed of weaponization seen across today's featured vulnerabilities, organizations should proactively validate their actual exposure to each affected product rather than relying solely on asset inventory records, which frequently underrepresent shadow IT or unmanaged instances.Find out in minutes, with a free exposure assessment, where your organization is truly exposed.Meet the Autonomous AI Pentest Agent →
Previous briefings
September 8, 2026Windows Under Active Exploit, ScreenConnect Zero-Day Detected Before CISA: September 8 Security BulletinSeptember 7, 202622 Critical CVEs Published on a Quiet Day, With Heavy Ransomware Pressure on BrazilSeptember 6, 2026Quiet Day Hides Real Risks: Tenda HG10, NEC UNIVERGE, and Brazilian Ransomware Surge Demand AttentionSeptember 5, 2026WordPress Plugin Wave and Tenda CP3 Flaws Lead a Calm But CVE-Heavy DaySeptember 4, 2026WordPress Plugins and FreeIPMI Lead a Calm but Patch-Heavy DaySeptember 3, 2026Four CVSS 10.0 Critical CVEs Headline a Calm But Dense Vulnerability DaySeptember 2, 2026WordPress Plugins Under Fire, Cisco IOS XR and NX-OS in the Crosshairs: ATTENTION Day With Active ExploitationSeptember 1, 2026Active Exploitation of Proxmox and SonicWall SMA1000 Leads a High-Alert DayAugust 31, 2026WordPress Plugins and Tenda Routers Dominate a High-Alert Day With 41 Critical CVEsAugust 30, 2026Calm Day Hides Sharp Edges: Critical Code Injection and Router Flaws Top August 30 BulletinAugust 29, 2026Ten Active-Exploitation CVEs Dominate as Ransomware Groups Hammer BrazilAugust 28, 202610 Actively Exploited CVEs Demand Immediate Action: Metabase, VMware, macOS, Cisco, and More Under FireAugust 27, 2026Router Firmware Under Active Exploitation and WordPress Wave Raises Alerts on August 27August 26, 2026Ubiquiti UniFi and Gitea Face Active Exploitation Alerts as 62 Critical CVEs Emergeview full archive →
Share