The StratQuad Daily Brief
A UK and NCSC-native read on the day in cyber, compiled from monitored open sources every weekday. Read the briefing free; the full operator brief lands in subscriber inboxes.
RSS feed- LOW
Four critical Apache CVEs disclosed today: CVE-2026-84939 in FreeMarker allows path traversal when an attacker can supply a malformed locale identifier, CVE-2026-56207 in Impala permits SAML bearer token forgery on the hs2-http interface, and CVE-2026-41871 and CVE-2026-41869 in Nutch Server expose the REST API to unsafe reflection and resource exhaustion attacks.
Read the briefing - CRITICAL
CISA added three vulnerabilities to the Known Exploited Vulnerabilities catalog on evidence of active exploitation: CVE-2026-42016 and CVE-2026-42018 in JFrog Artifactory, both incorrect authorisation flaws, and a third item not fully detailed in today's reporting.
Read the briefing - CRITICAL
CISA added four vulnerabilities to the Known Exploited Vulnerabilities catalog today: CVE-2026-85706, a path traversal flaw in GitLab Community and Enterprise Edition that permits unauthenticated arbitrary file reads; CVE-2026-84869 in ConnectWise ScreenConnect, allowing unauthorised file transfer and execution through active remote sessions; and CVE-2026-42016 and CVE-2026-42018 in JFrog Artifactory, both authentication and authorisation bypasses enabling privilege escalation and exposure of resources when anonymous access is disabled.
Read the briefing - CRITICAL
CISA added two MikroTik RouterOS vulnerabilities to the KEV catalogue, CVE-2026-67277 (missing authentication in the btest service allowing kernel memory disclosure and denial of service) and CVE-2026-86060 (argument delimiter neutralisation flaw enabling privilege escalation via policy mask manipulation), both under active exploitation.
Read the briefing - CRITICAL
Cisco Talos reports active exploitation of two vulnerabilities in Secure Firewall Management Center, one of which (CVE-2026-20079) CISA added to the KEV catalogue today alongside CVE-2026-19490 in Citrix NetScaler, CVE-2025-25249 in Fortinet FortiOS, and CVE-2026-87491 in Chrome V8.
Read the briefing - CRITICAL
Microsoft's September 2026 Patch Tuesday addresses 974 vulnerabilities, a record volume that includes two actively exploited Windows zero-days now on CISA's KEV: CVE-2026-85880, a heap-based buffer overflow in Windows Advanced Local Procedure Call, and CVE-2026-81963, a link following flaw in the Windows Update Stack, both allowing local privilege escalation to SYSTEM.
Read the briefing - LOW
CVE-2026-86218 in N-central is under active exploitation, allowing unauthenticated remote code execution; NHS Digital issued a medium severity alert yesterday.
Read the briefing - LOW
N-able has shipped an emergency hotfix for a maximum-severity remote code execution flaw in its N-central RMM platform, with the vendor confirming active exploitation.
Read the briefing - MEDIUM
Attackers are exploiting CVE-2026-81578 and CVE-2026-82078 in PaperCut to steal credentials and gain privileged access in education-sector attacks across the United States and Europe, according to Arctic Wolf researchers.
Read the briefing - MEDIUM
CVE-2026-85046, a type confusion vulnerability in Google Chromium V8, is under active exploitation and has been added to CISA's Known Exploited Vulnerabilities catalogue.
Read the briefing - CRITICAL
CISA added CVE-2026-59822 and CVE-2026-48710 to the Known Exploited Vulnerabilities catalogue, the former an authentication bypass in BerriAI LiteLLM's MCP Streamable HTTP endpoint allowing unauthenticated session establishment with an arbitrary bearer token, the latter a request smuggling flaw in Kludex Starlette enabling path injection into the host component that can bypass authentication mechanisms reliant on reconstructed URL paths.
Read the briefing - CRITICAL
SonicWall disclosed CVE-2026-83548 and CVE-2026-83549 in SMA1000 series appliances, both zero-days under active exploitation that can be chained for unauthenticated remote code execution.
