The trailing ~48 hours (August 13–15, 2026) were defined by exploitation catching up to recent patches rather than by fresh disclosures. Every item below was confirmed against a primary source — a vendor advisory, a national CERT bulletin, original incident-response research, or a company’s own breach notice — and dated on that source’s page.
Max-severity SAP Commerce Cloud RCE exploited three days after patch day
SAP · August 14, 2026
CVE-2026-58231, an improper-authorization flaw in the Data Hub Adapter extension of SAP Commerce Cloud, is being probed in the wild three days after SAP shipped a fix. SAP scored it CVSS 10.0 as CNA (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H, CWE-94); NVD has not yet issued its own assessment. Affected products are COM_CLOUD 2211 and 2211-JDK21, patched via SAP Note 3771065 on the August 11 Security Patch Day. Threat intelligence firm Defused reported the first exploitation attempts against its honeypots on August 14. The CVE is not in the CISA KEV catalog, and Defused states no public proof-of-concept exists.
“First exploitation attempts against CVE-2026-58231 (unauth RCE in SAP Commerce Cloud, CVSS 10.0) is now hitting our honeypots – 3 days after patch day. This vulnerability has no public PoC and is not known to be exploited.” — Defused
Source: SAP Note 3771065 · NVD · BleepingComputer
vCenter exploitation campaign attributed to a Chinese-speaking actor, with ESXi ransomware in the chain
QUIRSO · August 14, 2026
German DFIR firm QUIRSO published a follow-up to its earlier survey of CVE-2026-59310, the CVSS 9.8 directory-traversal-to-RCE flaw in the vCenter Syslog Server that Broadcom disclosed in VMSA-2026-0006 on July 29 and revised on August 3. The new report adds a full incident-response case study: unauthenticated RCE, cron-based execution, an open-source reverse_ssh implant for C2, rogue adminuser accounts created on every ESXi host, and a Babuk-derived ESXi ransomware payload that also encrypted ESXi logs. QUIRSO counts 361 victim IPs across 47 countries, with first callbacks on August 3 — five days after disclosure. It also reports possible exploitation of the related CVE-2026-59309, a CVSS 9.8 authentication bypass in VMware Directory Service, beginning August 1. Fixed builds are vCenter 9.1.0.0300, 9.0.2.0100, and 8.0 U3k or 8.0 U2f; Broadcom lists no workarounds. Neither CVE is in KEV.
“QUIRSO assesses with moderate confidence that the exploitation campaign targeting CVE-2026–59310 is operated by a Chinese-speaking threat actor, probably working in a UTC+8 environment.” — QUIRSO GmbH
Source: Broadcom VMSA-2026-0006 · QUIRSO · BleepingComputer
macOS Screen Sharing authentication bypass abused to drop Monero miners
NCSC-NL · August 12, 2026
The Netherlands’ National Cyber Security Centre updated advisory NCSC-2026-0280 to report in-the-wild abuse of CVE-2026-65400, an authentication bypass in macOS Screen Sharing that lets a network attacker authenticate over VNC (TCP 5900) without valid credentials. Apple patched it on August 6 in macOS Tahoe 26.6.1, Sequoia 15.7.9, and Sonoma 14.8.9, describing it as “an authentication issue… addressed with improved state management” and crediting Alfredo Pesoli (@__rev) via Bynario Atlas. Apple assigns no CVSS and NVD has not scored it; the only published score is CISA-ADP’s 7.1 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N), which NCSC-NL matches. Some outlets have circulated a 9.8 figure that no primary source supports. Exploit code is public, root was obtained on every affected host observed, and the CVE is not in KEV. Where patching is not immediate, disabling Screen Sharing under General → Sharing removes exposure.
