VYPR
AI Brief2026-08-13· generated Aug 13, 2026

What you need to know today.

Log4j2, Cisco Firepower, and Microsoft Exchange Server flaws are actively exploited, with VMware and SonicWall also seeing critical vulnerabilities added to KEV.

The Apache Log4j2 vulnerability (CVE-2021-44228), a critical remote code execution flaw, continues to be a significant concern. Exploitation of this vulnerability has been observed in various cyberattacks, including those involving the SharkLoader malware, which deploys Cobalt Strike. Threat actors are actively leveraging this flaw to gain initial access and execute malicious payloads. The vulnerability's widespread use in the wild underscores the ongoing need for patching and mitigation efforts, as highlighted by ongoing research and CISA alerts. The Hacker News reported, and Securelist detailed the use of SharkLoader in conjunction with this CVE. Contrast Security has also introduced a tool to help protect applications against such threats while patches are deployed, as Help Net Security covered.

Cisco's Firepower devices are under attack from a new backdoor dubbed FIRESTARTER, which is capable of surviving security patches. This backdoor has been observed targeting U.S. federal agencies and critical networks in Poland and Asia. The vulnerability exploited, CVE-2025-20333, is a critical remote code execution flaw in the VPN web server of Cisco Secure Firewall ASA and FTD software. While an authenticated attacker is typically required, the persistence and stealth of FIRESTARTER make it a significant threat. Cisco Talos Intelligence and CISA have released analyses of this threat, detailing its capabilities and impact. The Hacker News and BleepingComputer have reported on these attacks.

Microsoft Exchange Server is once again in the spotlight due to critical remote code execution vulnerabilities, specifically CVE-2021-26855 and CVE-2021-27065. These flaws allow unauthenticated attackers to execute arbitrary code on vulnerable servers. The widespread impact of these vulnerabilities has been noted in various threat intelligence reports, including those detailing Russian threat groups using compromised VPNs and supply chain attacks for initial access. The ongoing exploitation of these Exchange Server flaws highlights the persistent risk to organizations relying on this platform. The Hacker News and The Register Security have covered the exploitation of these vulnerabilities.

Several critical vulnerabilities affecting VMware vCenter Server and related components have been added to the KEV catalog. CVE-2021-21985 and CVE-2021-21972, both critical remote code execution flaws in the vSphere Client, allow attackers with network access to execute commands on the underlying system. Additionally, CVE-2020-3992, a use-after-free issue in OpenSLP used by VMware ESXi, presents a critical risk to management networks. These vulnerabilities underscore the importance of timely patching for VMware environments, as they provide significant opportunities for attackers to compromise critical infrastructure.

SonicWall Email Security and SSLVPN SMA100 products are facing exploitation due to critical vulnerabilities. CVE-2021-20021 allows an attacker to create an administrative account via a crafted HTTP request, while CVE-2021-20016 is a SQL-injection vulnerability that can expose sensitive user and session information. Tenable has reported on the exploitation of similar vulnerabilities in SonicWall SMA 1000 devices, indicating a continued focus on SonicWall products by threat actors. Organizations using SonicWall products should prioritize patching these vulnerabilities to prevent unauthorized access and data breaches. Tenable Blog covered the exploitation of these vulnerabilities.

Metabase, a business intelligence platform, has a critical vulnerability (CVE-2026-72898) that allows unauthenticated attackers to inject arbitrary SQL via the password reset endpoint, leading to administrator access. This flaw was recently added to the CISA Known Exploited Vulnerabilities (KEV) catalog, indicating active exploitation. The ease of exploitation and the high-impact outcome make this a priority for organizations using Metabase. CISA Alerts noted the addition of this CVE to the KEV catalog.

Synthesized by Vypr AI
Log4j2, Cisco Firepower, Exchange Server Exploited · VYPR