VYPR
AI Brief2026-08-12· generated Aug 12, 2026

What you need to know today.

CISA adds Progress LoadMaster and Check Point SmartConsole flaws to KEV, while critical SAP and Microsoft vulnerabilities are disclosed.

The CISA has added a critical command injection vulnerability in Progress LoadMaster appliances to its Known Exploited Vulnerabilities catalog, citing hundreds of exploit attempts. Tracked as CVE-2026-8037, the flaw allows unauthenticated attackers to execute arbitrary commands on the affected LoadMaster appliance by exploiting unsanitized input in multiple command endpoints. This vulnerability carries a CVSS score of 9.6 and has been observed in the wild, prompting an urgent call for patching from CISA. Progress has released updates to address this critical security risk.

A critical authentication bypass vulnerability in Check Point's SmartConsole, CVE-2026-16232, has been exploited in the wild, leading to its addition to the CISA KEV catalog. This flaw allows unauthenticated remote attackers to obtain an application login token, granting them full administrative privileges. A public proof-of-concept is available, increasing the risk of further exploitation. Check Point has released a patch to mitigate this vulnerability, and users are strongly advised to update immediately.

Critical vulnerabilities affecting SAP Commerce Cloud and SAP NetWeaver Visual Composer have been disclosed, with CVE-2026-58231 and CVE-2025-42999 respectively. CVE-2026-58231 allows unauthenticated attackers to abuse a default authentication client to achieve arbitrary code execution. CVE-2025-42999 involves a deserialization vulnerability where a privileged user can upload malicious content, potentially leading to confidentiality, integrity, and availability compromises. Both vulnerabilities have high CVSS scores and are considered critical.

A critical template injection vulnerability in Rejetto HTTP File Server (HFS) version 2.3m, CVE-2024-23692, has been added to the CISA KEV catalog. This flaw enables remote, unauthenticated attackers to execute arbitrary commands on the affected system by sending specially crafted requests. The vulnerability has a CVSS score of 9.8, highlighting its severity. Users are urged to update to a patched version or implement mitigations to protect against potential exploitation.

Microsoft Exchange Server remains a target with multiple critical vulnerabilities, including CVE-2021-34473 (Remote Code Execution) and CVE-2021-34523 (Elevation of Privilege), both with high CVSS scores and actively exploited. Additionally, CVE-2021-38647, a critical RCE in Microsoft OMI, and CVE-2021-34527, a high-severity RCE in the Windows Print Spooler service, have been added to the CISA KEV. These vulnerabilities, some dating back to 2021, underscore the persistent threats against Microsoft products and the importance of timely patching.

Synthesized by Vypr AI
KEV Updates: Progress, Check Point, SAP, and Microsoft Flaws Highlighted · VYPR