Graphic visualization of monthly vulnerability trends and high-impact security threats

August 2026 CVE Landscape

In August 2026, Insikt Group® identified 73 high-impact vulnerabilities that should be prioritized for remediation, 43 of which had a Very Critical Recorded Future Risk Score. This represents a 14% decrease from last month. 31 of these vulnerabilities were surfaced through the US Cybersecurity and Infrastructure Security Agency (CISA)’s Known Exploited Vulnerabilities (KEV) catalog, 32 were reported in open sources and validated by Insikt Group, seven were sourced through security vendor telemetry, and three were exclusively surfaced through honeypot data.

The 73 vulnerabilities in this blog affected products from 45 vendors, with Microsoft accounting for approximately 11% of the vulnerabilities. The remaining exposure spanned remote monitoring and management, virtualization, application delivery, collaboration, artificial intelligence, developer, analytics, identity, operational technology, content management, network edge, video surveillance, and endpoint technologies.

In August, Insikt Group created Nuclei templates to detect CVE-2025-62593 (Ray), CVE-2026-72898 (Metabase), and CVE-2026-9198 (IBM Langflow). Each of these vulnerabilities is featured in this blog. Additionally, Insikt Group had previously created templates to detect CVE-2026-3395 (MaxSite CMS) and CVE-2026-59800 (decolua 9Router), but their exploitation was reported in July, so they are not listed in the August 2026 Vulnerability Table. Additionally, Insikt Group created a Nuclei template to detect GitHub Issue #4255 affecting Apache Log4j, a deserialization allowlist bypass that Apache classified as a hardening gap rather than a Log4j vulnerability; as such, it was not assigned a CVE. These Nuclei templates are available to customers via the Recorded Future Intelligence Platform.

Quick reference: August 2026 vulnerability table

All 70 vulnerabilities below were actively exploited or operationally weaponized in August 2026. This table does not include the three CVEs that were primarily surfaced through honeypot data, which are available to Recorded Future Intelligence Platform customers via the CVE Monthly report. The table below also provides examples of public PoCs identified by Insikt Group. These PoCs were not tested for accuracy or efficacy. Vulnerability management teams should exercise caution and verify the validity of PoCs before testing.

