{
 "provider": "Senserva",
 "note": "Every mass alert emailed to Senserva Watch members: when it went out, the CVEs and KBs it named, and the text. What was sent, never to whom.",
 "updated": "2026-09-11T12:32:29.420Z",
 "count": 38,
 "alerts": [
  {
   "at": "2026-09-08T21:58:54.009Z",
   "cves": [
    {
     "id": "CVE-2026-81963",
     "page": true
    },
    {
     "id": "CVE-2026-85880",
     "page": true
    },
    {
     "id": "CVE-2024-43451",
     "page": true
    },
    {
     "id": "CVE-2024-49039",
     "page": true
    },
    {
     "id": "CVE-2026-75650",
     "page": true
    },
    {
     "id": "CVE-2026-86218",
     "page": true
    }
   ],
   "kbs": [
    {
     "id": "KB5122878",
     "page": true
    },
    {
     "id": "KB5124008",
     "page": true
    },
    {
     "id": "KB5122880",
     "page": true
    },
    {
     "id": "KB5046615",
     "page": true
    }
   ],
   "text": "Microsoft's September 2026 Patch Tuesday shipped today: 1,169 CVEs across 60 updates, 118 rated Critical, and two Windows zero-days that CISA added to the KEV list the same day.\n\nPATCH THESE FIRST, EVERYWHERE\n- CVE-2026-81963, Windows Update Stack, elevation of privilege, CVSS 7.8, exploitation detected, on CISA KEV.\n- CVE-2026-85880, Windows Advanced Local Procedure Call (ALPC), elevation of privilege, CVSS 7.8, exploitation detected, on CISA KEV.\nBoth landed on the KEV list on release day, which is faster than the usual few days. Federal agencies have until September 22. Everyone else should treat that as the deadline too.\nBoth are local: the machines people log into come first. The fixes ride in this month's cumulative updates. Each CVE page lists every update carrying it, by Windows version:\nhttps://senserva.com/cve/CVE-2026-81963.html\nhttps://senserva.com/cve/CVE-2026-85880.html\n\nTODAY'S 60 UPDATES, BY FAMILY\n- Windows 10, Windows 11 and Windows Server cumulative updates, including KB5122878 (Windows 10 / Server 2019), KB5124008 and KB5122880 (Windows 11).\n- 18 .NET updates, 10 SQL Server updates, 14 Office and SharePoint updates, and 8 others.\nAlso this month: CVSS 10.0 entries in Azure AI Language and Azure AD B2C, a 9.9 in Entra ID, and a 9.8 remote code execution in Skype for Business Server.\nEvery update, worst first: https://senserva.com/patch-tuesday-2026-09.html#updates\n\nHOT KBs RIGHT NOW\nThe hottest Microsoft updates on the Senserva Ranking today are still the November 2024 cumulative updates, KB5046615 and its siblings for Windows 10 1809, Server 2019 and Server 2022: two of their CVEs (CVE-2024-43451, CVE-2024-49039) are on the CISA KEV list with ransomware use, CVSS 9.8, EPSS 0.84, and they are what people are searching for this week. Any machine on those builds that never took them is exposed today; this month's cumulative update carries the same fixes.\nThe full list: https://senserva.com/whats-hot-cve-kb.html\n\nThe same CISA alert also added CVE-2026-75650 in Adobe Commerce and Magento, and CVE-2026-86218 in N-able N-central. Not Microsoft, but if you run either, they belong in this week's queue.\n\nThe release, ranked by risk: https://senserva.com/patch-tuesday.html\nThe write-up: https://senserva.com/blog/september-2026-patch-tuesday"
  },
  {
   "at": "2026-09-03T21:12:14.402Z",
   "cves": [
    {
     "id": "CVE-2026-82329",
     "page": true
    },
    {
     "id": "CVE-2026-66384",
     "page": true
    }
   ],
   "kbs": [],
   "text": "CISA added CVE-2026-82329 to the Known Exploited Vulnerabilities catalog on\n2026-09-02 and gave federal agencies until 2026-09-05 to remediate it. Three\ndays again, and for the same reason: exploitation is confirmed in the wild, not\npredicted. JFrog shipped the patch on August 28. Attackers were on it by\nSeptember 1.\n\nThe flaw is in JFrog Artifactory, the artifact repository that holds your\nbinaries, containers, packages, and models. Senserva records a CVSS score of\n9.8, the v3.1 base score from the National Vulnerability Database. No\nv4 score has been published. Earlier this week FIRST still had the 30 day exploitation\nprobability under half a percent, which is the one signal here pointing the\nother way. While a predictive score is useful, the confirmed exploitation bumps\nup the priority.\n\nTwo things make it worse than a normal authentication bug. It is the default\nconfiguration that is vulnerable, so there is no misconfiguration to point at\nand no hardening step anyone skipped. Artifactory is a control plane, not an\napplication. Administrative access there reaches repository configuration, the\nidentities and tokens stored alongside it, and the distribution paths that feed\nyour build and production systems.\n\nWhat attackers actually did matters for your response. WatchTowr observed them\nminting administrator tokens, then enumerating users, groups, credential sets,\nand federated access relationships. In a smaller number of cases they created\nbackdoor users. That is persistence that survives the patch, so make sure to\naudit as well after applying the update.\n\nWhat to do this week. Upgrade self-hosted Artifactory to 7.161.20, 7.146.38,\n7.133.29, 7.125.20, 7.117.28, or 7.111.21, whichever matches your branch. JFrog\nhas already patched cloud instances, so this is a self-managed problem. Then\nassess, because patching alone does not close it: review the admin user list for\naccounts nobody created, audit access tokens and revoke ones you cannot account\nfor, and rotate the credentials and integration secrets that Artifactory held.\nCheck your CI/CD service accounts and any federated trust Artifactory brokers to\nother systems. If the upgrade has to wait for a change window, take the instance\noff any network path that does not need it.\n\nWorth noting that this is the second Artifactory entry in KEV in a week.\nCVE-2026-66384 was added on August 27. If you are only tracking one, you are\ntracking half the problem.\n\nThe full record, with every change we have tracked since it was listed:\nhttps://senserva.com/cve/CVE-2026-82329.html\n\nEverything CISA has added beyond Microsoft this month:\nhttps://senserva.com/non-microsoft-cve-tracker.html"
  },
  {
   "at": "2026-09-01T22:54:26.253Z",
   "cves": [],
   "kbs": [],
   "text": "Siemserva by Senserva now includes a browser-based Interactive UI. Download the latest release and work with your results in the browser: every missing patch ranked by real attacks, all 600+ security checks across Microsoft 365, Intune, Defender, and Entra ID, and full reports. Setup takes minutes, and your data stays local, in a results database only you hold.\n\nThe download is open to everyone, so pass it along: anyone can install Siemserva and explore the Interactive UI on the built-in demo data, no key needed.\n\nAs a Senserva Watch member, you get more. Your personalized key unlocks your Three Free Unlimited Audits of your own tenant: one to Find it, one to Fix it, one to Prove it. All users, all settings, all patches, all tenants, no time limit. Each audit includes the complete Senserva MCP server for Claude, so you can ask your own questions of the results. Included in this message is a reminder of your personalized key.\n\nDirect downloads:\n\nWindows (x64), signed executable:\nhttps://github.com/Senserva/Siemserva-Releases/releases/latest/download/siemserva-win-x64-signed.exe\n\nWindows (x64), ZIP:\nhttps://github.com/Senserva/Siemserva-Releases/releases/latest/download/siemserva-win-x64-signed.zip\n\nmacOS (Apple Silicon):\nhttps://github.com/Senserva/Siemserva-Releases/releases/latest/download/siemserva-osx-arm64-signed.zip\n\nLatest release:\nhttps://github.com/Senserva/Siemserva-Releases/releases/latest\n\nThank you for being part of Senserva Watch,\nThe Senserva team"
  },
  {
   "at": "2026-08-27T19:58:48.654Z",
   "cves": [
    {
     "id": "CVE-2026-8452",
     "page": true
    },
    {
     "id": "CVE-2026-8451",
     "page": true
    },
    {
     "id": "CVE-2026-19490",
     "page": true
    }
   ],
   "kbs": [],
   "text": "CISA added CVE-2026-8452 to the Known Exploited Vulnerabilities catalog on\n2026-08-26 and gave federal agencies until 2026-08-29 to remediate it. Three\ndays again, and the same reason as last time: exploitation is confirmed, not\npredicted.\n\nThe flaw is in Citrix NetScaler ADC and NetScaler Gateway, the appliances that\nterminate SSL VPN, ICA proxy, clientless VPN, and RDP proxy sessions at the\nedge. Senserva records a CVSS score of 8.8, the version 4 base score Citrix\nassigned in advisory CTX696604 on June 30. Credit for the original report goes\nto Michael Tucker of the JPMorgan Chase XOR team.\n\nRead the vendor description carefully, because it is the weak point in this one.\nCitrix calls it a memory overflow leading to unpredictable or erroneous behavior\nand denial of service, and CISA's KEV entry repeats the denial of service\nframing. watchTowr Labs published the root cause and carried the same bug\nthrough to a webshell. Bishop Fox reproduced the memory corruption in a lab on a\nbuild the public proof of concept was not written for. Scoping your response to\nthe vendor's wording would understate this.\n\nThe mechanism is worth one sentence because it explains the scoping. Before\nNetScaler verifies the signature on an inbound SAML message, it first rewrites\nthe signed content into canonical form, and one attacker-supplied field in that\nstep, the PrefixList, gets copied into a fixed-size buffer without a length\ncheck. The rewrite happens before any authentication, so a single unsigned\nPOST from a stranger reaches the vulnerable code.\n\nThat means the unit of work is the virtual server, not the appliance. Citrix\nnames Gateway and AAA virtual servers without mentioning SAML, but Bishop Fox\nfound the vulnerable endpoints exist only where SAML is actually configured and\na policy is attached. An appliance with three virtual servers can be vulnerable\non one and unreachable on the other two. Standby HA nodes count, since an\nunpatched secondary is fully exposed the moment it takes over.\n\nSenserva Watch leans Microsoft. This one is not, and it is in your inbox because\nexploitation is confirmed and the clock is three days.\n\nWhat to do this week. Upgrade to at least 13.1-63.18 or 14.1-72.61, which are\nthe minimum builds carrying the fix, and go past them to the latest on your\nbranch. FIPS and NDcPP fleets run their own cadence: 14.1-72.61 FIPS, or\n13.1-37.272 for 13.1-FIPS and 13.1-NDcPP. Nothing is coming for 12.1 or 13.0, so\nthose need migration rather than patching. Inventory with\n\"show ns runningConfig | grep -i saml\" to find where SAML policies are actually\nbound, then confirm the installed build with \"show ns version\" on active and\nstandby nodes both.\n\nThen assess, because the patch does not tell you whether someone already came\nthrough. Look for unexpected files under /var/vpn/theme/, nsppe crashes in\nns.log with pitboss reporting the process died, and fresh NSPPE-* core files\nunder /var/core. One correction to the intuition here: a reboot does not\ndistinguish a failed attempt from a successful one, so triage on what is in the\nfile system.\n\nWhile you have the inventory open, two siblings share the same exposure.\nCVE-2026-8451 is a memory disclosure bug in the same SAML feature and is also\nunder active exploitation. CVE-2026-19490, from the August 19 bulletin, is a\ndifferent bug that needs the same SAML configuration on current builds. One pass\ncovers all three.\n\nThe full record, with every change we have tracked since it was listed:\nhttps://senserva.com/cve/CVE-2026-8452.html\n\nEverything CISA has added beyond Microsoft this month:\nhttps://senserva.com/non-microsoft-cve-tracker.html"