“The NCSC has received a notification indicating that active abuse of this vulnerability has been observed on multiple systems on which port 5900 was accessible from the Internet.” — NCSC-NL, advisory NCSC-2026-0280
Source: Apple HT148170 · NCSC-NL NCSC-2026-0280 · BleepingComputer
Trezor customer data exposed through a two-hop supply chain rooted in the Metabase zero-day
Trezor · August 13, 2026
Hardware wallet maker Trezor disclosed that 13,689 customers had data exposed after its fulfilment provider ShipMonk was breached. ShipMonk attributes its own compromise to exploitation of Metabase, the analytics platform hit by CVE-2026-72898 — a CVSS 10.0 SQL injection zero-day granting unauthenticated admin access, which CISA added to the KEV catalog on August 11. The chain therefore runs Metabase → ShipMonk → Trezor. Trezor says its own systems were not touched and that private keys, wallet backups, recovery seeds, and customer funds are unaffected. ShipMonk notified Trezor on August 10; Trezor disclosed publicly three days later.
“The incident affects 11,742 customers with full exposure (name, email, phone number, shipping address) and 1,947 customers with partial exposure (name, city, email).” — Trezor
Source: Trezor · CISA KEV alert · BleepingComputer
Have I Been Pwned puts a number on the RingCentral extortion leak: 1.6 million accounts
Have I Been Pwned · August 13, 2026
Have I Been Pwned indexed the RingCentral breach, deriving 1.6 million unique email addresses from the archive ShinyHunters published after the company declined to pay. Exposed fields are email addresses, names, phone numbers, and physical addresses; HIBP records no passwords. The figure comes from attacker-leaked data, not from RingCentral, which has published no count. RingCentral’s own security bulletin of July 28 attributes the intrusion to a social engineering campaign against its systems, states that the core platform was not impacted, and has not confirmed how access was obtained or attributed the incident to any group.
“In July 2026, the cloud-based business communications platform RingCentral was the target of a ShinyHunters ‘pay or leak’ extortion campaign.” — Have I Been Pwned
Source: Have I Been Pwned · RingCentral security bulletin · BleepingComputer
Still developing
Windows privilege escalation from a researcher on a disclosure campaign — Microsoft · August 11–12, 2026. Microsoft’s August Patch Tuesday closed “LegacyHive,” CVE-2026-62832, a CVSS 7.8 link-following flaw (CWE-59) in the Windows User Profile Service that a researcher using the handle Nightmare Eclipse had published a proof-of-concept for hours after July’s Patch Tuesday. CISA’s SSVC record lists exploitation as none and the CVE is not in KEV. The same researcher then released “ShieldBreak,” claimed as a bypass of Microsoft’s earlier RoguePlanet fix for a Microsoft Defender race condition tracked as CVE-2026-50656, said to yield SYSTEM on fully patched Windows 11 and Server 2025. The bypass claim is the researcher’s and has not been confirmed by Microsoft.
Source: MSRC · BleepingComputer · SecurityWeek
Lazarus exploited the WinSock driver zero-day against defence firms — Check Point · August 12, 2026. Check Point Research tied CVE-2026-68820, the use-after-free in the Windows Ancillary Function Driver for WinSock (afd.sys) that Microsoft patched on August 11 as actively exploited, to a new Operation Dream Job wave running since early July. The chain delivered an updated FudModule kernel rootkit alongside a backdoor tracked as Troy. Microsoft scored the flaw 7.0 as CNA, and CISA added it to KEV on August 11 with a remediation deadline of August 25.
Source: MSRC · Check Point Research · BleepingComputer
This brief covers the trailing ~48 hours (August 13–15, 2026).
Primary sources:
- SAP Security Note 3771065 — CVE-2026-58231
- NVD — CVE-2026-58231
- Broadcom VMSA-2026-0006 — CVE-2026-59309, CVE-2026-59310
- QUIRSO — Global Exploitation of CVE-2026-59310
- Apple — macOS Tahoe 26.6.1 security content
- NCSC-NL — NCSC-2026-0280
- Trezor — customer data exposed in shipping provider incident
- CISA — KEV additions, August 11, 2026
- Have I Been Pwned — RingCentral
- RingCentral — security bulletin
- MSRC — CVE-2026-62832
- MSRC — CVE-2026-68820
- Check Point Research — Shattering the Dream