Contacts
Book a Meet
Close

Contacts

Bulgaria, Kavarna
Saudi Arabia, Riyadh

+359 875 328030

sales@diamatix.com

Contacts

Bulgaria, Kavarna
Saudi Arabia, Riyadh

+359 875 328030

sales@diamatix.com

DIAMATIX_Post_18.08.2026_new template

ThreatScope by DIAMATIX

Metabase, Cisco VPN, Windows and AI/ML Infrastructure Risks (August 12–18, 2026)

Reporting period: August 12–18, 2026
Threat level: Critical

🎧 Listen to this week’s ThreatScope (audio brief)

Executive Snapshot

Executive Snapshot 
Highest RiskMetabase
Internet-facing PriorityMetabase, Cisco ASA/FTD Remote Access SSL VPN, Adobe ColdFusion
Windows Infrastructure RiskWindows AFD, DNS Server, Deployment Services, QUIC
Development & AI RiskRay, GitLab, Adobe Commerce, SAP Commerce Cloud
Additional ExposureWordPress Forminator, macOS Screen Sharing, OT/ICS systems

This week’s ThreatScope covers four actively exploited vulnerabilities affecting analytics platforms, network-security infrastructure, Windows endpoints and AI/ML development environments, together with a significant Microsoft security release and several critical enterprise application vulnerabilities.

The highest operational priority is CVE-2026-72898 in Metabase. Successful exploitation may provide unauthenticated access to the Metabase application database and subsequently expose administrator accounts, connected-database credentials, API keys and business data. Metabase has confirmed active exploitation.

Cisco also confirmed active exploitation of CVE-2026-20349, which can remotely crash ASA and FTD devices providing Remote Access SSL VPN services. Although the immediate technical impact is denial of service, loss of VPN connectivity can directly affect business continuity and emergency administrative access.

The reporting period also includes an actively exploited Windows privilege-escalation vulnerability, active exploitation of Ray through DNS rebinding, multiple critical Microsoft remote-code-execution paths and high-severity vulnerabilities affecting Adobe Commerce, ColdFusion, SAP Commerce Cloud, GitLab and the Forminator WordPress plugin.

Patching remains necessary, but organisations should also establish whether exposed systems were compromised before remediation, revoke sessions and credentials where appropriate, and validate downstream services and data access.

Is This Report Relevant to Your Organization?

This report is particularly relevant if your organization operates any of the following technologies or environments.

Technology or EnvironmentCommonly Found InWhy It Matters
MetabaseEnterprise analytics, finance, SaaS, data teamsMay contain administrator access, connected-database credentials and sensitive business information
Cisco ASA / FTD Remote Access SSL VPNEnterprise, government, healthcare, finance, critical infrastructureProvides remote access and may support business continuity and incident-response connectivity
Microsoft Windows infrastructureAll enterprise environmentsIncludes endpoints, domain services, DNS, DHCP, WDS, QUIC and other core services
RayAI/ML development, data science, cloud environmentsProvides execution capabilities and may expose cloud, repository and AI-provider credentials
Adobe Commerce / MagentoE-commerce, retail, online servicesHandles customer sessions, administrator access, transactions and payment integrations
Adobe ColdFusionEnterprise applications, legacy web platformsCritical server-side code execution may affect application infrastructure
SAP Commerce CloudRetail, manufacturing, enterprise commerceCritical business application with potential unauthenticated remote-code execution
GitLab CE/EESoftware development, DevOps, enterprise ITStores source code, projects and development workflows
WordPress ForminatorPublic websites, marketing sites, SMB and enterprise web estatesUnauthenticated file upload may lead to full website compromise
macOS Screen SharingEnterprise Apple environments, remote supportExposed remote-screen access may provide direct system access
OT/ICS systemsManufacturing, energy, utilities, transportation, critical infrastructureOperational constraints may delay patching and require compensating controls

If these technologies are not present in your environment, immediate remediation may not be required. However, the wider trends remain relevant to organisations operating internet-facing analytics platforms, remote-access infrastructure, Windows core services, AI development environments or public-facing business applications.

