Microsoft Patch Tuesday August 2026
This month we got patches for 418 vulnerabilities. Of these, 62 are critical, 1 is being exploited in the wild, and 2 were publicly disclosed as zero-days. Notable fixes include Windows privilege escalation, container tampering, and critical QUIC and DNS Server remote code execution bugs.
A few vulnerabilities worth mentioning:
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability (CVE-2026-68820)
This Important-severity elevation of privilege vulnerability is listed by Microsoft as exploited in the wild but not publicly disclosed, and it has a CVSS score of 7.0. The flaw is a use-after-free issue in the Windows Ancillary Function Driver for WinSock affecting supported Windows client and server versions; a locally authenticated attacker with low privileges could run a specially crafted application to trigger a race condition and, if successful, gain SYSTEM privileges. The CVSS vector reflects local access, low privileges required, no user interaction, and high attack complexity because exploitation requires winning that race condition. Administrators should prioritize applying the relevant Windows security updates, particularly on systems where local code execution by untrusted users is possible, and monitor for suspicious privilege-escalation activity.
Windows User Profile Service Elevation of Privilege Vulnerability (CVE-2026-62832)
Microsoft says this vulnerability has been publicly disclosed but has not been exploited in the wild, making it a zero-day disclosure without confirmed exploitation at this time. Rated Important with a CVSS score of 7.8, this Windows User Profile Service flaw is an improper link resolution, or “link following,” issue that could allow a local authenticated attacker to elevate privileges. To exploit it, an attacker would need credentials for another local account and could run a specially crafted application to load another user’s registry hive; successful exploitation could allow access to or modification of another user’s data and ultimately grant administrator privileges. User interaction is not required. Administrators should prioritize applying the Microsoft security updates across affected Windows 10, Windows 11, Windows Server 2022, and Windows Server 2025 systems, and should also limit local account reuse and monitor for unusual registry hive loading or profile service activity.
Windows Container Isolation FS Filter Driver (unionfs.sys) Tampering Vulnerability (CVE-2026-72971)
This vulnerability was publicly disclosed before Patch Tuesday, making it a zero-day, but Microsoft says it has not been exploited in the wild; it is rated Important with a CVSS score of 5.5. The flaw is an improper link-resolution, or “link following,” issue in the Windows Container Isolation file system filter driver, unionfs.sys, affecting Windows 11 Version 26H1 on x64 and ARM64 systems. A local, authenticated attacker could exploit it with low complexity and no user interaction to tamper with files, resulting in high integrity impact, though Microsoft rates confidentiality and availability impact as none. Administrators should apply the Windows updates that correct the driver’s link-handling behavior, particularly on systems using Windows containers or container isolation features.
Microsoft QUIC Remote Code Execution Vulnerability (CVE-2026-62815)
This Critical Microsoft QUIC remote code execution vulnerability is not listed as exploited in the wild or publicly disclosed. It carries a CVSS score of 9.8 and is a use-after-free flaw that could allow an unauthenticated remote attacker to send a specially crafted packet to an affected service over the network and execute code on the target system, with no user interaction required. Affected platforms include Windows 11 and Windows Server 2022/2025, including Server Core installations. Administrators should prioritize applying the Microsoft update, especially on systems exposing QUIC-enabled services to untrusted networks, and consider limiting network exposure where patching cannot be completed immediately.
Windows DNS Server Remote Code Execution Vulnerability (CVE-2026-62878)
Microsoft reports that CVE-2026-62878 is neither exploited in the wild nor publicly disclosed; it is a Critical Windows DNS Server remote code execution vulnerability with a CVSS score of 9.8. The flaw is a stack-based buffer overflow in Windows DNS that can be triggered remotely by an unauthenticated attacker sending a specially crafted packet to an affected service over the network, with no user interaction required, potentially allowing code execution on the target DNS server. Affected systems include multiple Windows Server releases from 2012 through 2025, as well as listed Windows 10 versions where the vulnerable component is present. Administrators should apply Microsoft’s security updates promptly, especially on DNS servers, and reduce exposure by limiting DNS service access to trusted networks where possible, blocking unnecessary inbound traffic at firewalls, and monitoring DNS servers for crashes or anomalous traffic patterns.
This was a summary of Microsoft’s monthly updates highlighting some important vulnerabilities. Prioritize the exploited WinSock privilege-escalation flaw, then the publicly disclosed User Profile Service and unionfs.sys issues, and patch internet-exposed QUIC services and DNS servers quickly due to remote code execution risk.
A detailed list of this month's vulnerabilities follows below. To search and filter them, visit my dashboard: https://patchlens.io
| Description | |||||||
|---|---|---|---|---|---|---|---|
| CVE | Disclosed | Exploited | Exploitability (old versions) | current version | Severity | CVSS Base (AVG) | CVSS Temporal (AVG) |
| .NET Core Remote Code Execution Vulnerability | |||||||
| %%cve:2026-70354%% | No | No | - | - | Important | 7.8 | 6.8 |
| .NET Denial of Service Vulnerability | |||||||
| %%cve:2026-62901%% | No | No | - | - | Important | 7.5 | 6.5 |
| .NET Elevation of Privilege Vulnerability | |||||||
| %%cve:2026-62909%% | No | No | - | - | Important | 7.8 | 6.8 |
| %%cve:2026-58641%% | No | No | - | - | Important | 7.8 | 6.8 |
| %%cve:2026-62871%% | No | No | - | - | Important | 7.8 | 6.8 |
| %%cve:2026-62886%% | No | No | - | - | Important | 7.8 | 6.8 |
| .NET Framework Elevation of Privilege Vulnerability | |||||||
| %%cve:2026-62872%% | No | No | - | - | Important | 8.8 | 7.7 |
| %%cve:2026-65810%% | No | No | - | - | Important | 7.8 | 6.8 |
| .NET Framework Remote Code Execution Vulnerability | |||||||
| %%cve:2026-62897%% | No | No | - | - | Important | 7.0 | 6.1 |
| .NET Information Disclosure Vulnerability | |||||||
| %%cve:2026-62900%% | No | No | - | - | Important | 5.9 | 5.2 |
| %%cve:2026-62902%% | No | No | - | - | Important | 6.5 | 5.7 |
| .NET Security Feature Bypass Vulnerability | |||||||
| %%cve:2026-62899%% | No | No | - | - | Important | 5.9 | 5.2 |
| AMD Zen Information Disclosure Vulnerability | |||||||
| %%cve:2026-59130%% | No | No | - | - | Important | 5.6 | 4.9 |
| %%cve:2026-59131%% | No | No | - | - | Important | 5.6 | 4.9 |
| Active Directory Security Feature Bypass Vulnerability | |||||||
| %%cve:2026-65777%% | No | No | - | - | Important | 5.3 | 4.6 |
| Application Information Services Elevation of Privilege Vulnerability | |||||||
| %%cve:2026-61357%% | No | No | - | - | Important | 7.8 | 6.8 |
| Application Insights Profiler Elevation of Privilege Vulnerability (no customer action required) |
|||||||
| %%cve:2026-49163%% | No | No | - | - | Critical | 8.8 | 7.7 |
| Azure Active Directory Elevation of Privilege Vulnerability (no customer action required) |
|||||||
| %%cve:2026-50481%% | No | No | - | - | Critical | 9.9 | 8.6 |
| Azure Confidential Ledger Remote Code Execution Vulnerability (no customer action required) |
|||||||
| %%cve:2026-68823%% | No | No | - | - | Critical | 9.1 | 7.9 |
| Azure CycleCloud Elevation of Privilege Vulnerability | |||||||
| %%cve:2026-70340%% | No | No | - | - | Important | 8.1 | 7.1 |
| Azure CycleCloud Information Disclosure Vulnerability | |||||||
| %%cve:2026-65806%% | No | No | - | - | Important | 6.5 | 5.7 |
| Azure Entra ID Spoofing Vulnerability (no customer action required) |
|||||||
| %%cve:2026-62869%% | No | No | - | - | Critical | 8.8 | 7.7 |
| Azure Logic Apps Information Disclosure Vulnerability (no customer action required) |
|||||||
| %%cve:2026-56161%% | No | No | - | - | Critical | 9.6 | 8.3 |
| Azure Monitor Agent Elevation of Privilege Vulnerability | |||||||
| %%cve:2026-47299%% | No | No | - | - | Important | 7.2 | 6.3 |
| Azure SQL Database Elevation of Privilege Vulnerability (no customer action required) |
|||||||
| %%cve:2026-63522%% | No | No | - | - | Critical | 7.8 | 6.8 |
| %%cve:2026-56162%% | No | No | - | - | Critical | 10.0 | 8.7 |
| Azure SQL Managed Instance Elevation of Privilege Vulnerability (no customer action required) |
|||||||
| %%cve:2026-62836%% | No | No | - | - | Critical | 8.7 | 7.6 |
| Azure SRE Agent Elevation of Privilege Vulnerability (no customer action required) |
|||||||
| %%cve:2026-62830%% | No | No | - | - | Critical | 9.9 | 8.6 |
| Azure Service Bus Remote Code Execution Vulnerability (no customer action required) |
|||||||
| %%cve:2026-50515%% | No | No | - | - | Critical | 9.9 | 8.6 |
| Azure Storage Explorer Elevation of Privilege Vulnerability | |||||||
| %%cve:2026-57104%% | No | No | - | - | Important | 8.8 | 7.7 |
| Capability Access Management Service (camsvc) Elevation of Privilege Vulnerability | |||||||