#
Vulnerability
Risk
Score
Vendor/Product
KEV
RCE
PoC
1
CVE-2026-81578
99
PaperCut NG/MF
Link ✓
2
CVE-2026-82078
99
PaperCut NG/MF
Link ✓
3
CVE-2015-3246
99
Red Hat Libuser
Link ✓
4
CVE-2015-5287
99
Red Hat Automatic Bug Reporting Tool
Link ✓
5
CVE-2017-0199
99
Microsoft Office and WordPad
Link ✓
6
CVE-2017-5753
99
Intel
Link ✓
7
CVE-2019-1068
99
Microsoft SQL Server
Link ✓
8
CVE-2019-18935
99
Progress Telerik UI for ASP.NET AJAX
Link ✓
9
CVE-2020-0796
99
Microsoft Windows 10 and Windows Server
Link ✓
10
CVE-2020-1472
99
Microsoft Windows Server
Link ✓
11
CVE-2021-23758
99
Ajax.NET Professional
Link ✓
12
CVE-2021-3156
99
sudo
Link ✓
13
CVE-2022-0847
99
Linux kernel
Link ✓
14
CVE-2022-0995
99
Linux kernel
Link ✓
15
CVE-2023-49105
99
ownCloud
16
CVE-2025-62593
99
Ray-Project Ray
Link ✓
17
CVE-2026-18556
99
N-able N-central
18
CVE-2026-18577
99
N-able N-central
19
CVE-2026-20349
99
Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD)
20
CVE-2026-21962
99
Oracle HTTP Server and Oracle WebLogic Server Proxy Plug-in
21
CVE-2026-33824
99
Microsoft Internet Key Exchange (IKE) Service Extensions
22
CVE-2026-34486
99
Apache Tomcat
Link ✓
23
CVE-2026-39987
99
Marimo
Link ✓
24
CVE-2026-53362
99
Linux kernel
25
CVE-2026-55040
99
Microsoft SharePoint
Link ✓
26
CVE-2026-59310
99
Broadcom VMware vCenter
Link ✓
27
CVE-2026-60004
99
Gitea
Link ✓
28
CVE-2026-63030
99
WordPress
Link ✓
29
CVE-2026-63077
99
JetBrains TeamCity
30
CVE-2026-64849
99
MLflow
Link ✓
31
CVE-2026-65400
99
Apple macOS
Link ✓
32
CVE-2026-68820
99
Microsoft Windows Ancillary Function Driver for WinSock
33
CVE-2026-72529
99
TrueConf Server
34
CVE-2026-72530
99
TrueConf Server
35
CVE-2026-72898
99
Metabase
36
CVE-2026-73570
99
Synacor Zimbra Collaboration Suite (ZCS)
37
CVE-2026-8037
99
Progress LoadMaster
Link ✓
38
CVE-2026-8452
99
Citrix NetScaler ADC and NetScaler Gateway
Link ✓
39
CVE-2026-9198
99
IBM Langflow
Link ✓
40
CVE-2026-66384
92
JFrog Artifactory
41
CVE-2017-7921
89
Hikvision cameras
Link ✓
42
CVE-2021-29441
89
Alibaba Nacos
Link ✓
43
CVE-2024-4577
89
PHP
Link ✓
44
CVE-2025-24813
89
Apache Tomcat
Link ✓
45
CVE-2025-43529
89
Apple Safari, iOS, iPadOS, macOS, tvOS, visionOS, and watchOS
Link ✓
46
CVE-2025-49113
89
Roundcube Webmail
Link ✓
47
CVE-2025-68613
89
n8n
Link ✓
48
CVE-2026-0300
89
Palo Alto Networks PAN-OS
49
CVE-2026-12569
89
PTC Windchill and FlexPLM
50
CVE-2026-21858
89
n8n
Link ✓
51
CVE-2026-3055
89
Citrix NetScaler ADC and NetScaler Gateway
Link ✓
52
CVE-2026-33017
89
Langflow
Link ✓
53
CVE-2010-3904
79
Linux kernel
Link ✓
54
CVE-2020-1013
79
Microsoft Windows
Link ✓
55
CVE-2021-29442
79
Alibaba Nacos
Link ✓
56
CVE-2021-33044
79
Dahua cameras and video devices
Link ✓
57
CVE-2021-33045
79
Dahua cameras and video devices
Link ✓
58
CVE-2022-1040
79
Sophos Firewall
Link ✓
59
CVE-2022-27925
79
Synacor Zimbra Collaboration Suite
Link ✓
60
CVE-2022-47986
79
IBM Aspera Faspex
Link ✓
61
CVE-2023-22527
79
Atlassian Confluence Data Center and Server
Link ✓
62
CVE-2023-46747
79
F5 BIG-IP
Link ✓
63
CVE-2024-55591
79
Fortinet FortiOS and FortiProxy
Link ✓
64
CVE-2025-24472
79
Fortinet FortiOS and FortiProxy
Link ✓
65
CVE-2025-31324
79
SAP NetWeaver Visual Composer
Link ✓
66
CVE-2026-15981
79
miniOrange SAML SSO Login
67
CVE-2026-19478
79
GitLab CE and EE
Link ✓
68
CVE-2026-25895
79
FUXA
Link ✓
69
CVE-2026-61979
79
miniOrange SAML SP SSO
70
CVE-2022-36883
76
Jenkins Git Plugin
Link ✓

Table 1: List of vulnerabilities that were actively exploited in August, 2026 based on Recorded Future data (excluding honeypot-sourced CVEs).

Trend analysis: AI-assisted workflows scale exploitation and target selection

Insikt Group detailed how Chinese-speaking threat group, UAT-10147, combined conventional exploitation with agentic artificial intelligence (AI) during post-compromise operations against internet-facing Windows and Linux web servers. Cisco Talos observed the threat actor exploiting or weaponizing CVE-2019-18935 in Telerik UI for ASP.NET AJAX, CVE-2021-23758 in AjaxPro, CVE-2021-29441 and CVE-2021-29442 in Nacos, and CVE-2022-27925 in Zimbra for initial access. After compromise, UAT-10147 used CVE-2010-3904, CVE-2015-3246, CVE-2015-5287, CVE-2021-3156, CVE-2022-0847, and CVE-2022-0995 for local privilege escalation on Linux.

