Analyst Guidance
This week saw three confirmed critical vulnerabilities with active exploitation: CVE-2023-49105 (ownCloud) was added to CISA's Known Exploited Vulnerabilities catalog after targeting a nuclear research facility; PaperCut NG/MF flaws are under active exploitation with bypass techniques discovered against initial patches; and. Organizations running ownCloud, PaperCut print management, and WordPress-dependent sites should prioritize patching immediately.
CVE Details & Remediation
🛡️CVE-2026-21962 – Oracle HTTP Server And Oracle Weblogic Server Proxy Plug-In ✓ NVD
Remediation Steps
- Apply the vendor security update for Oracle HTTP Server And Oracle Weblogic Server Proxy Plug-In as a priority.
- Restrict network exposure of the affected service to trusted sources until patched.
- Review logs and detections for indicators of exploitation.
- Confirm fixed versions against the official vendor advisory before deploying.
References:
🛡️CVE-2026-16812 – Arista VeloCloud Orchestrator ✓ NVD
Remediation Steps
- Apply the vendor security update for Arista VeloCloud Orchestrator On-Prem as a priority.
- Restrict network exposure of the affected service to trusted sources until patched.
- Review logs and detections for indicators of exploitation.
- Confirm fixed versions against the official vendor advisory before deploying.
References:
🛡️CVE-2026-72898 – Metabase ✓ NVD
Remediation Steps
- Apply the vendor security update for Metabase Metabase as a priority.
- Restrict network exposure of the affected service to trusted sources until patched.
- Review logs and detections for indicators of exploitation.
- Confirm fixed versions against the official vendor advisory before deploying.
References:
🛡️CVE-2023-49105 – Owncloud Server ✓ NVD
Remediation Steps
- Apply ownCloud security patch for CVE-2023-49105
- Review access logs for unauthorized file access or exfiltration
- Audit user accounts for unauthorized privilege escalation
- Restrict network access to ownCloud instances to trusted networks
References:
🛡️CVE-2021-23758 – Ajaxpro.2 Project Ajaxpro.2 (also: Michaelschwarz) ✓ NVD
Remediation Steps
- Apply the vendor security update for Ajaxpro.2 Project Ajaxpro.2 as a priority.
- Restrict network exposure of the affected service to trusted sources until patched.
- Review logs and detections for indicators of exploitation.
- Confirm fixed versions against the official vendor advisory before deploying.
References:
🛡️CVE-2026-72529 – TrueConf Server ✓ NVD
Remediation Steps
- Apply the vendor security patch
- Review system logs for evidence of exploitation
- Verify affected systems are fully patched
- Monitor for suspicious activity post-remediation
References:
🛡️CVE-2026-33824 – Microsoft Internet Key Exchange (IKE) Service Extensions ✓ NVD
Remediation Steps
- Consult CISA Known Exploited Vulnerabilities Catalog for affected product details
- Apply vendor patch when available
- Verify patch deployment across affected systems
References:
🛡️CVE-2026-59310 – Broadcom VMware VCenter ✓ NVD
Remediation Steps
- Apply the vendor security update for Vmware Vcenter Server as a priority.
- Restrict network exposure of the affected service to trusted sources until patched.
- Review logs and detections for indicators of exploitation.
- Confirm fixed versions against the official vendor advisory before deploying.
References:
🛡️CVE-2026-65400 – Apple MacOS ✓ NVD
Remediation Steps
- Apply the vendor security update for Apple Macos as a priority.
- Restrict network exposure of the affected service to trusted sources until patched.
- Review logs and detections for indicators of exploitation.
- Confirm fixed versions against the official vendor advisory before deploying.
References:
🛡️CVE-2026-8037 – Progress LoadMaster ✓ NVD
Remediation Steps
- Apply the vendor security update for Progress Connection Manager For Objectscale as a priority.
- Restrict network exposure of the affected service to trusted sources until patched.
- Review logs and detections for indicators of exploitation.
- Confirm fixed versions against the official vendor advisory before deploying.
References:
🛡️CVE-2026-63077 – JetBrains TeamCity ✓ NVD
Remediation Steps
- Check CISA's Known Exploited Vulnerabilities catalog for confirmation that this CVE affects your systems
- Apply the vendor patch immediately
- Monitor systems for evidence of exploitation
- Review access logs for suspicious activity on affected assets
References:
🛡️CVE-2026-9198 – IBM Langflow ✓ NVD
Remediation Steps
- Consult CISA Known Exploited Vulnerabilities catalog for affected product details
- Identify affected systems in your environment
- Apply vendor patch as soon as available
- Verify patch installation across all instances
References:
🛡️CVE-2026-60004 – Gitea ✓ NVD
Remediation Steps
- Apply the vendor security update for Gitea Gitea as a priority.
- Restrict network exposure of the affected service to trusted sources until patched.
- Review logs and detections for indicators of exploitation.
- Confirm fixed versions against the official vendor advisory before deploying.