| %%cve:2026-62892%% | No | No | - | - | Important | 7.0 | 6.1 |
| CoPilot Chat Security Feature Bypass Vulnerability | |||||||
| %%cve:2026-65675%% | No | No | - | - | Important | 7.1 | 6.2 |
| Copilot Cowork Elevation of Privilege Vulnerability (no customer action required) |
|||||||
| %%cve:2026-59118%% | No | No | - | - | Critical | 9.3 | 8.1 |
| Desktop Window Manager Elevation of Privilege Vulnerability | |||||||
| %%cve:2026-65786%% | No | No | - | - | Important | 7.8 | 6.8 |
| %%cve:2026-65787%% | No | No | - | - | Important | 7.8 | 6.8 |
| %%cve:2026-65788%% | No | No | - | - | Important | 7.0 | 6.1 |
| GitHub Copilot and Visual Studio Code Elevation of Privilege Vulnerability | |||||||
| %%cve:2026-70335%% | No | No | - | - | Important | 7.8 | 6.8 |
| Microsoft 365 Admin Center Elevation of Privilege Vulnerability (no customer action required) |
|||||||
| %%cve:2026-62873%% | No | No | - | - | Critical | 9.8 | 8.5 |
| Microsoft Access Remote Code Execution Vulnerability | |||||||
| %%cve:2026-64906%% | No | No | - | - | Important | 7.8 | 6.8 |
| %%cve:2026-64912%% | No | No | - | - | Important | 7.8 | 6.8 |
| %%cve:2026-64908%% | No | No | - | - | Important | 7.8 | 6.8 |
| %%cve:2026-64914%% | No | No | - | - | Important | 7.8 | 6.8 |
| %%cve:2026-64920%% | No | No | - | - | Important | 7.8 | 6.8 |
| %%cve:2026-64919%% | No | No | - | - | Important | 7.8 | 6.8 |
| Microsoft Azure Kubernetes Service Elevation of Privilege Vulnerability (no customer action required) |
|||||||
| %%cve:2026-50516%% | No | No | - | - | Critical | 9.4 | 8.2 |
| Microsoft COM for Windows Information Disclosure Vulnerability | |||||||
| %%cve:2026-59136%% | No | No | - | - | Important | 5.5 | 4.8 |
| Microsoft Defender for Endpoint for Mac Information Disclosure Vulnerability | |||||||
| %%cve:2026-54123%% | No | No | - | - | Important | 5.5 | 4.8 |
| Microsoft Digest Authentication Elevation of Privilege Vulnerability | |||||||
| %%cve:2026-62698%% | No | No | - | - | Important | 7.8 | 6.8 |
| Microsoft Dynamics 365 (On-Premises) Information Disclosure Vulnerability | |||||||
| %%cve:2026-66301%% | No | No | - | - | Important | 6.5 | 5.7 |
| Microsoft Dynamics 365 On-Premises Remote Code Execution Vulnerability | |||||||
| %%cve:2026-65815%% | No | No | - | - | Important | 8.8 | 7.7 |
| Microsoft Dynamics Business Central Information Disclosure Vulnerability | |||||||
| %%cve:2026-40375%% | No | No | - | - | Important | 6.5 | 5.7 |
| Microsoft Entra Connect Elevation of Privilege Vulnerability | |||||||
| %%cve:2026-65673%% | No | No | - | - | Important | 7.8 | 6.8 |
| Microsoft Entra Provisioning Service Elevation of Privilege Vulnerability (no customer action required) |
|||||||
| %%cve:2026-59115%% | No | No | - | - | Critical | 9.9 | 8.6 |
| Microsoft Excel Information Disclosure Vulnerability | |||||||
| %%cve:2026-68802%% | No | No | - | - | Important | 5.5 | 4.8 |
| %%cve:2026-68808%% | No | No | - | - | Important | 5.5 | 4.8 |
| %%cve:2026-68813%% | No | No | - | - | Important | 5.5 | 4.8 |
| %%cve:2026-70318%% | No | No | - | - | Important | 5.5 | 4.8 |
| %%cve:2026-70327%% | No | No | - | - | Important | 6.5 | 5.7 |
| %%cve:2026-70328%% | No | No | - | - | Important | 6.5 | 5.7 |
| %%cve:2026-68797%% | No | No | - | - | Important | 5.5 | 4.8 |
| %%cve:2026-68799%% | No | No | - | - | Important | 5.5 | 4.8 |
| Microsoft Excel Remote Code Execution Vulnerability | |||||||
| %%cve:2026-65807%% | No | No | - | - | Important | 8.8 | 7.7 |
| %%cve:2026-68793%% | No | No | - | - | Important | 7.8 | 6.8 |
| %%cve:2026-68794%% | No | No | - | - | Critical | 7.8 | 6.8 |
| %%cve:2026-68795%% | No | No | - | - | Important | 7.8 | 6.8 |
| %%cve:2026-68796%% | No | No | - | - | Important | 7.8 | 6.8 |
| %%cve:2026-68800%% | No | No | - | - | Important | 7.8 | 6.8 |
| %%cve:2026-68807%% | No | No | - | - | Important | 7.8 | 6.8 |
| %%cve:2026-68806%% | No | No | - | - | Important | 7.8 | 6.8 |
| %%cve:2026-68810%% | No | No | - | - | Important | 7.8 | 6.8 |
| %%cve:2026-68811%% | No | No | - | - | Important | 7.8 | 6.8 |
| %%cve:2026-68815%% | No | No | - | - | Important | 7.8 | 6.8 |
| %%cve:2026-68816%% | No | No | - | - | Critical | 7.8 | 6.8 |
| %%cve:2026-68798%% | No | No | - | - | Important | 7.8 | 6.8 |
| %%cve:2026-68801%% | No | No | - | - | Important | 7.8 | 6.8 |
| %%cve:2026-68803%% | No | No | - | - | Important | 7.8 | 6.8 |
| %%cve:2026-68804%% | No | No | - | - | Critical | 7.8 | 6.8 |
| %%cve:2026-68805%% | No | No | - | - | Important | 7.8 | 6.8 |
| %%cve:2026-68812%% | No | No | - | - | Important | 7.8 | 6.8 |
| %%cve:2026-68814%% | No | No | - | - | Important | 7.8 | 6.8 |
| %%cve:2026-68817%% | No | No | - | - | Important | 7.8 | 6.8 |
| Microsoft Exchange Server Denial of Service Vulnerability | |||||||
| %%cve:2026-62912%% | No | No | - | - | Important | 6.5 | 5.7 |
| Microsoft Exchange Server Elevation of Privilege Vulnerability | |||||||
| %%cve:2026-62910%% | No | No | - | - | Important | 7.2 | 6.3 |
| %%cve:2026-65813%% | No | No | - | - | Important | 6.5 | 5.7 |
| %%cve:2026-62911%% | No | No | - | - | Critical | 8.0 | 7.0 |
| Microsoft Exchange Server Remote Code Execution Vulnerability | |||||||
| %%cve:2026-62913%% | No | No | - | - | Important | 8.8 | 7.7 |
| Microsoft Exchange Server Security Feature Bypass Vulnerability | |||||||
| %%cve:2026-62915%% | No | No | - | - | Important | 6.5 | 5.7 |
| Microsoft Exchange Server Spoofing Vulnerability | |||||||
| %%cve:2026-62914%% | No | No | - | - | Important | 7.3 | 6.4 |
| Microsoft High Performance Computing (HPC) Pack Elevation of Privilege Vulnerability | |||||||
| %%cve:2026-59133%% | No | No | - | - | Important | 8.8 | 7.7 |
| Microsoft High Performance Computing (HPC) Pack Remote Code Execution Vulnerability | |||||||
| %%cve:2026-59124%% | No | No | - | - | Important | 9.8 | 8.5 |
| Microsoft Local Security Authority Server (lsasrv) Remote Code Execution Vulnerability | |||||||
| %%cve:2026-62784%% | No | No | - | - | Important | 8.8 | 7.7 |
| Microsoft Office Elevation of Privilege Vulnerability | |||||||
| %%cve:2026-68792%% | No | No | - | - | Important | 7.8 | 6.8 |
| Microsoft Office Graphics Component Information Disclosure Vulnerability | |||||||
| %%cve:2026-63517%% | No | No | - | - | Important | 5.5 | 4.8 |
| %%cve:2026-62842%% | No | No | - | - | Important | 5.5 | 4.8 |
| %%cve:2026-66809%% | No | No | - | - | Important | 5.5 | 4.8 |
| Microsoft Office Graphics Component Remote Code Execution Vulnerability | |||||||
| %%cve:2026-63513%% | No | No | - | - | Critical | 7.8 | 6.8 |
| %%cve:2026-63519%% | No | No | - | - | Critical | 7.8 | 6.8 |
| %%cve:2026-65664%% | No | No | - | - | Critical | 7.8 | 6.8 |
| %%cve:2026-63526%% | No | No | - | - | Critical | 7.8 | 6.8 |
| %%cve:2026-66807%% | No | No | - | - | Critical | 7.8 | 6.8 |
| Microsoft Office Information Disclosure Vulnerability | |||||||
| %%cve:2026-70315%% | No | No | - | - | Important | 5.5 | 4.8 |
| %%cve:2026-70314%% | No | No | - | - | Important | 5.5 | 4.8 |
| %%cve:2026-70317%% | No | No | - | - | Important | 5.5 | 4.8 |
| %%cve:2026-70323%% | No | No | - | - | Important | 5.5 | 4.8 |
| %%cve:2026-63524%% | No | No | - | - | Important | 5.5 | 4.8 |
| %%cve:2026-63529%% | No | No | - | - | Important | 5.5 | 4.8 |
| %%cve:2026-64899%% | No | No | - | - | Important | 5.5 | 4.8 |
| Microsoft Office Remote Code Execution Vulnerability | |||||||
| %%cve:2026-63515%% | No | No | - | - | Critical | 7.8 | 6.8 |
| %%cve:2026-65657%% | No | No | - | - | Critical | 7.8 | 6.8 |
| %%cve:2026-65656%% | No | No | - | - | Important | 7.8 | 6.8 |
| %%cve:2026-65661%% | No | No | - | - | Important | 7.8 | 6.8 |
| %%cve:2026-63532%% | No | No | - | - | Critical | 7.8 | 6.8 |
| %%cve:2026-63533%% | No | No | - | - | Important | 7.8 | 6.8 |
| %%cve:2026-64898%% | No | No | - | - | Critical | 7.8 | 6.8 |
| %%cve:2026-64903%% | No | No | - | - | Critical | 7.8 | 6.8 |
| %%cve:2026-64904%% | No | No | - | - | Important | 7.8 | 6.8 |
| %%cve:2026-64909%% | No | No | - | - | Critical | 7.8 | 6.8 |
| %%cve:2026-64910%% | No | No | - | - | Critical | 7.8 | 6.8 |
| %%cve:2026-64911%% | No | No | - | - | Critical | 7.8 | 6.8 |
| %%cve:2026-70130%% | No | No | - | - | Critical | 8.4 | 7.3 |
| Microsoft Office SharePoint Spoofing Vulnerability | |||||||
| %%cve:2026-57105%% | No | No | - | - | Important | 8.0 | 7.0 |
| %%cve:2026-70306%% | No | No | - | - | Important | 9.3 | 8.1 |
| %%cve:2026-70332%% | No | No | - | - | Critical | 9.6 | 8.3 |
| Microsoft Office Word Information Disclosure Vulnerability | |||||||
| %%cve:2026-63521%% | No | No | - | - | Important | 5.5 | 4.8 |
| %%cve:2026-70319%% | No | No | - | - | Important | 5.5 | 4.8 |
| %%cve:2026-63528%% | No | No | - | - | Important | 5.5 | 4.8 |
| %%cve:2026-63530%% | No | No | - | - | Important | 5.5 | 4.8 |
| %%cve:2026-63531%% | No | No | - | - | Important | 5.5 | 4.8 |
| %%cve:2026-64917%% | No | No | - | - | Important | 5.5 | 4.8 |
| %%cve:2026-66806%% | No | No | - | - | Important | 5.5 | 4.8 |
| %%cve:2026-66810%% | No | No | - | - | Important | 5.5 | 4.8 |
| Microsoft Office Word Remote Code Execution Vulnerability | |||||||
| %%cve:2026-63518%% | No | No | - | - | Critical | 7.8 | 6.8 |
| %%cve:2026-70311%% | No | No | - | - | Important | 7.8 | 6.8 |
| %%cve:2026-63525%% | No | No | - | - | Critical | 7.8 | 6.8 |
| %%cve:2026-63527%% | No | No | - | - | Important | 7.8 | 6.8 |
| %%cve:2026-64905%% | No | No | - | - | Important | 7.8 | 6.8 |
| %%cve:2026-64907%% | No | No | - | - | Critical | 7.8 | 6.8 |