Executive Summary

The reporting period was dominated by four actively exploited vulnerabilities:

  • CVE-2026-72898 affecting Metabase;

  • CVE-2026-20349 affecting Cisco ASA/FTD Remote Access SSL VPN;

  • CVE-2026-68820 affecting the Windows Ancillary Function Driver for WinSock;

  • CVE-2025-62593 affecting Ray.

Metabase represents the most severe compromise scenario this week. An unauthenticated attacker can inject SQL through the password-reset functionality and potentially gain administrator access, steal connected-database credentials, generate API keys and persistent sessions, and access or export business information. Internet-facing vulnerable Metabase instances should therefore be treated as potentially compromised.

Cisco ASA and FTD environments are also under active exploitation. Crafted HTTP requests can cause affected devices to reload without authentication or user interaction. Organisations relying on affected VPN services should patch immediately and verify high-availability behaviour, configuration synchronisation and emergency administrative access.

CVE-2026-68820 in Windows is a post-compromise privilege-escalation vulnerability. A locally authenticated low-privilege attacker can elevate to SYSTEM, making the issue particularly useful to ransomware operators and advanced attackers after initial access has already been obtained.

Ray introduces a different risk to AI and machine-learning environments. DNS rebinding may allow a malicious website to reach a locally running Ray dashboard and submit jobs for execution. Development systems should therefore be reviewed not only for internet exposure, but also for locally exposed services accessible through the user’s browser.

Microsoft’s August security release addressed approximately 415 vulnerabilities, including one actively exploited zero-day and 62 Critical vulnerabilities. Several critical paths allow unauthenticated remote code execution through Windows DNS Server, Deployment Services, QUIC and other core network services.

Key Vulnerabilities

CVEProduct and ScopeCVSS / StatusMost Relevant ForBusiness ImpactRequired Response
CVE-2026-72898Metabase10.0 / Confirmed / KEVEnterprise analytics, finance, SaaSSQL injection, administrator takeover, connected-database credential theft and data exposureUpgrade immediately, revoke sessions, review administrators and rotate database credentials
CVE-2026-20349Cisco ASA / FTD8.6 / Confirmed / KEVEnterprise, government, finance, healthcareUnauthenticated SSL VPN denial of service and loss of remote connectivityApply hotfixes, verify VPN resilience and review device crashes
CVE-2026-68820Microsoft Windows AFD7.0 / Confirmed / KEVAll Windows enterprise environmentsPrivilege escalation from low privilege to SYSTEMDeploy August updates and hunt for suspicious elevation activity
CVE-2025-62593RayCritical / Confirmed / KEVAI/ML, cloud, data scienceCode execution through DNS rebinding and access to development credentialsUpgrade to 2.52.0+, restrict dashboards and review job history
CVE-2026-71362Adobe Commerce / Magento9.1 / Exploitation attempts reportedE-commerce, retailAccount takeover and elevated accessApply isolated patch, revoke sessions and review account changes
CVE-2026-48362Adobe ColdFusion10.0Enterprise application serversUnauthenticated arbitrary code executionPatch internet-facing deployments immediately
CVE-2026-58231SAP Commerce Cloud10.0Retail, manufacturing, enterprise commerceUnauthenticated RCE and internal compromiseUpgrade and restrict affected import paths
CVE-2026-19478GitLab CE/EE9.4Software development, DevOpsUnauthenticated modification or deletion of public projects and user dataUpgrade self-managed GitLab
CVE-2026-15748WordPress Forminator9.8 / Public technical disclosurePublic websites, marketing and web estatesUnauthenticated PHP upload and possible RCEUpdate immediately and inspect recent uploads
CVE-2026-62815Microsoft QUIC9.8Windows network infrastructureUnauthenticated network RCEApply August Microsoft updates
CVE-2026-62878Windows DNS Server9.8Domain and network infrastructureUnauthenticated remote code executionPrioritise exposed and highly trusted DNS servers
CVE-2026-62893Windows Deployment Services9.8Enterprise deployment infrastructureUnauthenticated RCE through TFTPPatch or disable WDS/TFTP where unused
CVE-2026-65400macOS Screen SharingCritical / Exploitation publicly reportedEnterprise Apple environmentsAuthentication bypass and remote system accessPatch macOS, disable unnecessary Screen Sharing and block TCP 5900

Vulnerability Analysis

Metabase. CVE-2026-72898

CVE-2026-72898 affects Metabase and represents the highest operational risk during this reporting period.