  },
  {
   "at": "2026-08-22T20:39:32.126Z",
   "cves": [
    {
     "id": "CVE-2026-55040",
     "page": true
    }
   ],
   "kbs": [],
   "text": "Microsoft SharePoint Server Security Feature Bypass Vulnerability (CVE-2026-55040) is the CVE to watch right now. The Microsoft SharePoint flaw is rated Critical with a CVSS score of 9.1. CISA added it to the Known Exploited Vulnerabilities catalog on 2026-08-18, which means it is being attacked in the wild, not just in theory. Rapid7 covered it on 2026-08-11: \"Rapid7 Analysis: Microsoft SharePoint JWT Token Authentication Bypass (CVE-2026-55040)\". \n\nIf it is in your environment, patch it now. \n\nDetails, affected versions, and remediation guidance: https://senserva.com/cve/CVE-2026-55040.html"
  },
  {
   "at": "2026-08-19T16:22:06.572Z",
   "cves": [
    {
     "id": "CVE-2025-62593",
     "page": true
    }
   ],
   "kbs": [],
   "text": "CISA added CVE-2025-62593 to the Known Exploited Vulnerabilities catalog on\n2026-08-17 and gave federal agencies until 2026-08-20 to remediate it. Three\ndays is unusually short, and that is the part to read: exploitation is\nconfirmed in the wild, not predicted.\n\nThe flaw is in Ray, the open source framework used to scale AI and machine\nlearning workloads. Senserva records a CVSS score of 8.8, the version 3.1 base\nscore from the National Vulnerability Database. The assigning authority also\npublished a version 4 score of 9.4, so an advisory quoting the higher number is\ndescribing the same flaw on a newer rubric. FIRST puts the 30 day exploitation\nprobability near 1 percent, which is the one signal here pointing the other way.\nWhen a confirmed exploitation source and a predictive score disagree, the\nconfirmed source wins.\n\nSenserva Watch leans Microsoft. This one is not, and it is in your inbox because\nexploitation is confirmed and the clock is three days.\n\nTwo things make it different from the usual Ray exposure story. It reaches Ray\ninstances that were never exposed to the internet, by way of a developer's own\nbrowser, so firewall rules and network segmentation do not stop it. And the\nmachines most at risk are workstations and laptops running Ray locally, not only\nclusters.\n\nWhat to do this week. Upgrade Ray to 2.52.0 or later everywhere it runs, and\ninventory by package rather than by host role: pip and conda environments,\ncontainer images, notebook kernels, continuous integration runners, and\ndeveloper laptops. Turn on the token authentication that 2.52.0 introduced,\nbecause it ships off by default. Then assess: on any machine that ran an earlier\nversion, review Ray job submission history for entries nobody recognizes, and\nrotate the credentials that were reachable from those environments. If the\nupgrade has to wait for a change window, separate the two halves of the attack\nand do not run Ray and a web browser on the same machine.\n\nThe full record, with every change we have tracked since it was listed:\nhttps://senserva.com/cve/CVE-2025-62593.html\n\nEverything CISA has added beyond Microsoft this month:\nhttps://senserva.com/non-microsoft-cve-tracker.html"
  },
  {
   "at": "2026-08-15T15:57:02.389Z",
   "cves": [
    {
     "id": "CVE-2026-58231",
     "page": true
    },
    {
     "id": "CVE-2026-34480",
     "page": true
    },
    {
     "id": "CVE-2026-5598",
     "page": true
    }
   ],
   "kbs": [],
   "text": "August 2026\n\nSAP's August Patch Day carried 28 new security notes, one GitHub advisory and two updates to existing notes. One of them outranks the rest.\n\nCVE-2026-58231, the Data Hub Adapter in SAP Commerce Cloud. CVSS 10.0, the highest the scale goes. Unauthenticated remote code execution: no credentials, no privileges, no administrator to trick into clicking anything. An attacker reaches the adapter over the network and runs code.\n\nThe fix is SAP Security Note 3771065. Affected versions are COM_CLOUD 2211 and 2211-JDK21.\n\nTHREE DAYS\n\nSAP disclosed on August 11. On August 14, Defused reported the first exploitation attempts against its honeypots. No public proof of concept existed at that point, which points to patch diffing or exploit development straight from the advisory text.\n\nBe precise about what that shows. Honeypot traffic means systems are trying the vulnerability. It does not mean a production SAP environment has been compromised. SAP had not classified the flaw as actively exploited at publication, and it was not in CISA's Known Exploited Vulnerabilities catalog. None of that is a reason to wait. Score of 10.0, no authentication required, vendor fix available, attack traffic observed by independent researchers. That is enough to act on.\n\nTHE EXPOSURE\n\nShadowserver counts more than 4,200 IP addresses carrying an SAP Commerce Cloud fingerprint, concentrated in Europe and North America. That is a footprint, not a vulnerability count. It includes patched hosts, duplicate observations, test systems and deployments that never expose the affected component.\n\nWhat makes the position uncomfortable is where Data Hub sits. It stages and moves data between internet-facing commerce infrastructure and internal business applications: product records, pricing, inventory, customer information, back-office exchanges. A compromised adapter is not an isolated web service.\n\nTHE REST OF THE RELEASE\n\nA 9.9 code injection flaw in SAP Manufacturing Integration and Intelligence. An updated 9.8 memory corruption note for NetWeaver Application Server ABAP. Two more Commerce Cloud items at 6.5: CVE-2026-34480, improper output encoding involving Apache Log4j Core in Commerce Cloud and Data Hub, and CVE-2026-5598, information disclosure tied to the Bouncy Castle Java library.\n\nOnapsis put CVE-2026-58231 under SAP's HotNews priority and at the top of the month's remediation list.\n\nTHREE THINGS THIS WEEK\n\nDetermine whether the Data Hub Adapter is installed and reachable, apply Note 3771065, and finish the rebuild or redeploy the fix requires. Installing without redeploying is not patched.\nInclude everything that is not production. Development, staging, disaster recovery and legacy environments run the same code with thinner monitoring and often broader network access.\nPatch, then assess. The update closes the door. It does not remove what was placed behind it beforehand. Pull logs for unauthenticated requests to Data Hub endpoints, unexpected child processes from the application runtime, new outbound connections, new or modified application packages, and changes to service accounts or authentication settings. Rotate any credentials the service can reach if the picture is unclear.\n\nIf patching has to wait on a change window, take the adapter off untrusted networks. Access controls, reverse proxies, WAF rules and segmentation buy time. They do not close the vulnerability.\n\nWHERE THESE NUMBERS COME FROM\n\nSeverity scores and affected versions are SAP's own, from the August 2026 Security Patch Day release and the National Vulnerability Database entry. Exploitation attempts reported by Defused on August 14. Exposure count from the Shadowserver Foundation. Priority ranking from Onapsis's August Patch Day analysis. \n\nTrack it as revisions are made through the month: https://senserva.com/non-microsoft-cve-tracker.html"
  },
  {
   "at": "2026-08-15T15:54:44.923Z",
   "cves": [
    {
     "id": "CVE-2026-58231",
     "page": true
    },
    {
     "id": "CVE-2026-34480",
     "page": true
    },
    {
     "id": "CVE-2026-5598",
     "page": true
    }
   ],
   "kbs": [],
   "text": "August 2026\n\nSAP's August Patch Day carried 28 new security notes, one GitHub advisory and two updates to existing notes. One of them outranks the rest.\n\nCVE-2026-58231, the Data Hub Adapter in SAP Commerce Cloud. CVSS 10.0, the highest the scale goes. Unauthenticated remote code execution: no credentials, no privileges, no administrator to trick into clicking anything. An attacker reaches the adapter over the network and runs code.\n\nThe fix is SAP Security Note 3771065. Affected versions are COM_CLOUD 2211 and 2211-JDK21.\n\nTHREE DAYS\n\nSAP disclosed on August 11. On August 14, Defused reported the first exploitation attempts against its honeypots. No public proof of concept existed at that point, which points to patch diffing or exploit development straight from the advisory text.\n\nBe precise about what that shows. Honeypot traffic means systems are trying the vulnerability. It does not mean a production SAP environment has been compromised. SAP had not classified the flaw as actively exploited at publication, and it was not in CISA's Known Exploited Vulnerabilities catalog. None of that is a reason to wait. Score of 10.0, no authentication required, vendor fix available, attack traffic observed by independent researchers. That is enough to act on.\n\nTHE EXPOSURE\n\nShadowserver counts more than 4,200 IP addresses carrying an SAP Commerce Cloud fingerprint, concentrated in Europe and North America. That is a footprint, not a vulnerability count. It includes patched hosts, duplicate observations, test systems and deployments that never expose the affected component.\n\nWhat makes the position uncomfortable is where Data Hub sits. It stages and moves data between internet-facing commerce infrastructure and internal business applications: product records, pricing, inventory, customer information, back-office exchanges. A compromised adapter is not an isolated web service.