References:
🛡️CVE-2026-8452 – Citrix NetScaler ADC And NetScaler Gateway ✓ NVD
Remediation Steps
- Apply the vendor security update for Citrix NetScaler ADC and NetScaler Gateway as a priority.
- Restrict network exposure of the affected service to trusted sources until patched.
- Review logs and detections for indicators of exploitation.
- Confirm fixed versions against the official vendor advisory before deploying.
References:
🛡️CVE-2026-64849 – Lfprojects Mlflow ✓ NVD
Remediation Steps
- Apply the vendor security patch
- Review system logs for evidence of exploitation
- Verify affected systems are fully patched
- Monitor for suspicious activity post-remediation
References:
🛡️CVE-2026-55040 – Microsoft SharePoint ✓ NVD
Remediation Steps
- Apply the vendor security update for Microsoft Sharepoint Server as a priority.
- Restrict network exposure of the affected service to trusted sources until patched.
- Review logs and detections for indicators of exploitation.
- Confirm fixed versions against the official vendor advisory before deploying.
References:
🛡️CVE-2026-72530 – TrueConf Server ✓ NVD
Remediation Steps
- Apply the vendor security update for Trueconf Server as a priority.
- Restrict network exposure of the affected service to trusted sources until patched.
- Review logs and detections for indicators of exploitation.
- Confirm fixed versions against the official vendor advisory before deploying.
References:
🛡️CVE-2026-19478 – GitLab ✓ NVD
Remediation Steps
- Apply the latest GitLab security patch addressing CVE-2026-19478 immediately
- Review audit logs for evidence of unauthorized project modifications or deletions
- Restrict public project visibility to trusted users pending patch deployment
- Monitor GitLab instances for suspicious code injection activity
References:
🛡️CVE-2026-73570 – Synacor Zimbra Collaboration Suite (ZCS) ✓ NVD
Remediation Steps
- Apply the vendor security update for Synacor Zimbra Collaboration Suite as a priority.
- Restrict network exposure of the affected service to trusted sources until patched.
- Review logs and detections for indicators of exploitation.
- Confirm fixed versions against the official vendor advisory before deploying.
References:
🛡️CVE-2025-62593 – Ray-Project Ray ✓ NVD
Remediation Steps
- Apply the vendor security update for Anyscale Ray as a priority.
- Restrict network exposure of the affected service to trusted sources until patched.
- Review logs and detections for indicators of exploitation.
- Confirm fixed versions against the official vendor advisory before deploying.
References:
🛡️CVE-2019-1068 – Microsoft SQL Server ✓ NVD
Remediation Steps
- Apply the vendor security update for Microsoft SQL Server as a priority.
- Restrict network exposure of the affected service to trusted sources until patched.
- Review logs and detections for indicators of exploitation.
- Confirm fixed versions against the official vendor advisory before deploying.
References:
🛡️CVE-2026-20349 – Cisco Secure Firewall Adaptive Security Appliance (ASA) And Secure Firewall Threat Defense (FTD) ✓ NVD
Remediation Steps
- Apply the vendor security update for Cisco Adaptive Security Appliance Software as a priority.
- Restrict network exposure of the affected service to trusted sources until patched.
- Review logs and detections for indicators of exploitation.
- Confirm fixed versions against the official vendor advisory before deploying.
References:
🛡️CVE-2026-18577 – N-Able N-Central ✓ NVD
Remediation Steps
- Apply the vendor security update for N-Able N-Central as a priority.
- Restrict network exposure of the affected service to trusted sources until patched.
- Review logs and detections for indicators of exploitation.
- Confirm fixed versions against the official vendor advisory before deploying.
References:
🛡️CVE-2026-53362 – Linux Kernel ✓ NVD
Remediation Steps
- Apply the vendor security update for Linux Kernel as a priority.
- Restrict network exposure of the affected service to trusted sources until patched.
- Review logs and detections for indicators of exploitation.
- Confirm fixed versions against the official vendor advisory before deploying.
References:
🛡️CVE-2015-5287 – Red Hat Automatic Bug Reporting Tool ✓ NVD
Remediation Steps
- Apply the vendor security update for Red Hat Automatic Bug Reporting Tool as a priority.
- Restrict network exposure of the affected service to trusted sources until patched.
- Review logs and detections for indicators of exploitation.
- Confirm fixed versions against the official vendor advisory before deploying.
References:
🛡️CVE-2022-0995 – Linux Kernel ✓ NVD
Remediation Steps
- Apply the vendor security update for Linux Kernel as a priority.
- Restrict network exposure of the affected service to trusted sources until patched.
- Review logs and detections for indicators of exploitation.
- Confirm fixed versions against the official vendor advisory before deploying.
References:
🛡️CVE-2026-34486 – Apache Tomcat ✓ NVD
Remediation Steps
- Apply the vendor security update for Apache Tomcat as a priority.
- Restrict network exposure of the affected service to trusted sources until patched.
- Review logs and detections for indicators of exploitation.
