ThreatScope by DIAMATIX
Metabase, Cisco VPN, Windows and AI/ML Infrastructure Risks (August 12–18, 2026)
Reporting period: August 12–18, 2026
Threat level: Critical
🎧 Listen to this week’s ThreatScope (audio brief)
Executive Snapshot
| Executive Snapshot | |
|---|---|
| Highest Risk | Metabase |
| Internet-facing Priority | Metabase, Cisco ASA/FTD Remote Access SSL VPN, Adobe ColdFusion |
| Windows Infrastructure Risk | Windows AFD, DNS Server, Deployment Services, QUIC |
| Development & AI Risk | Ray, GitLab, Adobe Commerce, SAP Commerce Cloud |
| Additional Exposure | WordPress Forminator, macOS Screen Sharing, OT/ICS systems |
This week’s ThreatScope covers four actively exploited vulnerabilities affecting analytics platforms, network-security infrastructure, Windows endpoints and AI/ML development environments, together with a significant Microsoft security release and several critical enterprise application vulnerabilities.
The highest operational priority is CVE-2026-72898 in Metabase. Successful exploitation may provide unauthenticated access to the Metabase application database and subsequently expose administrator accounts, connected-database credentials, API keys and business data. Metabase has confirmed active exploitation.
Cisco also confirmed active exploitation of CVE-2026-20349, which can remotely crash ASA and FTD devices providing Remote Access SSL VPN services. Although the immediate technical impact is denial of service, loss of VPN connectivity can directly affect business continuity and emergency administrative access.
The reporting period also includes an actively exploited Windows privilege-escalation vulnerability, active exploitation of Ray through DNS rebinding, multiple critical Microsoft remote-code-execution paths and high-severity vulnerabilities affecting Adobe Commerce, ColdFusion, SAP Commerce Cloud, GitLab and the Forminator WordPress plugin.
Patching remains necessary, but organisations should also establish whether exposed systems were compromised before remediation, revoke sessions and credentials where appropriate, and validate downstream services and data access.
Is This Report Relevant to Your Organization?
This report is particularly relevant if your organization operates any of the following technologies or environments.
| Technology or Environment | Commonly Found In | Why It Matters |
|---|---|---|
| Metabase | Enterprise analytics, finance, SaaS, data teams | May contain administrator access, connected-database credentials and sensitive business information |
| Cisco ASA / FTD Remote Access SSL VPN | Enterprise, government, healthcare, finance, critical infrastructure | Provides remote access and may support business continuity and incident-response connectivity |
| Microsoft Windows infrastructure | All enterprise environments | Includes endpoints, domain services, DNS, DHCP, WDS, QUIC and other core services |
| Ray | AI/ML development, data science, cloud environments | Provides execution capabilities and may expose cloud, repository and AI-provider credentials |
| Adobe Commerce / Magento | E-commerce, retail, online services | Handles customer sessions, administrator access, transactions and payment integrations |
| Adobe ColdFusion | Enterprise applications, legacy web platforms | Critical server-side code execution may affect application infrastructure |
| SAP Commerce Cloud | Retail, manufacturing, enterprise commerce | Critical business application with potential unauthenticated remote-code execution |
| GitLab CE/EE | Software development, DevOps, enterprise IT | Stores source code, projects and development workflows |
| WordPress Forminator | Public websites, marketing sites, SMB and enterprise web estates | Unauthenticated file upload may lead to full website compromise |
| macOS Screen Sharing | Enterprise Apple environments, remote support | Exposed remote-screen access may provide direct system access |
| OT/ICS systems | Manufacturing, energy, utilities, transportation, critical infrastructure | Operational constraints may delay patching and require compensating controls |
If these technologies are not present in your environment, immediate remediation may not be required. However, the wider trends remain relevant to organisations operating internet-facing analytics platforms, remote-access infrastructure, Windows core services, AI development environments or public-facing business applications.
Executive Summary
The reporting period was dominated by four actively exploited vulnerabilities:
CVE-2026-72898 affecting Metabase;
CVE-2026-20349 affecting Cisco ASA/FTD Remote Access SSL VPN;
CVE-2026-68820 affecting the Windows Ancillary Function Driver for WinSock;
CVE-2025-62593 affecting Ray.
Metabase represents the most severe compromise scenario this week. An unauthenticated attacker can inject SQL through the password-reset functionality and potentially gain administrator access, steal connected-database credentials, generate API keys and persistent sessions, and access or export business information. Internet-facing vulnerable Metabase instances should therefore be treated as potentially compromised.
Cisco ASA and FTD environments are also under active exploitation. Crafted HTTP requests can cause affected devices to reload without authentication or user interaction. Organisations relying on affected VPN services should patch immediately and verify high-availability behaviour, configuration synchronisation and emergency administrative access.
