New ShieldBreak zero-day elevates Defender privileges
🔒 A new zero-day named ShieldBreak was published by researcher Nightmare Eclipse after Microsoft's August 2026 Patch Tuesday. The exploit is a bypass for the earlier RoguePlanet privilege escalation flaw and can grant SYSTEM privileges on patched Windows 10, Windows 11, and Windows Server installations. The researcher claims a 100% success rate in tested builds and ties the release to an ongoing dispute over Microsoft's disclosure and bug bounty practices.
Microsoft patches 400 vulnerabilities in August update
🔒 Microsoft released its August Patch Tuesday addressing 400 CVEs, including one actively exploited zero-day and two publicly disclosed zero-days. The exploited flaw, CVE-2026-68820, is a use-after-free issue in the Windows Ancillary Function Driver for WinSock that can allow local low-privileged attackers to gain system privileges. Other notable fixes include EoP issues in the User Profile Service (CVE-2026-62832) and a Windows Container Isolation FS Filter Driver tampering flaw (CVE-2026-72971). Organizations without automated, risk-based patching will face challenges prioritizing these updates.
Microsoft Patch Tuesday — August 2026 Update Summary
🛡️ Microsoft released its August 2026 Patch Tuesday with 421 vulnerabilities across many products, including 62 rated critical. One flaw has known exploitation in the wild: CVE-2026-68820 affecting the Windows Ancillary Function Driver for WinSock. The bulletin highlights numerous RCEs in Windows, Office, SharePoint, Azure services and more, and flags several high-scoring elevation-of-privilege issues.
Microsoft patches 398 vulnerabilities, including active zero-day
🛡️ Microsoft released its August security updates closing 398 CVEs, including one actively exploited Windows kernel privilege-escalation bug in afd.sys (CVE-2026-68820). Four unauthenticated RCEs affecting Windows DNS Server, Windows Deployment Services, Microsoft QUIC, and HPC Pack each score 9.8 and require prioritization based on service exposure. The release also completes a two-part SharePoint remediation started in July by fixing the RCE component.
Researchers Weaponize Windows PnP Auto-Install Flaw
🔒 Security researchers demonstrated that Windows Plug and Play auto-install can be abused to fetch signed vendor software for an emulated USB device and escalate to SYSTEM on an updated Windows 11 machine. The technique also works over Remote Desktop when low-level USB or PnP redirection is enabled, though Microsoft notes this is not enabled by default. The researchers presented their findings at DEF CON 34 and provided tooling to emulate devices and chain co-installer behavior to privileged execution.
18-year Linux SCTP flaw lets attackers escalate root
🛡️ A long-standing use-after-free bug in Linux's SCTP implementation, tracked as CVE-2026-64564 and called SCTPhantom, can be exploited to achieve local privilege escalation and, according to Tencent Zhuque Lab, to escape containers and reach the host. Stable kernel fixes (7.1.6, 6.18.42, 6.12.101 and 6.6.148) were released on August 3. Systems with reachable SCTP should apply vendor updates or disable the module if unused.
Researchers expose TONTOU Spectre v2 bypass on CPUs
🛡️ Researchers at MIT CSAIL disclosed a new CPU side-channel exploit called TONTOU that bypasses neutralization-based Spectre v2 mitigations on Intel and AMD processors. They developed an Interrupt Injection technique to re-poison branch predictors after mitigation cleaning and demonstrated leaking kernel memory, including /etc/shadow hashes, from Linux machines. The team presented results at Black Hat USA and will publish further details at USENIX Security 2026.
Zapscape KVM vulnerability allows nested VM escape
🔒 Zapscape (CVE-2026-64561) is a Linux KVM/x86 shadow-MMU flaw that can let an attacker with kernel privileges in an L1 guest escape KVM isolation and run code on the host. Disclosed by researcher Hyunwoo Kim, the issue is a stale-root ordering bug causing a use-after-free during page-fault handling when nested virtualization is exposed. The upstream fix has been merged; administrators should update kernels or vendor packages that backport the patch.
Interrupt Injection: New Spectre-class Risk on Linux
🔒 Researchers from MIT CSAIL discovered INTERRUPT INJECTION, a technique that times interrupts to re-poison the branch predictor between a processor's sanitization and kernel use, bypassing Spectre v2 mitigations. On AMD Zen 2 with Linux 6.14 and default protections, their exploit read kernel memory at ~5.47 B/s and retrieved /etc/shadow in multiple trials. AMD issued bulletin AMD-SB-7061 and plans patches; Intel currently deems mitigation unnecessary. The disclosure highlights gaps in detection and reporting for deployed fixes.
Post‑exploitation toolkit embedded inside Oracle DB
🛡️ Huntress discovered a post‑exploitation toolkit compiled and stored as schema objects inside an Oracle database, enabling command execution on the underlying Windows host. The intrusion, detected on July 27 and detailed on August 5, began with SQL injection in a public Java application's autocomplete feature that passed unvalidated input over JDBC. Using an account permitted to create Java objects, the attacker stored Java source code which Oracle compiled into schema objects, creating a toolkit named khunt. Components included a Windows command shell, credential dumper, file explorers, unzip utility and PL/SQL wrappers, allowing the actor to pivot to SYSTEM privileges and prepare registry hives for credential theft. Huntress highlighted detection gaps because endpoint tools typically do not inspect Java classes and PL/SQL objects inside databases, turning the DB into an operational foothold; they recommended input sanitization, parameterized queries and least‑privilege for query‑capable accounts.