| %%cve:2026-64915%% | No | No | - | - | Important | 7.8 | 6.8 |
| Microsoft OneDrive for MacOS Elevation of Privilege Vulnerability | |||||||
| %%cve:2026-65680%% | No | No | - | - | Important | 6.7 | 5.8 |
| Microsoft Outlook Remote Code Execution Vulnerability | |||||||
| %%cve:2026-70329%% | No | No | - | - | Important | 8.8 | 7.7 |
| Microsoft Outlook Spoofing Vulnerability | |||||||
| %%cve:2026-62882%% | No | No | - | - | Important | 4.3 | 3.8 |
| Microsoft Planetary Computer Pro Elevation of Privilege Vulnerability (no customer action required) |
|||||||
| %%cve:2026-63508%% | No | No | - | - | Critical | 10.0 | 8.7 |
| Microsoft PowerPoint Remote Code Execution Vulnerability | |||||||
| %%cve:2026-70313%% | No | No | - | - | Important | 7.8 | 6.8 |
| Microsoft PowerShell Remote Code Execution Vulnerability | |||||||
| %%cve:2026-70337%% | No | No | - | - | Important | 8.8 | 7.7 |
| Microsoft PowerShell Security Feature Bypass Vulnerability | |||||||
| %%cve:2026-70338%% | No | No | - | - | Important | 7.8 | 6.8 |
| Microsoft Purview eDiscovery Elevation of Privilege Vulnerability (no customer action required) |
|||||||
| %%cve:2026-65668%% | No | No | - | - | Critical | 8.8 | 7.7 |
| Microsoft QUIC Information Disclosure Vulnerability | |||||||
| %%cve:2026-62898%% | No | No | - | - | Important | 7.5 | 6.5 |
| Microsoft QUIC Remote Code Execution Vulnerability | |||||||
| %%cve:2026-62815%% | No | No | - | - | Critical | 9.8 | 8.5 |
| Microsoft Remote Registry Service Denial of Service Vulnerability | |||||||
| %%cve:2026-59138%% | No | No | - | - | Important | 6.5 | 5.7 |
| %%cve:2026-61345%% | No | No | - | - | Important | 6.5 | 5.7 |
| Microsoft SharePoint Elevation of Privilege Vulnerability | |||||||
| %%cve:2026-70324%% | No | No | - | - | Important | 8.8 | 7.7 |
| Microsoft SharePoint Remote Code Execution Vulnerability | |||||||
| %%cve:2026-70321%% | No | No | - | - | Important | 8.8 | 7.7 |
| Microsoft SharePoint Server Elevation of Privilege Vulnerability | |||||||
| %%cve:2026-62827%% | No | No | - | - | Critical | 8.8 | 7.7 |
| %%cve:2026-70355%% | No | No | - | - | Important | 7.3 | 7.3 |
| %%cve:2026-64921%% | No | No | - | - | Critical | 8.8 | 7.7 |
| %%cve:2026-70326%% | No | No | - | - | Important | 8.8 | 7.7 |
| Microsoft SharePoint Server Information Disclosure Vulnerability | |||||||
| %%cve:2026-62837%% | No | No | - | - | Important | 6.5 | 5.7 |
| Microsoft SharePoint Server Remote Code Execution Vulnerability | |||||||
| %%cve:2026-63514%% | No | No | - | - | Important | 8.8 | 7.7 |
| %%cve:2026-63520%% | No | No | - | - | Important | 8.1 | 7.1 |
| %%cve:2026-65658%% | No | No | - | - | Important | 8.8 | 7.7 |
| %%cve:2026-65663%% | No | No | - | - | Important | 8.8 | 7.7 |
| %%cve:2026-65665%% | No | No | - | - | Critical | 8.8 | 7.7 |
| %%cve:2026-64901%% | No | No | - | - | Important | 8.8 | 7.7 |
| %%cve:2026-66805%% | No | No | - | - | Important | 8.8 | 7.7 |
| %%cve:2026-66808%% | No | No | - | - | Important | 8.8 | 7.7 |
| Microsoft SharePoint Server Spoofing Vulnerability | |||||||
| %%cve:2026-62829%% | No | No | - | - | Important | 4.6 | 4.0 |
| %%cve:2026-63516%% | No | No | - | - | Important | 6.5 | 5.7 |
| %%cve:2026-64922%% | No | No | - | - | Important | 4.6 | 4.0 |
| %%cve:2026-65660%% | No | No | - | - | Important | 6.5 | 5.7 |
| %%cve:2026-64897%% | No | No | - | - | Important | 4.6 | 4.0 |
| %%cve:2026-64900%% | No | No | - | - | Important | 7.3 | 6.4 |
| %%cve:2026-64902%% | No | No | - | - | Important | 4.6 | 4.0 |
| %%cve:2026-64916%% | No | No | - | - | Important | 4.6 | 4.0 |
| %%cve:2026-58639%% | No | No | - | - | Important | 6.5 | 5.7 |
| %%cve:2026-62839%% | No | No | - | - | Important | 6.5 | 5.7 |
| %%cve:2026-62917%% | No | No | - | - | Important | 4.6 | 4.0 |
| Microsoft SharePoint Server Tampering Vulnerability | |||||||
| %%cve:2026-63512%% | No | No | - | - | Important | 6.5 | 5.7 |
| Microsoft Teams Elevation of Privilege Vulnerability (no customer action required) |
|||||||
| %%cve:2026-62896%% | No | No | - | - | Critical | 9.6 | 8.3 |
| %%cve:2026-65667%% | No | No | - | - | Critical | 10.0 | 8.7 |
| Microsoft Teams Remote Code Execution Vulnerability | |||||||
| %%cve:2026-65768%% | No | No | - | - | Important | 8.8 | 7.7 |
| Microsoft Teams Spoofing Vulnerability (no customer action required) |
|||||||
| %%cve:2026-62918%% | No | No | - | - | Critical | 7.5 | 6.5 |
| Microsoft Teams for Android and iOS Spoofing Vulnerability | |||||||
| %%cve:2026-65767%% | No | No | - | - | Important | 8.8 | 7.7 |
| Microsoft Teams iOS Information Disclosure Vulnerability | |||||||
| %%cve:2026-65769%% | No | No | - | - | Important | 6.5 | 5.7 |
| Microsoft Windows Cross Device Service Elevation of Privilege Vulnerability | |||||||
| %%cve:2026-66804%% | No | No | - | - | Important | 7.8 | 6.8 |
| Microsoft Windows Search Component Information Disclosure Vulnerability | |||||||
| %%cve:2026-59135%% | No | No | - | - | Important | 5.5 | 4.8 |
| Microsoft Windows Storage Port Driver Elevation of Privilege Vulnerability | |||||||
| %%cve:2026-65814%% | No | No | - | - | Important | 7.8 | 6.8 |
| Microsoft Word Information Disclosure Vulnerability | |||||||
| %%cve:2026-70310%% | No | No | - | - | Important | 5.5 | 4.8 |
| Microsoft Word Remote Code Execution Vulnerability | |||||||
| %%cve:2026-58651%% | No | No | - | - | Important | 7.8 | 6.8 |
| Power BI Remote Code Execution Vulnerability | |||||||
| %%cve:2026-65811%% | No | No | - | - | Important | 8.8 | 7.7 |
| PowerShell Elevation of Privilege Vulnerability | |||||||
| %%cve:2026-59119%% | No | No | - | - | Important | 7.3 | 6.4 |
| PowerShell Information Disclosure Vulnerability | |||||||
| %%cve:2026-58612%% | No | No | - | - | Important | 7.4 | 6.4 |
| Powerpoint Information Disclosure Vulnerability | |||||||
| %%cve:2026-68809%% | No | No | - | - | Important | 5.5 | 4.8 |
| %%cve:2026-70312%% | No | No | - | - | Important | 5.5 | 4.8 |
| %%cve:2026-70316%% | No | No | - | - | Important | 5.5 | 4.8 |
| %%cve:2026-70325%% | No | No | - | - | Important | 5.5 | 4.8 |
| %%cve:2026-70320%% | No | No | - | - | Important | 5.5 | 4.8 |
| %%cve:2026-70322%% | No | No | - | - | Important | 5.5 | 4.8 |
| RPC Runtime Library Remote Code Execution Vulnerability | |||||||
| %%cve:2026-62781%% | No | No | - | - | Important | 8.1 | 7.1 |
| Remote Access API Elevation of Privilege Vulnerability | |||||||
| %%cve:2026-65671%% | No | No | - | - | Important | 7.8 | 6.8 |
| %%cve:2026-65672%% | No | No | - | - | Important | 7.8 | 6.8 |
| Remote Access Management service/API (RPC server) Elevation of Privilege Vulnerability | |||||||
| %%cve:2026-42976%% | No | No | - | - | Important | 7.8 | 6.8 |
| Remote Desktop Client Remote Code Execution Vulnerability | |||||||
| %%cve:2026-59134%% | No | No | - | - | Important | 7.5 | 6.5 |
| %%cve:2026-61352%% | No | No | - | - | Important | 7.5 | 6.5 |
| %%cve:2026-61363%% | No | No | - | - | Important | 7.5 | 6.5 |
| %%cve:2026-62824%% | No | No | - | - | Critical | 8.8 | 7.7 |
| Remote Procedure Call Denial of Service Vulnerability | |||||||
| %%cve:2026-54113%% | No | No | - | - | Important | 7.5 | 6.5 |
| Virtual Hard Disk (VHD) Miniport Driver Elevation of Privilege Vulernability | |||||||
| %%cve:2026-59125%% | No | No | - | - | Important | 7.0 | 6.1 |
| Visual Studio Code Information Disclosure Vulnerability | |||||||
| %%cve:2026-47285%% | No | No | - | - | Important | 6.5 | 5.7 |
| Visual Studio Code Python Extension Security Feature Bypass Vulnerability | |||||||
| %%cve:2026-54981%% | No | No | - | - | Important | 7.8 | 6.8 |
| Visual Studio Code Remote Code Execution Vulnerability | |||||||
| %%cve:2026-59113%% | No | No | - | - | Important | 8.8 | 7.7 |
| %%cve:2026-69320%% | No | No | - | - | Important | 8.8 | 7.7 |
| %%cve:2026-70336%% | No | No | - | - | Important | 8.8 | 7.7 |
| Visual Studio Code Security Feature Bypass Vulnerability | |||||||
| %%cve:2026-58650%% | No | No | - | - | Important | 7.8 | 6.8 |
| %%cve:2026-69278%% | No | No | - | - | Important | 7.8 | 6.8 |
| %%cve:2026-69306%% | No | No | - | - | Important | 8.2 | 7.1 |
| Win32k Information Disclosure Vulnerability | |||||||
| %%cve:2026-62746%% | No | No | - | - | Important | 5.5 | 4.8 |
| %%cve:2026-62798%% | No | No | - | - | Important | 5.5 | 4.8 |
| %%cve:2026-62743%% | No | No | - | - | Important | 5.5 | 4.8 |
| %%cve:2026-62786%% | No | No | - | - | Important | 5.5 | 4.8 |
| Windows Accessibility Infrastructure (ATBroker.exe) Elevation of Privilege Vulnerability | |||||||
| %%cve:2026-61358%% | No | No | - | - | Important | 7.8 | 6.8 |
| Windows Active Directory Certificate Services (AD CS) Remote Code Execution Vulnerability | |||||||
| %%cve:2026-62818%% | No | No | - | - | Critical | 8.8 | 7.7 |
| Windows Active Directory Domain Services Remote Code Execution Vulnerability | |||||||
| %%cve:2026-49179%% | No | No | - | - | Important | 8.8 | 7.7 |
| Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | |||||||
| %%cve:2026-61348%% | No | No | - | - | Important | 7.0 | 6.1 |
| %%cve:2026-68820%% | No | Yes | - | - | Important | 7.0 | 6.1 |
| %%cve:2026-70307%% | No | No | - | - | Important | 7.0 | 6.1 |
| Windows Autopilot Elevation of Privilege Vulnerability | |||||||
| %%cve:2026-65783%% | No | No | - | - | Important | 7.0 | 6.1 |
| %%cve:2026-65779%% | No | No | - | - | Important | 7.0 | 6.1 |
| %%cve:2026-65780%% | No | No | - | - | Important | 7.0 | 6.1 |
| %%cve:2026-65778%% | No | No | - | - | Important | 7.0 | 6.1 |
