top of page

Weekly Cybersecurity Update: 17–24 August 2026

  • Writer: SOC Team
    SOC Team
  • 11 minutes ago
  • 3 min read

1. Critical VMware vCenter Vulnerability Exploited in the Wild


Attackers are actively exploiting a critical vulnerability in VMware vCenter Server that can allow remote attackers with network access to execute arbitrary code. The vulnerability affects the vCenter Syslog service and is caused by improper restriction of file paths, allowing attackers to perform directory traversal.

Security researchers have reported exploitation targeting exposed vCenter infrastructure, with CISA adding the vulnerability to its Known Exploited Vulnerabilities catalogue.


CVE ID: CVE-2026-59310 (CVSS Score: 9.8)

Why It Matters: VMware vCenter is a highly privileged management platform used to administer virtual infrastructure. Successful exploitation could allow attackers to gain control of virtual environments, access virtual machines and potentially deploy ransomware or move further into an organisation's network.

Actions: Verify that affected vCenter systems have been updated to a fixed version. Restrict access to vCenter management interfaces and investigate for unexpected processes, accounts, network connections or other signs of compromise.

Source: The Hacker News – Suspected China-Nexus Actor Exploits VMware vCenter Flaw, Deploys Babuk-Derived Ransomwarehttps://thehackernews.com/2026/08/suspected-china-nexus-actor-exploits.html


2. Microsoft Windows IKE Vulnerability Added to CISA's Exploited Vulnerabilities List


A critical vulnerability affecting the Windows Internet Key Exchange (IKE) Extension is being actively exploited. The flaw is caused by a double-free condition and can allow an unauthorised attacker to execute arbitrary code remotely over a network without requiring authentication.


CVE ID: CVE-2026-33824 (CVSS Score: 9.8)

Why It Matters: IKE is used as part of IPsec-based secure communications and VPN infrastructure. Exploitation of a remote, unauthenticated vulnerability in this component could provide attackers with a path into systems supporting remote connectivity and network security.

Actions: Apply Microsoft's security updates immediately and prioritise internet-facing Windows systems and systems providing VPN or IPsec functionality. Monitor for unusual network connections, unexpected process execution and suspicious activity around remote-access infrastructure.

Source: BleepingComputer – CISA: Critical Windows IKE Extension flaw now actively exploited in attackshttps://www.bleepingcomputer.com/news/security/cisa-critical-windows-ike-extension-flaw-now-exploited-in-attacks/


3. Zimbra Collaboration Suite Vulnerability Under Active Exploitation


A critical vulnerability in Zimbra Collaboration Suite (ZCS) is being actively exploited. The vulnerability affects installations where the optional zimbra-snmp package is installed and SNMP notifications are enabled. An unauthenticated attacker can send specially crafted requests that may result in operating-system command execution.


CVE ID: CVE-2026-73570 (CVSS Score: 8.9)

Why It Matters: Zimbra servers provide email and collaboration services and may contain large volumes of sensitive corporate communications. Successful exploitation could give attackers access to the mail environment and provide a foothold for further compromise.

Actions: Organisations using Zimbra should upgrade to Zimbra Collaboration 10.1.20 or later and verify whether the affected SNMP functionality is enabled. Review server logs for suspicious requests, unexpected processes and signs of unauthorised access.

Source: Security Affairs – Poland's CERT Warns of Active Exploitation of Critical Zimbra Collaboration Suite Flawhttps://securityaffairs.com/197610/security/polands-cert-warns-of-active-exploitation-of-critical-zimbra-collaboration-suite-flaw.html


4. MLflow Vulnerability Exploited to Target Cloud Credentials


Attackers have begun exploiting a critical vulnerability in MLflow, an open-source platform used to manage machine-learning and AI workloads. The vulnerability is an unauthenticated Server-Side Request Forgery (SSRF) flaw that can allow attackers to access internal services and cloud metadata endpoints.

Researchers observed scanning and exploitation attempts shortly after the vulnerability was disclosed.


CVE ID: CVE-2026-64849 (CVSS Score: 9.3)

Why It Matters: Cloud metadata services can contain temporary credentials and other sensitive information. An exposed MLflow server could therefore become a pathway to cloud credential theft, internal network access and compromise of associated cloud resources.

Actions: Upgrade MLflow to version 3.15.0 or later. Identify internet-facing MLflow deployments and review application and cloud audit logs for suspicious requests. Rotate potentially exposed cloud credentials and ensure MLflow services are not unnecessarily accessible from the public internet.

Source: The Hacker News – Attackers Exploit MLflow SSRF Flaw to Steal Cloud Credentials and Secretshttps://thehackernews.com/2026/08/attackers-exploit-mlflow-ssrf-flaw-to.html


Key Recommendations


  • Prioritise actively exploited vulnerabilities: Review exposure to CVE-2026-59310, CVE-2026-33824, CVE-2026-73570 and CVE-2026-64849 and apply available security updates as a priority.

  • Secure internet-facing infrastructure: Restrict external access to VMware vCenter, Zimbra, MLflow, VPN and other management services wherever possible.

  • Protect privileged and cloud credentials: Enforce MFA, minimise administrative privileges and rotate credentials if there is any possibility they have been exposed.

  • Strengthen monitoring: Monitor for suspicious processes, privilege escalation, unexpected network connections, unusual authentication activity and access to sensitive infrastructure.

  • Review critical infrastructure: Financial services, healthcare, defence and education organisations should prioritise these vulnerabilities due to the potential operational and data-security impact.

  • Maintain incident-response readiness: Ensure logging, endpoint monitoring, network visibility and tested recovery procedures are in place in case exploitation has already occurred.

 
 
bottom of page