Thursday, August 27, 2026 | Jonathan Brown

CISA flags an exploited NetScaler flaw as researchers warn of possible pre-authentication code execution

CISA added CVE-2026-8452 to its Known Exploited Vulnerabilities catalog on August 26, confirming active exploitation and requiring U.S. federal civilian agencies to remediate it by August 29. The vulnerability affects customer-managed NetScaler ADC and Gateway appliances configured as a Gateway or an authentication, authorization and auditing virtual server.

NetScaler officially describes CVE-2026-8452 as a memory-overflow vulnerability that can cause unpredictable behavior or denial of service. WatchTowr researchers believe the same CVE covers a remotely reachable flaw in SAML processing for which they demonstrated pre-authentication code execution. Citrix has not publicly confirmed that CVE-to-exploit mapping, so exploitation is confirmed but the demonstrated code-execution path remains a researcher attribution.

Organizations should upgrade NetScaler ADC and Gateway 14.1 to 14.1-72.61 or later, 13.1 to 13.1-63.18 or later, 14.1-FIPS to 14.1-72.61 or later, and 13.1-FIPS or 13.1-NDcPP to 13.1-37.272 or later. Previously exposed appliances should be examined for web shells, unexpected command execution, new administrative sessions and configuration changes. Patching does not remove persistence; rotate credentials and secrets if the investigation finds evidence of compromise.

Watch for: Citrix confirmation of the code-execution mapping, exploitation procedures, affected organizations and any ransomware connection.

Sources: CISA Known Exploited Vulnerabilities Catalog update, August 26, 2026; NetScaler security bulletin CTX696604, June 30, 2026, updated July 20, 2026; WatchTowr Labs analysis, August 14, 2026.

Five legacy flaws join CISA’s exploited list as four overlap an AI-assisted server campaign

CISA added five additional vulnerabilities on August 26: Microsoft SQL Server CVE-2019-1068, Ajax.NET Professional CVE-2021-23758, Red Hat libuser CVE-2015-3246, Red Hat ABRT CVE-2015-5287 and Linux kernel CVE-2022-0995. The federal remediation deadline is August 29 for the SQL Server flaw and September 9 for the other four.

Their attack requirements differ materially. CVE-2019-1068 allows a remote attacker who already has valid SQL Server credentials to submit a malicious query that triggers memory corruption, escapes normal database permissions, and executes arbitrary native code with the privileges of the SQL Server Database Engine service account. It is authenticated remote code execution, not unauthenticated initial access. CVE-2021-23758 is an unsafe-deserialization flaw that can provide remote code execution through a vulnerable Ajax.NET application endpoint. CVE-2015-3246, CVE-2015-5287 and CVE-2022-0995 are local Linux privilege-escalation vulnerabilities, not unauthenticated remote-entry flaws.

Cisco Talos observed the Ajax.NET flaw as an initial-access technique and the three Linux flaws in the privilege-escalation arsenal of UAT-10147, a Chinese-speaking, financially motivated group using AI-assisted reconnaissance and exploit orchestration against web servers. This four-CVE overlap is notable but does not establish that UAT-10147 caused the CISA additions; Talos did not connect CVE-2019-1068 to that campaign, and CISA has not disclosed its exploitation path. Defenders should locate forgotten Ajax.NET applications, SQL Server instances and obsolete Linux builds, migrate to maintained packages, remove unsupported forks and decommission end-of-life systems rather than treating perimeter patching as sufficient.

Watch for: CISA disclosure of the SQL Server exploitation method, additional affected products and any formal connection between the KEV additions and UAT-10147.

Sources: CISA Known Exploited Vulnerabilities Catalog update, August 26, 2026; Microsoft Security Response Center, July 9, 2019; GitHub Security Advisory GHSA-6r7c-6w96-8pvw, December 5, 2021; Red Hat security advisories, July and November 2015; Ubuntu security notice, March 25, 2022; Cisco Talos Intelligence, August 20, 2026.

Attackers probe a public SharePoint chain that can reach unauthenticated code execution

Defused observed August 25 activity testing a Microsoft SharePoint JWT authentication bypass, enumerating administrators and probing the Business Data Connectivity code path used by a second vulnerability. Its honeypots had not observed successful code execution at the time of reporting. CVE-2026-55040 is independently confirmed as exploited and was added to CISA’s Known Exploited Vulnerabilities catalog on August 18; exploitation of CVE-2026-63520 or the complete two-step chain has not yet been confirmed.