| %%cve:2026-65782%% | No | No | - | - | Important | 7.0 | 6.1 |
| %%cve:2026-65781%% | No | No | - | - | Important | 7.0 | 6.1 |
| Windows Backup Engine Elevation of Privilege Vulnerability | |||||||
| %%cve:2026-62908%% | No | No | - | - | Important | 7.0 | 6.1 |
| Windows Bind Filter Driver Elevation of Privilege Vulnerability | |||||||
| %%cve:2026-61927%% | No | No | - | - | Important | 7.0 | 6.1 |
| %%cve:2026-61934%% | No | No | - | - | Important | 7.8 | 6.8 |
| %%cve:2026-62705%% | No | No | - | - | Important | 7.0 | 6.1 |
| %%cve:2026-62722%% | No | No | - | - | Important | 7.8 | 6.8 |
| Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability | |||||||
| %%cve:2026-62713%% | No | No | - | - | Important | 7.8 | 6.8 |
| %%cve:2026-62771%% | No | No | - | - | Important | 7.8 | 6.8 |
| Windows Common Log File System Driver Elevation of Privilege Vulnerability | |||||||
| %%cve:2026-62728%% | No | No | - | - | Important | 7.0 | 6.1 |
| Windows Container Isolation FS Filter Driver (unionfs.sys) Elevation of Privilege Vulnerability | |||||||
| %%cve:2026-62772%% | No | No | - | - | Important | 7.8 | 6.8 |
| Windows Container Isolation FS Filter Driver (unionfs.sys) Information Disclosure Vulnerability | |||||||
| %%cve:2026-62775%% | No | No | - | - | Important | 5.5 | 4.8 |
| Windows Container Isolation FS Filter Driver (unionfs.sys) Tampering Vulnerability | |||||||
| %%cve:2026-72971%% | Yes | No | - | - | Important | 5.5 | 4.8 |
| Windows DHCP Client Denial of Service Vulnerability | |||||||
| %%cve:2026-65785%% | No | No | - | - | Important | 6.5 | 5.7 |
| Windows DHCP Client Elevation of Privilege Vulnerability | |||||||
| %%cve:2026-62755%% | No | No | - | - | Important | 7.8 | 6.8 |
| %%cve:2026-62736%% | No | No | - | - | Important | 7.8 | 6.8 |
| Windows DHCP Client Remote Code Execution Vulnerability | |||||||
| %%cve:2026-61361%% | No | No | - | - | Important | 7.0 | 6.1 |
| Windows DHCP Server Elevation of Privilege Vulnerability | |||||||
| %%cve:2026-62812%% | No | No | - | - | Important | 7.8 | 6.8 |
| %%cve:2026-62761%% | No | No | - | - | Important | 7.8 | 6.8 |
| %%cve:2026-62776%% | No | No | - | - | Important | 7.8 | 6.8 |
| %%cve:2026-62803%% | No | No | - | - | Important | 7.8 | 6.8 |
| %%cve:2026-62807%% | No | No | - | - | Important | 7.8 | 6.8 |
| Windows DHCP Server Information Disclosure Vulnerability | |||||||
| %%cve:2026-62718%% | No | No | - | - | Important | 6.5 | 5.7 |
| %%cve:2026-62715%% | No | No | - | - | Important | 6.5 | 5.7 |
| %%cve:2026-62716%% | No | No | - | - | Important | 6.5 | 5.7 |
| %%cve:2026-62742%% | No | No | - | - | Important | 6.5 | 5.7 |
| %%cve:2026-62745%% | No | No | - | - | Important | 6.5 | 5.7 |
| %%cve:2026-62720%% | No | No | - | - | Important | 6.5 | 5.7 |
| %%cve:2026-62714%% | No | No | - | - | Important | 6.5 | 5.7 |
| %%cve:2026-62814%% | No | No | - | - | Important | 6.5 | 5.7 |
| Windows DHCP Server Remote Code Execution Vulnerability | |||||||
| %%cve:2026-62823%% | No | No | - | - | Critical | 8.8 | 7.7 |
| Windows DNS Elevation of Privilege Vulnerability | |||||||
| %%cve:2026-70304%% | No | No | - | - | Important | 6.7 | 5.8 |
| %%cve:2026-70330%% | No | No | - | - | Important | 6.7 | 5.8 |
| %%cve:2026-62769%% | No | No | - | - | Important | 6.7 | 5.8 |
| %%cve:2026-62778%% | No | No | - | - | Important | 8.1 | 7.1 |
| %%cve:2026-62881%% | No | No | - | - | Important | 6.7 | 5.8 |
| %%cve:2026-62883%% | No | No | - | - | Important | 6.7 | 5.8 |
| %%cve:2026-65795%% | No | No | - | - | Important | 6.7 | 5.8 |
| %%cve:2026-65797%% | No | No | - | - | Important | 6.7 | 5.8 |
| %%cve:2026-65799%% | No | No | - | - | Important | 6.7 | 5.8 |
| %%cve:2026-65798%% | No | No | - | - | Important | 6.7 | 5.8 |
| Windows DNS Server Remote Code Execution Vulnerability | |||||||
| %%cve:2026-62787%% | No | No | - | - | Important | 7.5 | 6.5 |
| %%cve:2026-62817%% | No | No | - | - | Critical | 8.8 | 7.7 |
| %%cve:2026-62820%% | No | No | - | - | Critical | 8.1 | 7.1 |
| %%cve:2026-62878%% | No | No | - | - | Critical | 9.8 | 8.5 |
| %%cve:2026-65789%% | No | No | - | - | Critical | 8.1 | 7.1 |
| %%cve:2026-61920%% | No | No | - | - | Important | 6.6 | 5.8 |
| Windows DWM Core Library Elevation of Privilege Vulnerability | |||||||
| %%cve:2026-61932%% | No | No | - | - | Important | 7.8 | 6.8 |
| %%cve:2026-62894%% | No | No | - | - | Important | 7.8 | 6.8 |
| %%cve:2026-62888%% | No | No | - | - | Important | 7.8 | 6.8 |
| Windows DWM Core Library Information Disclosure Vulnerability | |||||||
| %%cve:2026-61933%% | No | No | - | - | Important | 5.5 | 4.8 |
| %%cve:2026-62703%% | No | No | - | - | Important | 5.5 | 4.8 |
| Windows Defender Firewall Service Security Feature Bypass Vulnerability | |||||||
| %%cve:2026-61936%% | No | No | - | - | Important | 5.5 | 4.8 |
| Windows Deployment Services TFTP Server Remote Code Execution Vulnerability | |||||||
| %%cve:2026-62893%% | No | No | - | - | Critical | 9.8 | 8.5 |
| Windows Device Association Service Elevation of Privilege Vulnerability | |||||||
| %%cve:2026-62747%% | No | No | - | - | Important | 7.8 | 6.8 |
| %%cve:2026-62710%% | No | No | - | - | Important | 7.8 | 6.8 |
| Windows Device Health Attestation (DHA) Remote Code Execution Vulnerability | |||||||
| %%cve:2026-66802%% | No | No | - | - | Critical | 8.1 | 7.1 |
| %%cve:2026-71331%% | No | No | - | - | Critical | 8.1 | 7.1 |
| Windows Display Enhancement Service Elevation of Privilege Vulnerability | |||||||
| %%cve:2026-61923%% | No | No | - | - | Important | 7.8 | 6.8 |
| Windows Encrypting File System (EFS) Information Disclosure Vulnerability | |||||||
| %%cve:2026-59128%% | No | No | - | - | Important | 5.5 | 4.8 |
| Windows Event Logging Service Elevation of Privilege Vulnerability | |||||||
| %%cve:2026-59126%% | No | No | - | - | Important | 7.0 | 6.1 |
| Windows Event Logging Service Information Disclosure Vulnerability | |||||||
| %%cve:2026-59137%% | No | No | - | - | Important | 5.5 | 4.8 |
| %%cve:2026-61347%% | No | No | - | - | Important | 5.5 | 4.8 |
| Windows GDI Information Disclosure Vulnerability | |||||||
| %%cve:2026-65662%% | No | No | - | - | Important | 5.5 | 4.8 |
| %%cve:2026-61360%% | No | No | - | - | Important | 5.5 | 4.8 |
| Windows GDI+ Elevation of Privilege Vulnerability | |||||||
| %%cve:2026-62890%% | No | No | - | - | Critical | 7.8 | 6.8 |
| Windows GDI+ Information Disclosure Vulnerability | |||||||
| %%cve:2026-62709%% | No | No | - | - | Important | 5.5 | 4.8 |
| Windows GDI+ Remote Code Execution Vulnerability | |||||||
| %%cve:2026-62822%% | No | No | - | - | Critical | 8.8 | 7.7 |
| Windows Graphics Kernel Denial of Service Vulnerability | |||||||
| %%cve:2026-62702%% | No | No | - | - | Important | 6.8 | 5.9 |
| Windows Graphics Kernel Elevation of Privilege Vulnerability | |||||||
| %%cve:2026-61346%% | No | No | - | - | Important | 7.0 | 6.1 |
| %%cve:2026-62774%% | No | No | - | - | Important | 7.0 | 6.1 |
| Windows HTTP Protocol Stack Tampering Vulnerability | |||||||
| %%cve:2026-62750%% | No | No | - | - | Important | 6.5 | 5.7 |
| Windows HTTP.sys Elevation of Privilege Vulnerability | |||||||
| %%cve:2026-61937%% | No | No | - | - | Important | 7.8 | 6.8 |
| %%cve:2026-62753%% | No | No | - | - | Important | 7.0 | 6.1 |
| %%cve:2026-62735%% | No | No | - | - | Important | 7.8 | 6.8 |
| %%cve:2026-62739%% | No | No | - | - | Important | 7.8 | 6.8 |
| %%cve:2026-62741%% | No | No | - | - | Important | 7.8 | 6.8 |
| %%cve:2026-62811%% | No | No | - | - | Important | 7.8 | 6.8 |
| Windows Hello Tampering Vulnerability | |||||||
| %%cve:2026-61928%% | No | No | - | - | Important | 5.5 | 4.8 |
| Windows Hyper-V Information Disclosure Vulnerability | |||||||
| %%cve:2026-61368%% | No | No | - | - | Important | 5.0 | 4.4 |
| Windows Imaging Component Information Disclosure Vulnerability | |||||||
| %%cve:2026-62740%% | No | No | - | - | Important | 5.5 | 4.8 |
| Windows Imaging Component Remote Code Execution Vulnerability | |||||||
| %%cve:2026-54984%% | No | No | - | - | Important | 7.8 | 6.8 |
| Windows Installer Elevation of Privilege Vulnerability | |||||||
| %%cve:2026-59127%% | No | No | - | - | Important | 7.8 | 6.8 |
| %%cve:2026-61925%% | No | No | - | - | Important | 7.8 | 6.8 |
| %%cve:2026-70344%% | No | No | - | - | Important | 7.8 | 6.8 |
| %%cve:2026-70345%% | No | No | - | - | Important | 7.8 | 6.8 |
| %%cve:2026-70346%% | No | No | - | - | Important | 7.8 | 6.8 |
| %%cve:2026-70347%% | No | No | - | - | Important | 7.8 | 6.8 |
| %%cve:2026-61938%% | No | No | - | - | Important | 7.0 | 6.1 |
| %%cve:2026-62768%% | No | No | - | - | Important | 7.8 | 6.8 |
| %%cve:2026-65774%% | No | No | - | - | Important | 7.8 | 6.8 |
| Windows Kerberos Elevation of Privilege Vulnerability | |||||||
| %%cve:2026-62754%% | No | No | - | - | Important | 7.8 | 6.8 |
| %%cve:2026-62766%% | No | No | - | - | Important | 7.0 | 6.1 |
| %%cve:2026-62773%% | No | No | - | - | Important | 7.0 | 6.1 |
| %%cve:2026-62752%% | No | No | - | - | Important | 7.8 | 6.8 |
| Windows Kernel Elevation of Privilege Vulnerability | |||||||
| %%cve:2026-61930%% | No | No | - | - | Important | 7.8 | 6.8 |
| %%cve:2026-62737%% | No | No | - | - | Important | 7.8 | 6.8 |
| %%cve:2026-61929%% | No | No | - | - | Important | 7.0 | 6.1 |
| %%cve:2026-62708%% | No | No | - | - | Important | 6.4 | 5.6 |
| %%cve:2026-62749%% | No | No | - | - | Important | 7.0 | 6.1 |
| %%cve:2026-62780%% | No | No | - | - | Important | 7.0 | 6.1 |
| %%cve:2026-62788%% | No | No | - | - | Important | 7.0 | 6.1 |
