Critical
2026-09-01
CVE-2026-82329
A 9.8 in JFrog Artifactory Went From Patch to Real Attacks in Four Days
JFrog Artifactory is the shelf that software teams keep their finished software on — build a package, store it there, and every server downstream pulls from that shelf. CVE-2026-82329 (CVSS 9.8) is an authentication bypass in JFrog Access, the component that issues and validates credentials. Under a default configuration, an unauthenticated attacker with network access may obtain administrative privileges: watchTowr reports that instances never given an additional join key receive a "phantom" join key an attacker can abuse to forge access and mint administrator credentials. JFrog fixed it in Artifactory 7.161.20, released August 28, 2026. Threat actors began weaponizing the flaw on September 1 to generate admin tokens and enumerate users, groups, credential sets, and federated access topologies.
Recommended action: If you run self-managed Artifactory, patch to 7.161.20 today, starting with anything reachable from the internet. Then treat the patch as step one: pull the audit logs and look for token creation and user enumeration you cannot account for, rotate any credential the platform held or issued, and review connected build pipelines, deployment targets, and cloud accounts for changes nobody on your team made. Most healthcare providers and municipalities in Puerto Rico do not run Artifactory themselves — but their EHR vendor, billing clearinghouse, and managed service provider very likely run something like it, and an attacker with administrator access to a build repository can tamper with software that later gets installed in your environment. Send your critical vendors three questions this week: do you use Artifactory or a comparable artifact repository, was it patched for CVE-2026-82329, and did you find evidence of unauthorized access. Keep the answers in writing with your vendor file.
Sources: CVE record for CVE-2026-82329 on CVE.org, JFrog self-managed release notes and security advisories, watchTowr statements attributed to Yordan Ganchev, The Hacker News (September 1, 2026).
Critical
2026-09-01
CVE-2026-0768 / CVE-2026-66066
The AI Tool Someone Installed Is Holding Your Cloud Keys — and It Is Under Attack
VulnCheck reports active exploitation of CVE-2026-0768 (CVSS 9.8), an unauthenticated remote code execution flaw in Langflow, an open-source framework used to build AI applications and agent workflows. The flaw sits in the code validator of Langflow's custom component editor, which fails to properly validate a user-supplied string before using it to execute Python code — and the code runs as root. VulnCheck recorded more than 50 detections within hours on August 30, 2026, reaching 360 by September 1, with traffic originating primarily from Russia. What the attackers are doing matters as much as the flaw: requests are querying environment variables including LANGFLOW_SUPERUSER, OPENAI_API, AWS_ACCESS and AWS_SECRET values, reading /root/.cache/langflow/secret_key, and checking .ssh access and .bash_history. This is credential harvesting. Public vulnerability databases list Langflow releases up to 1.4.2 as affected, and JFrog has previously shown a Langflow release described as fixed remained exploitable for a separate flaw — so upgrade to the latest available release rather than the first one labeled patched. VulnCheck separately reports active exploitation of Ruby on Rails CVE-2026-66066 (CVSS 9.5), which leaks secret_key_base, the Rails master key, database passwords, and cloud credentials, ultimately enabling code execution.
Recommended action: The first task is discovery, and it is a Shadow AI problem. Ask whether Langflow — or any AI application builder, agent framework, or workflow orchestrator — is running anywhere in your environment. These platforms rarely arrive through procurement; they arrive as a pilot on a spare server or a cloud instance charged to a departmental card. Ask your IT provider and your developers separately, because the answers often differ. If you find one, get it off the public internet today, regardless of patch level. Then assume the credentials are already gone: rotate AI provider API keys, AWS access and secret keys, the Langflow superuser password, database credentials, and SSH keys, and review cloud provider logs for use of those keys from unfamiliar addresses. Upgrade to the latest available release, not the first one described as fixed. The governance lesson underneath: AI platforms are attractive targets because they concentrate credentials for everything else. Your AI usage policy should require inventory and approval before any AI platform is connected to production data or issued a credential, with a named owner and rotation schedule for every key it holds. If such a platform handled ePHI, a suspected compromise starts your incident procedures under 45 CFR §164.308(a)(6).
Sources: VulnCheck research and statements from Caitlin Condon and Patrick Garrity, Zero Day Initiative advisory ZDI-26-034, JFrog Security Research on Langflow patch completeness, The Hacker News (September 1, 2026), BleepingComputer (September 1, 2026).
High
2026-09-01
CVE-2026-62911
Nearly 22,000 Exchange Servers Are Still Open to a Flaw That Hands Over Every Mailbox
CVE-2026-62911 is an authentication bypass by capture-replay in Microsoft Exchange Server, patched in the August 2026 Patch Tuesday release. Microsoft's description of the impact is unusually direct: an attacker "would be able to take over the mailboxes of all Exchange users, attackers can send emails, read emails, download attachments." It affects Exchange Server 2016, 2019, and Subscription Edition. Exploitation requires basic privileges on the server and user interaction, which is why it is rated high rather than critical — but the Netherlands National Cyber Security Centre reports exploit code is already circulating publicly. On September 1, 2026 Shadowserver counted 21,899 unpatched Exchange servers exposed online, most in the United States (about 6,200) and Germany (about 5,100), and Germany's BSI warned roughly 85 percent of on-premises Exchange servers there remain vulnerable.