\n\nTHE REST OF THE RELEASE\n\nA 9.9 code injection flaw in SAP Manufacturing Integration and Intelligence. An updated 9.8 memory corruption note for NetWeaver Application Server ABAP. Two more Commerce Cloud items at 6.5: CVE-2026-34480, improper output encoding involving Apache Log4j Core in Commerce Cloud and Data Hub, and CVE-2026-5598, information disclosure tied to the Bouncy Castle Java library.\n\nOnapsis put CVE-2026-58231 under SAP's HotNews priority and at the top of the month's remediation list.\n\nTHREE THINGS THIS WEEK\n\nDetermine whether the Data Hub Adapter is installed and reachable, apply Note 3771065, and finish the rebuild or redeploy the fix requires. Installing without redeploying is not patched.\nInclude everything that is not production. Development, staging, disaster recovery and legacy environments run the same code with thinner monitoring and often broader network access.\nPatch, then assess. The update closes the door. It does not remove what was placed behind it beforehand. Pull logs for unauthenticated requests to Data Hub endpoints, unexpected child processes from the application runtime, new outbound connections, new or modified application packages, and changes to service accounts or authentication settings. Rotate any credentials the service can reach if the picture is unclear.\n\nIf patching has to wait on a change window, take the adapter off untrusted networks. Access controls, reverse proxies, WAF rules and segmentation buy time. They do not close the vulnerability.\n\nWHERE THESE NUMBERS COME FROM\n\nSeverity scores and affected versions are SAP's own, from the August 2026 Security Patch Day release and the National Vulnerability Database entry. Exploitation attempts reported by Defused on August 14. Exposure count from the Shadowserver Foundation. Priority ranking from Onapsis's August Patch Day analysis. \n\nTrack it as revisions are made through the month: https://senserva.com/non-microsoft-cve-tracker.html"
  },
  {
   "at": "2026-08-15T15:50:41.621Z",
   "cves": [
    {
     "id": "CVE-2026-58231",
     "page": true
    },
    {
     "id": "CVE-2026-34480",
     "page": true
    },
    {
     "id": "CVE-2026-5598",
     "page": true
    }
   ],
   "kbs": [],
   "text": "August 2026\n\nSAP's August Patch Day carried 28 new security notes, one GitHub advisory and two updates to existing notes. One of them outranks the rest.\n\nCVE-2026-58231, the Data Hub Adapter in SAP Commerce Cloud. CVSS 10.0, the highest the scale goes. Unauthenticated remote code execution: no credentials, no privileges, no administrator to trick into clicking anything. An attacker reaches the adapter over the network and runs code.\n\nThe fix is SAP Security Note 3771065. Affected versions are COM_CLOUD 2211 and 2211-JDK21.\n\nTHREE DAYS\n\nSAP disclosed on August 11. On August 14, Defused reported the first exploitation attempts against its honeypots. No public proof of concept existed at that point, which points to patch diffing or exploit development straight from the advisory text.\n\nBe precise about what that shows. Honeypot traffic means systems are trying the vulnerability. It does not mean a production SAP environment has been compromised. SAP had not classified the flaw as actively exploited at publication, and it was not in CISA's Known Exploited Vulnerabilities catalog. None of that is a reason to wait. Score of 10.0, no authentication required, vendor fix available, attack traffic observed by independent researchers. That is enough to act on.\n\nTHE EXPOSURE\n\nShadowserver counts more than 4,200 IP addresses carrying an SAP Commerce Cloud fingerprint, concentrated in Europe and North America. That is a footprint, not a vulnerability count. It includes patched hosts, duplicate observations, test systems and deployments that never expose the affected component.\n\nWhat makes the position uncomfortable is where Data Hub sits. It stages and moves data between internet-facing commerce infrastructure and internal business applications: product records, pricing, inventory, customer information, back-office exchanges. A compromised adapter is not an isolated web service.\n\nTHE REST OF THE RELEASE\n\nA 9.9 code injection flaw in SAP Manufacturing Integration and Intelligence. An updated 9.8 memory corruption note for NetWeaver Application Server ABAP. Two more Commerce Cloud items at 6.5: CVE-2026-34480, improper output encoding involving Apache Log4j Core in Commerce Cloud and Data Hub, and CVE-2026-5598, information disclosure tied to the Bouncy Castle Java library.\n\nOnapsis put CVE-2026-58231 under SAP's HotNews priority and at the top of the month's remediation list.\n\nTHREE THINGS THIS WEEK\n\nDetermine whether the Data Hub Adapter is installed and reachable, apply Note 3771065, and finish the rebuild or redeploy the fix requires. Installing without redeploying is not patched.\nInclude everything that is not production. Development, staging, disaster recovery and legacy environments run the same code with thinner monitoring and often broader network access.\nPatch, then assess. The update closes the door. It does not remove what was placed behind it beforehand. Pull logs for unauthenticated requests to Data Hub endpoints, unexpected child processes from the application runtime, new outbound connections, new or modified application packages, and changes to service accounts or authentication settings. Rotate any credentials the service can reach if the picture is unclear.\n\nIf patching has to wait on a change window, take the adapter off untrusted networks. Access controls, reverse proxies, WAF rules and segmentation buy time. They do not close the vulnerability.\n\nWHERE THESE NUMBERS COME FROM\n\nSeverity scores and affected versions are SAP's own, from the August 2026 Security Patch Day release and the National Vulnerability Database entry. Exploitation attempts reported by Defused on August 14. Exposure count from the Shadowserver Foundation. Priority ranking from Onapsis's August Patch Day analysis. \n\nTrack it as revisions are made through the month: https://senserva.com/non-microsoft-cve-tracker.html"
  },
  {
   "at": "2026-08-15T15:42:46.132Z",
   "cves": [
    {
     "id": "CVE-2026-58231",
     "page": true
    },
    {
     "id": "CVE-2026-34480",
     "page": true
    },
    {
     "id": "CVE-2026-5598",
     "page": true
    }
   ],
   "kbs": [],
   "text": "August 2026\n\nSAP's August Patch Day carried 28 new security notes, one GitHub advisory and two updates to existing notes. One of them outranks the rest.\n\nCVE-2026-58231, the Data Hub Adapter in SAP Commerce Cloud. CVSS 10.0, the highest the scale goes. Unauthenticated remote code execution: no credentials, no privileges, no administrator to trick into clicking anything. An attacker reaches the adapter over the network and runs code.\n\nThe fix is SAP Security Note 3771065. Affected versions are COM_CLOUD 2211 and 2211-JDK21.\n\nTHREE DAYS\n\nSAP disclosed on August 11. On August 14, Defused reported the first exploitation attempts against its honeypots. No public proof of concept existed at that point, which points to patch diffing or exploit development straight from the advisory text.\n\nBe precise about what that shows. Honeypot traffic means systems are trying the vulnerability. It does not mean a production SAP environment has been compromised. SAP had not classified the flaw as actively exploited at publication, and it was not in CISA's Known Exploited Vulnerabilities catalog. None of that is a reason to wait. Score of 10.0, no authentication required, vendor fix available, attack traffic observed by independent researchers. That is enough to act on.\n\nTHE EXPOSURE\n\nShadowserver counts more than 4,200 IP addresses carrying an SAP Commerce Cloud fingerprint, concentrated in Europe and North America. That is a footprint, not a vulnerability count. It includes patched hosts, duplicate observations, test systems and deployments that never expose the affected component.\n\nWhat makes the position uncomfortable is where Data Hub sits. It stages and moves data between internet-facing commerce infrastructure and internal business applications: product records, pricing, inventory, customer information, back-office exchanges. A compromised adapter is not an isolated web service.\n\nTHE REST OF THE RELEASE\n\nA 9.9 code injection flaw in SAP Manufacturing Integration and Intelligence. An updated 9.8 memory corruption note for NetWeaver Application Server ABAP. Two more Commerce Cloud items at 6.5: CVE-2026-34480, improper output encoding involving Apache Log4j Core in Commerce Cloud and Data Hub, and CVE-2026-5598, information disclosure tied to the Bouncy Castle Java library.\n\nOnapsis put CVE-2026-58231 under SAP's HotNews priority and at the top of the month's remediation list.\n\nTHREE THINGS THIS WEEK\n\nDetermine whether the Data Hub Adapter is installed and reachable, apply Note 3771065, and finish the rebuild or redeploy the fix requires. Installing without redeploying is not patched.\nInclude everything that is not production. Development, staging, disaster recovery and legacy environments run the same code with thinner monitoring and often broader network access.\nPatch, then assess. The update closes the door. It does not remove what was placed behind it beforehand. Pull logs for unauthenticated requests to Data Hub endpoints, unexpected child processes from the application runtime, new outbound connections, new or modified application packages, and changes to service accounts or authentication settings. Rotate any credentials the service can reach if the picture is unclear.\n\nIf patching has to wait on a change window, take the adapter off untrusted networks. Access controls, reverse proxies, WAF rules and segmentation buy time. They do not close the vulnerability.\n\nWHERE THESE NUMBERS COME FROM\n\nSeverity scores and affected versions are SAP's own, from the August 2026 Security Patch Day release and the National Vulnerability Database entry. Exploitation attempts reported by Defused on August 14. Exposure count from the Shadowserver Foundation. Priority ranking from Onapsis's August Patch Day analysis. \n\nTrack it as revisions are made through the month: https://senserva.com/non-microsoft-cve-tracker.html"
  },
  {
   "at": "2026-08-15T15:40:31.949Z",
   "cves": [
    {
     "id": "CVE-2026-58231",
     "page": true
    },
    {
     "id": "CVE-2026-34480",
     "page": true
    },
    {
     "id": "CVE-2026-5598",
     "page": true
    }
   ],
   "kbs": [],