| %%cve:2026-65773%% | No | No | - | - | Important | 7.8 | 6.8 |
| Windows Key Guard Elevation of Privilege Vulnerability | |||||||
| %%cve:2026-66799%% | No | No | - | - | Critical | 7.8 | 6.8 |
| Windows LDAP - Lightweight Directory Access Protocol Remote Code Execution Vulnerability | |||||||
| %%cve:2026-62785%% | No | No | - | - | Important | 8.8 | 7.7 |
| %%cve:2026-62795%% | No | No | - | - | Important | 8.8 | 7.7 |
| Windows LUA File Virtualization Filter Driver Elevation of Privilege Vulnerability | |||||||
| %%cve:2026-50472%% | No | No | - | - | Important | 7.0 | 6.1 |
| Windows License Manager Elevation of Privilege Vulnerability | |||||||
| %%cve:2026-62777%% | No | No | - | - | Important | 7.8 | 6.8 |
| Windows MIDI Service Module Elevation of Privileges Vulnerability | |||||||
| %%cve:2026-62688%% | No | No | - | - | Important | 7.8 | 6.8 |
| %%cve:2026-62693%% | No | No | - | - | Important | 7.0 | 6.1 |
| Windows Management Instrumentation Information Disclosure Vulnerability | |||||||
| %%cve:2026-62738%% | No | No | - | - | Important | 5.5 | 4.8 |
| Windows Management Services Denial of Service Vulnerability | |||||||
| %%cve:2026-70348%% | No | No | - | - | Important | 5.5 | 4.8 |
| Windows Message Queuing Elevation of Privilege Vulnerability | |||||||
| %%cve:2026-62719%% | No | No | - | - | Important | 7.8 | 6.8 |
| %%cve:2026-62717%% | No | No | - | - | Important | 7.8 | 6.8 |
| %%cve:2026-65790%% | No | No | - | - | Important | 7.8 | 6.8 |
| Windows Modern Device Management (MDM) Elevation of Privilege Vulnerability | |||||||
| %%cve:2026-62707%% | No | No | - | - | Important | 7.8 | 6.8 |
| Windows NTFS Elevation of Privilege Vulnerability | |||||||
| %%cve:2026-62797%% | No | No | - | - | Important | 7.8 | 6.8 |
| %%cve:2026-62700%% | No | No | - | - | Important | 7.8 | 6.8 |
| %%cve:2026-62880%% | No | No | - | - | Important | 7.8 | 6.8 |
| Windows NTFS Information Disclosure Vulnerability | |||||||
| %%cve:2026-61350%% | No | No | - | - | Important | 4.6 | 4.0 |
| %%cve:2026-62796%% | No | No | - | - | Important | 5.5 | 4.8 |
| %%cve:2026-65784%% | No | No | - | - | Important | 5.5 | 4.8 |
| %%cve:2026-62793%% | No | No | - | - | Important | 5.5 | 4.8 |
| %%cve:2026-62887%% | No | No | - | - | Important | 5.5 | 4.8 |
| Windows Narrator Braille Elevation of Privilege Vulnerability | |||||||
| %%cve:2026-56174%% | No | No | - | - | Important | 7.8 | 6.8 |
| Windows Network Address Translation (NAT) Spoofing Vulnerability | |||||||
| %%cve:2026-56179%% | No | No | - | - | Moderate | 8.3 | 7.2 |
| Windows Network Connection Broker Elevation of Privilege Vulnerability | |||||||
| %%cve:2026-61366%% | No | No | - | - | Important | 7.0 | 6.1 |
| Windows Network File System Denial of Service Vulnerability | |||||||
| %%cve:2026-68819%% | No | No | - | - | Important | 5.9 | 5.2 |
| Windows Package Manager Elevation of Privilege Vulnerability | |||||||
| %%cve:2026-68821%% | No | No | - | - | Important | 7.3 | 6.4 |
| Windows Program Compatibility Assistant Service Elevation of Privilege Vulnerability | |||||||
| %%cve:2026-62696%% | No | No | - | - | Important | 7.8 | 6.8 |
| Windows Projected File System Elevation of Privilege Vulnerability | |||||||
| %%cve:2026-62751%% | No | No | - | - | Important | 7.8 | 6.8 |
| Windows Push Notifications Elevation of Privilege Vulnerability | |||||||
| %%cve:2026-62690%% | No | No | - | - | Important | 7.0 | 6.1 |
| Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability | |||||||
| %%cve:2026-62816%% | No | No | - | - | Critical | 8.8 | 7.7 |
| Windows Remote Access Connection Manager Elevation of Privilege Vulnerability | |||||||
| %%cve:2026-62783%% | No | No | - | - | Important | 7.8 | 6.8 |
| %%cve:2026-62758%% | No | No | - | - | Important | 7.8 | 6.8 |
| Windows Remote Desktop Client Information Disclosure Vulnerability | |||||||
| %%cve:2026-61924%% | No | No | - | - | Important | 6.5 | 5.7 |
| %%cve:2026-61918%% | No | No | - | - | Important | 6.5 | 5.7 |
| %%cve:2026-61921%% | No | No | - | - | Important | 6.5 | 5.7 |
| Windows Remote Desktop Services Elevation of Privilege Vulnerability | |||||||
| %%cve:2026-61356%% | No | No | - | - | Important | 7.8 | 6.8 |
| %%cve:2026-61367%% | No | No | - | - | Important | 7.8 | 6.8 |
| %%cve:2026-62692%% | No | No | - | - | Important | 7.8 | 6.8 |
| %%cve:2026-61364%% | No | No | - | - | Important | 7.8 | 6.8 |
| %%cve:2026-61365%% | No | No | - | - | Important | 7.8 | 6.8 |
| Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | |||||||
| %%cve:2026-62819%% | No | No | - | - | Critical | 8.1 | 7.1 |
| Windows SMB Client Elevation of Privilege Vulnerability | |||||||
| %%cve:2026-62799%% | No | No | - | - | Important | 7.8 | 6.8 |
| Windows SMB Client Information Disclosure Vulnerability | |||||||
| %%cve:2026-62782%% | No | No | - | - | Important | 6.5 | 5.7 |
| %%cve:2026-65794%% | No | No | - | - | Important | 6.5 | 5.7 |
| Windows SMBv3 Server Remote Code Execution Vulnerability | |||||||
| %%cve:2026-62800%% | No | No | - | - | Important | 8.8 | 7.7 |
| %%cve:2026-62790%% | No | No | - | - | Important | 8.8 | 7.7 |
| Windows Schannel Elevation of Privilege Vulnerability | |||||||
| %%cve:2026-62779%% | No | No | - | - | Important | 7.8 | 6.8 |
| Windows Schannel Security Feature Bypass Vulnerability | |||||||
| %%cve:2026-62757%% | No | No | - | - | Important | 5.3 | 4.6 |
| Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability | |||||||
| %%cve:2026-62889%% | No | No | - | - | Critical | 8.1 | 7.1 |
| Windows Sensor Data Service Elevation of Privilege Vulnerability | |||||||
| %%cve:2026-61355%% | No | No | - | - | Important | 7.8 | 6.8 |
| Windows Shell Elevation of Privilege Vulnerability | |||||||
| %%cve:2026-62770%% | No | No | - | - | Important | 7.8 | 6.8 |
| Windows Storage Elevation of Privilege Vulnerability | |||||||
| %%cve:2026-62695%% | No | No | - | - | Important | 7.8 | 6.8 |
| %%cve:2026-61359%% | No | No | - | - | Important | 7.8 | 6.8 |
| Windows TCP/IP Denial of Service Vulnerability | |||||||
| %%cve:2026-59132%% | No | No | - | - | Important | 7.5 | 6.5 |
| Windows TCP/IP Remote Code Execution Vulnerability | |||||||
| %%cve:2026-62792%% | No | No | - | - | Important | 8.1 | 7.1 |
| Windows Telephony Service Elevation of Privilege Vulnerability | |||||||
| %%cve:2026-61353%% | No | No | - | - | Important | 7.8 | 6.8 |
| %%cve:2026-62723%% | No | No | - | - | Important | 7.0 | 6.1 |
| %%cve:2026-62724%% | No | No | - | - | Important | 7.0 | 6.1 |
| %%cve:2026-62748%% | No | No | - | - | Important | 7.0 | 6.1 |
| %%cve:2026-62729%% | No | No | - | - | Important | 7.0 | 6.1 |
| %%cve:2026-59122%% | No | No | - | - | Important | 7.0 | 6.1 |
| %%cve:2026-62701%% | No | No | - | - | Important | 7.8 | 6.8 |
| %%cve:2026-62725%% | No | No | - | - | Important | 7.0 | 6.1 |
| %%cve:2026-62726%% | No | No | - | - | Important | 7.0 | 6.1 |
| %%cve:2026-62732%% | No | No | - | - | Important | 7.8 | 6.8 |
| %%cve:2026-62734%% | No | No | - | - | Important | 7.0 | 6.1 |
| Windows USB Driver Elevation of Privilege Vulnerability | |||||||
| %%cve:2026-61926%% | No | No | - | - | Important | 7.8 | 6.8 |
| Windows Universal Disk Format File System Driver (UDFS) Remote Code Execution Vulnerability | |||||||
| %%cve:2026-62699%% | No | No | - | - | Important | 6.8 | 5.9 |
| Windows User Profile Service Elevation of Privilege Vulnerability | |||||||
| %%cve:2026-62832%% | Yes | No | - | - | Important | 7.8 | 6.8 |
| Windows User-Mode Power Service (UMPS) Elevation of Privilege Vulnerability | |||||||
| %%cve:2026-62721%% | No | No | - | - | Important | 7.8 | 6.8 |
| Windows Win32k Elevation of Privilege Vulnerability | |||||||
| %%cve:2026-62712%% | No | No | - | - | Important | 7.8 | 6.8 |
| %%cve:2026-62876%% | No | No | - | - | Important | 7.8 | 6.8 |
| %%cve:2026-62877%% | No | No | - | - | Important | 7.8 | 6.8 |
| %%cve:2026-65678%% | No | No | - | - | Important | 7.0 | 6.1 |
| %%cve:2026-62711%% | No | No | - | - | Important | 7.8 | 6.8 |
| %%cve:2026-62733%% | No | No | - | - | Important | 7.8 | 6.8 |
| %%cve:2026-62885%% | No | No | - | - | Important | 7.8 | 6.8 |
| %%cve:2026-65775%% | No | No | - | - | Important | 7.8 | 6.8 |
| %%cve:2026-65776%% | No | No | - | - | Important | 7.0 | 6.1 |
| Windows Wired AutoConfig Service Information Disclosure Vulnerability | |||||||
| %%cve:2026-62730%% | No | No | - | - | Important | 5.5 | 4.8 |
| Windows Work Folder Service Elevation of Privilege Vulnerability | |||||||
| %%cve:2026-61349%% | No | No | - | - | Important | 7.8 | 6.8 |
| Windows iSCSI Target Service Denial of Service Vulnerability | |||||||
| %%cve:2026-65681%% | No | No | - | - | Important | 7.5 | 6.5 |
| %%cve:2026-65796%% | No | No | - | - | Important | 5.9 | 5.2 |
| Windows iSCSI Target Service Remote Code Execution Vulnerability | |||||||
| %%cve:2026-65679%% | No | No | - | - | Important | 8.1 | 7.1 |
| %%cve:2026-65791%% | No | No | - | - | Critical | 9.8 | 8.5 |
| Winlogon Elevation of Privilege Vulnerability | |||||||
| %%cve:2026-61939%% | No | No | - | - | Important | 7.0 | 6.1 |
Scans for Solana (Surfpool?) Endpoints
Solana is a crypto platform known for speed. Developers like it to develop distributed applications or to implement crypto payments. To interact with the blockchain, APIs are provided for developers. These APIs will either "speak" JSON or gRPC. One implementation often used for development is "surfpool," which is used to test programs before deploying them to a Solana network.