Recommended action: Confirm this week whether you still have an Exchange server on premises. Many clinics and municipalities in Puerto Rico moved mail to Microsoft 365 years ago but left one Exchange server running for hybrid identity, and that server is frequently forgotten, rarely patched, and still reachable. Apply the August 2026 Exchange security update, and verify that Exchange 2016 and 2019 systems are actually enrolled in the Extended Security Update program — unenrolled servers received nothing. Take Outlook Web Access and the Exchange Control Panel off the public internet, enforce MFA on every mailbox and administrator account, and disable legacy authentication protocols that bypass MFA. Because the flaw hands over mailbox contents, review forwarding rules, inbox rules, delegate permissions, and mailbox audit logs for changes nobody requested. Mailboxes in healthcare are usually full of protected health information, so unauthorized access is a security incident under 45 CFR §164.308(a)(6) and requires a documented risk assessment under 45 CFR §164.402. Finally, put October 2026 on the leadership calendar: Extended Security Updates for Exchange 2016 and 2019 end then.
Sources: Microsoft Security Response Center advisory for CVE-2026-62911, NIST National Vulnerability Database, NCSC-NL alert, Shadowserver Foundation scan data, Germany's BSI, BleepingComputer (September 1, 2026).
High
2026-09-01
A Vendor You May Never Have Heard Of Just Reported 9.5 Million Patients Breached
Aesto LLC, operating as Aesto Health, has reported to HHS that a data breach affects 9,540,683 individuals. The company is not a hospital or a health plan — it sells software-as-a-service used to migrate, archive, and access patient data when an organization replaces an electronic health record system or acquires a practice, which means it holds records that other organizations moved off their own systems. The timeline is worth reading twice: the unauthorized access occurred between about December 2 and December 18, 2025; Aesto confirmed it internally on May 26, 2026 after an outside forensic investigation; it posted a public notice on June 24 describing a compromise of a limited portion of its AWS infrastructure; and it began notifying individuals on August 21. The data involved includes names, dates of birth, medical information, driver's license numbers, financial account numbers, health insurance information, taxpayer and other government identification numbers, and Social Security numbers. The HIPAA Journal reports the incident indirectly affects 29 healthcare providers, including VillageMD, Everside Health (Marathon Health), Marana Health, and Together Women's Health.
Recommended action: Start with a question most organizations cannot answer quickly: who is holding our old patient records right now? When a practice replaces an EHR or a group acquires a clinic, the legacy data rarely disappears — it moves to an archive platform and sits there for years under a contract signed during a system conversion. Those vendors are business associates, they hold complete historical records, and they are almost never in the annual vendor review because no one uses them day to day. Build the list this month: every archive, migration, and legacy read-only platform your organization or any practice you acquired has used, who holds it now, what is in it, and whether a current business associate agreement is on file. The notification timeline is the second lesson — access in December 2025, internal confirmation in May 2026, notices in August 2026. Under 45 CFR §164.410 a business associate must notify you without unreasonable delay and no later than 60 days from discovery, and your own clock under §164.404 runs from your discovery. Check whether your agreements state a specific number of days, cover suspected as well as confirmed incidents, and require cooperation with your investigation. Finally, consider retention: the strongest control over a legacy archive is not having one.
Sources: Aesto Health notice of data security incident, U.S. Department of Health and Human Services breach report, The HIPAA Journal, BleepingComputer (September 1, 2026).
Critical
2026-08-31
CVE-2026-82078 / CVE-2026-81578
PaperCut Is Now on CISA's Known Exploited List — the Federal Deadline Is September 14
On August 31, 2026, CISA added both PaperCut print management flaws to its Known Exploited Vulnerabilities catalog and set a remediation deadline of September 14, 2026 for federal civilian agencies. CVE-2026-81578 (CVSS 8.8), catalogued as missing authentication for a critical function, lets an unauthenticated remote attacker modify certain system configuration settings in PaperCut NG and MF. CVE-2026-82078 (CVSS 9.4), catalogued as unsafe reflection, lets an attacker manipulate configuration parameters and execute arbitrary Java bytecode already on the application classpath, under the security context of the PaperCut server process. Chained, the first bypasses authentication and the second delivers code execution; all versions of PaperCut NG and MF are affected. PaperCut published a second emergency update after researchers demonstrated multiple ways to bypass the initial fixes — Huntress reported a bypass of the first patch set, and watchTowr said it found further bypasses affecting the latest fully patched version. A KEV listing means CISA has evidence the flaws are being used against real targets.
Recommended action: Remove public internet exposure first and treat that as the control you are actually relying on, because researchers have reported bypasses affecting even the fully patched version. Put the Application Server behind a VPN or restrict its web interface to trusted internal addresses, then apply the second emergency patch — if you applied the first one last week, you are not finished, since that one has a published bypass. Municipal, government, and healthcare organizations should adopt the September 14 federal deadline as their own internal target; it is a defensible date to put in front of leadership and the one an auditor or cyber insurer will likely reference later. Then hunt, assuming the logs may not be trustworthy: the attacker tooling deletes server.log and derby.log, so an unexplained gap is itself evidence. Look for "Database error looking up cardID: VALUES CAST", unusual pc-app.exe activity, and any Udydn.out or stray .class files under the installation directory, and preserve log copies off the server. PaperCut runs with elevated privileges, authenticates against Active Directory, and often shares a domain with clinical or financial systems, and print queues routinely carry ePHI — so a confirmed compromise is a security incident under 45 CFR §164.308(a)(6). Rotate the service account and any AD credentials it holds.
Sources: CISA alert — two vulnerabilities added to the Known Exploited Vulnerabilities Catalog (August 31, 2026), CISA KEV entries for CVE-2026-81578 and CVE-2026-82078, PaperCut urgent security advisory and second emergency patch, Canadian Centre for Cyber Security advisory AV26-858 Update 2, Huntress research, watchTowr Labs research, Rapid7, BleepingComputer.
Bulletins summarize publicly reported information for awareness and are not a substitute for vendor advisories or a tailored assessment.