An unauthenticated attacker can inject SQL into the Metabase application database through the password-reset functionality. Successful exploitation may allow the attacker to change platform configuration, create or modify administrator accounts, steal connected-database credentials, access business data and generate API keys or persistent sessions.

Metabase has confirmed active exploitation, and the vulnerability is included in the CISA Known Exploited Vulnerabilities Catalog.

Most Relevant For

  • organizations using Metabase for business intelligence and analytics;

  • financial services;

  • SaaS providers;

  • data and analytics teams;

  • enterprises with internet-facing Metabase instances.

How to Verify Exposure

Confirm the following:

  • Is Metabase deployed?

  • Is the instance accessible from the internet?

  • Is the deployed version one of the affected releases from branches 58 through 63?

  • Has /api/session/reset_password received unexpected requests?

  • Have administrator accounts or API keys changed unexpectedly?

  • Are there unusual queries, exports or data-warehouse access events?

Required Response

Upgrade immediately to the applicable corrected version.

If patching cannot be completed immediately, temporarily block /api/session/reset_password. Revoke all active Metabase sessions, review administrator accounts and API keys, rotate credentials for every connected database and investigate query history, exports and data-warehouse logs.

An internet-facing vulnerable Metabase instance should be treated as potentially compromised.

Cisco ASA / FTD Remote Access SSL VPN. CVE-2026-20349

CVE-2026-20349 affects Cisco ASA and FTD systems providing Remote Access SSL VPN services.

A crafted HTTP request can cause an affected device to reload unexpectedly without credentials or user interaction. The exposure may also apply to IKEv2 Remote Access VPN deployments with client services and Zero Trust Network Access configurations.

Although the immediate impact is denial of service, loss of VPN connectivity can directly affect remote operations, business continuity and incident-response access.

Most Relevant For

  • large enterprises;

  • government;

  • healthcare;

  • financial services;

  • critical infrastructure;

  • organizations relying on Cisco remote-access VPN.

How to Verify Exposure

Confirm the following:

  • Are Cisco ASA or FTD devices deployed?

  • Is Remote Access SSL VPN enabled?

  • Are VPN listeners accessible from the internet?

  • Has the applicable Cisco hotfix been installed?

  • Have unexplained device reloads, crash information or lina process failures occurred?

  • Has high-availability failover been tested?

Required Response

Install the applicable Cisco hotfix immediately.

Identify all internet-facing VPN listeners, monitor malformed or abnormal HTTP requests, verify high-availability failover and configuration synchronisation, and confirm that emergency administrative access does not depend solely on the affected VPN service.

Windows AFD. CVE-2026-68820

CVE-2026-68820 is a use-after-free vulnerability in the Windows Ancillary Function Driver for WinSock, afd.sys.

A locally authenticated low-privilege attacker can exploit the flaw to elevate privileges to SYSTEM.

This is primarily a post-compromise vulnerability rather than an initial-access vector. It is therefore particularly valuable to ransomware operators and advanced attackers because restricted access can be converted into full endpoint control.

Most Relevant For

  • enterprise Windows environments;

  • domain controllers;

  • administrative workstations;

  • jump servers;

  • internet-facing Windows systems.

How to Verify Exposure

Confirm the following:

  • Have the August Windows security updates been deployed?

  • Were privileged systems prioritised?

  • Have unexpected transitions from standard-user sessions to SYSTEM been observed?

  • Are there unusual new services or scheduled tasks?

  • Has suspicious LSASS access been detected?

  • Are EDR agents and Microsoft Defender signatures current?

Required Response

Deploy the August Windows security updates immediately.