The requests that we are observing right now look like:
POST /solana HTTP/1.1
Host: [redacted]
User-Agent: HelloScan/1.0
Accept: */*
Connection: keep-alive
Content-Type: application/json
Content-Length: 45
{"jsonrpc":"2.0","id":1,"method":"getHealth"}
A typical response from Surfpool to this request:
HTTP/1.1 200 OK
content-type: application/json; charset=utf-8
content-length: 39
date: Mon, 10 Aug 2026 15:20:54 GMT
{"jsonrpc":"2.0","result":"ok","id":1}
A classical fingerprint request of someone attempting to enumerate Solana API endpoints. The "/solana" path is not required and should just be ignored. Usually, the API listens on port 8899, a port our honeypots are not listening on. The requests we are seeing are going to port 80. But they are likely assuming some form of proxy (for example an API gateway) that will map /solana to the backend API.
Other payloads that were used:
{"jsonrpc":"2.0","method":"eth_chainId","params":[],"id":1}
???????{"jsonrpc":"2.0","id":1,"method":"getVersion"}
The same scanner hitting the "/solana" endpoint also scans for "/jsonrpc", "/rpc", "/v1" and '/' which could possibly be related. It also looks for a few URLs associated with credentials (for example,/.env, /.env.bak /.env.local, and others)
--
Johannes B. Ullrich, Ph.D. , Dean of Research, SANS.edu
Twitter|
0 Comments
Linux Shell Forensic: Let?s Dive Into Atuin!
UNIX systems (including Linux) are well-known to record a lot of activities in many different locations. But there is one domain where they definitely lack of "modern" logging: shells. Most shells provide an historization of the typed commands through a flat file in the $HOME directory (ex: $HOME/.bash_history). They suffer of multiple problems:
- History is stored in memory and the file is updated when the shell exits
- The order of commands is not reliable
- There is no timestamps (by default)
- The size of history can be limited (see $HISTFILESIZE)
- Can be removed/tampered by the user
Note that if you use sudo to switch to another user (usually root), events are sent to the classic logging mechanism (syslog or journal):
Aug 05 15:30:48 lab0 sudo[211956]: xavier : TTY=pts/1 ; PWD=/tmp ; USER=root ; COMMAND=/usr/bin/whoami
To search across the history, the shell user can use the “reverse-i-search” feature available in Bash (but also other shells). This is the built-in incremental search through your command history, bound to CTRL-R. You hit it, start typing part of a command you ran before, and bash walks backwards through history showing the most recent match as you type — hence "reverse" (newest-first) and "i" for incremental (it updates on every keystroke).
xavier@lab0:~$ (reverse-i-search)`grep': dpkg -l | grep curl
It’s nice but, again, limited!
There are tools that expand the power of reverse-i-search and the shell history by storing everything into a database. One that became popular is called “Atuin”[1].

It enhances your shell history with a SQLite database, and records extra context for every command:
- The directory it ran in,
- how long it took,
- whether it succeeded,
- which machine and session it came from.
Even better, it can also sync your history across all of your machines, end-to-end encrypted. The official Atuin server can be used but, of course, it’s possible to deploy your own server (that's what I do in my infrastructure). From a forensic point of view, this tool is both a gift and a trap for the investigator. If you don’t know that Atuin is used, you’ll maybe loose lot of evidences. But if you spot it, it’s for sure a win!
First step to check: Where the artifacts live?
Atuin follows XDG paths[2], so check every user's home directory plus root (per-user install):
| File | Purpose |
|---|---|
| ~/.local/share/atuin/history.db | Primary evidence (SQLite) |
| ~/.local/share/atuin/history.db-wal | Uncommitted records (DO NOT MISS) |
| ~/.local/share/atuin/history.db-shm | |
| ~/.local/share/atuin/key | E2E sync encryption key |
| ~/.local/share/atuin/session | Server session token (API bearer) |
| ~/.config/atuin/config.toml | Config: sync target, filters, custom paths |
Do not assume the default location. The config location can be overridden with $ATUIN_CONFIG_DIR, and the database, key, and session paths are all individually configurable in config.toml. It's recommended to read the config first.
Atuin must be enable at shell level (for every shell, every user). Search for proof-of-activation in the shell RC files:
xavier@lab0:~$ grep atuin $HOME/.bashrc . "$HOME/.atuin/bin/env" eval "$(atuin init bash)"
Second step: Build your timeline
Forensicators love timelines! The main DB table is called “history”:
xavier@lab0:~$ sqlite3 history.db
SQLite version 3.46.1 2024-08-13 09:16:08
Enter ".help" for usage hints.
sqlite> .schema history
CREATE TABLE history (
id text primary key,
timestamp integer not null,
duration integer not null,
exit integer not null,
command text not null,
cwd text not null,
session text not null,
hostname text not null, deleted_at integer, author text, intent text, shell text,
unique(timestamp, cwd, command)
);
CREATE INDEX idx_history_timestamp on history(timestamp);
CREATE INDEX idx_history_command_timestamp on history(
command,
timestamp
);
CREATE INDEX idx_history_active_timestamp on history(timestamp)
where deleted_at is null;
CREATE INDEX idx_history_session_timestamp on history(session, timestamp)
where deleted_at is null;
CREATE INDEX idx_history_cwd_timestamp on history(cwd, timestamp)
where deleted_at is null;
CREATE INDEX idx_history_hostname_timestamp on history(lower(hostname), timestamp)
where deleted_at is null;
sqlite>
The id is a client-generated identifier used for syncing, and deleted_at is a soft-delete marker.
Compared to .bash_history this gives you, per command:
- a UTC timestamp (nanoseconds since epoch — divide by 1e9),
- the working directory,
- the exit code,
- execution duration,
- a session ID,
- the hostname
Triage query, read-only:
xavier@lab0:~$ sqlite3 "file:history.db?mode=ro&immutable=1" \
"SELECT datetime(timestamp/1000000000,'unixepoch') AS utc,
hostname, session, cwd, exit, command
FROM history ORDER BY timestamp;" | grep lab0 | head -5
2026-08-05 16:21:05|lab0:xavier|019fd2ba42c7779284d508825c4b2bd4|/home/xavier|0|vi .bashrc
2026-08-05 16:21:16|lab0:xavier|019fd2ba42c7779284d508825c4b2bd4|/home/xavier|0|cat $HOME/.atuin/bin/env
2026-08-05 16:22:53|lab0:xavier|019fd2bc13b174c094100175e489ade5|/home/xavier|0|byobu
2026-08-05 16:22:58|lab0:xavier|019fd2bc264c799196071edfbfe9d452|/home/xavier|0|ll
2026-08-05 16:23:11|lab0:xavier|019fd2bc264c799196071edfbfe9d452|/home/xavier|0|cd footprint
Interesting tips to keep in mind during investigations:
- "session" lets you reconstruct individual terminal sessions: Use "group by" to rebuild what an operator did in one window, in order.
- If sync is enabled, commands executed on other machines under the same account are pulled into this host's database. A row in this db is not proof the command ran on this host.
Next step, investigate deleted and residual data:
The "soft-delete" design works is a goldmine: rows deleted via Atuin are marked with "deleted_at" rather than physically purged in many cases. Try to use "WHERE deleted_at IS NOT NULL" to recover "deleted" activity. Standard SQLite carving applies: freelist/unallocated pages and the WAL can hold prior row versions and dropped records (undark, bring2lite, or manual page carving).
A good news, the standard flat history file (~/.bash_history or ~/.zsh_history) is still written alongside Atuin, so cross-reference it.
Finally, don't forget the "sync" feature:
Check the configuration file, if "auto_sync = true" and the user is logged in, history is end-to-end encrypted and pushed to a server (by default: https://api.atuin.sh). If you are authenticated and have the E2E encryption key, history may be pullable back from the server. But a self-hosted server can be used. In this case, more evidences can be found on this server but raw data will also be encrypted.
A final note: The configuration file allows to specify commands that will never be recorded:
## prevent commands matching any of these regexes from being written to history. ## Note that these regular expressions are unanchored, i.e. if they don't start ## with ^ or end with $, they'll match anywhere in the command. ## For details on the supported regular expression syntax, see ## https://docs.rs/regex/latest/regex/#syntax # history_filter = [ # "^secret-cmd", # "^innocuous-cmd .*--secret=.+", # ] ## prevent commands run with cwd matching any of these regexes from being written ## to history. Note that these regular expressions are unanchored, i.e. if they don't ## start with ^ or end with $, they'll match anywhere in CWD. ## For details on the supported regular expression syntax, see ## https://docs.rs/regex/latest/regex/#syntax # cwd_filter = [ # "^/very/secret/area", # ]
Absence of a command in the database is therefore not evidence it wasn't run. Other gaps: non-interactive shells and scripts (no init hook = no capture), and commands in a sh session without the hook.
[1] https://docs.atuin.sh/latest/
[2] https://specifications.freedesktop.org/basedir/latest/
Xavier Mertens (@xme)
Senior ISC Handler | SANS Principal Instructor | Freelance Consultant
Xameco | PGP Key
29 Comments
22 Seconds to Compromise: How Automated SSH Actors Move From Login to Persistence Before You Can Blink [Guest Diary]
[This is a Guest Diary by Daryl Jiminez, an ISC intern as part of the SANS.edu BACS program]
Introduction
On May 23, 2026, a threat actor successfully authenticated to my Cowrie SSH honeypot using compromised credentials and, within 22 seconds, injected a backdoor SSH key, changed the root password, attempted to clear host-based access restrictions, and performed automated system reconnaissance. The speed and consistency of the behavior left no room for doubt: this was not a human attacker manually working through a system. This was automated post-exploitation infrastructure executing a pre-scripted playbook the instant it found an open door.
This post documents that intrusion, the broader campaign it belongs to, and what defenders can do about it. The data comes from a self-managed Raspberry Pi 5 honeypot running Cowrie, operating continuously since April 2026 as part of my SANS Internet Storm Center internship. Over the 30-day monitoring period analyzed here, the sensor captured over 112,000 SSH sessions and 72,000+ authentication attempts from 175+ unique malicious source IPs.
The Sensor and Setup
The honeypot runs Cowrie v2.3.0 on a Raspberry Pi 5 with a residential internet connection. Cowrie simulates an SSH server that accepts connections on port 2222 (forwarded from external port 22), logs all attacker activity including commands, file transfers, and credentials, and submits data automatically to ISC DShield. The sensor's logs are archived daily and analyzed for attacker TTPs, campaign patterns, and threat intelligence value.
All data referenced in this post was extracted from raw JSON Cowrie logs using jq queries and cross-referenced against AbuseIPDB, VirusTotal, GreyNoise, ISC DShield, AlienVault OTX, Shodan, and Whois.
The Intrusion: 22 Seconds From Login to Persistence
At 01:06:43 UTC on May 23, 2026, source IP 163.7.8.79 initiated an SSH connection to the honeypot. One second later, the actor successfully authenticated using the credentials root / Aa123123123, a weak password consistent with credentials leaked in past data breaches and commonly cycled through automated attack tools.
What happened next is best understood through the session timeline:
Session Timeline — 163.7.8.79 — May 23, 2026

The SSH key injected into authorized_keys was captured by Cowrie with the following hash:
a8460f446be540410004b1a8db4083773fa46f7fe76fa84219c93daa1669f8f2
The actor also removed the existing .ssh directory and recreated it before injecting the key, a technique used to eliminate existing authorized keys and ensure exclusive backdoor access. Changing the root password immediately after key injection further locks out legitimate administrators. Clearing /etc/hosts.deny removes any host-based access restrictions that might block future connections from the actor's infrastructure.
The entire sequence executed in 22 seconds. There was no hesitation, no exploration, no human decision-making visible in the command pattern. This is automation: a pre-scripted playbook executing the moment authentication succeeded.
The Attacker Kept Coming Back
After reviewing the full May 23 logs, I found that 163.7.8.79 returned to the sensor multiple times throughout the day, reconnecting approximately every few minutes and executing the same automated command sequence on each successful session. The consistency across sessions, identical command order, identical timing patterns, identical SSH key material, confirms this is not a human operator adapting to findings but an automated tool running a fixed exploitation script.
