Welcome to the latest CVE WATCHTOWER security briefing. Our weekly threat intelligence report highlights a dangerous surge in cyber threats. Between August 17 and August 23, 2026, researchers cataloged 3,179 new security vulnerabilities. Therefore, defenders must evaluate new active vulnerability exploits immediately. Threat actors are aggressively targeting cloud infrastructure and machine learning engines. Consequently, security teams must patch internet-facing services to stop imminent network breaches.
CISA KEV Catalog Surges With Critical Zero-Days
The Cybersecurity and Infrastructure Security Agency (CISA) added nine critical flaws to its Known Exploited Vulnerabilities catalog. Specifically, adversaries are attacking enterprise virtualization and collaboration tools.
For example, VMware vCenter Server suffers from a critical directory traversal flaw in its Syslog component (CVE-2026-59310). Attackers can exploit this weakness to achieve unauthenticated remote code execution. Furthermore, TrueConf Server faces active exploitation through undocumented functions on TCP port 4307 (CVE-2026-72529 and CVE-2026-72530). Remote attackers can break out of isolated environments to take over host systems. Additionally, Zimbra Collaboration servers are vulnerable to arbitrary command execution via SNMP notification handling (CVE-2026-73570).
Actively Exploited Vulnerabilities Overview
We tracked multiple active threats across enterprise networks. Below is a detailed breakdown of these critical security flaws.
| CVE Identifier | Affected Software | CVSS Score | Vulnerability Summary |
| CVE-2026-59310 | VMware vCenter Server | 9.8 |
Directory traversal in Syslog server allowing remote code execution. |
| CVE-2026-33824 | Windows IKE Extension | 9.8 |
Double free flaw allowing remote code execution over the network. |
| CVE-2025-62593 | Ray AI Compute Engine | 9.4 |
Browser-based RCE via DNS rebinding and manipulated headers. |
| CVE-2026-64849 | MLflow AI Platform | 9.3 |
Unauthenticated SSRF via webhook testing to access cloud metadata. |
| CVE-2026-55040 | Microsoft SharePoint | 9.1 |
Weak authentication permitting security feature bypass. |
| CVE-2026-65400 | macOS Screen Sharing | 9.8 |
State management flaw permitting unauthorized Screen Sharing access. |
| CVE-2026-72529 | TrueConf Server | 9.8 |
Unauthenticated script execution via undocumented port 4307 functions. |
| CVE-2026-73570 | Zimbra Collaboration | 8.9 |
Improper input sanitization during SNMP processing leading to RCE. |
| CVE-2026-77806 | SPIP CMS | 9.8 |
Code injection via |
Artificial Intelligence and Cloud Platforms Under Siege
Modern artificial intelligence infrastructure remains a prime target for malicious actors. Notably, the Ray AI compute engine faces active exploitation through client-side browser attacks (CVE-2025-62593). Developers visiting malicious websites can trigger remote code execution inside local clusters.
Moreover, MLflow contains an unauthenticated Server-Side Request Forgery vulnerability (CVE-2026-64849). Hackers can redirect webhook test requests to steal cloud instance metadata. In addition, Xinference contains a critical 10.0 CVSS flaw that evaluates model tool-call outputs directly via eval() (CVE-2026-61539). As a result, prompt-injection attacks can grant full server control.
What You Should Do Now
Enterprise defenders must act swiftly on this weekly threat intelligence report. First, administrators must prioritize updating VMware vCenter and TrueConf servers. Next, organizations running Ray and MLflow must restrict AI endpoint exposure to internal networks.
Furthermore, web administrators must patch SPIP installations and WordPress plugins like Pods immediately. Finally, keep watching this space. Our CVE Watchtower service tracks these shifts every week, so you can act before attackers do.
Support Our Threat Intelligence
If you find our CVE report and cybersecurity news helpful, consider supporting our work.