Prioritise domain controllers, administrative workstations, jump servers and internet-facing systems. Investigate suspicious privilege escalation before rebuilding systems or closing related security alerts.

Ray. CVE-2025-62593

CVE-2025-62593 affects Ray versions before 2.52.0 and is actively exploited.

Insufficient protection of sensitive dashboard and job-submission endpoints allows exploitation through DNS rebinding. A developer using Firefox or Safari may be compromised after visiting a malicious website or advertisement. The attacker can then reach the locally running Ray dashboard, commonly available on TCP port 8265, and submit a malicious job for execution.

Most Relevant For

  • AI and machine-learning development teams;

  • data science environments;

  • cloud development environments;

  • organizations operating Ray locally or in shared development infrastructure.

How to Verify Exposure

Confirm the following:

  • Is Ray deployed?

  • Is the version earlier than 2.52.0?

  • Is the dashboard or job API exposed beyond approved interfaces?

  • Is TCP port 8265 reachable from untrusted networks?

  • Have unexpected jobs or processes appeared?

  • Could cloud, repository or AI-provider credentials have been exposed?

Required Response

Upgrade Ray to version 2.52.0 or later.

Ensure that dashboard and job APIs are not internet-accessible, restrict port 8265 through host and network firewalls, implement DNS-rebinding protection on corporate resolvers and review Ray job history for suspicious activity.

Rotate cloud, repository and AI-provider credentials accessible to potentially affected development environments.

Microsoft Critical RCE Cluster

Microsoft’s August security release addressed approximately 415 vulnerabilities, including one actively exploited zero-day and 62 Critical vulnerabilities.

Several of the most important issues affect core network services and permit unauthenticated remote code execution:

  • CVE-2026-62815. Microsoft QUIC;

  • CVE-2026-62878. Windows DNS Server;

  • CVE-2026-62893. Windows Deployment Services;

  • CVE-2026-65791. Windows iSCSI Target Service;

  • CVE-2026-62823. Windows DHCP Server;

  • CVE-2026-59124. Microsoft HPC Pack.

Most Relevant For

  • enterprise Windows environments;

  • domain and network infrastructure;

  • data centres;

  • organizations using Windows deployment and infrastructure services.

How to Verify Exposure

Identify where the following services are enabled:

  • DNS;

  • DHCP;

  • Windows Deployment Services;

  • iSCSI Target;

  • HPC Pack;

  • HTTP/3 and QUIC.

Required Response

Patch externally reachable and highly trusted servers first.

Disable WDS/TFTP and iSCSI Target where unused and restrict infrastructure services through network segmentation. Test the August updates against domain services and critical applications, but do not delay remediation of highly exposed systems.

Adobe Critical Security Updates

Adobe Commerce / Magento. CVE-2026-71362

CVE-2026-71362 can allow an unauthenticated attacker to interfere with customer sessions and gain elevated access to sensitive resources. Exploitation attempts were reported shortly after disclosure.

Required Response

  • Install the corresponding isolated Adobe patch.

  • Invalidate active customer and administrator sessions.

  • Review newly created administrator accounts.

  • Inspect customer-account and order changes.

  • Rotate integration and payment-related API credentials where compromise is suspected.

Adobe ColdFusion. CVE-2026-48362

CVE-2026-48362 is an unauthenticated operating-system command-injection vulnerability with a CVSS score of 10.0. Successful exploitation may result in arbitrary code execution.

The same ColdFusion security release also addresses additional Critical vulnerabilities involving evaluation injection, authorisation, memory corruption and security-control bypass.

Internet-facing ColdFusion deployments should therefore be patched as a priority.

Enterprise and Application Security Watch

SAP Commerce Cloud. CVE-2026-58231

A maximum-severity authorisation vulnerability affects the SAP Commerce Cloud Data Hub Adapter. An unauthenticated attacker may submit malicious input and potentially achieve remote code execution.

Upgrade to SAP Commerce Cloud 2211.55, 2211-jdk21.17 or later. Until the update is applied, restrict /datahubadapter/import/** to trusted Data Hub addresses.

GitLab. CVE-2026-19478

Self-managed GitLab CE/EE installations are vulnerable to unauthenticated modification or deletion of public projects and user data through a GraphQL directive.

Corrected versions are 18.11.11, 19.0.8, 19.1.6 and 19.2.4. GitLab.com and GitLab Dedicated were already patched.

No active exploitation was reported at the assessment cut-off, but self-managed environments should be upgraded promptly.

WordPress Forminator. CVE-2026-15748

Forminator Forms versions through 1.56.1 allow an unauthenticated attacker to upload potentially executable PHP files. Successful exploitation may result in complete WordPress-site compromise.

Update to version 1.56.2 or later, review recent uploads and search web directories for unexpected PHP files.

macOS Screen Sharing Exposure

CVE-2026-65400 allows a network attacker to authenticate to macOS Screen Sharing without valid credentials. The highest risk applies to systems with Screen Sharing enabled and TCP port 5900 exposed.

Required Response

  • Deploy the applicable macOS update.

  • Disable Screen Sharing where not required.

  • Block TCP 5900 at internet and untrusted-network boundaries.

  • Review remote-screen-sharing events and newly created accounts.

  • Investigate unexpected cryptocurrency-mining or persistence activity.

OT/ICS Security Watch

CISA published a substantial group of industrial control system advisories on 13 August. Priority systems include:

  • AVEVA Enterprise SCADA, with unsafe deserialisation that may result in code execution;

  • Siemens Siveillance Video, with remote-code-execution exposure affecting video-management servers;

  • Johnson Controls Airwall, with authentication bypass, arbitrary file access and exposure of protected resources;

  • Siemens Desigo controllers, with denial of service through malformed BACnet traffic;

  • ANDRITZ HIPASE, with potential device-data access and workstation compromise;

  • Hitachi Energy APM Edge, affected by Dirty Frag vulnerabilities impacting confidentiality, integrity and availability.

OT and ICS environments should follow approved change procedures. Where immediate patching is not operationally feasible, organizations should restrict remote access, isolate affected systems and increase monitoring.

What Deserves Attention This Week?

Analytics and Business Data

Priority systems:

  • Metabase.

Primary actions:

  • upgrade immediately;

  • revoke active sessions;

  • review administrator accounts and API keys;

  • rotate connected-database credentials;

  • review queries, exports and data-warehouse logs.

Remote Access and Network Security

Priority systems:

  • Cisco ASA / FTD;

  • internet-facing VPN infrastructure.

Primary actions:

  • apply Cisco hotfixes;

  • identify exposed VPN listeners;

  • review crashes and reloads;

  • test high-availability failover;

  • maintain independent emergency administrative access.

Windows Infrastructure

Priority systems:

  • Windows endpoints;

  • DNS Server;

  • WDS;

  • DHCP;

  • QUIC;

  • iSCSI;

  • HPC Pack.

Primary actions:

  • deploy August security updates;

  • prioritise highly trusted and exposed systems;

  • disable unused services;

  • hunt for suspicious privilege escalation.

AI and Development Infrastructure

Priority systems:

  • Ray;

  • GitLab;

  • AI development workstations.

Primary actions:

  • upgrade Ray;

  • restrict local development services;

  • review exposed ports and job history;

  • rotate potentially exposed cloud and AI-provider credentials;

  • upgrade self-managed GitLab.

Public-facing Applications

Priority systems:

  • Adobe Commerce;

  • Adobe ColdFusion;

  • SAP Commerce Cloud;

  • WordPress Forminator.

Primary actions:

  • apply vendor updates;

  • review sessions and administrator accounts;

  • inspect unexpected file uploads;

  • rotate integration credentials where exposure cannot be excluded.

Recommended Management Actions

Immediate Actions (0–7 Days)

  • Identify whether Metabase, Cisco ASA/FTD Remote Access SSL VPN, vulnerable Windows systems, Ray, Adobe Commerce, ColdFusion, SAP Commerce Cloud, GitLab or Forminator are present in the environment.

  • Patch and investigate internet-accessible Metabase instances immediately.

  • Apply Cisco ASA/FTD hotfixes and verify VPN resilience and emergency administrative access.

  • Deploy Microsoft August security updates to critical Windows endpoints and infrastructure servers.

  • Upgrade Ray to version 2.52.0 or later and remove unnecessary exposure of development interfaces.

  • Patch Adobe Commerce and internet-facing ColdFusion deployments.

  • Remove public access to unnecessary administrative, analytics and AI-development interfaces.

Actions Within 30 Days

  • Review administrative accounts, sessions and credentials associated with Metabase, Adobe, Ray and GitLab environments.

  • Validate network segmentation around analytics, VPN, development and infrastructure services.

  • Review Windows DNS, WDS, DHCP, iSCSI and QUIC exposure across the estate.

  • Upgrade self-managed GitLab, Forminator and affected SAP Commerce Cloud components.

  • Validate external attack-surface inventory for exposed ports 443, 5900 and 8265.

  • Close or formally document unresolved remediation exceptions.

Strategic Actions (Within 90 Days)

  • Reduce unnecessary public exposure of administrative, analytics and development interfaces.

  • Integrate AI/ML development platforms into vulnerability management and continuous monitoring.

  • Improve visibility of externally reachable Windows infrastructure services.

  • Review business-continuity dependencies on VPN and remote-access infrastructure.

  • Strengthen session, credential and API-key lifecycle management for analytics and commerce platforms.

  • Review OT/ICS remediation procedures and compensating controls for systems that cannot be patched immediately.

Enterprise Exposure Assessment

Security teams should prioritise systems based on four factors.

1. Active Exploitation

Metabase, Cisco ASA/FTD, Windows AFD and Ray have confirmed active exploitation and are included in the CISA Known Exploited Vulnerabilities Catalog.

Confirmed exploitation should immediately increase remediation priority.

2. External Accessibility

Internet-facing analytics platforms, VPN services, development interfaces, remote-screen-sharing services and application servers require the highest attention.

A vulnerable internal system and an externally accessible administrative or data platform do not represent the same operational risk.

3. Business Role

The operational role of the affected technology should influence response priority.

Compromise of Metabase may expose business data and connected databases.

Disruption of Cisco ASA/FTD may affect remote work and emergency access.

Windows privilege escalation can convert limited access into full endpoint control.

Compromise of Ray may expose development infrastructure, cloud credentials and AI services.

4. Recovery Readiness

Organizations should confirm that critical platforms can be restored safely.

Recovery planning should include tested backups, high-availability and failover for VPN services, validated database backups and review of exposed sessions, credentials and API keys.

Ongoing Security Controls

Beyond the immediate remediation cycle, security teams should:

  • maintain an accurate inventory of internet-facing applications, VPN services and development interfaces;

  • map business-critical platforms to their owners and dependent services;

  • validate remediation through authenticated scanning and configuration review;

  • monitor privileged access, session creation and administrative changes;

  • conduct threat hunting when confirmed exploitation overlaps with external exposure;

  • monitor analytics and commerce platforms for abnormal data access and export activity;

  • include AI/ML development environments in vulnerability and credential-management programmes;

  • test backup restoration, high availability and failover for critical infrastructure;

  • report unresolved remediation exceptions and accepted risks to management.

Questions for Leadership

Boards and executive teams should ask:

  • Do we operate any of the technologies covered in this report?

  • Which affected systems were accessible from the internet while vulnerable?

  • Have all actively exploited vulnerabilities been patched or isolated?

  • Have internet-facing Metabase instances been investigated for compromise?

  • Can remote operations continue if primary VPN infrastructure becomes unavailable?

  • Have critical Windows infrastructure services received the August security updates?

  • Are AI and development environments exposing services or credentials unnecessarily?

  • Have potentially exposed sessions, API keys and database credentials been revoked or rotated?

  • Can critical services be restored from validated backups or fail over to alternative infrastructure?

  • Which remediation exceptions remain open, and who has accepted the associated risk?

ISO 27001 Alignment

The actions described in this report support several areas of an Information Security Management System (ISMS) aligned with ISO/IEC 27001, including:

  • asset inventory and ownership;

  • vulnerability management;

  • secure configuration;

  • identity and access management;

  • logging and monitoring;

  • incident response;

  • network security;

  • application and development security;

  • backup and recovery;

  • business continuity;

  • risk treatment and management review.

Evidence should be retained for every remediation activity. Confirmation that an update has been installed is not sufficient on its own. Organizations should preserve version records, vulnerability scan results, compromise-assessment outcomes, session and credential reviews, and recovery or failover validation.

ISO 9001 Alignment

The response activities described in this report also support quality-management principles under ISO 9001 by promoting:

  • clearly defined ownership;

  • controlled change management;

  • documented evidence;

  • corrective actions;

  • validation of remediation outcomes;

  • management review;

  • continual improvement.

The objective is not simply to deploy updates but to demonstrate that remediation has successfully reduced operational risk.

Need Help Assessing Your Exposure?

If your organization operates any of the technologies covered in this report, identifying them is only the first step.

The next step is understanding:

  • whether vulnerable systems were exposed before remediation;

  • whether indicators of attempted or successful compromise exist;

  • whether active sessions, credentials or API keys require revocation or rotation;

  • whether business data or connected systems may have been affected;

  • which systems should be prioritised according to operational impact.

DIAMATIX helps organizations assess exposure, validate remediation and strengthen continuous monitoring through expert-led Security Operations Center as a Service (SOCaaS), Managed Detection and Response as a Service (MDRaaS) and Incident Response services.

Contact our team to discuss your environment.

Conclusion

This week’s findings combine three significant risk patterns: compromise of security and remote-access infrastructure, compromise of business-data platforms, and increased targeting of development and AI environments.

Metabase represents the most significant direct data-compromise scenario because successful exploitation may provide administrator access, connected-database credentials and access to business information. Internet-facing vulnerable instances should therefore be investigated, not merely updated.

Cisco ASA and FTD require immediate attention because disruption of Remote Access SSL VPN services can affect remote operations and incident-response access. Windows environments also require rapid remediation due to the actively exploited AFD privilege-escalation vulnerability and the broader group of critical unauthenticated remote-code-execution issues included in the August Microsoft release.

Ray demonstrates that development infrastructure can be exposed even when a service is not intentionally published to the internet. Local development dashboards, browser behaviour and DNS rebinding protections should therefore form part of the security review.

Across Metabase, Cisco ASA/FTD, Windows AFD and Ray, the appropriate response is not limited to patching. Organizations should document compromise assessments, revoke exposed sessions, rotate relevant credentials, review logs and validate downstream systems and data access.

The objective is to establish, with evidence, that exposure has been reduced, compromise has been investigated and critical business services remain reliable.

Sources

  • ThreatScope Weekly Research

  • CISA Known Exploited Vulnerabilities additions, August 12–18, 2026

  • Official Metabase Security Advisory

  • Cisco Security Advisory

  • Microsoft August 2026 Security Update analysis

  • Ray Security Advisory

  • Adobe Commerce Security Bulletin APSB26-92

  • Adobe ColdFusion Security Bulletin APSB26-90

  • SAP August Security Patch Day

  • GitLab Critical Patch Release

  • Wordfence technical advisory for Forminator

  • Apple Security Advisory

  • CISA ICS Advisories

  • AVEVA Enterprise SCADA advisory

  • Siemens Siveillance Video advisory

  • Johnson Controls Airwall advisory

Methodology

This report is based on open-source threat intelligence and vulnerability intelligence, prioritising confirmed exploitation, CISA KEV status, vendor advisories, external exposure and business criticality.

Applicability should always be validated against the organization’s actual asset inventory, deployed software versions and configuration.

The report does not, by itself, confirm the presence or absence of compromise.

Trusted · Innovative · Vigilant

Subscribe for latest updates & insights

Please enable JavaScript in your browser to complete this form.