When I queried the logs for all successful authentications on May 23, I found 21 successful logins from 21 different source IPs within a single 24-hour period. The logins were clustered heavily between 01:00 and 02:30 UTC, suggesting coordinated wave-based scanning rather than independent actors discovering the honeypot randomly. A sample of the credentials used shows the breadth of the wordlists being deployed:

The presence of 'minecraft / 12345' is particularly noteworthy. Someone compiled a wordlist that includes gaming server default credentials, indicating active scanning for Minecraft or similar game server installations, not just generic Linux systems.
The Campaign Is Not Isolated and Has Not Stopped
To understand whether this was a one-time event or part of a sustained campaign, I cross-referenced the full list of IPs my sensor had observed over 30+ days of operation against a compiled list of IPs associated with the mdrfckr SSH campaign, a persistent automated SSH scanning operation that has been documented across multiple honeypot operators worldwide.
The result: 93 IPs from the mdrfckr campaign list were still actively hitting my sensor weeks after first being documented. This is not a historical observation. These actors did not stop. The campaign has been running continuously throughout the monitoring period.
Additionally, analysis of the top connecting IPs by session volume revealed a coordinated subnet cluster:
80.94.92.184 — high volume connections
80.94.92.186 — high volume connections
80.94.92.171 — high volume connections
Three IPs from the same /24 subnet hitting the sensor simultaneously is not coincidence. This is coordinated scanning infrastructure, either a botnet or a distributed scanning platform, operating multiple nodes from the same network block to maximize coverage while distributing the load.
Threat Intelligence on 163.7.8.79
Cross-referencing the primary actor IP across multiple threat intelligence platforms confirmed its malicious reputation:
AbuseIPDB: 100% confidence of abuse, over 5,700 reported incidents primarily related to SSH brute-force attacks, with recent reports confirming continued active scanning activity.
VirusTotal: Multiple security vendors classify the IP as malicious or suspicious.
GreyNoise: Identified as part of internet-wide SSH brute-force and reconnaissance scanning activity, confirming this is not a targeted attack but systematic exploitation of any reachable vulnerable host.
Whois: The IP is associated with Byteplus infrastructure (AS150436), a cloud hosting provider, consistent with the pattern of actors using cloud resources to scale automated attack campaigns.
MITRE ATT&CK Mapping
T1078 — Valid Accounts: Actor authenticated using compromised credentials from a wordlist.
T1098 — Account Manipulation: Malicious SSH key injected into authorized_keys to establish persistent access.
T1059 — Command Execution: Multiple shell commands executed immediately following authentication.
T1562 — Impair Defenses: /etc/hosts.deny cleared and processes terminated to remove access restrictions.
Why This Matters
The 22-second compromise window is the most important takeaway from this observation. In the time it takes a human to notice an alert, review it, and begin investigation, a fully automated actor has already established a persistent backdoor, locked out legitimate administrators, and completed system reconnaissance. On a real system with no monitoring, the attack would be invisible until the damage was done.
The credential root / Aa123123123 is not sophisticated. It follows a simple pattern: a common word plus repeating numbers plus a capital letter. Millions of systems remain accessible with credentials exactly like this, whether because they were provisioned with weak defaults, never hardened, or left unchanged after initial setup. The actors hitting your honeypot are not targeting you specifically. They are sweeping the internet for anyone who left a door unlocked.
The sustained nature of this campaign, 93 returning IPs still active weeks after first documented observation, reinforces that these actors are not deterred by a single failed attempt. They keep scanning. They keep trying. The math works in their favor when millions of internet-connected systems are in scope.
Who Benefits From This Information
System administrators who are responsible for any internet-exposed Linux system. If your system is reachable on port 22 with password authentication enabled, you are in scope for this campaign right now.
Security operations teams monitoring SSH authentication events. The behavioral signatures documented here, automated command sequences executing within seconds of authentication, consistent credential patterns, recurring source IPs, are detectable with proper log monitoring and should be included in detection rule sets.
Threat intelligence analysts tracking automated SSH campaigns. The mdrfckr campaign correlation data and the coordinated subnet cluster observations contribute to the shared picture of this ongoing threat.
Recommendations (MITRE Mitigations)
M1027 — Password Policies: Enforce strong passwords across all accounts. The credentials used in this campaign, including Aa123123123, follow predictable patterns that password complexity requirements would eliminate. Eliminate default credentials entirely.
M1036 — Account Use Policies: Implement rate limiting and account lockout for SSH authentication failures. Tools like fail2ban can automatically block IPs after repeated failed attempts, dramatically reducing the attack surface for automated scanners.
M1042 — Disable or Remove Feature: Disable SSH password authentication entirely and require public key authentication only. This single configuration change renders the entire credential stuffing attack class ineffective regardless of wordlist quality or campaign scale.
M1030 — Network Segmentation: Restrict SSH access to trusted IP ranges or VPN connections only. Internet-exposed SSH on port 22 is an open invitation to this class of automated attack.
M1047 — Audit: Monitor authentication logs continuously. The behavioral pattern of automated post-exploitation, rapid command sequences executing within seconds of login, is highly detectable with proper alerting in place.
Indicators of Compromise
IP: 163.7.8.79 (Byteplus, AS150436) — primary actor
Credentials: root / Aa123123123
SSH Key Hash: a8460f446be540410004b1a8db4083773fa46f7fe76fa84219c93daa1669f8f2
Associated Campaign: mdrfckr SSH campaign (93 confirmed overlapping IPs)
Conclusion
Automated SSH credential stuffing is not a sophisticated attack. It requires no novel exploits, no zero-days, and no targeted intelligence. It requires only an internet-connected system with weak credentials and no rate limiting. The 22-second compromise timeline documented here shows that the window between successful authentication and full backdoor establishment is too short for human response alone. Detection and prevention must be configured before the attack arrives, not after.
The campaign documented here has not stopped. The same infrastructure continues to scan, the same credential lists continue to be deployed, and the same post-exploitation playbook continues to execute the instant a weak system is found. The defenders who have hardened their SSH configuration are invisible to this campaign. The ones who have not are being hit right now.

[1] ISC DShield: https://isc.sans.edu/ipinfo/163.7.8.79
[2] AbuseIPDB: https://www.abuseipdb.com/check/163.7.8.79
[3] VirusTotal: https://www.virustotal.com/gui/ip-address/163.7.8.79
[4] GreyNoise: https://viz.greynoise.io/ip/163.7.8.79
[5] AlienVault OTX: https://otx.alienvault.com/indicator/ip/163.7.8.79
[6] Whois: https://whois.domaintools.com/163.7.8.79
[7] MITRE ATT&CK T1078: https://attack.mitre.org/techniques/T1078/
[8] MITRE ATT&CK T1098: https://attack.mitre.org/techniques/T1098/
[9] MITRE ATT&CK T1059: https://attack.mitre.org/techniques/T1059/
[10] MITRE ATT&CK T1562: https://attack.mitre.org/techniques/T1562/
[11] fail2ban: https://en.wikipedia.org/wiki/Fail2ban
[12] https://www.sans.edu/cyber-security-programs/bachelors-degree/
Note: This blog post was produced with the assistance of Claude (Anthropic) as a writing and organizational tool. All analysis, log data, threat intelligence findings, and conclusions are my own.
-----------
Guy Bruneau IPSS Inc.
My GitHub Page
Twitter: GuyBruneau
gbruneau at isc dot sans dot edu
23 Comments
Don't Revoke That Token Yet: Inside the keyv/cacheable npm Worm
When you learn that a compromised package executed on one of your build hosts, muscle memory takes over: revoke the npm token, rotate the GitHub PAT, cycle the cloud keys. That reflex has been correct in almost every supply-chain incident I have worked. In the keyv/cacheable compromise that has been unfolding since yesterday, it is the one thing you should not do first — because revoking the stolen token is exactly what arms the payload.
Let me back up.
What happened
On August 4, 2026, an attacker took over the maintainer account behind the widely used keyv and cacheable npm namespaces — caching libraries that sit near the bottom of a very large number of dependency trees — and published trojanized releases. Socket's Threat Research team, which did the primary analysis, places the first malicious release, [email protected], at 09:35 UTC. The poisoned versions ship a preinstall hook:
"scripts": { "preinstall": "node setup.mjs" }
setup.mjs downloads a standalone Bun runtime, runs an obfuscated second stage (Math_Symbol.js, ~728 KB), and harvests whatever it can reach: AWS instance metadata, cloud keys, Vault tokens, Kubernetes service-account tokens, GitHub Actions secrets, npm tokens, plus a generic regex sweep for private keys and bearer tokens on disk. Then — and this is why the campaign grew from roughly ten packages to several hundred within hours — it uses the stolen npm token to inject the same hook into other packages the compromised identity can publish, recomputes the integrity hashes, and republishes. It is a worm. The public IOC lists now cover more than 440 packages across two thousand-plus versions, and they are still moving.
Two properties make this one worth a closer look than the average typosquat.
It does not need npm install
Most teams scope this kind of incident to "who ran npm install in the exposure window." That misses half the population. The source repository also received IDE and agent autostart hooks — a SessionStart entry in .claude/settings.json and a folderOpen task in .vscode/tasks.json — that run the loader when the cloned folder is simply opened. No install, nothing built.
Sit with who that includes. It includes the security engineer who cloned the repository to investigate the incident after reading about it. It includes the AI coding agent that opened the directory to "take a look." I do not think we have seen AI-agent configuration files used as a first-class supply-chain execution vector at this scale before, and it is worth internalizing: a checked-out repository is now an execution surface, and .claude/, .cursor/, and .vscode/ are part of it.
It punishes remediation
Here is the part that should change how you respond. Alongside the credential theft, the payload installs a host-level dead-man's switch. It writes the stolen GitHub token and an attacker-supplied handler command to ~/.config/gh-token-monitor/, then persists itself as a macOS LaunchAgent or a Linux systemd user service with loginctl enable-linger so it survives logout. The systemd unit describes itself, helpfully, as a "GitHub Token Validity Monitor," so at a glance it reads like a developer convenience.
A watcher script polls the GitHub API with the stolen token every 60 seconds. While the token works, nothing happens. The moment the token stops working — an HTTP 4xx, which is precisely what your revocation produces — it evals the remote-supplied handler string, then deletes its own state and exits. It is single-shot and self-clearing, and it also self-destructs after a 24-hour TTL.
What is in the handler? Public analysis cannot say, because it is attacker-controlled text pulled at runtime and can be changed remotely. It could be data destruction, re-implant, or nothing at all. That is the whole problem: the risk is not that the trap does something specific and known — it is that you cannot assess it, and it fires at the exact moment your team believes it is containing the incident and starts to relax.
One consequence is counterintuitive but load-bearing: isolating the host from the network is safe. With no connectivity there is no HTTP response, so there is no 4xx, so the switch does not fire — and exfiltration stops at the same time. Isolate first. Do not power off; volatile memory is evidence.
Why the usual checks miss it
- "The signature was valid."
[email protected]shipped with a passing SLSA attestation. Provenance attests to build integrity, not source integrity — the legitimate workflow faithfully built already-trojanized code. - "The diff was clean." The library itself was not modified. The malice lives in
package.jsonand two added files. Adist/comparison shows nothing. - "We don't use keyv." You almost certainly do, transitively. The common path is
eslint → file-entry-cache → flat-cache → keyv. Very few victims installed any of these directly. - "Nobody ran
npm install." See the second section.
What to actually do
The order matters more than the individual steps:
- Isolate the host from the network. Safe, for the reason above. Do not shut it down.
- Preserve evidence before you delete anything — the watcher self-clears in ~24 hours. Copy
~/.config/gh-token-monitor/{handler,token,started_at}, the payloads, the plist/unit, and record hashes. Do not execute the handler; treat it as inert text.started_atbounds your exposure window. - Eradicate: kill the watcher, unload the LaunchAgent / disable the systemd unit, drop
loginctllinger, remove the files and the.claude/.vscodehooks, and clear the package caches. - Rotate — now, and only now. npm token first, to stop propagation; then GitHub, cloud, Vault, Kubernetes, CI secrets, and anything that was sitting in a file, because there was a regex sweep. Revoke, do not merely rotate.