- Confirm fixed versions against the official vendor advisory before deploying.
References:
🛡️CVE-2026-18556 – N-Able N-Central ✓ NVD
Remediation Steps
- Apply the vendor security update for N-Able N-Central as a priority.
- Restrict network exposure of the affected service to trusted sources until patched.
- Review logs and detections for indicators of exploitation.
- Confirm fixed versions against the official vendor advisory before deploying.
References:
🛡️CVE-2026-68820 – Microsoft Windows Ancillary Function Driver For WinSock ✓ NVD
Remediation Steps
- Apply the vendor security update for Microsoft Windows 10 1607 as a priority.
- Restrict network exposure of the affected service to trusted sources until patched.
- Review logs and detections for indicators of exploitation.
- Confirm fixed versions against the official vendor advisory before deploying.
References:
🛡️CVE-2026-76640 – Unitree G1 EDU Humanoid Robot ✓ NVD
Remediation Steps
- Apply vendor security update for Unitree G1 EDU
- Restrict Bluetooth Low Energy (BLE) access to authorized devices only
- Audit robot system logs for unauthorized root access attempts
- Consider disabling unnecessary wireless interfaces if operationally feasible
References:
🛡️CVE-2025-68686 – Fortinet FortiOS ✓ NVD
Remediation Steps
- Apply the vendor security update for Fortinet Fortios as a priority.
- Restrict network exposure of the affected service to trusted sources until patched.
- Review logs and detections for indicators of exploitation.
- Confirm fixed versions against the official vendor advisory before deploying.
References:
🛡️CVE-2026-66384 – JFrog Artifactory ✓ NVD
Remediation Steps
- Apply the vendor security update for Jfrog Artifactory as a priority.
- Restrict network exposure of the affected service to trusted sources until patched.
- Review logs and detections for indicators of exploitation.
- Confirm fixed versions against the official vendor advisory before deploying.
References:
🛡️CVE-2026-20316 – Cisco Secure Firewall Management Center (FMC) ✓ NVD
Remediation Steps
- Apply the vendor security update for Cisco Secure Firewall Management Center as a priority.
- Restrict network exposure of the affected service to trusted sources until patched.
- Review logs and detections for indicators of exploitation.
- Confirm fixed versions against the official vendor advisory before deploying.
References:
🛡️CVE-2015-3246 – Red Hat Libuser ✓ NVD
Remediation Steps
- Apply the vendor security update for Red Hat Libuser as a priority.
- Restrict network exposure of the affected service to trusted sources until patched.
- Review logs and detections for indicators of exploitation.
- Confirm fixed versions against the official vendor advisory before deploying.
References:
🛡️CVE-2026-76581 – WordPress plugins (WPMU DEV Dashboard, Avada, TranslatePress, Pods, GiveWP) ✓ NVD
Remediation Steps
- Update all affected WordPress plugins to patched versions
- Review admin account login logs for unauthorized access
- Audit user roles and permissions for unexpected changes
- Consider temporary deactivation of vulnerable plugins if immediate patch is unavailable
References:
🛡️CVE-2026-15981 – MiniOrange SAML 2.0 SSO Plugin (WordPress) ✓ NVD
Remediation Steps
- Apply the vendor security update for MiniOrange SAML 2.0 SSO Plugin (WordPress) as a priority.
- Restrict network exposure of the affected service to trusted sources until patched.
- Review logs and detections for indicators of exploitation.
- Confirm fixed versions against the official vendor advisory before deploying.
References:
🛡️CVE-2026-18963 – Red Hat Keycloak ✓ NVD
Remediation Steps
- Apply Red Hat security patch for Keycloak immediately
- Verify that password reset flows require proper authentication
- Audit recent account activity and password reset requests
- Consider implementing additional MFA controls for sensitive accounts
References:
🛡️CVE-2026-76639 – Unitree G1 EDU Humanoid Robot ✓ NVD
Remediation Steps
- Apply vendor security update for Unitree G1 EDU
- Restrict network access to affected robots to trusted networks
- Disable Bluetooth Low Energy (BLE) if not required for operations
- Monitor robot systems for unauthorized access or anomalous behavior
References:
🛡️CVE-2026-61979 – MiniOrange SAML 2.0 SSO Plugin (WordPress) ✓ NVD
Remediation Steps
- Apply the vendor security update for MiniOrange SAML 2.0 SSO Plugin (WordPress) as a priority.
- Restrict network exposure of the affected service to trusted sources until patched.
- Review logs and detections for indicators of exploitation.
- Confirm fixed versions against the official vendor advisory before deploying.
References:
🛡️CVE-2026-19913 – Kaltura mwEmbed ✓ NVD
Remediation Steps
- Apply the vendor security update for Kaltura mwEmbed as a priority.
- Restrict network exposure of the affected service to trusted sources until patched.
- Review logs and detections for indicators of exploitation.
- Confirm fixed versions against the official vendor advisory before deploying.
References: