
CVE-2026-18577: N-able RMM — Rapid Ransomware Deployment Risk (August 2026)
CVE-2026-18577 (high severity) in N-able RMM is being actively exploited by Storm-1175 for rapid ransomware deployment. Patch all affected systems by August 10, 2026.
Security vulnerabilities remain the most common entry point for cyber attacks. This section tracks newly discovered CVEs, zero-day vulnerabilities, and actively exploited flaws affecting enterprise infrastructure, cloud environments, and software supply chains.
228 articles

CVE-2026-18577 (high severity) in N-able RMM is being actively exploited by Storm-1175 for rapid ransomware deployment. Patch all affected systems by August 10, 2026.

CVE-2007-3010, CVE-2016-6277, and eight additional CVEs (critical) are being exploited by Evooo1Bot to seize control of Linux edge devices. Immediate patching is required to prevent DDoS, proxy abuse, and credential theft.

CVE-2026-XXXX is a high-severity Metabase SQL injection zero-day exploited to breach ShipMonk and expose 14,000 Trezor customer records. Immediate patching is critical.

CVE-2026-58231 is a critical, CVSS 10.0 vulnerability in SAP Commerce Cloud under active exploitation attempts. Immediate patching is mandatory to prevent code execution.

CVE-2020-9771 is a high-severity macOS vulnerability exploited by AmnesiaStealer malware to exfiltrate sensitive data and control browser sessions. Immediate mitigation is required.

CVE-2026-65400 (high severity) enables remote root compromise of macOS via screen sharing; active exploitation confirmed. Patch immediately—deadline not yet announced.

CVE-2026-55040 is a critical authentication bypass in Microsoft SharePoint now under active exploitation. Immediate patching is required to prevent unauthorized data access.

CVE-2026-59310 is a critical directory traversal flaw (CVSS 9.8) in VMware vCenter, actively exploited since July 29, 2026. Patch immediately to prevent remote code execution.

CVE-2026-72898 is a critical SQL injection flaw in Metabase, exploited in the wild for full database takeover. Patch to the latest version immediately.

CVE-2026-71362 is a critical authorization flaw in Adobe Commerce and Magento enabling unauthenticated account hijack. Patch immediately to prevent compromise.

CVE-2026-64561 is a high-severity Linux KVM vulnerability enabling privileged L1 guest code to escape to the host. Patch all affected kernels immediately.

CVE-2026-12537 and CVE-2026-54316 are critical vulnerabilities (CVSS up to 10.0) enabling code execution and secret exfiltration on Anthropic, Google, and OpenAI CI runners. Immediate patching is required.