- Audit what was done in your name: repositories freshly described "Shai-Hulud: Here We Go Again," unexpected npm publishes under your accounts, and credential use in your cloud logs during the
started_atwindow.
CI runners and any host with confirmed execution should be rebuilt, not cleaned. Arbitrary code ran; the list of known artifacts is not a completeness guarantee.
A small tool to help with the triage
Enumerating this by hand across a fleet is tedious, and the moving IOC list makes a hardcoded grep obsolete within hours. I wrote a scanner to help with the triage: it checks lockfiles and node_modules for the compromised name/version set (with the transitive chain, so "we don't use keyv" gets answered on the spot), flags the host persistence and the dead-man's switch, and prints the response order above so nobody rotates before cleaning.
It is built to be easy to trust during exactly this kind of incident: one auditable file you can read in fifteen minutes, zero dependencies, zero egress (it never phones home; --update is the only network call and it is explicit), and read-only. It runs offline. It is MIT-licensed and open source, and — disclosure — it comes out of my work at Securest8; the IOC data is not mine but the public research of Socket, Wiz, and Kodem, credited in the repository.
If you only take the tool, take the response order with it. The scanner finds the problem; the order in which you touch credentials is what keeps a bad day from getting worse.
Bottom line
The novel part of this campaign is not the credential theft — it is the two design choices around it: an execution path that does not require installing anything, and a switch that turns your remediation reflex into the trigger. Scope the second vector, isolate before you revoke, and clean the host before you touch a single token.
References
- Socket, "Popular npm Packages in the keyv and Cacheable Namespaces Compromised in Active Supply Chain Attack," August 4, 2026. https://socket.dev/blog/popular-npm-packages-in-the-keyv-and-cacheable-namespaces-compromised-in-active-supply-chain
- Wiz Research, public IOC feed (keyv/cacheable). https://github.com/wiz-sec-public/wiz-research-iocs/blob/main/reports/keyv-packages.csv
- Wiz, "keyv and cacheable npm supply chain attack." https://www.wiz.io/blog/keyv-and-cacheable-npm-supply-chain-attack
- Kodem Security, keyv supply-chain attack IOCs and first-hour runbook. https://www.kodemsecurity.com/resources/keyv-supply-chain-attack-shai-hulud-npm-worm-affected-versions-iocs-and-first-hour-response-runbook
--
27 Comments
Botnet Hunting for Vulnerabilities in Diagnostic Tools
This morning, I noticed specific sources "hunting" for vulnerabilities in URLs that I haven't noticed before. All of these URLs appear to be associated with diagnostic tools:
| URL | Count | Vulnerability |
|---|---|---|
| / | 1 | (simple recon for index page) |
| /apply.cgi | 20 | CVE-2024-12856 Four-Faith router command injection |
| /cgi-bin/adv_ping.cgi | 20 | ? |
| /cgi-bin/diagnostic.cgi | 20 | CVE-2013-7179 Seowon Intech WiMAX SWU-9100 mobile route |
| /cgi-bin/DiagnosticsMsg.cgi | 20 | ? |
| /cgi-bin/ping.cgi | 20 | |
| /cgi-bin/system_mgr.cgi | 20 | |
| /cgi-bin/traceroute.cgi | 20 | |
| /diag_ping.cgi | 20 | CVE-2020-8949 (maybe.. slightly different URL) Gocloud devices |
| /goform/diagTool | 20 | CVE-2024-48419 (maybe..) Edimax Routers |
| /goform/ping | 20 | |
| /ping_test.cgi | 20 | |
| /sys_diag.html | 20 |
The naming of these URLs points to diagnostic tools. I was unable to find any specific vulnerabilities associated with many of the URLs, but the table above reflects those I found. But diagnostic tools often suffer from file inclusion and code execution vulnerabilities.
These tools will often call operating system commands directly, without properly separating user-provided arguments. Here is a sample vulnerability in a ping utility:
response = os.system("ping -c 1 -w2 " + hostname )
The above example is in Python. But most (all?) languages have something equivalent to "os.system" (often called "exec", "shell_exec", "process" ...) Often, proper input validation and output encoding are used to prevent this vulnerability, but, in my opinion, there is a better approach that should always be used in addition to input validation, and I do not see it used much.
As with many other vulnerabilities, the root cause of command injection is the concatenation of user data and commands. Mixing control plane and data plane has been an issue since blue boxing and continues today with prompt injection. The real fix is to avoid this comingling of data and commands and instead properly separate them. Prepared statements in SQL are probably the best-known approach following this principle.
For OS command execution, we do have a very similar solution. The "system" command in your language will typically call the standard C function "exec" [1]. This family of function implements some meant to pass command line arguments: execv ("exec vector"). In addition to the command, it accepts an array of command-line arguments that are then passed to the command, properly separating the command from the arguments.
Python implements execv as part of the subprocess module:
response = subprocess.run("ping", "-c", 1, "-w", 2, hostname )
Using "subprocess.run" eliminates the possibility of command injection in this example.
For example, if you are using "google.com; ls" as a hostname, you get:
ping: cannot resolve google.com; ls: Unknown host
The entire string "google.com; ls" was used as a hostname, and the ";" no longer acted as a separator. Give it a try with other command injection strings, and you will see similar results.
There are a few cases where "execv" is not sufficient. Some operating system commands may execute additional commands passed on the command line. For example, tcpdump offers the "-z" option to execute a "postrotate command". But these cases are rare, and if you are running into them, you are back to proper input validation to use these specific command line options. In most cases, users cannot specify the command-line option itself but only the parameter; using the "execv" API will help.
A while ago, I also made a brief video with more details on preventing OS command injection: https://www.youtube.com/watch?v=7QDO3pZbum8. It also covers some of the issues around Windows, which implements different APIs.
[1] https://man7.org/linux/man-pages/man3/exec.3.html
--
Johannes B. Ullrich, Ph.D. , Dean of Research, SANS.edu
Twitter|
23 Comments
Atomic MacOS (AMOS) stealer infection
Introduction
This diary provides indicators from an Atomic MacOS (AMOS) stealer infection that I generated in my lab on July 31st, 2026. This was distributed through a web page from getmacouscloud[.]com with instructions to paste text into a macOS Terminal window, supposedly for "macOS toolkit," but instead the text is a command to retrieve and install AMOS stealer malware.
Of note, I ran the text in the Terminal window twice, because I wanted to make sure I retrieved copies of files in the host's /tmp directory before entering the user account password. This is why the initial infection traffic is repeated, and also likely why there are two different directories with the AMOS stealer malware persistent on my infected lab host.
Images from the Infection

Shown above: Website with instructions to copy and paste text into a Terminal window, supposedly for a "macOS toolkit" but actually for malware.

Shown above: The malicious text pasted into a Terminal Window on a macOS host.

Shown above: Files from my infected host's /tmp directory, showing data stolen and other info for AMOS stealer.

Shown above: Examples of AMOS stealer persistent on my infected macOS host.

Shown above: Traffic from the AMOS stealer infection filtered in Wireshark.
Indicators of Compromise
Traffic leading to the getmacouscloud[.]com page on Friday 2026-07-31:
- hxxps[:]//macostruecloud[.]xyz/?h=2f9548d041648a8030c040ae0e1e530b&z=304
- macspheres[.]com - HTTPS traffic
- hxxps[:]//getmacouscloud[.]com/?FSSbmnNdviEDE5S?io=16vwsb0rgIiPNIgM
URL from the base64 text provided by getmacouscloud[.]com for the initial download:
- hxxps[:]//render65[.]com/curl/f5509695dd98a9732378e5256d6235415d64d92194459bb08525c7ce5991a0c9
URLs from extracted from the payload returned from the initial download:
- hxxps[:]//grove-89[.]com/api/metrics/run?event=pasted
- hxxps[:]//render65[.]com/2kqYRM0DCrnyJgoS4gVLl_FHJRRdTUhGCbjyuYwpZ6c/m1/update
AMOS stealer C2 traffic - HTTP POST requests over TCP port 80:
- hxxp[:]//188.166.78[.]138/api/metrics/run?event=started&stage=boot
- hxxp[:]//188.166.78[.]138/api/metrics/run?event=stage&stage=init_session
- hxxp[:]//188.166.78[.]138/api/metrics/run?event=stage&stage=messengers
- hxxp[:]//188.166.78[.]138/api/metrics/run?event=stage&stage=credentials
- hxxp[:]//188.166.78[.]138/api/metrics/run?event=stage&stage=browsers
- hxxp[:]//188.166.78[.]138/api/metrics/run?event=stage&stage=wallets
- hxxp[:]//188.166.78[.]138/contact
- hxxp[:]//188.166.78[.]138/api/metrics/run?event=stage&stage=resolve_auth
- hxxp[:]//188.166.78[.]138/api/metrics/run?event=stage&stage=local_data
- hxxp[:]//188.166.78[.]138/api/join/
- hxxp[:]//188.166.78[.]138/api/bots/device-info
- hxxp[:]//188.166.78[.]138/api/tasks/ack
- hxxp[:]//188.166.78[.]138/api/feed/register
AMOS stealer C2 traffic - examples of HTTP GET requests over TCP port 80:
- hxxp[:]//188.166.78[.]138/api/tasks/r3dqbX7fptIT-gXz--D_nw?v=2.1
- hxxp[:]//188.166.78[.]138/api/feed/items/49359f77ebb4ffd9a95568d27a8ff3e7
SHA-256 hash: b9ec3261d633c289e51c5fa8842af4350efe68446df39cb995de82e0941d0f3c
- File size: 1,973 bytes
- File type: Paul Falstad's zsh script text executable, ASCII text
- File description: Initial file retrieved by malicious text in Terminal window
SHA-256 hash: 13b868b3ea8b492e7fbab1ca04535c53d0930650185b5a082cd59c1974689cd5
- File size: 1,227 bytes
- File type: Paul Falstad's zsh script text executable, ASCII text, with very long lines (315)
- File description: Script extracted from a gzip-compressed file from base64 text in the above file
SHA-256 hash: 9f25ec533cb23d020e568fb771500d7776b1300f07119ad9d0876f4329ce22ab
- File size: 297,952 bytes
- File location: /tmp/helper
- File type: Mach-O universal binary with 2 architectures: x86_64 & arm64
SHA-256 hash: 0a03cf18de28017c0ea591dffc380a6b41fedd2acc3a39e901e58d9188c01836
- File size: 438,656 bytes
- File location: /Users/[username]/Library/Application Support/.com.apple.accountsd/AccountsHelper
- File type: Mach-O universal binary with 2 architectures: x86_64 & arm64
SHA-256 hash: 01a0d5332b09bb299f7784bf0d0c43c4199269ed6a0712377279eeb999847d20
- File size: 503,152 bytes
- File location: /Users/[username]/Library/Application Support/.com.apple.metadata.mds/mdworker_shared
- File type: Mach-O universal binary with 2 architectures: x86_64 & arm64
---
Bradley Duncan
brad [at] malware-traffic-analysis.net
20 Comments
Phishing Campaigns Targeting AI Solutions Providers
Most phishing campaigns rely on the fact that the victim is afraid to loose "something": money, access to information, ... Many brands have been impersonated by campaigns but I spotted some phishing emails that focus on AI services like ChatGPT.
Yesterday, I found this email that was properly designed but also sent with a very good timing: the end of the month when your classic billing process is restarted!

The threat actor is just trying to grab your payment details:

Seeing the importance of AI used by most companies but also residential users, this is a clever move from threat actors! Many people will be afraid to loose their access to ChatGPT.
Xavier Mertens (@xme)
Senior ISC Handler | SANS Principal Instructor | Freelance Consultant
Xameco | PGP Key
29 Comments

0 Comments