Skip to content
Cyber Times

Independent threat intelligence for security leaders.

Go back

CISO Intelligence Update — Wednesday, 26 August 2026

🛡️ Cyber Times — CISO Intelligence Update

Wednesday, 26 August 2026 · Coverage: 25 Aug 2026 08:00 IST → 26 Aug 2026 08:00 IST

The high-confidence sweep produced 36 publishable records. This edition presents 10 source-linked updates across 3 security domains; 9 are marked for priority review.

🔴 Critical Threats & Active Exploitation

CVE-2026-60004 added to CISA KEV — Gitea Gitea

CRITICAL — Gitea contains a code injection vulnerability that allows an attacker with repository write access to send a malicious patch to the diffpatch API endpoint to plant an executable Git hook and run shell commands as the Gitea service account. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in…

Defender action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for…

Validation: primary source · Published: 25 Aug 2026 05:30 IST Sources: CISA KEV

CVE-2026-77136 — The extension passes the raw value of a form field configured as “This field contains the name of the sender” directly into a Fluid View as template source…

CRITICAL — NVD CVSS 9.5 (critical). The extension passes the raw value of a form field configured as “This field contains the name of the sender” directly into a Fluid View as template source, without any sanitization, and renders it. An anonymous, unauthenticated user can submit Fluid template syntax in that field to execute arbitrary Fluid ViewHelpers leading to disclosure of server configuration, environment variables and…

Defender action: Confirm affected versions in the asset inventory, review the vendor advisory, and prioritize remediation by exposure.

Validation: primary source · Published: 25 Aug 2026 14:47 IST Sources: NVD

🛡️ Vulnerabilities Worth Attention

CVE-2026-76197 — Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an OS Command (‘OS Command Injection’) vulnerability that…

CRITICAL — NVD CVSS 10.0 (critical). Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an OS Command (‘OS Command Injection’) vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.

Defender action: Confirm affected versions in the asset inventory, review the vendor advisory, and prioritize remediation by exposure.

Validation: primary source · Published: 25 Aug 2026 23:48 IST Sources: NVD

CVE-2026-76195 — Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an OS Command (‘OS Command Injection’) vulnerability that…

CRITICAL — NVD CVSS 10.0 (critical). Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an OS Command (‘OS Command Injection’) vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.

Defender action: Confirm affected versions in the asset inventory, review the vendor advisory, and prioritize remediation by exposure.

Validation: primary source · Published: 25 Aug 2026 23:48 IST Sources: NVD

CVE-2026-76193 — Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in arbitrary code execution in the context of…

CRITICAL — NVD CVSS 10.0 (critical). Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.

Defender action: Confirm affected versions in the asset inventory, review the vendor advisory, and prioritize remediation by exposure.

Validation: primary source · Published: 25 Aug 2026 23:48 IST Sources: NVD

CVE-2026-65093 — NVIDIA OpenShell for Linux contains a vulnerability where an attacker could cause a sandbox escape

CRITICAL — NVD CVSS 9.9 (critical). NVIDIA OpenShell for Linux contains a vulnerability where an attacker could cause a sandbox escape. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, and information disclosure.

Defender action: Confirm affected versions in the asset inventory, review the vendor advisory, and prioritize remediation by exposure.

Validation: primary source · Published: 26 Aug 2026 02:47 IST Sources: NVD

CVE-2026-65083 — NVIDIA OpenShell for Linux contains a vulnerability in its sandbox provisioning API, where an attacker could cause an incomplete list of disallowed inputs

CRITICAL — NVD CVSS 9.9 (critical). NVIDIA OpenShell for Linux contains a vulnerability in its sandbox provisioning API, where an attacker could cause an incomplete list of disallowed inputs. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, information disclosure, data tampering, and denial of service.

Defender action: Confirm affected versions in the asset inventory, review the vendor advisory, and prioritize remediation by exposure.

Validation: primary source · Published: 26 Aug 2026 02:47 IST Sources: NVD

CVE-2026-45018 — Chainlit is a Python framework for building production-ready conversational AI applications

CRITICAL — NVD CVSS 9.8 (critical). Chainlit is a Python framework for building production-ready conversational AI applications. From 2.4.0rc0 until 2.12.0, Chainlit deployments with features.mcp.enabled set to true in .chainlit/config.toml expose the POST /mcp endpoint without requiring authentication. For stdio transport, the endpoint accepts a user-controlled fullCommand string. The validate_mcp_command() function in…

Defender action: Confirm affected versions in the asset inventory, review the vendor advisory, and prioritize remediation by exposure.

Validation: primary source · Published: 26 Aug 2026 01:46 IST Sources: NVD

CRITICAL — NVD CVSS 9.3 (critical). A security vulnerability has been detected in TOTOLINK N600R 4.3.0cu.7647_B20210106. The affected element is the function setSystemConfig of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Such manipulation of the argument Hostname leads to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used.

Defender action: Confirm affected versions in the asset inventory, review the vendor advisory, and prioritize remediation by exposure.

Validation: primary source · Published: 26 Aug 2026 04:47 IST Sources: NVD

🏗️ DevSecOps, Cloud & Supply Chain

Fast Track ISM-ready cloud environments and IRAP Assessments with Landing Zone Accelerator on AWS

INFORMATIONAL — This post announces the availability of a new independent assessment report available on AWS Artifact analyzing how Landing Zone Accelerator on AWS (LZA) can automatically deploy multi-account environments in Amazon Web Services (AWS) with Australian Government Information Security Manual (ISM) security controls coverage at scale. The report includes findings from an independent third-party analysis conducted […]

Defender action: Review the linked evidence, confirm organizational exposure, and update detections or mitigations where applicable.

Validation: direct source · Published: 26 Aug 2026 03:23 IST Sources: AWS Security

💡 Defensive Priority

Open the linked primary or corroborating evidence before changing production systems. Confirm asset exposure, use vendor guidance for remediation, and retain the source links with the operational change record.


Collection: 2,840 records inspected · 84 passed collection filters · 36 passed the high-confidence evidence gate · 23/28 source endpoints available. Automated intelligence is a triage aid; verify exposure and remediation against the linked primary advisory.


Topics in this briefing

Share this post on:

Previous Post
CISO Intelligence Update — Thursday, 27 August 2026
Next Post
CISO Intelligence Update — Tuesday, 25 August 2026