Multiple critical software vulnerabilities patched in August 2026

Between August 25–27, 2026, five major software projects released patches for critical remote code execution and authentication vulnerabilities affecting GitPython, JSONata, Zscaler, LazyOwn, Veeam, and Apache Tomcat. Each vulnerability allowed attackers to execute arbitrary code or bypass authentication controls.

9 reportsother

Claim audit

No BS check run yet — press ⚖ to extract this story's claims and verify them against independent sources.

All coverage

GitPython Patches Critical RCE Vulnerability in Config Parser GitPython version 3.1.59 patches a critical remote code execution vulnerability (CVE-2026-78676) caused by improper handling of multi-line

mastodon:infosec-exchangeother35d ago kagi ↗

GitPython Patches Critical RCE Vulnerability in Config Parser GitPython version 3.1.59 patches a critical remote code execution vulnerability (CVE-2026-78676) caused by improper handling of multi-line configuration values. The flaw allows attackers to inject malicious Git directives that execute arbitrary code during routine repository operations. **If you use GitPython in any application or CI/CD

Critical Remote Code Execution Vulnerability Discovered in JSONata Library JSONata patched a critical vulnerability (CVE-2026-77413) that allows attackers to execute arbitrary code by exploiting a mis

mastodon:infosec-exchangeother34d ago kagi ↗

Critical Remote Code Execution Vulnerability Discovered in JSONata Library JSONata patched a critical vulnerability (CVE-2026-77413) that allows attackers to execute arbitrary code by exploiting a missing prototype check. The flaw enables full system takeover if an application processes malicious JSONata expressions. **If your applications or systems use the JSONata library, upgrade ASAP to versio

Zscaler Patches Critical Unauthenticated RCE in Client Connector for Windows Zscaler fixed a critical vulnerability (CVE-2026-59568) that allowed unauthenticated remote code execution and privilege es

mastodon:infosec-exchangeother34d ago kagi ↗

Zscaler Patches Critical Unauthenticated RCE in Client Connector for Windows Zscaler fixed a critical vulnerability (CVE-2026-59568) that allowed unauthenticated remote code execution and privilege escalation as well as three other flaws in its Client Connector for Windows **If you use Zscaler Client Connector on Windows, update every endpoint to the latest patched version. Anything released befor

Ubiquiti patches critical UniFi flaws across product line

kite:cybersecurityother34d ago kagi ↗

Ubiquiti released fixes Aug. 26 for a large set of UniFi security vulnerabilities, including three maximum-severity flaws rated 10.0 on the CVSS scale and 21 critical flaws, according to company bulletins described by CyberScoop, BleepingComputer and Cyber Security News [cyberscoop.com#1][bleepingcomputer.com#1][cybersecuritynews.com#1]. The affected UniFi ecosystem includes products used for netw

Google Patches 327 Security Flaws in Massive Chrome 152 Update Chrome 152 (152.0.7977.64/.65) patches 327 security vulnerabilities across Windows, Mac, and Linux, including 10 critical flaws that allo

mastodon:infosec-exchangeother33d ago kagi ↗

Google Patches 327 Security Flaws in Massive Chrome 152 Update Chrome 152 (152.0.7977.64/.65) patches 327 security vulnerabilities across Windows, Mac, and Linux, including 10 critical flaws that allow remote attackers to execute arbitrary code via crafted web content, in some cases escaping the browser sandbox for full host takeover. **Update Google Chrome to version 152.0.7977.64/.65 for Windows

Ubiquiti Patches 22 Vulnerabilities in UniFi Ecosystem Including Three CVSS 10.0 Flaws Ubiquiti has patched 22 vulnerabilities across its UniFi product line, including three CVSS 10.0 flaws that allow

mastodon:infosec-exchangeother33d ago kagi ↗

Ubiquiti Patches 22 Vulnerabilities in UniFi Ecosystem Including Three CVSS 10.0 Flaws Ubiquiti has patched 22 vulnerabilities across its UniFi product line, including three CVSS 10.0 flaws that allow unauthenticated remote command execution and authentication bypass. The update addresses critical flaws in UniFi OS, Protect, Talk, and Network applications, impacting devices like Dream Machines and

LazyOwn RedTeam Framework Patches Critical Default Credential Vulnerability LazyOwn RedTeam/APT Framework patched a critical vulnerability (CVE-2026-68503) that allows attackers to gain full administr

mastodon:infosec-exchangeother33d ago kagi ↗

LazyOwn RedTeam Framework Patches Critical Default Credential Vulnerability LazyOwn RedTeam/APT Framework patched a critical vulnerability (CVE-2026-68503) that allows attackers to gain full administrative control over C2 dashboards using hardcoded default credentials. The flaw enables unauthorized users to hijack red-team campaigns, issue commands to beacons, and access exfiltrated data. **If you

Veeam Patches Critical Authentication Coercion Flaw in Veeam ONE Veeam released patches for a critical vulnerability (CVE-2026-65641) in Veeam ONE that allows unauthenticated attackers to steal servic

mastodon:infosec-exchangeother33d ago kagi ↗

Veeam Patches Critical Authentication Coercion Flaw in Veeam ONE Veeam released patches for a critical vulnerability (CVE-2026-65641) in Veeam ONE that allows unauthenticated attackers to steal service account NTLM credentials via SMB coercion. The flaw affects version 13 builds and could lead to unauthorized access to backup infrastructure. **If you're running Veeam ONE version 13.1.0.7034 or any

Apache Tomcat Patches Critical Security Constraint Bypass Vulnerability Apache Tomcat addressed a critical vulnerability (CVE-2026-65182) that allows unauthenticated attackers to bypass security restr

mastodon:infosec-exchangeother33d ago kagi ↗

Apache Tomcat Patches Critical Security Constraint Bypass Vulnerability Apache Tomcat addressed a critical vulnerability (CVE-2026-65182) that allows unauthenticated attackers to bypass security restrictions by exploiting path-ordering logic. Administrators should update to the latest versions or remove the examples application to prevent unauthorized access. **If you run Apache Tomcat (versions 9