1. Top Action Item

Patch SAP Commerce Cloud now — CVE-2026-58231 (CVSS 10.0) is being actively exploited days after SAP shipped the fix. The flaw lets an unauthenticated attacker abuse a default authentication client and submit requests due to insufficient authorization checks and input validation, giving a maximum-severity foothold in the platform. If you cannot patch within 48 hours, isolate externally reachable Commerce Cloud instances and audit for unauthorized access using that default client.


2. Exploited This Week

SAP Commerce Cloud — CVE-2026-58231

Apple macOS Screen Sharing — CVE-2026-65400

VMware vCenter Server — CVE-2026-59310

GeoServer — zero-day (no CVE assigned yet)


3. Critical Patch Roundup

Microsoft August 2026 Patch Tuesday — 421 CVEs, 62 critical

Microsoft Edge (Chromium-based) — CVE-2026-72970

Chromium (Chrome / Edge) — CVE-2026-19556 through CVE-2026-19560

Fortinet — FortiWeb Remote Radius Type Admin Authentication (FG-IR-26-158)

Fortinet — FortiManager FGFM Authentication Weakening (FG-IR-26-160)

Fortinet — FortiClient Windows kernel driver heap overflow (FG-IR-26-156)


4. Home / SOHO Impact


5. Enterprise Impact


6. What To Patch First

  1. SAP Commerce Cloud — CVE-2026-58231 (exploited, CVSS 10.0)
  2. VMware vCenter Server — CVE-2026-59310 (exploited, critical)
  3. Apple macOS — CVE-2026-65400 (exploited, CVSS 9.8)
  4. GeoServer — unpatched zero-day (exploited; mitigation: restrict/isolate)
  5. Microsoft August 2026 Patch Tuesday — 421 CVEs, 62 critical (widely deployed)
  6. Microsoft Edge — CVE-2026-72970 (remote code execution)
  7. Google Chrome / Microsoft Edge Chromium — CVE-2026-19556 through CVE-2026-19560 (use-after-free, widely deployed)
  8. FortiWeb — FG-IR-26-158 (CVSS 8.8, authentication bypass)
  9. FortiManager / FortiManager Cloud — FG-IR-26-160 (CVSS 7.3, authentication bypass)
  10. FortiClient Windows — FG-IR-26-156 (CVSS 7.3, kernel driver RCE)

Sources