Read the briefing - LOW
Six critical-severity vulnerabilities published today across VMware Spring Framework, Spring Security, and Apache Tomcat, all affecting widely deployed enterprise components.
Read the briefing - LOW
CISA added CVE-2026-81578 and CVE-2026-82078 to the Known Exploited Vulnerabilities catalogue today, both affecting PaperCut NG/MF.
Read the briefing - LOW
Extortion group FulcrumSec claims it stole 86GB from Manchester Airports Group after finding API credentials exposed in client-side JavaScript, affecting customers of Manchester, London Stansted, and East Midlands airports.
Read the briefing - LOW
PaperCut Software disclosed active exploitation of an unnamed zero-day affecting its NG and MF print management products, with emergency patches released but no CVE assigned or technical detail published yet.
Read the briefing - CRITICAL
Love Electric, a UK electric vehicle salary sacrifice broker, has had 877,000 driver records offered for sale on an English-language breach forum for $600, exposing sensitive identity data held by third-party fleet providers.
Read the briefing - CRITICAL
Australian Federal Police arrested two alleged TeamPCP operators behind the Shai-Hulud worm and related supply chain attacks, working with the FBI.
Read the briefing - CRITICAL
CISA added five vulnerabilities to the Known Exploited Vulnerabilities Catalog, including CVE-2026-8452 in Citrix NetScaler ADC and NetScaler Gateway, which is under active exploitation.
Read the briefing - HIGH
CVE-2026-68820, an actively exploited Windows vulnerability, entered CISA's KEV catalog yesterday with remediation timelines under BOD 26-04 now running from three to fourteen days depending on risk classification.
Read the briefing - LOW
ToxicPanda Android malware has expanded to target 349 applications with support for 167 remote commands, building on the supply chain compromise of Android car head unit update infrastructure reported earlier this week.
Read the briefing - HIGH
CVE-2026-19478 in GitLab is under active exploitation, allowing unauthenticated attackers to remotely modify or delete public projects via a GraphQL flaw rated 9.4 CVSS; GitLab issued an emergency patch this week and WatchTowr confirmed live abuse.
Read the briefing - CRITICAL
CISA added CVE-2026-73570, an unauthenticated OS command injection in Zimbra Collaboration Suite, to the KEV catalogue based on evidence of active exploitation.
Read the briefing - CRITICAL
CVE-2026-69414 in the Microsoft Malware Protection Engine allows a low-privilege local attacker to escalate to SYSTEM, public PoC released 12 August, Microsoft assigned the CVE two days later, no patch available.
Read the briefing - CRITICAL
CISA added CVE-2026-64849, a server-side request forgery in MLflow, to the Known Exploited Vulnerabilities catalog on evidence of active exploitation.
Read the briefing - CRITICAL
CISA added four vulnerabilities to the Known Exploited Vulnerabilities Catalog today: CVE-2026-33824 in Microsoft Internet Key Exchange Service Extensions, CVE-2026-59310 in Broadcom VMware vCenter, CVE-2026-55040 in Microsoft SharePoint, and CVE-2026-65400 in Apple macOS Screen Sharing.
Read the briefing - HIGH
CISA added CVE-2025-62593 in Ray-Project Ray to the Known Exploited Vulnerabilities catalogue today, a code injection flaw allowing remote code execution against developers using Ray as a development tool through Firefox and Safari.
Read the briefing - MEDIUM
Researchers at Birmingham and Durham universities have published a technique named Download More RAM that defeats Windows 11 memory integrity protections by writing to the Serial Presence Detect chip on standard DIMM modules, requiring prior privileged access but no physical tampering with the machine.
Read the briefing - MEDIUM
CVE-2026-58231 in SAP Commerce Cloud is under active exploitation days after SAP released a patch for the maximum severity authorisation and input validation flaw.
Read the briefing - MEDIUM
CVE-2026-8452 in Citrix NetScaler ADC and NetScaler Gateway now has a public proof-of-concept demonstrating remote code execution, according to NHS Digital reporting.
Read the briefing