CVE-2026-55040 lets a remote, unauthenticated attacker impersonate a SharePoint user or administrator when sufficient identity information is known or discovered. CVE-2026-63520 permits an authenticated attacker to instantiate unsafe .NET types through SharePoint Business Connectivity Services and execute code under the SharePoint site service account. Public research demonstrates that combining them can convert the authenticated second step into unauthenticated remote code execution against supported on-premises SharePoint editions. SharePoint Online is not affected.

Administrators should verify installation of both the July authentication-bypass update and the August code-execution fix. August fixed builds are Subscription Edition 16.0.19725.20522 through KB5002893; SharePoint 2019 16.0.10417.20198 through KB5002894 and KB5002896; and SharePoint 2016 16.0.5565.1001 through KB5002905 and KB5002906. Reduce direct internet exposure and investigate forged JWT activity, administrator enumeration, unusual Business Data Catalog requests, child processes, web shells and unauthorized account changes.

Watch for: Confirmed exploitation of CVE-2026-63520, successful use of the complete chain, a second CISA KEV entry and evidence establishing victim scale.

Sources: Microsoft Security Response Center, July 14 and August 11, 2026; CISA SharePoint advisory and KEV update, August 18, 2026; Rapid7 research, August 11 and August 24, 2026; VulnCheck research, August 24, 2026; Defused telemetry, August 25, 2026; BleepingComputer, August 26, 2026.

U.S. seizures disable China-linked exploitation and proxy platforms used against critical infrastructure

The U.S. Justice Department announced August 26 that court-authorized domain seizures had made the QScan exploitation platform and QTRouter proxy network inoperable. Both services were operated under the QTFY brand and linked to Nanjing Xinjiuwei Network Technology. The Justice Department says paying customers included organizations associated with China’s Ministry of State Security and People’s Liberation Army.

QScan combined automated scanning with a library of more than 200 Python proof-of-concept exploits, while QTRouter routed operations through compromised internet-of-things devices, commercial proxies and virtual servers to conceal their origin. A joint FBI, NSA and U.S. Cyber Command advisory says the infrastructure generated more than two million scanning or penetration-testing tasks on one day in 2024 and supported activity dating to 2018.

The documented record includes exploitation or attempted targeting involving Pulse Secure CVE-2019-11510, Check Point CVE-2024-24919, Ivanti CVE-2024-8190, CVE-2024-8963 and CVE-2024-9380, CrushFTP CVE-2025-31161 and BeyondTrust CVE-2026-1731. Not every scan resulted in compromise, and the government advisory distinguishes several unsuccessful attempts. Organizations should vet the published indicators before blocking because some are historical or shared infrastructure, conduct retrospective hunts and avoid treating apparently domestic source addresses as evidence of domestic origin.

Watch for: Replacement domains, reconstituted infrastructure, victim notifications, criminal charges and migration to other proxy or exploit services.

Sources: U.S. Department of Justice announcement, August 26, 2026; FBI, NSA and U.S. Cyber Command joint cybersecurity advisory JCSA-20260826-01, August 26, 2026; National Security Agency announcement, August 26, 2026.

CISA says July activity targeted more than 100 exposed water-sector systems

CISA reports that malicious activity during July targeted more than 100 internet-exposed water and wastewater systems, commonly programmable logic controllers connected directly through cellular modems. The number describes systems targeted, not a confirmed compromise count.

CISA says threat actors did obtain remote access in some cases, changing controller IP addresses and passwords, causing loss of monitoring or control and occasionally disrupting operations. The new guidance does not attribute the entire July activity set. A related, earlier advisory associated exploitation of exposed programmable logic controllers with Iranian-affiliated actors, but that does not by itself establish attribution for every system in the new count.

Water utilities should identify every externally reachable operational-technology device, remove direct PLC exposure and place required remote access behind a managed gateway or jump host with phishing-resistant multifactor authentication. Default credentials must be replaced, firmware kept current and operational alarms validated against physical process conditions. Sites should also test manual operation and recovery procedures in case network visibility is lost.

