This Week in Threats: Aug 18–Sep 01, 2026

Expert cybersecurity insights for IT professionals

Last updated: September 1, 2026

By FixTheVuln Team Peer-reviewed security content Sources: CISA Known Exploited Vulnerabilities Catalog, NVD

Weekly Threat Summary

22 vulnerabilities were added to the CISA Known Exploited Vulnerabilities (KEV) catalog this period. The highest CVSS score is 10.0.

This week includes 14 critical-severity vulnerabilities (CVSS 9.0+) that require immediate attention.

This Week's Vulnerabilities

CVE-2026-21962 — Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in Improper Access Control Vulnerability

CVE-2026-81578 — PaperCut NG/MF Missing Authentication for Critical Function Vulnerability

CVE-2026-60004 — Gitea Code Injection Vulnerability

CVE-2026-8452 — Citrix NetScaler ADC and NetScaler Gateway Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability

CVE-2023-49105 — ownCloud Improper Authentication Vulnerability

CVE-2026-72529 — TrueConf Server Missing Authentication for Critical Function Vulnerability

CVE-2026-65400 — Apple macOS Improper Authentication Vulnerability

CVE-2026-59310 — Broadcom VMware vCenter Path Traversal Vulnerability

CVE-2026-33824 — Microsoft Internet Key Exchange (IKE) Service Extensions Double Free Vulnerability

CVE-2025-62593 — Ray-Project Ray Code Injection Vulnerability

CVE-2026-64849 — MLflow Server-Side Request Forgery Vulnerability

CVE-2026-82078 — PaperCut NG/MF Unsafe Reflection Vulnerability

CVE-2026-55040 — Microsoft SharePoint Weak Authentication Vulnerability

CVE-2026-72530 — TrueConf Server Code Injection Vulnerability

CVE-2026-73570 — Zimbra Collaboration Suite (ZCS) OS Command Injection Vulnerability

CVE-2019-1068 — Microsoft SQL Server Remote Code Execution Vulnerability

CVE-2021-23758 — Ajax.NET Professional Deserialization of Untrusted Data Vulnerability

CVE-2022-0995 — Linux Kernel Out-of-Bounds Write Vulnerability

CVE-2015-5287 — Red Hat Automatic Bug Reporting Tool Privilege Escalation Vulnerability

CVE-2026-53362 — Linux Kernel Unspecified Vulnerability

CVE-2026-66384 — JFrog Artifactory Improper Limitation of a Pathname to a Restricted Directory Vulnerability

CVE-2015-3246 — Red Hat Libuser Race Condition Vulnerability

What This Means for You

If you run any of the affected products, patch immediately. Critical-severity vulnerabilities are actively exploited in the wild — CISA adds them to the KEV catalog specifically because they represent real, current threats.

Use the CVSS Calculator to assess how these scores apply to your specific environment.

Cert Study Angles

These CVEs map directly to certification exam objectives. Use them as real-world case studies:

CompTIA Security+

ISC2 CISSP

Cisco CCNA

See all CVEs mapped to your cert: Exploit Tracker

Tools to Help

Stay Updated

This roundup is published every Tuesday. Bookmark the FixTheVuln Blog to stay on top of the latest threats — or subscribe via RSS.

Explore More

Free Security Tools Practice Quizzes Cert Comparisons

FixTheVuln Store

CISSP Exam Prep? Get the Study Planner

Comprehensive planner for (ISC)2 certifications. Domain-mapped study schedules, practice tracking, and more.

Shop CISSP Planner

Also available: SSCP, CCSP

CyberFolio

Building cybersecurity skills? Track them in one place.

Build a shareable cybersecurity portfolio that highlights your certifications, projects, and skills — free.

Build Your Portfolio →
← Back to Home ← All Blog Posts