1. Top Action Item
Patch self-managed GitLab immediately. CVE-2026-19478 (CVSS 9.4) is a code-injection flaw that came under active exploitation within days of public disclosure; per watchTowr, an unauthenticated attacker can modify or delete publicly accessible GitLab projects and rewrite their data under certain conditions. Any organization running self-hosted GitLab with public projects is exposed. Update to the patched GitLab release now and audit project integrity.
2. Exploited This Week
GitLab — CVE-2026-19478
- Source: The Hacker News
- Link: The Hacker News
- Severity: Critical (CVSS 9.4)
- What's happening: The flaw has come under active exploitation within days of public disclosure; unauthenticated attackers can inject code to modify or delete publicly accessible GitLab projects and rewrite their data.
- Fix: Upgrade to the patched GitLab release — see source.
3. Critical Patch Roundup
Microsoft Entra ID — CVE-2026-69836
- Source: The Hacker News
- Link: The Hacker News
- Severity: Critical (CVSS 10.0)
- What's happening: Remote code execution in Microsoft Entra ID. Microsoft initially flagged the "Exploited" field as "Yes" but corrected it to "No" on August 21 and confirmed the vulnerability was not exploited in the wild.
- Fix: Apply Microsoft's patch for Entra ID — see source.
Cisco Crosswork platforms & Secure Workload — nine flaws, five at CVSS 10.0
- Source: The Hacker News
- Link: The Hacker News
- Severity: Critical (five of nine flaws scored CVSS 10.0)
- What's happening: Cisco released updates for nine vulnerabilities affecting Crosswork Data Gateway, Crosswork Network Controller, Crosswork Planning, and Secure Workload; four affect the Crosswork products regardless of device configuration.
- Fix: Apply the new Cisco security updates — see source.
4. Home / SOHO Impact
- Small businesses and solo developers running self-hosted GitLab: install the patched release immediately — CVE-2026-19478 is being actively exploited.
- Windows and Microsoft Office users: make sure the latest updates are installed; MSRC advisories updated this week cover Excel, Word, and Office remote code execution (e.g., CVE-2026-68801) — see source.
- MSPs and SMBs using the N-able Passportal password manager: apply the vendor patch addressing exposure of password-vault master keys; Dark Reading notes the product remains risky even after patching due to its cloud-based design — see source.
- If you have an aftermarket Android car head unit made by DoFun: Kaspersky found a malware family spreading through its built-in updaters for ad fraud and proxy-botnet purposes; only install firmware from trusted sources — see source.
5. Enterprise Impact
- Patch self-managed GitLab now — CVE-2026-19478 is under active exploitation (CVSS 9.4); audit public projects for tampering.
- Apply Microsoft's fix for Entra ID CVE-2026-69836 (CVSS 10.0 RCE). Microsoft confirmed it was not exploited in the wild, but it is a critical identity-system flaw.
- Update Cisco Crosswork Data Gateway, Crosswork Network Controller, Crosswork Planning, and Secure Workload — five flaws rated CVSS 10.0.
- Review Check Point's BTR.sys disclosure: Microsoft Defender's own signed boot-time removal driver can be abused for arbitrary kernel-level file/registry operations on Windows 7 through 11 25H2. There is no CVE or patch — no software flaw is exploited and no external driver is imported — so focus on endpoint hardening and monitoring while reviewing the research.
- Supply-chain audit: malicious versions of Rust crates arrayref 0.3.10, internment 0.8.7, and append-only-vec 0.1.9 (245M+ combined downloads) were pulled from crates.io after a maintainer compromise; rebuild with fixed versions and check builds for the typosquatted dependency. Separately, audit npm for 14 trojanized packages that deliver the RedC2 4.0 Linux backdoor with AI-assisted C2.
- OT/ICS teams: the U.S. government warned of an "active threat" using AI-generated exploit scripts to conduct reconnaissance against Siemens S7 Series PLCs in critical infrastructure; inventory and segment exposed PLCs.
- Review new MSRC advisories for Exchange Online (CVE-2026-65801, SSRF-based elevation of privilege) and Azure Data Factory (CVE-2026-62834, improper cryptographic-signature verification) — severity details see source.
- After the "TheHatman" credential-theft claims, follow Unit 42's guidance for mitigating large-scale credential attacks against Microsoft Entra tenants (enforce MFA and conditional access) — see source.
6. What To Patch First
- GitLab self-managed — patched release — CVE-2026-19478 (exploited in the wild; CVSS 9.4)
- Microsoft Entra ID — CVE-2026-69836 (critical; CVSS 10.0 RCE)
- Cisco Crosswork / Secure Workload — see source (five CVEs at CVSS 10.0)
- Rust crates arrayref / internment / append-only-vec — fixed versions (supply chain; 245M+ downloads)
- N-able Passportal — vendor patch (password-vault master key exposure)
- Microsoft Office / Windows — current updates — CVE-2026-68801 / CVE-2026-55134 (Excel/Word RCE advisories; see source)
Sources
- GitLab CVE-2026-19478 Comes Under Active Exploitation Within Days of Disclosure
- Microsoft Patches Severe Entra ID Flaw (CVSS 10.0) Allowing Remote Code Execution
- Cisco Patches Nine Crosswork and Secure Workload Flaws, Five Scoring CVSS 10.0
- Microsoft Defender's Own Driver Can Be Weaponized to Delete Security Software at Boot
- Rust Supply Chain Attack Puts Build-Time Malware in Crates with 245 Million Downloads
- 14 Trojanized npm Packages Drop RedC2 4.0 Linux Backdoor With AI-Assisted C2
- AI-Generated Exploit Scripts Target Siemens S7 PLCs in U.S. Critical Infrastructure
- Android Car Malware Spreads Through Built-In Updaters for Ad Fraud, Proxy Botnet
- N-able Bug Exposes Password Vault Master Keys
- Threat Brief: Mitigating Large-Scale Credential Attacks (Updated August 18)
- CVE-2026-62834 Azure Data Factory Elevation of Privilege Vulnerability
- CVE-2026-65801 Microsoft Exchange Online Elevation of Privilege Vulnerability
- CVE-2026-68801 Microsoft Excel Remote Code Execution Vulnerability