Watch for: A confirmed compromise total, evidence of process manipulation, victim notifications and attribution specific to the July campaign.

Sources: CISA Internet Exposure Reduction Guidance, August 21, 2026; CISA advisory AA26-097A, revised July 22, 2026; CISA water and wastewater systems alert, July 30, 2026.

Boston Scientific cyber incident disrupts global operations and customer-order shipping

Boston Scientific disclosed August 26 that a cyber incident identified on August 25 had disrupted information-technology systems and business applications worldwide. The disruption affected order processing and product shipping, and the company warned that limitations would continue while systems were restored.

The company had not established a full restoration timetable or determined the incident’s complete operational and financial effects. Neither its public statement nor its Securities and Exchange Commission filing confirmed ransomware, data theft, medical-device compromise or a patient-safety impact. Those possibilities should not be inferred from the network outage alone.

Healthcare providers and distributors should validate order status and inventory through trusted channels, review alternative sourcing for time-sensitive products and monitor partner connections for unexpected authentication or data-transfer activity. Any contingency planning should distinguish a corporate fulfillment disruption from an unconfirmed clinical-product security issue.

Watch for: Restoration milestones, supply availability, regulatory updates, confirmed data access, ransomware attribution and any change to the company’s materiality assessment.

Sources: Boston Scientific newsroom statement, August 26, 2026; Boston Scientific Form 8-K filed with the U.S. Securities and Exchange Commission, August 26, 2026.

Apache Tomcat updates fix four Important access-control and denial-of-service flaws

Apache disclosed four Important-severity Tomcat vulnerabilities on August 25. Fixed releases are Tomcat 11.0.25, 10.1.59 and 9.0.121. Tomcat 10.1.58 did not complete the project’s release process, making 10.1.59 the first downloadable fixed release in that branch.

CVE-2026-65182 can bypass a security constraint when a longer-path rule precedes a more restrictive shorter-path rule. CVE-2026-68569 can cause principal lookup to fail open in certain CLIENT-CERT or SPNEGO configurations when the authenticated identity is absent from the configured realm. CVE-2026-68763 is an HTTP/2 allocation leak triggered by reset streams that can produce denial of service. CVE-2026-65927 is an off-by-one error in the RewriteValve “next” flag that can skip the first rewrite rule and potentially bypass an access-control decision.

Organizations should upgrade all standalone, embedded and vendor-bundled Tomcat instances, then test overlapping security constraints, RewriteValve rules, certificate or SPNEGO authentication backed by database realms, and HTTP/2 resource controls. Apache had not reported active exploitation when the advisories were published.

Watch for: Public exploit code, confirmed exploitation and downstream advisories for products that embed affected Tomcat releases.

Sources: Apache Tomcat 9, 10 and 11 security pages, August 25, 2026; Apache Tomcat project security announcements, August 25, 2026.

Record denial-of-service attack strains Norway’s shared public-service gateways

A distributed denial-of-service attack that began at 3:38 a.m. local time on August 24 disrupted services operated by Norway’s Directorate of Digitalisation and its provider, Vivicta. Digdir described it as the largest attack yet against its shared solutions and the third such incident in a short period.

Affected services included ID-porten, MinID, Maskinporten, Altinn, electronic signing, digital mailboxes and several government registers and exchange services. Most remained available but experienced slow authentication, intermittent failures or brief outages during the three-day attack. Digdir reported no indication that systems were breached or personal data exposed.

The self-described pro-Russian group Server Killers claimed responsibility and framed the operation as retaliation for Norwegian support to Ukraine. Norwegian authorities had not verified that claim, and it is not proof of state sponsorship. Operators dependent on shared identity services should review denial-of-service capacity, alternate authentication paths, failure behavior and downstream continuity plans without treating availability loss alone as evidence of network compromise.

Watch for: Official attribution, renewed attacks, final service-impact measurements and changes to Norway’s shared-service resilience architecture.

Sources: Norwegian Directorate of Digitalisation incident statement, August 25, 2026; Associated Press, August 26, 2026.


Jonathan Brown is a cybersecurity researcher and investigative journalist at bordercybergroup.com.

If you would like to support our work — useful, well-researched, ad-free cybersecurity intelligence — subscribe, comment, or buy us a coffee! Thanks.

© 2026 Border Cyber Group. All rights reserved.