   "text": "August 2026\n\nSAP's August Patch Day carried 28 new security notes, one GitHub advisory and two updates to existing notes. One of them outranks the rest.\n\nCVE-2026-58231, the Data Hub Adapter in SAP Commerce Cloud. CVSS 10.0, the highest the scale goes. Unauthenticated remote code execution: no credentials, no privileges, no administrator to trick into clicking anything. An attacker reaches the adapter over the network and runs code.\n\nThe fix is SAP Security Note 3771065. Affected versions are COM_CLOUD 2211 and 2211-JDK21.\n\nTHREE DAYS\n\nSAP disclosed on August 11. On August 14, Defused reported the first exploitation attempts against its honeypots. No public proof of concept existed at that point, which points to patch diffing or exploit development straight from the advisory text.\n\nBe precise about what that shows. Honeypot traffic means systems are trying the vulnerability. It does not mean a production SAP environment has been compromised. SAP had not classified the flaw as actively exploited at publication, and it was not in CISA's Known Exploited Vulnerabilities catalog. None of that is a reason to wait. Score of 10.0, no authentication required, vendor fix available, attack traffic observed by independent researchers. That is enough to act on.\n\nTHE EXPOSURE\n\nShadowserver counts more than 4,200 IP addresses carrying an SAP Commerce Cloud fingerprint, concentrated in Europe and North America. That is a footprint, not a vulnerability count. It includes patched hosts, duplicate observations, test systems and deployments that never expose the affected component.\n\nWhat makes the position uncomfortable is where Data Hub sits. It stages and moves data between internet-facing commerce infrastructure and internal business applications: product records, pricing, inventory, customer information, back-office exchanges. A compromised adapter is not an isolated web service.\n\nTHE REST OF THE RELEASE\n\nA 9.9 code injection flaw in SAP Manufacturing Integration and Intelligence. An updated 9.8 memory corruption note for NetWeaver Application Server ABAP. Two more Commerce Cloud items at 6.5: CVE-2026-34480, improper output encoding involving Apache Log4j Core in Commerce Cloud and Data Hub, and CVE-2026-5598, information disclosure tied to the Bouncy Castle Java library.\n\nOnapsis put CVE-2026-58231 under SAP's HotNews priority and at the top of the month's remediation list.\n\nTHREE THINGS THIS WEEK\n\nDetermine whether the Data Hub Adapter is installed and reachable, apply Note 3771065, and finish the rebuild or redeploy the fix requires. Installing without redeploying is not patched.\nInclude everything that is not production. Development, staging, disaster recovery and legacy environments run the same code with thinner monitoring and often broader network access.\nPatch, then assess. The update closes the door. It does not remove what was placed behind it beforehand. Pull logs for unauthenticated requests to Data Hub endpoints, unexpected child processes from the application runtime, new outbound connections, new or modified application packages, and changes to service accounts or authentication settings. Rotate any credentials the service can reach if the picture is unclear.\n\nIf patching has to wait on a change window, take the adapter off untrusted networks. Access controls, reverse proxies, WAF rules and segmentation buy time. They do not close the vulnerability.\n\nWHERE THESE NUMBERS COME FROM\n\nSeverity scores and affected versions are SAP's own, from the August 2026 Security Patch Day release and the National Vulnerability Database entry. Exploitation attempts reported by Defused on August 14. Exposure count from the Shadowserver Foundation. Priority ranking from Onapsis's August Patch Day analysis. \n\nTrack it as revisions are made through the month: https://senserva.com/non-microsoft-cve-tracker.html"
  },
  {
   "at": "2026-08-15T13:16:05.637Z",
   "cves": [
    {
     "id": "CVE-2026-58231",
     "page": true
    },
    {
     "id": "CVE-2026-34480",
     "page": true
    },
    {
     "id": "CVE-2026-5598",
     "page": true
    }
   ],
   "kbs": [],
   "text": "August 2026\n\nSAP's August Patch Day carried 28 new security notes, one GitHub advisory and two updates to existing notes. One of them outranks the rest.\n\nCVE-2026-58231, the Data Hub Adapter in SAP Commerce Cloud. CVSS 10.0, the highest the scale goes. Unauthenticated remote code execution: no credentials, no privileges, no administrator to trick into clicking anything. An attacker reaches the adapter over the network and runs code.\n\nThe fix is SAP Security Note 3771065. Affected versions are COM_CLOUD 2211 and 2211-JDK21.\n\nTHREE DAYS\n\nSAP disclosed on August 11. On August 14, Defused reported the first exploitation attempts against its honeypots. No public proof of concept existed at that point, which points to patch diffing or exploit development straight from the advisory text.\n\nBe precise about what that shows. Honeypot traffic means systems are trying the vulnerability. It does not mean a production SAP environment has been compromised. SAP had not classified the flaw as actively exploited at publication, and it was not in CISA's Known Exploited Vulnerabilities catalog. None of that is a reason to wait. Score of 10.0, no authentication required, vendor fix available, attack traffic observed by independent researchers. That is enough to act on.\n\nTHE EXPOSURE\n\nShadowserver counts more than 4,200 IP addresses carrying an SAP Commerce Cloud fingerprint, concentrated in Europe and North America. That is a footprint, not a vulnerability count. It includes patched hosts, duplicate observations, test systems and deployments that never expose the affected component.\n\nWhat makes the position uncomfortable is where Data Hub sits. It stages and moves data between internet-facing commerce infrastructure and internal business applications: product records, pricing, inventory, customer information, back-office exchanges. A compromised adapter is not an isolated web service.\n\nTHE REST OF THE RELEASE\n\nA 9.9 code injection flaw in SAP Manufacturing Integration and Intelligence. An updated 9.8 memory corruption note for NetWeaver Application Server ABAP. Two more Commerce Cloud items at 6.5: CVE-2026-34480, improper output encoding involving Apache Log4j Core in Commerce Cloud and Data Hub, and CVE-2026-5598, information disclosure tied to the Bouncy Castle Java library.\n\nOnapsis put CVE-2026-58231 under SAP's HotNews priority and at the top of the month's remediation list.\n\nTHREE THINGS THIS WEEK\n\nDetermine whether the Data Hub Adapter is installed and reachable, apply Note 3771065, and finish the rebuild or redeploy the fix requires. Installing without redeploying is not patched.\nInclude everything that is not production. Development, staging, disaster recovery and legacy environments run the same code with thinner monitoring and often broader network access.\nPatch, then assess. The update closes the door. It does not remove what was placed behind it beforehand. Pull logs for unauthenticated requests to Data Hub endpoints, unexpected child processes from the application runtime, new outbound connections, new or modified application packages, and changes to service accounts or authentication settings. Rotate any credentials the service can reach if the picture is unclear.\n\nIf patching has to wait on a change window, take the adapter off untrusted networks. Access controls, reverse proxies, WAF rules and segmentation buy time. They do not close the vulnerability.\n\nWHERE THESE NUMBERS COME FROM\n\nSeverity scores and affected versions are SAP's own, from the August 2026 Security Patch Day release and the National Vulnerability Database entry. Exploitation attempts reported by Defused on August 14. Exposure count from the Shadowserver Foundation. Priority ranking from Onapsis's August Patch Day analysis. \n\nTrack it as revisions are made through the month: https://senserva.com/non-microsoft-cve-tracker.html"
  },
  {
   "at": "2026-08-15T13:10:13.387Z",
   "cves": [
    {
     "id": "CVE-2026-58231",
     "page": true
    },
    {
     "id": "CVE-2026-34480",
     "page": true
    },
    {
     "id": "CVE-2026-5598",
     "page": true
    }
   ],
   "kbs": [],
   "text": "August 2026\n\nSAP's August Patch Day carried 28 new security notes, one GitHub advisory and two updates to existing notes. One of them outranks the rest.\n\nCVE-2026-58231, the Data Hub Adapter in SAP Commerce Cloud. CVSS 10.0, the highest the scale goes. Unauthenticated remote code execution: no credentials, no privileges, no administrator to trick into clicking anything. An attacker reaches the adapter over the network and runs code.\n\nThe fix is SAP Security Note 3771065. Affected versions are COM_CLOUD 2211 and 2211-JDK21.\n\nTHREE DAYS\n\nSAP disclosed on August 11. On August 14, Defused reported the first exploitation attempts against its honeypots. No public proof of concept existed at that point, which points to patch diffing or exploit development straight from the advisory text.\n\nBe precise about what that shows. Honeypot traffic means systems are trying the vulnerability. It does not mean a production SAP environment has been compromised. SAP had not classified the flaw as actively exploited at publication, and it was not in CISA's Known Exploited Vulnerabilities catalog. None of that is a reason to wait. Score of 10.0, no authentication required, vendor fix available, attack traffic observed by independent researchers. That is enough to act on.\n\nTHE EXPOSURE\n\nShadowserver counts more than 4,200 IP addresses carrying an SAP Commerce Cloud fingerprint, concentrated in Europe and North America. That is a footprint, not a vulnerability count. It includes patched hosts, duplicate observations, test systems and deployments that never expose the affected component.\n\nWhat makes the position uncomfortable is where Data Hub sits. It stages and moves data between internet-facing commerce infrastructure and internal business applications: product records, pricing, inventory, customer information, back-office exchanges. A compromised adapter is not an isolated web service.\n\nTHE REST OF THE RELEASE\n\nA 9.9 code injection flaw in SAP Manufacturing Integration and Intelligence. An updated 9.8 memory corruption note for NetWeaver Application Server ABAP. Two more Commerce Cloud items at 6.5: CVE-2026-34480, improper output encoding involving Apache Log4j Core in Commerce Cloud and Data Hub, and CVE-2026-5598, information disclosure tied to the Bouncy Castle Java library.\n\nOnapsis put CVE-2026-58231 under SAP's HotNews priority and at the top of the month's remediation list.\n\nTHREE THINGS THIS WEEK\n\nDetermine whether the Data Hub Adapter is installed and reachable, apply Note 3771065, and finish the rebuild or redeploy the fix requires. Installing without redeploying is not patched.\nInclude everything that is not production. Development, staging, disaster recovery and legacy environments run the same code with thinner monitoring and often broader network access.\nPatch, then assess. The update closes the door. It does not remove what was placed behind it beforehand. Pull logs for unauthenticated requests to Data Hub endpoints, unexpected child processes from the application runtime, new outbound connections, new or modified application packages, and changes to service accounts or authentication settings. Rotate any credentials the service can reach if the picture is unclear.\n\nIf patching has to wait on a change window, take the adapter off untrusted networks. Access controls, reverse proxies, WAF rules and segmentation buy time. They do not close the vulnerability.\n\nWHERE THESE NUMBERS COME FROM\n\nSeverity scores and affected versions are SAP's own, from the August 2026 Security Patch Day release and the National Vulnerability Database entry. Exploitation attempts reported by Defused on August 14. Exposure count from the Shadowserver Foundation. Priority ranking from Onapsis's August Patch Day analysis. \n\nTrack it as revisions are made through the month: https://senserva.com/non-microsoft-cve-tracker.html"
