VYPR
AI Brief2026-08-15· generated Aug 14, 2026

What you need to know today.

Microsoft and Adobe release critical patches, while older vulnerabilities in Java and ColdFusion are added to the KEV catalog.

A critical use-after-free vulnerability in Windows Deployment Services (CVE-2026-62893) has been patched by Microsoft. This flaw allows unauthenticated attackers to execute arbitrary code over a network. The vulnerability was disclosed as part of Microsoft's August 2026 Patch Tuesday, which addressed a total of 421 CVEs, including one zero-day actively exploited in the wild. Several security vendors, including The Hacker News and Cisco Talos Intelligence, have highlighted this vulnerability and the broader Patch Tuesday release. The vulnerability is detailed by the Zero Day Initiative.

Adobe has released critical patches for multiple vulnerabilities in ColdFusion and Campaign Classic. Notably, CVE-2026-48362, a critical OS command injection flaw in ColdFusion, allows for arbitrary code execution. This vulnerability, along with others in ColdFusion and Campaign Classic, carries a CVSS score of 10.0. Adobe is urging immediate patching, as highlighted by SecurityWeek and Cyber Security News. The Vypr Intelligence blog also notes that 16 vulnerabilities in ColdFusion have been addressed, including RCE and authentication bypass flaws.

Several older, but still critical, vulnerabilities have been added to the Known Exploited Vulnerabilities (KEV) catalog. These include a Java Runtime Environment flaw (CVE-2012-0507) and multiple directory traversal vulnerabilities in Adobe ColdFusion (CVE-2010-2861). Additionally, a Progress Telerik UI for ASP.NET AJAX vulnerability (CVE-2017-11357) that allowed arbitrary file uploads or code execution is now listed. These additions underscore the ongoing risk posed by unpatched legacy systems.

Microsoft's August Patch Tuesday also addressed significant vulnerabilities in its Windows operating systems, including two high-severity flaws in the SMBv1 server (CVE-2017-0144 and CVE-2017-0145). These vulnerabilities could allow remote attackers to execute code. While these are older vulnerabilities, their inclusion in the KEV catalog signifies active exploitation or high confidence in exploitation. Tenable has provided analysis on the broader context of such vulnerabilities.

Kaseya VSA has seen two critical vulnerabilities patched, both present in versions prior to 9.5.7. CVE-2021-30116 involves credential disclosure, which was exploited in the wild in July 2021. CVE-2021-30120 allows for a bypass of the two-factor authentication (2FA) requirement by exploiting client-side enforcement. These vulnerabilities highlight the risks associated with remote management software and the importance of timely patching.

Synthesized by Vypr AI
Microsoft, Adobe Patch Critical Flaws; KEV Adds Old Vulns · VYPR