CVE-2026-68820 in Windows is a post-compromise privilege-escalation vulnerability. A locally authenticated low-privilege attacker can elevate to SYSTEM, making the issue particularly useful to ransomware operators and advanced attackers after initial access has already been obtained.
Ray introduces a different risk to AI and machine-learning environments. DNS rebinding may allow a malicious website to reach a locally running Ray dashboard and submit jobs for execution. Development systems should therefore be reviewed not only for internet exposure, but also for locally exposed services accessible through the user’s browser.
Microsoft’s August security release addressed approximately 415 vulnerabilities, including one actively exploited zero-day and 62 Critical vulnerabilities. Several critical paths allow unauthenticated remote code execution through Windows DNS Server, Deployment Services, QUIC and other core network services.
Key Vulnerabilities
| CVE | Product and Scope | CVSS / Status | Most Relevant For | Business Impact | Required Response |
|---|---|---|---|---|---|
| CVE-2026-72898 | Metabase | 10.0 / Confirmed / KEV | Enterprise analytics, finance, SaaS | SQL injection, administrator takeover, connected-database credential theft and data exposure | Upgrade immediately, revoke sessions, review administrators and rotate database credentials |
| CVE-2026-20349 | Cisco ASA / FTD | 8.6 / Confirmed / KEV | Enterprise, government, finance, healthcare | Unauthenticated SSL VPN denial of service and loss of remote connectivity | Apply hotfixes, verify VPN resilience and review device crashes |
| CVE-2026-68820 | Microsoft Windows AFD | 7.0 / Confirmed / KEV | All Windows enterprise environments | Privilege escalation from low privilege to SYSTEM | Deploy August updates and hunt for suspicious elevation activity |
| CVE-2025-62593 | Ray | Critical / Confirmed / KEV | AI/ML, cloud, data science | Code execution through DNS rebinding and access to development credentials | Upgrade to 2.52.0+, restrict dashboards and review job history |
| CVE-2026-71362 | Adobe Commerce / Magento | 9.1 / Exploitation attempts reported | E-commerce, retail | Account takeover and elevated access | Apply isolated patch, revoke sessions and review account changes |
| CVE-2026-48362 | Adobe ColdFusion | 10.0 | Enterprise application servers | Unauthenticated arbitrary code execution | Patch internet-facing deployments immediately |
| CVE-2026-58231 | SAP Commerce Cloud | 10.0 | Retail, manufacturing, enterprise commerce | Unauthenticated RCE and internal compromise | Upgrade and restrict affected import paths |
| CVE-2026-19478 | GitLab CE/EE | 9.4 | Software development, DevOps | Unauthenticated modification or deletion of public projects and user data | Upgrade self-managed GitLab |
| CVE-2026-15748 | WordPress Forminator | 9.8 / Public technical disclosure | Public websites, marketing and web estates | Unauthenticated PHP upload and possible RCE | Update immediately and inspect recent uploads |
| CVE-2026-62815 | Microsoft QUIC | 9.8 | Windows network infrastructure | Unauthenticated network RCE | Apply August Microsoft updates |
| CVE-2026-62878 | Windows DNS Server | 9.8 | Domain and network infrastructure | Unauthenticated remote code execution | Prioritise exposed and highly trusted DNS servers |
| CVE-2026-62893 | Windows Deployment Services | 9.8 | Enterprise deployment infrastructure | Unauthenticated RCE through TFTP | Patch or disable WDS/TFTP where unused |
| CVE-2026-65400 | macOS Screen Sharing | Critical / Exploitation publicly reported | Enterprise Apple environments | Authentication bypass and remote system access | Patch macOS, disable unnecessary Screen Sharing and block TCP 5900 |
Vulnerability Analysis
Metabase. CVE-2026-72898
CVE-2026-72898 affects Metabase and represents the highest operational risk during this reporting period.
An unauthenticated attacker can inject SQL into the Metabase application database through the password-reset functionality. Successful exploitation may allow the attacker to change platform configuration, create or modify administrator accounts, steal connected-database credentials, access business data and generate API keys or persistent sessions.
Metabase has confirmed active exploitation, and the vulnerability is included in the CISA Known Exploited Vulnerabilities Catalog.
Most Relevant For
organizations using Metabase for business intelligence and analytics;
financial services;
SaaS providers;
data and analytics teams;
enterprises with internet-facing Metabase instances.
How to Verify Exposure
Confirm the following:
Is Metabase deployed?
Is the instance accessible from the internet?
Is the deployed version one of the affected releases from branches 58 through 63?
Has
/api/session/reset_passwordreceived unexpected requests?Have administrator accounts or API keys changed unexpectedly?
Are there unusual queries, exports or data-warehouse access events?
Required Response
Upgrade immediately to the applicable corrected version.