Figure 1: Risk Rules history on the Vulnerability Intelligence Card® for CVE-2021-23758 in Recorded Future (Source: Recorded Future)

UAT-10147 used DeepAudit and PentestGPT to accelerate vulnerability discovery, PoC execution, payload generation, validation, and troubleshooting, but the operation remained semi-autonomous and required human involvement. Its Windows post-compromise activity included the use of EfsPotato, QuasarRAT, BadIIS, ASHX web shells, Defender exclusions for IIS directories, a Google Chrome Start scheduled task, and rogue privileged accounts. On Linux, the threat actor deployed NoodleRAT, SPECTRE, and Meterpreter after gaining root access. When assessed against Recorded Future’s AI Malware Maturity Model (AIM3), this activity falls at Level 4 (Transforming). UAT-10147 used agentic AI systems to orchestrate multi-step exploitation, reconnaissance, payload generation, validation, troubleshooting, and persistence workflows, but the operations remained semi-autonomous and required human involvement rather than running end-to-end without human oversight.

Insikt Group described a separate Chinese-speaking threat actor that used Hermes Agent with DeepSeek to automate target enumeration, public-exploit acquisition, exploit selection, and exploitation attempts. The agent attempted to exploit CVE-2026-33017 (Langflow) against 84 enumerated instances and chained CVE-2026-21858 with CVE-2025-68613 (n8n) while scanning more than 50 additional targets. The Langflow attempt failed because the discovered target lacked the required public-flow conditions, and the n8n attempts failed because the identified forms required authentication. The threat actor also cloned a placeholder repository for CVE-2026-0300 (PAN-OS), although Unit 42 found no evidence that the threat actor modified or executed it.

Additionally, the threat actor also exploited CVE-2026-3055 (NetScaler) to exfiltrate memory from three organizations and searched the output for authentication cookies. The threat actor also exploited CVE-2026-39987 (Marimo) to achieve command execution on 11 Marimo notebook deployments, attempted Java deserialization reverse shells against nine Apache Tomcat servers by leveraging CVE-2026-34486, and attempted reverse-shell callbacks against three Windows Internet Key Exchange virtual private network endpoints with CVE-2026-33824. Across both operations, the Chinese-speaking threat actors combined AI-assisted automation with conventional exploitation techniques.

Figure 2: Vulnerability Intelligence Card® for CVE-2026-34486 in Recorded Future (Source: Recorded Future)

Additional trends and analyses from July are available to Recorded Future customers.

Take action

Timely and relevant information on vulnerabilities in your environment and that of your vendors and suppliers is critical for reducing risk. Find out how Recorded Future can support your team by increasing visibility, improving efficiency, and enabling confident decisions.

Vulnerability Prioritization – Prioritize vulnerabilities based on the likelihood of exploitation – not just the severity. Easily understand the risk of exploitation alongside severity, and real-time contextualized intelligence to help you quickly make confident decisions, patch what matters, and prevent attacks.

Attack Surface Intelligence – Identify internet-facing assets vulnerable to a specific CVE. Attack Surface Intelligence provides an outside-in view of your organization to help you actively discover, prioritize, and respond to unknown, vulnerable, or misconfigured assets.

Third-Party Risk – Gain an external view of the security posture of your vendors and partners. Eliminate time-consuming research and vendor communication cycles with the ability to promptly assess vulnerabilities in their internet-facing systems.

Insikt Group® – Receive access to exclusive reports on new vulnerabilities and trends from Recorded Future’s team of experts, the Insikt Group®. Download Nuclei templates created by Insikt Group® for select CVEs to detect actively exploited vulnerabilities.

Recorded Future Professional Services – Work with our Professional Services team on a Vulnerability Analysis Engagement. Designed to equip your team with advanced strategies for identifying, prioritizing, and mitigating threats effectively, this program delves into technologies and operations essential for a successful vulnerability management program. (Learn more about how our Professional Services team can help elevate your team by watching our recent Vulnerability Prioritization Workshop)

About Insikt Group®

Recorded Future’s Insikt Group, the company’s threat research division, comprises analysts and security researchers with deep government, law enforcement, military, and intelligence agency experience. Their mission is to produce intelligence that reduces risk for customers, enables tangible outcomes, and prevents business disruption.

Explore expert insights, reports, and tools to strengthen your cybersecurity strategy.