VYPR
AI Brief2026-08-14· generated Aug 14, 2026

KEV Adds Critical Drupal, QNAP, Kaseya RCEs; Microsoft Vulns Highlighted

CISA adds critical Drupal, QNAP, and Kaseya RMM RCE flaws to KEV; Microsoft Windows faces multiple high-severity vulns.

A critical remote code execution vulnerability in Drupal (CVE-2018-7602) is among the actively exploited flaws added to the CISA Known Exploited Vulnerabilities (KEV) catalog. This flaw, affecting Drupal 7.x and 8.x, allows attackers to compromise sites through multiple attack vectors. The KEV catalog also includes a critical command injection vulnerability in QNAP QTS (CVE-2018-19949), enabling remote attackers to execute arbitrary commands, and a critical vulnerability in Kaseya VSA RMM (CVE-2018-20753), which allows unprivileged remote attackers to execute PowerShell payloads on managed devices. This Kaseya RMM flaw has been actively exploited since January 2018.

Quest KACE System Management Appliance (CVE-2018-11138) faces a critical vulnerability where an unauthenticated user can execute arbitrary commands on the system via the '/common/download_agent_installer.php' script. ConnectWise ManagedITSync integration (CVE-2017-18362) is also affected by a critical unauthenticated remote command execution flaw, granting direct access to the Kaseya VSA database, and has seen active exploitation since February 2019. Additionally, a critical deserialization vulnerability in JBoss Application Server (CVE-2017-12149) within Red Hat Enterprise Application Platform 5.2 allows for potential remote code execution.

Microsoft Windows is impacted by several high-severity vulnerabilities. CVE-2018-8453 and CVE-2018-8120 are Win32k elevation of privilege vulnerabilities due to improper handling of objects in memory. CVE-2018-8174 is a remote code execution vulnerability in the VBScript engine. These vulnerabilities affect various Windows versions, including Windows 7 and Windows Server editions. Separately, a high-severity use-after-free vulnerability in Adobe Flash Player (CVE-2018-15982) could lead to arbitrary code execution.

Oracle WebLogic Server (CVE-2017-10271) has a critical vulnerability in its WLS Security component that is easily exploitable and allows for remote code execution. Attackers have been rapidly weaponizing this flaw, as noted in a recent honeypot study. In the realm of file handling, WinRAR versions prior to 5.61 are susceptible to a path traversal vulnerability (CVE-2018-20250) when handling ACE archives, which has been observed being used in attacks targeting Ukraine.

Gigabyte's system utility software, including APP Center, AORUS GRAPHICS ENGINE, XTREME GAMING ENGINE, and OC GURU II, contains multiple high-severity vulnerabilities (CVE-2018-19323, CVE-2018-19322, CVE-2018-19321, CVE-2018-19320). These flaws in low-level drivers like GDrv and GPCIDrv allow for arbitrary memory reads/writes, IO port access, and potential local privilege escalation. WordPress sites are also affected by critical vulnerabilities in the WP BASE Booking plugin (CVE-2026-61962) and QA Analytics plugin (CVE-2026-27544), both allowing unauthenticated arbitrary code execution.

Synthesized by Vypr AI