OVSwrap Linux kernel flaw enables local privilege escalation
🔒 A memory corruption vulnerability in the Linux kernel's Open vSwitch datapath, tracked as CVE-2026-64531 and dubbed OVSwrap, allows ordinary local users to escalate to root on many default-configured distributions. Disclosed on July 28, 2026 by Asim Manizada, the bug exploits a 16-bit length wrap in nested Netlink attributes and ships with a public PoC containing records for ~800 kernel builds. Upstream fixes were released on July 24; mitigations include blocking the openvswitch module, unloading it, rebooting, or disabling unprivileged user namespaces.
🔒 cPanel issued a targeted security release addressing a database privilege escalation flaw (CVE-2026-58048) that allowed an authenticated cPanel account with MySQL/MariaDB access to execute SQL in the administrative database context. The update also patches an HTTP request-smuggling issue in cpsrvd (CVE-2026-58047) and multiple Exim vulnerabilities; temporary workarounds are available for systems that cannot immediately upgrade. Administrators should apply the listed builds or revoke MySQL access until patched.
🛡️ Adobe released updates for Campaign Classic (ACC) to patch a maximum-severity authorization vulnerability (CVE-2026-48449, CVSS 10.0) that could enable arbitrary code execution without user interaction. The fixes, delivered in ACC v7.4.3 build 9398 for Windows and Linux, also address a high-severity SQL injection (CVE-2026-48448, CVSS 8.6) enabling arbitrary file reads. Adobe additionally remediated eight critical-rated flaws in Adobe Bridge that could lead to privilege escalation and code execution, crediting multiple external researchers. Users are urged to apply the updates promptly for protection.
VMware patches critical auth bypass and VM escape flaws
🔒 Broadcom released emergency security updates for VMware vCenter, ESX, Workstation, and Fusion to address five vulnerabilities, including three critical flaws that allow authentication bypass, remote code execution, and VM escape. Affected products include VMware Cloud Foundation and various telco platform offerings; administrators should assume prepatched versions are vulnerable and apply fixes immediately. There are no effective workarounds, and some updates require service interruptions or host reboots.
🛡️ AI-assisted research uncovered a years-old use-after-free race in the Linux kernel's net/sched code that permits local privilege escalation to root (CVE-2026-53264). The bug arises from mismatched locking where an entry can be freed before an RCU grace period ends, creating a window for the kernel to access freed memory. The flaw was found by Lee Jia Jie of STAR Labs, who used AI to locate and reliably reproduce the race; a patch defers freeing until after the grace period. Distributions should apply upstream fixes via normal security channels.
AI-assisted exploit yields local Linux root escalation
🔒 STAR Labs published a local privilege-escalation exploit for CentOS Stream 9 that abuses a use-after-free race in the kernel traffic-control subsystem (CVE-2026-53264, CVSS 7.8). Researcher Lee Jia Jie says AI aided discovery and exploit development; the exploit requires specific kernel options, unprivileged user namespaces, and a kernel-specific ROP chain. Upstream fixes landed June 1, 2026 and have been backported to multiple stable branches, but distribution coverage remains uneven.
🔒 A proof-of-concept exploit for the “Certighost” Active Directory Certificate Services vulnerability (CVE-2026-54121) was released after Microsoft patched the issue in the July 2026 Patch Tuesday updates. Researchers showed how a low-privileged user can abuse the AD CS “chase” fallback to have a CA contact an attacker-controlled host and issue certificates for targeted machine accounts. The exploit automates PKINIT authentication as a domain controller to obtain Kerberos credentials and perform domain-level actions; Microsoft added validation to the chase process as a fix.
Certighost AD CS exploit lets low-privileged users
🔒 Researchers published a working exploit on July 24 that lets a low-privileged Active Directory user obtain a certificate for a Domain Controller and authenticate as that machine. Codenamed Certighost, the flaw enables a Kerberos credential capable of DCSync to retrieve the krbtgt secret. Microsoft patched AD CS as CVE-2026-54121 on July 14 and rated it a CVSS 8.8; the full proof-of-concept was released publicly.
🔒 Aikido Security's AI pentest agents found eight high-severity vulnerabilities in NodeBB, affecting every version before 4.14.0; NodeBB has issued patches and administrators should upgrade to 4.14.2. The issues ranged from a settings-based elevation that opened the admin dashboard to ordinary members, to unauthenticated access to private messages and categories, to a page-rendering flaw enabling injected links that execute code. Five flaws lived in federation code connecting forums to the fediverse, and several fixes were deployed piecemeal between May and July, with 4.14.0 rebuilding page text handling.
XFS reflink race lets local unprivileged users gain root
🔒 Qualys TRU disclosed a decade-old race condition in the Linux XFS filesystem that allows an unprivileged local user to gain full root access on kernels 4.11+ when XFS reflink is enabled. The flaw, tracked as CVE-2026-64600 and dubbed RefluXFS, lets a race between concurrent writes corrupt the copy-on-write mechanism so the original file is modified directly on disk without kernel logs. Vendors merged a patch into upstream in July; affected organizations should apply vendor kernel updates and reboot to mitigate.