  },
  {
   "at": "2026-08-15T13:00:58.331Z",
   "cves": [
    {
     "id": "CVE-2026-58231",
     "page": true
    },
    {
     "id": "CVE-2026-34480",
     "page": true
    },
    {
     "id": "CVE-2026-5598",
     "page": true
    }
   ],
   "kbs": [],
   "text": "August 2026\n\nSAP's August Patch Day carried 28 new security notes, one GitHub advisory and two updates to existing notes. One of them outranks the rest.\n\nCVE-2026-58231, the Data Hub Adapter in SAP Commerce Cloud. CVSS 10.0, the highest the scale goes. Unauthenticated remote code execution: no credentials, no privileges, no administrator to trick into clicking anything. An attacker reaches the adapter over the network and runs code.\n\nThe fix is SAP Security Note 3771065. Affected versions are COM_CLOUD 2211 and 2211-JDK21.\n\nTHREE DAYS\n\nSAP disclosed on August 11. On August 14, Defused reported the first exploitation attempts against its honeypots. No public proof of concept existed at that point, which points to patch diffing or exploit development straight from the advisory text.\n\nBe precise about what that shows. Honeypot traffic means systems are trying the vulnerability. It does not mean a production SAP environment has been compromised. SAP had not classified the flaw as actively exploited at publication, and it was not in CISA's Known Exploited Vulnerabilities catalog. None of that is a reason to wait. Score of 10.0, no authentication required, vendor fix available, attack traffic observed by independent researchers. That is enough to act on.\n\nTHE EXPOSURE\n\nShadowserver counts more than 4,200 IP addresses carrying an SAP Commerce Cloud fingerprint, concentrated in Europe and North America. That is a footprint, not a vulnerability count. It includes patched hosts, duplicate observations, test systems and deployments that never expose the affected component.\n\nWhat makes the position uncomfortable is where Data Hub sits. It stages and moves data between internet-facing commerce infrastructure and internal business applications: product records, pricing, inventory, customer information, back-office exchanges. A compromised adapter is not an isolated web service.\n\nTHE REST OF THE RELEASE\n\nA 9.9 code injection flaw in SAP Manufacturing Integration and Intelligence. An updated 9.8 memory corruption note for NetWeaver Application Server ABAP. Two more Commerce Cloud items at 6.5: CVE-2026-34480, improper output encoding involving Apache Log4j Core in Commerce Cloud and Data Hub, and CVE-2026-5598, information disclosure tied to the Bouncy Castle Java library.\n\nOnapsis put CVE-2026-58231 under SAP's HotNews priority and at the top of the month's remediation list.\n\nTHREE THINGS THIS WEEK\n\nDetermine whether the Data Hub Adapter is installed and reachable, apply Note 3771065, and finish the rebuild or redeploy the fix requires. Installing without redeploying is not patched.\nInclude everything that is not production. Development, staging, disaster recovery and legacy environments run the same code with thinner monitoring and often broader network access.\nPatch, then assess. The update closes the door. It does not remove what was placed behind it beforehand. Pull logs for unauthenticated requests to Data Hub endpoints, unexpected child processes from the application runtime, new outbound connections, new or modified application packages, and changes to service accounts or authentication settings. Rotate any credentials the service can reach if the picture is unclear.\n\nIf patching has to wait on a change window, take the adapter off untrusted networks. Access controls, reverse proxies, WAF rules and segmentation buy time. They do not close the vulnerability.\n\nWHERE THESE NUMBERS COME FROM\n\nSeverity scores and affected versions are SAP's own, from the August 2026 Security Patch Day release and the National Vulnerability Database entry. Exploitation attempts reported by Defused on August 14. Exposure count from the Shadowserver Foundation. Priority ranking from Onapsis's August Patch Day analysis. \n\nTrack it as revisions are made through the month: https://senserva.com/non-microsoft-cve-tracker.html"
  },
  {
   "at": "2026-08-15T12:58:52.245Z",
   "cves": [
    {
     "id": "CVE-2026-58231",
     "page": true
    },
    {
     "id": "CVE-2026-34480",
     "page": true
    },
    {
     "id": "CVE-2026-5598",
     "page": true
    }
   ],
   "kbs": [],
   "text": "August 2026\n\nSAP's August Patch Day carried 28 new security notes, one GitHub advisory and two updates to existing notes. One of them outranks the rest.\n\nCVE-2026-58231, the Data Hub Adapter in SAP Commerce Cloud. CVSS 10.0, the highest the scale goes. Unauthenticated remote code execution: no credentials, no privileges, no administrator to trick into clicking anything. An attacker reaches the adapter over the network and runs code.\n\nThe fix is SAP Security Note 3771065. Affected versions are COM_CLOUD 2211 and 2211-JDK21.\n\nTHREE DAYS\n\nSAP disclosed on August 11. On August 14, Defused reported the first exploitation attempts against its honeypots. No public proof of concept existed at that point, which points to patch diffing or exploit development straight from the advisory text.\n\nBe precise about what that shows. Honeypot traffic means systems are trying the vulnerability. It does not mean a production SAP environment has been compromised. SAP had not classified the flaw as actively exploited at publication, and it was not in CISA's Known Exploited Vulnerabilities catalog. None of that is a reason to wait. Score of 10.0, no authentication required, vendor fix available, attack traffic observed by independent researchers. That is enough to act on.\n\nTHE EXPOSURE\n\nShadowserver counts more than 4,200 IP addresses carrying an SAP Commerce Cloud fingerprint, concentrated in Europe and North America. That is a footprint, not a vulnerability count. It includes patched hosts, duplicate observations, test systems and deployments that never expose the affected component.\n\nWhat makes the position uncomfortable is where Data Hub sits. It stages and moves data between internet-facing commerce infrastructure and internal business applications: product records, pricing, inventory, customer information, back-office exchanges. A compromised adapter is not an isolated web service.\n\nTHE REST OF THE RELEASE\n\nA 9.9 code injection flaw in SAP Manufacturing Integration and Intelligence. An updated 9.8 memory corruption note for NetWeaver Application Server ABAP. Two more Commerce Cloud items at 6.5: CVE-2026-34480, improper output encoding involving Apache Log4j Core in Commerce Cloud and Data Hub, and CVE-2026-5598, information disclosure tied to the Bouncy Castle Java library.\n\nOnapsis put CVE-2026-58231 under SAP's HotNews priority and at the top of the month's remediation list.\n\nTHREE THINGS THIS WEEK\n\nDetermine whether the Data Hub Adapter is installed and reachable, apply Note 3771065, and finish the rebuild or redeploy the fix requires. Installing without redeploying is not patched.\nInclude everything that is not production. Development, staging, disaster recovery and legacy environments run the same code with thinner monitoring and often broader network access.\nPatch, then assess. The update closes the door. It does not remove what was placed behind it beforehand. Pull logs for unauthenticated requests to Data Hub endpoints, unexpected child processes from the application runtime, new outbound connections, new or modified application packages, and changes to service accounts or authentication settings. Rotate any credentials the service can reach if the picture is unclear.\n\nIf patching has to wait on a change window, take the adapter off untrusted networks. Access controls, reverse proxies, WAF rules and segmentation buy time. They do not close the vulnerability.\n\nWHERE THESE NUMBERS COME FROM\n\nSeverity scores and affected versions are SAP's own, from the August 2026 Security Patch Day release and the National Vulnerability Database entry. Exploitation attempts reported by Defused on August 14. Exposure count from the Shadowserver Foundation. Priority ranking from Onapsis's August Patch Day analysis. \n\nTrack it as revisions are made through the month: https://senserva.com/microsoft-patch-tracker.html"
  },
  {
   "at": "2026-08-15T12:50:40.042Z",
   "cves": [
    {
     "id": "CVE-2026-58231",
     "page": true
    },
    {
     "id": "CVE-2026-34480",
     "page": true
    },
    {
     "id": "CVE-2026-5598",
     "page": true
    }
   ],
   "kbs": [],
