Threat and Vulnerabilities Report - August 2026

September 1, 2026

Executive Summary

August 2026 proved arelentless month for defenders, as CISA added 32 vulnerabilities to its KnownExploited Vulnerabilities catalog, confirming that attackers were activelybreaking into real systems across a wide sweep of enterprise technology.Microsoft led the additions with five flaws, followed by two apiece fromPaperCut NG/MF, N-able N-central, TrueConf, and Red Hat, with single entriesspanning IBM, Apache, N-able, JetBrains, Progress, Metabase, Cisco, RayProject, Apple, Broadcom, MLflow, Synacor, Oracle, Gitea, Citrix, Ajax.NETProfessional, ownCloud, and JFrog. The catalog additions reached from operatingsystems and virtualization platforms to print management, artifactrepositories, AI tooling, and decade-old open-source components, underscoringhow attackers weaponized both freshly disclosed flaws and long-forgotten oneswith equal ease.

Beyond the catalog, activeexploitation struck platforms including Palo Alto Networks, BeyondTrust, andCitrix, several within days of disclosure. The month also spotlighteddetermined state-aligned and financially motivated actors: the China-linkedQTFY group breached US critical infrastructure using its custom scanning andbotnet platforms, the Chinese-speaking UAT-10147 group deployed thecross-platform SPECTRE backdoor while folding AI into its operations, and theMirai-derived Evooo1Bot botnet turned internet-facing edge devices intostealthy proxy relays and attack nodes.

Ransomware pressureintensified in parallel, with Qilin topping the month at 162 affectedorganizations, followed by TheGentlemen with 111 and Cl0p with 85.

Download Report

Subscribe to our Newsletter