   "text": "August 2026\n\nSAP's August Patch Day carried 28 new security notes, one GitHub advisory and two updates to existing notes. One of them outranks the rest.\n\nCVE-2026-58231, the Data Hub Adapter in SAP Commerce Cloud. CVSS 10.0, the highest the scale goes. Unauthenticated remote code execution: no credentials, no privileges, no administrator to trick into clicking anything. An attacker reaches the adapter over the network and runs code.\n\nThe fix is SAP Security Note 3771065. Affected versions are COM_CLOUD 2211 and 2211-JDK21.\n\nTHREE DAYS\n\nSAP disclosed on August 11. On August 14, Defused reported the first exploitation attempts against its honeypots. No public proof of concept existed at that point, which points to patch diffing or exploit development straight from the advisory text.\n\nBe precise about what that shows. Honeypot traffic means systems are trying the vulnerability. It does not mean a production SAP environment has been compromised. SAP had not classified the flaw as actively exploited at publication, and it was not in CISA's Known Exploited Vulnerabilities catalog. None of that is a reason to wait. Score of 10.0, no authentication required, vendor fix available, attack traffic observed by independent researchers. That is enough to act on.\n\nTHE EXPOSURE\n\nShadowserver counts more than 4,200 IP addresses carrying an SAP Commerce Cloud fingerprint, concentrated in Europe and North America. That is a footprint, not a vulnerability count. It includes patched hosts, duplicate observations, test systems and deployments that never expose the affected component.\n\nWhat makes the position uncomfortable is where Data Hub sits. It stages and moves data between internet-facing commerce infrastructure and internal business applications: product records, pricing, inventory, customer information, back-office exchanges. A compromised adapter is not an isolated web service.\n\nTHE REST OF THE RELEASE\n\nA 9.9 code injection flaw in SAP Manufacturing Integration and Intelligence. An updated 9.8 memory corruption note for NetWeaver Application Server ABAP. Two more Commerce Cloud items at 6.5: CVE-2026-34480, improper output encoding involving Apache Log4j Core in Commerce Cloud and Data Hub, and CVE-2026-5598, information disclosure tied to the Bouncy Castle Java library.\n\nOnapsis put CVE-2026-58231 under SAP's HotNews priority and at the top of the month's remediation list.\n\nTHREE THINGS THIS WEEK\n\nDetermine whether the Data Hub Adapter is installed and reachable, apply Note 3771065, and finish the rebuild or redeploy the fix requires. Installing without redeploying is not patched.\nInclude everything that is not production. Development, staging, disaster recovery and legacy environments run the same code with thinner monitoring and often broader network access.\nPatch, then assess. The update closes the door. It does not remove what was placed behind it beforehand. Pull logs for unauthenticated requests to Data Hub endpoints, unexpected child processes from the application runtime, new outbound connections, new or modified application packages, and changes to service accounts or authentication settings. Rotate any credentials the service can reach if the picture is unclear.\n\nIf patching has to wait on a change window, take the adapter off untrusted networks. Access controls, reverse proxies, WAF rules and segmentation buy time. They do not close the vulnerability.\n\nWHERE THESE NUMBERS COME FROM\n\nSeverity scores and affected versions are SAP's own, from the August 2026 Security Patch Day release and the National Vulnerability Database entry. Exploitation attempts reported by Defused on August 14. Exposure count from the Shadowserver Foundation. Priority ranking from Onapsis's August Patch Day analysis. \n\nTrack it as revisions are made through the month: https://senserva.com/microsoft-patch-tracker.html"
  },
  {
   "at": "2026-08-15T12:35:27.327Z",
   "cves": [
    {
     "id": "CVE-2026-58231",
     "page": true
    },
    {
     "id": "CVE-2026-34480",
     "page": true
    },
    {
     "id": "CVE-2026-5598",
     "page": true
    }
   ],
   "kbs": [],
   "text": "August 2026\n\nSAP's August Patch Day carried 28 new security notes, one GitHub advisory and two updates to existing notes. One of them outranks the rest.\n\nCVE-2026-58231, the Data Hub Adapter in SAP Commerce Cloud. CVSS 10.0, the highest the scale goes. Unauthenticated remote code execution: no credentials, no privileges, no administrator to trick into clicking anything. An attacker reaches the adapter over the network and runs code.\n\nThe fix is SAP Security Note 3771065. Affected versions are COM_CLOUD 2211 and 2211-JDK21.\n\nTHREE DAYS\n\nSAP disclosed on August 11. On August 14, Defused reported the first exploitation attempts against its honeypots. No public proof of concept existed at that point, which points to patch diffing or exploit development straight from the advisory text.\n\nBe precise about what that shows. Honeypot traffic means systems are trying the vulnerability. It does not mean a production SAP environment has been compromised. SAP had not classified the flaw as actively exploited at publication, and it was not in CISA's Known Exploited Vulnerabilities catalog. None of that is a reason to wait. Score of 10.0, no authentication required, vendor fix available, attack traffic observed by independent researchers. That is enough to act on.\n\nTHE EXPOSURE\n\nShadowserver counts more than 4,200 IP addresses carrying an SAP Commerce Cloud fingerprint, concentrated in Europe and North America. That is a footprint, not a vulnerability count. It includes patched hosts, duplicate observations, test systems and deployments that never expose the affected component.\n\nWhat makes the position uncomfortable is where Data Hub sits. It stages and moves data between internet-facing commerce infrastructure and internal business applications: product records, pricing, inventory, customer information, back-office exchanges. A compromised adapter is not an isolated web service.\n\nTHE REST OF THE RELEASE\n\nA 9.9 code injection flaw in SAP Manufacturing Integration and Intelligence. An updated 9.8 memory corruption note for NetWeaver Application Server ABAP. Two more Commerce Cloud items at 6.5: CVE-2026-34480, improper output encoding involving Apache Log4j Core in Commerce Cloud and Data Hub, and CVE-2026-5598, information disclosure tied to the Bouncy Castle Java library.\n\nOnapsis put CVE-2026-58231 under SAP's HotNews priority and at the top of the month's remediation list.\n\nTHREE THINGS THIS WEEK\n\nDetermine whether the Data Hub Adapter is installed and reachable, apply Note 3771065, and finish the rebuild or redeploy the fix requires. Installing without redeploying is not patched.\nInclude everything that is not production. Development, staging, disaster recovery and legacy environments run the same code with thinner monitoring and often broader network access.\nPatch, then assess. The update closes the door. It does not remove what was placed behind it beforehand. Pull logs for unauthenticated requests to Data Hub endpoints, unexpected child processes from the application runtime, new outbound connections, new or modified application packages, and changes to service accounts or authentication settings. Rotate any credentials the service can reach if the picture is unclear.\n\nIf patching has to wait on a change window, take the adapter off untrusted networks. Access controls, reverse proxies, WAF rules and segmentation buy time. They do not close the vulnerability.\n\nWHERE THESE NUMBERS COME FROM\n\nSeverity scores and affected versions are SAP's own, from the August 2026 Security Patch Day release and the National Vulnerability Database entry. Exploitation attempts reported by Defused on August 14. Exposure count from the Shadowserver Foundation. Priority ranking from Onapsis's August Patch Day analysis. \n\nTrack it as revisions are made through the month: https://senserva.com/microsoft-patch-tracker.html"
  },
  {
   "at": "2026-08-15T12:27:35.406Z",
   "cves": [
    {
     "id": "CVE-2026-58231",
     "page": true
    },
    {
     "id": "CVE-2026-34480",
     "page": true
    },
    {
     "id": "CVE-2026-5598",
     "page": true
    }
   ],
   "kbs": [],
   "text": "August 2026\n\nSAP's August Patch Day carried 28 new security notes, one GitHub advisory and two updates to existing notes. One of them outranks the rest.\n\nCVE-2026-58231, the Data Hub Adapter in SAP Commerce Cloud. CVSS 10.0, the highest the scale goes. Unauthenticated remote code execution: no credentials, no privileges, no administrator to trick into clicking anything. An attacker reaches the adapter over the network and runs code.\n\nThe fix is SAP Security Note 3771065. Affected versions are COM_CLOUD 2211 and 2211-JDK21.\n\nTHREE DAYS\n\nSAP disclosed on August 11. On August 14, Defused reported the first exploitation attempts against its honeypots. No public proof of concept existed at that point, which points to patch diffing or exploit development straight from the advisory text.\n\nBe precise about what that shows. Honeypot traffic means systems are trying the vulnerability. It does not mean a production SAP environment has been compromised. SAP had not classified the flaw as actively exploited at publication, and it was not in CISA's Known Exploited Vulnerabilities catalog. None of that is a reason to wait. Score of 10.0, no authentication required, vendor fix available, attack traffic observed by independent researchers. That is enough to act on.\n\nTHE EXPOSURE\n\nShadowserver counts more than 4,200 IP addresses carrying an SAP Commerce Cloud fingerprint, concentrated in Europe and North America. That is a footprint, not a vulnerability count. It includes patched hosts, duplicate observations, test systems and deployments that never expose the affected component.\n\nWhat makes the position uncomfortable is where Data Hub sits. It stages and moves data between internet-facing commerce infrastructure and internal business applications: product records, pricing, inventory, customer information, back-office exchanges. A compromised adapter is not an isolated web service.\n\nTHE REST OF THE RELEASE\n\nA 9.9 code injection flaw in SAP Manufacturing Integration and Intelligence. An updated 9.8 memory corruption note for NetWeaver Application Server ABAP. Two more Commerce Cloud items at 6.5: CVE-2026-34480, improper output encoding involving Apache Log4j Core in Commerce Cloud and Data Hub, and CVE-2026-5598, information disclosure tied to the Bouncy Castle Java library.\n\nOnapsis put CVE-2026-58231 under SAP's HotNews priority and at the top of the month's remediation list.\n\nTHREE THINGS THIS WEEK\n\nDetermine whether the Data Hub Adapter is installed and reachable, apply Note 3771065, and finish the rebuild or redeploy the fix requires. Installing without redeploying is not patched.\nInclude everything that is not production. Development, staging, disaster recovery and legacy environments run the same code with thinner monitoring and often broader network access.\nPatch, then assess. The update closes the door. It does not remove what was placed behind it beforehand. Pull logs for unauthenticated requests to Data Hub endpoints, unexpected child processes from the application runtime, new outbound connections, new or modified application packages, and changes to service accounts or authentication settings. Rotate any credentials the service can reach if the picture is unclear.\n\nIf patching has to wait on a change window, take the adapter off untrusted networks. Access controls, reverse proxies, WAF rules and segmentation buy time. They do not close the vulnerability.\n\nWHERE THESE NUMBERS COME FROM\n\nSeverity scores and affected versions are SAP's own, from the August 2026 Security Patch Day release and the National Vulnerability Database entry. Exploitation attempts reported by Defused on August 14. Exposure count from the Shadowserver Foundation. Priority ranking from Onapsis's August Patch Day analysis. \n\nTrack it as revisions are made through the month: https://senserva.com/microsoft-patch-tracker.html"
  },
  {
   "at": "2026-08-14T17:36:08.165Z",
   "cves": [
    {
     "id": "CVE-2026-68820",
     "page": true
    }
   ],
   "kbs": [],
   "text": "Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability (CVE-2026-68820) is the CVE to watch right now. The Microsoft Windows Ancillary Function Driver for WinSock flaw is rated High with a CVSS score of 7. CISA added it to the Known Exploited Vulnerabilities catalog on 2026-08-11, which means it is being attacked in the wild, not just in theory. BleepingComputer covered it on 2026-08-12: \"Lazarus hackers exploited Windows zero-day to target defense firms\". If it is in your environment, patch it now. Details, affected versions, and remediation guidance: \n\nhttps://senserva.com/cve/CVE-2026-68820.html"
  },
  {
   "at": "2026-08-14T17:33:12.485Z",
   "cves": [
    {
     "id": "CVE-2026-68820",
     "page": true
    }
   ],
   "kbs": [],
   "text": "Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability (CVE-2026-68820) is the CVE to watch right now. The Microsoft Windows Ancillary Function Driver for WinSock flaw is rated High with a CVSS score of 7. CISA added it to the Known Exploited Vulnerabilities catalog on 2026-08-11, which means it is being attacked in the wild, not just in theory. BleepingComputer covered it on 2026-08-12: \"Lazarus hackers exploited Windows zero-day to target defense firms\". If it is in your environment, patch it now. Details, affected versions, and remediation guidance: \n\nhttps://senserva.com/cve/CVE-2026-68820.html"
  },
  {
   "at": "2026-08-14T17:31:36.469Z",
   "cves": [
    {
     "id": "CVE-2026-68820",
     "page": true
    }
   ],
   "kbs": [],
   "text": "Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability (CVE-2026-68820) is the CVE to watch right now. The Microsoft Windows Ancillary Function Driver for WinSock flaw is rated High with a CVSS score of 7. CISA added it to the Known Exploited Vulnerabilities catalog on 2026-08-11, which means it is being attacked in the wild, not just in theory. BleepingComputer covered it on 2026-08-12: \"Lazarus hackers exploited Windows zero-day to target defense firms\". If it is in your environment, patch it now. Details, affected versions, and remediation guidance: \n\nhttps://senserva.com/cve/CVE-2026-68820.html"
  },
  {
   "at": "2026-08-14T17:23:24.006Z",
   "cves": [
    {
     "id": "CVE-2026-68820",
     "page": true
    }
   ],
   "kbs": [],
   "text": "Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability (CVE-2026-68820) is the CVE to watch right now. The Microsoft Windows Ancillary Function Driver for WinSock flaw is rated High with a CVSS score of 7. CISA added it to the Known Exploited Vulnerabilities catalog on 2026-08-11, which means it is being attacked in the wild, not just in theory. BleepingComputer covered it on 2026-08-12: \"Lazarus hackers exploited Windows zero-day to target defense firms\". If it is in your environment, patch it now. Details, affected versions, and remediation guidance: \n\nhttps://senserva.com/cve/CVE-2026-68820.html"
  },
  {
   "at": "2026-08-14T17:20:45.874Z",
   "cves": [
    {
     "id": "CVE-2026-68820",
     "page": true
    }
   ],
   "kbs": [],
   "text": "Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability (CVE-2026-68820) is the CVE to watch right now. The Microsoft Windows Ancillary Function Driver for WinSock flaw is rated High with a CVSS score of 7. CISA added it to the Known Exploited Vulnerabilities catalog on 2026-08-11, which means it is being attacked in the wild, not just in theory. BleepingComputer covered it on 2026-08-12: \"Lazarus hackers exploited Windows zero-day to target defense firms\". If it is in your environment, patch it now. Details, affected versions, and remediation guidance: \n\nhttps://senserva.com/cve/CVE-2026-68820.html"
  },
  {
   "at": "2026-08-14T16:44:01.397Z",
   "cves": [
    {
     "id": "CVE-2026-68820",
     "page": true
    }
   ],
   "kbs": [],
   "text": "Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability (CVE-2026-68820) is the CVE to watch right now. The Microsoft Windows Ancillary Function Driver for WinSock flaw is rated High with a CVSS score of 7. CISA added it to the Known Exploited Vulnerabilities catalog on 2026-08-11, which means it is being attacked in the wild, not just in theory. BleepingComputer covered it on 2026-08-12: \"Lazarus hackers exploited Windows zero-day to target defense firms\". If it is in your environment, patch it now. Details, affected versions, and remediation guidance: \n\nhttps://senserva.com/cve/CVE-2026-68820.html"
  },
  {
   "at": "2026-08-14T16:39:00.971Z",
   "cves": [
    {
     "id": "CVE-2026-68820",
     "page": true
    }
   ],
   "kbs": [],
   "text": "Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability (CVE-2026-68820) is the CVE to watch right now. The Microsoft Windows Ancillary Function Driver for WinSock flaw is rated High with a CVSS score of 7. CISA added it to the Known Exploited Vulnerabilities catalog on 2026-08-11, which means it is being attacked in the wild, not just in theory. BleepingComputer covered it on 2026-08-12: \"Lazarus hackers exploited Windows zero-day to target defense firms\". If it is in your environment, patch it now. Details, affected versions, and remediation guidance: \n\nhttps://senserva.com/cve/CVE-2026-68820.html"
  },
  {
   "at": "2026-08-14T16:33:44.430Z",
   "cves": [
    {
     "id": "CVE-2026-68820",
     "page": true
    }
   ],
   "kbs": [],
   "text": "Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability (CVE-2026-68820) is the CVE to watch right now. The Microsoft Windows Ancillary Function Driver for WinSock flaw is rated High with a CVSS score of 7. CISA added it to the Known Exploited Vulnerabilities catalog on 2026-08-11, which means it is being attacked in the wild, not just in theory. BleepingComputer covered it on 2026-08-12: \"Lazarus hackers exploited Windows zero-day to target defense firms\". If it is in your environment, patch it now. Details, affected versions, and remediation guidance: \n\nhttps://senserva.com/cve/CVE-2026-68820.html"
  },
  {
   "at": "2026-08-14T16:31:33.550Z",
   "cves": [
    {
     "id": "CVE-2026-68820",
     "page": true
    }
   ],
   "kbs": [],
   "text": "Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability (CVE-2026-68820) is the CVE to watch right now. The Microsoft Windows Ancillary Function Driver for WinSock flaw is rated High with a CVSS score of 7. CISA added it to the Known Exploited Vulnerabilities catalog on 2026-08-11, which means it is being attacked in the wild, not just in theory. BleepingComputer covered it on 2026-08-12: \"Lazarus hackers exploited Windows zero-day to target defense firms\". If it is in your environment, patch it now. Details, affected versions, and remediation guidance: \n\nhttps://senserva.com/cve/CVE-2026-68820.html"
  },
  {
   "at": "2026-08-14T16:28:41.413Z",
   "cves": [
    {
     "id": "CVE-2026-68820",
     "page": true
    }
   ],
   "kbs": [],
   "text": "Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability (CVE-2026-68820) is the CVE to watch right now. The Microsoft Windows Ancillary Function Driver for WinSock flaw is rated High with a CVSS score of 7. CISA added it to the Known Exploited Vulnerabilities catalog on 2026-08-11, which means it is being attacked in the wild, not just in theory. BleepingComputer covered it on 2026-08-12: \"Lazarus hackers exploited Windows zero-day to target defense firms\". If it is in your environment, patch it now. Details, affected versions, and remediation guidance: \n\nhttps://senserva.com/cve/CVE-2026-68820.html"
  },
  {
   "at": "2026-08-13T21:41:17.791Z",
   "cves": [
    {
     "id": "CVE-2026-68820",
     "page": true
    }
   ],
   "kbs": [],
   "text": "Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability (CVE-2026-68820) is the CVE to watch right now. The Microsoft Windows Ancillary Function Driver for WinSock flaw is rated Critical with a CVSS score of 9.8. CISA added it to the Known Exploited Vulnerabilities catalog on 2026-08-11, which means it is being attacked in the wild, not just in theory. BleepingComputer covered it on 2026-08-12: \"Lazarus hackers exploited Windows zero-day to target defense firms\". If it is in your environment, patch it now. Details, affected versions, and remediation guidance: https://senserva.com/cve/CVE-2026-68820.html"
  },
  {
   "at": "2026-08-13T21:37:36.687Z",
   "cves": [
    {
     "id": "CVE-2026-68820",
     "page": true
    }
   ],
   "kbs": [],
   "text": "Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability (CVE-2026-68820) is the CVE to watch right now. The Microsoft Windows Ancillary Function Driver for WinSock flaw is rated Critical with a CVSS score of 9.8. CISA added it to the Known Exploited Vulnerabilities catalog on 2026-08-11, which means it is being attacked in the wild, not just in theory. BleepingComputer covered it on 2026-08-12: \"Lazarus hackers exploited Windows zero-day to target defense firms\". If it is in your environment, patch it now. Details, affected versions, and remediation guidance: https://senserva.com/cve/CVE-2026-68820.html"
  },
  {
   "at": "2026-08-13T21:33:44.416Z",
   "cves": [
    {
     "id": "CVE-2026-68820",
     "page": true
    }
   ],
   "kbs": [],
   "text": "Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability (CVE-2026-68820) is the CVE to watch right now. The Microsoft Windows Ancillary Function Driver for WinSock flaw is rated Critical with a CVSS score of 9.8. CISA added it to the Known Exploited Vulnerabilities catalog on 2026-08-11, which means it is being attacked in the wild, not just in theory. BleepingComputer covered it on 2026-08-12: \"Lazarus hackers exploited Windows zero-day to target defense firms\". If it is in your environment, patch it now. Details, affected versions, and remediation guidance: https://senserva.com/cve/CVE-2026-68820.html"
  },
  {
   "at": "2026-08-13T21:28:06.796Z",
   "cves": [
    {
     "id": "CVE-2026-68820",
     "page": true
    }
   ],
   "kbs": [],
   "text": "Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability (CVE-2026-68820) is the CVE to watch right now. The Microsoft Windows Ancillary Function Driver for WinSock flaw is rated Critical with a CVSS score of 9.8. CISA added it to the Known Exploited Vulnerabilities catalog on 2026-08-11, which means it is being attacked in the wild, not just in theory. BleepingComputer covered it on 2026-08-12: \"Lazarus hackers exploited Windows zero-day to target defense firms\". If it is in your environment, patch it now. Details, affected versions, and remediation guidance: https://senserva.com/cve/CVE-2026-68820.html"
  },
  {
   "at": "2026-08-13T21:20:20.346Z",
   "cves": [
    {
     "id": "CVE-2026-68820",
     "page": true
    }
   ],
   "kbs": [],
   "text": "Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability (CVE-2026-68820) is the CVE to watch right now. The Microsoft Windows Ancillary Function Driver for WinSock flaw is rated Critical with a CVSS score of 9.8. CISA added it to the Known Exploited Vulnerabilities catalog on 2026-08-11, which means it is being attacked in the wild, not just in theory. BleepingComputer covered it on 2026-08-12: \"Lazarus hackers exploited Windows zero-day to target defense firms\". If it is in your environment, patch it now. Details, affected versions, and remediation guidance: https://senserva.com/cve/CVE-2026-68820.html"
  },
  {
   "at": "2026-08-13T20:17:37.065Z",
   "cves": [
    {
     "id": "CVE-2026-68820",
     "page": true
    }
   ],
   "kbs": [],
   "text": "Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability (CVE-2026-68820) is the CVE to watch right now. The Microsoft Windows Ancillary Function Driver for WinSock flaw is rated Critical with a CVSS score of 9.8. CISA added it to the Known Exploited Vulnerabilities catalog on 2026-08-11, which means it is being attacked in the wild, not just in theory. BleepingComputer covered it on 2026-08-12: \"Lazarus hackers exploited Windows zero-day to target defense firms\". If it is in your environment, patch it now. Details, affected versions, and remediation guidance: https://senserva.com/cve/CVE-2026-68820.html"
  },
  {
   "at": "2026-08-13T01:08:17.480Z",
   "cves": [
    {
     "id": "CVE-2026-68820",
     "page": true
    }
   ],
   "kbs": [],
   "text": "Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability (CVE-2026-68820) is the CVE to watch right now. The Microsoft Windows Ancillary Function Driver for WinSock flaw is rated Critical with a CVSS score of 9.8. CISA added it to the Known Exploited Vulnerabilities catalog on 2026-08-11, which means it is being attacked in the wild, not just in theory. Help Net Security covered it on 2026-08-12: \"Microsoft patches 400+ vulnerabilities, one zero-day under attack (CVE-2026-68820)\". If it is in your environment, patch it now. Details, affected versions, and remediation guidance: https://senserva.com/cve/CVE-2026-68820.html"
  },
  {
   "at": "2026-08-11T20:13:34.204Z",
   "cves": [
    {
     "id": "CVE-2026-68820",
     "page": true
    },
    {
     "id": "CVE-2026-62832",
     "page": true
    },
    {
     "id": "CVE-2026-72971",
     "page": true
    }
   ],
   "kbs": [
    {
     "id": "KB5120238",
     "page": true
    },
    {
     "id": "KB5120242",
     "page": true
    },
    {
     "id": "KB5120229",
     "page": true
    },
    {
     "id": "KB5120249",
     "page": true
    }
   ],
   "text": "August 2026\n\nMicrosoft shipped fixes for 751 vulnerabilities across 67 update articles.\n\nOne of them is already being exploited: CVE-2026-68820, the Windows Ancillary Function Driver for WinSock (AFD.sys). Elevation of privilege, CVSS 7.0, and Microsoft marks it Exploitation Detected.  It does not get an attacker onto a machine; it takes an attacker who is already there and makes them administrator.\n\nThe fix ships in this month's cumulative updates. Depending on your build: KB5120238, KB5120242, KB5120229, KB5120249. Thirteen updates carry it in total, so if your build is not in that list, check the CVE page:  https://senserva.com/cve/CVE-2026-68820.html\n\nEvery KB in this release, all 67, with what each one fixes: https://senserva.com/patch-tuesday.html\n\nPUBLIC BEFORE THE PATCH\n\nTwo more were publicly disclosed before a fix existed. Neither is confirmed as being attacked, but the details were out while everyone was exposed.\n\nCVE-2026-62832, Windows User Profile Service, elevation of privilege, CVSS 7.8. Microsoft rates it Exploitation More Likely, and it scores higher than the one under active attack. https://senserva.com/cve/CVE-2026-62832.html\n\nCVE-2026-72971, Windows Container Isolation file system filter driver, tampering, CVSS 5.5. Narrower: mostly Windows container hosts. https://senserva.com/cve/CVE-2026-72971.html\n\nTHE SHAPE OF THE MONTH\n\n108 of the 751 are rated Critical by Microsoft. The Severity split covers 743 of them (108 Critical, 396 Important, 207 Moderate, 32 Low); the remaining 8 carry no rating at all.\n\nWorth noting where the Critical ones live. SharePoint Server, Teams and Azure SQL Managed Instance all appear, all elevation of privilege. Most patching routines have a rhythm for Windows and nothing like it for the collaboration and cloud services sitting alongside.\n\nTHREE THINGS THIS WEEK\n\n1. The exploited one first: AFD.sys, this month's cumulative update, today.\n\n2. The two public ones next. Public plus unpatched is how a proof of concept becomes a campaign.\n\n3. Look past Windows. SharePoint, Teams and Azure SQL rarely share a maintenance window with the servers.\n\nEvery CVE and every KB above has its own page on senserva.com, with the  affected products, the known issues in Microsoft's own words, and the change trail as Microsoft revises through the month.\n\nTrack it as Microsoft revises through the month: https://senserva.com/microsoft-patch-tracker.html\n\nWHERE THESE NUMBERS COME FROM\n\nEvery figure above is Microsoft's own, from the Security Response Center's CVRF 2026-Aug release document, read directly on release day. Senserva tracks 347 of the 751 against update articles we hold pages for, and the difference is largely Azure Linux entries that ship no KB article, so you will see both numbers on the site, labeled."
  },
  {
   "at": "2026-08-11T19:46:58.235Z",
   "cves": [
    {
     "id": "CVE-2026-68820",
     "page": true
    },
    {
     "id": "CVE-2026-62832",
     "page": true
    },
    {
     "id": "CVE-2026-72971",
     "page": true
    }
   ],
   "kbs": [
    {
     "id": "KB5120238",
     "page": true
    },
    {
     "id": "KB5120242",
     "page": true
    },
    {
     "id": "KB5120229",
     "page": true
    },
    {
     "id": "KB5120249",
     "page": true
    }
   ],
   "text": "August 2026, and the number that matters is not 751.\n\nMicrosoft shipped fixes for 751 vulnerabilities across 67 update articles.\nOne of them is already being exploited.\n\nSTART HERE\nCVE-2026-68820, the Windows Ancillary Function Driver for WinSock (AFD.sys).\nElevation of privilege, CVSS 7.0, and Microsoft marks it Exploitation\nDetected. It does not get an attacker onto a machine; it takes an attacker\nwho is already there and makes them administrator.\n\nThe fix ships in this month's cumulative updates. Depending on your build:\nKB5120238, KB5120242, KB5120229, KB5120249. Thirteen updates carry it in\ntotal, so if your build is not in that list, check the CVE page:\nhttps://senserva.com/cve/CVE-2026-68820.html\n\nEvery KB in this release, all 67, with what each one fixes:\nhttps://senserva.com/patch-tuesday.html\n\nPUBLIC BEFORE THE PATCH\nTwo more were publicly disclosed before a fix existed. Neither is confirmed\nas being attacked, but the details were out while everyone was exposed.\n\nCVE-2026-62832, Windows User Profile Service, elevation of privilege,\nCVSS 7.8. Microsoft rates it Exploitation More Likely, and it scores higher\nthan the one under active attack.\nhttps://senserva.com/cve/CVE-2026-62832.html\n\nCVE-2026-72971, Windows Container Isolation file system filter driver,\ntampering, CVSS 5.5. Narrower: mostly Windows container hosts.\nhttps://senserva.com/cve/CVE-2026-72971.html\n\nTHE SHAPE OF THE MONTH\n108 of the 751 are rated Critical by Microsoft. The Severity split covers 743\nof them (108 Critical, 396 Important, 207 Moderate, 32 Low); the remaining 8\ncarry no rating at all.\n\nWorth noting where the Critical ones live. SharePoint Server, Teams and Azure\nSQL Managed Instance all appear, all elevation of privilege. Most patching\nroutines have a rhythm for Windows and nothing like it for the collaboration\nand cloud services sitting alongside.\n\nTHREE THINGS THIS WEEK\n1. The exploited one first: AFD.sys, this month's cumulative update, today.\n2. The two public ones next. Public plus unpatched is how a proof of concept\n   becomes a campaign.\n3. Look past Windows. SharePoint, Teams and Azure SQL rarely share a\n   maintenance window with the servers.\n\nEvery CVE and every KB above has its own page on senserva.com, with the\naffected products, the known issues in Microsoft's own words, and the change\ntrail as Microsoft revises through the month.\n\nTrack it as Microsoft revises through the month:\nhttps://senserva.com/microsoft-patch-tracker.html\n\nSource: Microsoft Security Response Center, CVRF 2026-Aug, read on release\nday. Figures are Microsoft's own."
  },
  {
   "at": "2026-08-11T19:46:18.956Z",
   "cves": [
    {
     "id": "CVE-2026-8037",
     "page": true
    }
   ],
   "kbs": [],
   "text": "Progress LoadMaster Command Injection Vulnerability (CVE-2026-8037) is the CVE to watch right now. The Progress LoadMaster flaw is rated Critical with a CVSS score of 9.8. CISA added it to the Known Exploited Vulnerabilities catalog on 2026-08-07, which means it is being attacked in the wild, not just in theory. If it is in your environment, patch it now. Details, affected versions, and remediation guidance: https://senserva.com/cve/CVE-2026-8037.html"
  }
 ]
}