If patching cannot be completed immediately, temporarily block /api/session/reset_password. Revoke all active Metabase sessions, review administrator accounts and API keys, rotate credentials for every connected database and investigate query history, exports and data-warehouse logs.
An internet-facing vulnerable Metabase instance should be treated as potentially compromised.
Cisco ASA / FTD Remote Access SSL VPN. CVE-2026-20349
CVE-2026-20349 affects Cisco ASA and FTD systems providing Remote Access SSL VPN services.
A crafted HTTP request can cause an affected device to reload unexpectedly without credentials or user interaction. The exposure may also apply to IKEv2 Remote Access VPN deployments with client services and Zero Trust Network Access configurations.
Although the immediate impact is denial of service, loss of VPN connectivity can directly affect remote operations, business continuity and incident-response access.
Most Relevant For
large enterprises;
government;
healthcare;
financial services;
critical infrastructure;
organizations relying on Cisco remote-access VPN.
How to Verify Exposure
Confirm the following:
Are Cisco ASA or FTD devices deployed?
Is Remote Access SSL VPN enabled?
Are VPN listeners accessible from the internet?
Has the applicable Cisco hotfix been installed?
Have unexplained device reloads, crash information or
linaprocess failures occurred?Has high-availability failover been tested?
Required Response
Install the applicable Cisco hotfix immediately.
Identify all internet-facing VPN listeners, monitor malformed or abnormal HTTP requests, verify high-availability failover and configuration synchronisation, and confirm that emergency administrative access does not depend solely on the affected VPN service.
Windows AFD. CVE-2026-68820
CVE-2026-68820 is a use-after-free vulnerability in the Windows Ancillary Function Driver for WinSock, afd.sys.
A locally authenticated low-privilege attacker can exploit the flaw to elevate privileges to SYSTEM.
This is primarily a post-compromise vulnerability rather than an initial-access vector. It is therefore particularly valuable to ransomware operators and advanced attackers because restricted access can be converted into full endpoint control.
Most Relevant For
enterprise Windows environments;
domain controllers;
administrative workstations;
jump servers;
internet-facing Windows systems.
How to Verify Exposure
Confirm the following:
Have the August Windows security updates been deployed?
Were privileged systems prioritised?
Have unexpected transitions from standard-user sessions to SYSTEM been observed?
Are there unusual new services or scheduled tasks?
Has suspicious LSASS access been detected?
Are EDR agents and Microsoft Defender signatures current?
Required Response
Deploy the August Windows security updates immediately.
Prioritise domain controllers, administrative workstations, jump servers and internet-facing systems. Investigate suspicious privilege escalation before rebuilding systems or closing related security alerts.
Ray. CVE-2025-62593
CVE-2025-62593 affects Ray versions before 2.52.0 and is actively exploited.
Insufficient protection of sensitive dashboard and job-submission endpoints allows exploitation through DNS rebinding. A developer using Firefox or Safari may be compromised after visiting a malicious website or advertisement. The attacker can then reach the locally running Ray dashboard, commonly available on TCP port 8265, and submit a malicious job for execution.
Most Relevant For
AI and machine-learning development teams;
data science environments;
cloud development environments;
organizations operating Ray locally or in shared development infrastructure.
How to Verify Exposure
Confirm the following:
Is Ray deployed?
Is the version earlier than 2.52.0?
Is the dashboard or job API exposed beyond approved interfaces?
Is TCP port 8265 reachable from untrusted networks?
Have unexpected jobs or processes appeared?
Could cloud, repository or AI-provider credentials have been exposed?
Required Response
Upgrade Ray to version 2.52.0 or later.
Ensure that dashboard and job APIs are not internet-accessible, restrict port 8265 through host and network firewalls, implement DNS-rebinding protection on corporate resolvers and review Ray job history for suspicious activity.
Rotate cloud, repository and AI-provider credentials accessible to potentially affected development environments.
Microsoft Critical RCE Cluster
Microsoft’s August security release addressed approximately 415 vulnerabilities, including one actively exploited zero-day and 62 Critical vulnerabilities.
Several of the most important issues affect core network services and permit unauthenticated remote code execution:
CVE-2026-62815. Microsoft QUIC;
CVE-2026-62878. Windows DNS Server;
CVE-2026-62893. Windows Deployment Services;
CVE-2026-65791. Windows iSCSI Target Service;
CVE-2026-62823. Windows DHCP Server;
CVE-2026-59124. Microsoft HPC Pack.
Most Relevant For
enterprise Windows environments;
domain and network infrastructure;
data centres;
organizations using Windows deployment and infrastructure services.
How to Verify Exposure
Identify where the following services are enabled:
DNS;
DHCP;
Windows Deployment Services;
iSCSI Target;
HPC Pack;
HTTP/3 and QUIC.
Required Response
Patch externally reachable and highly trusted servers first.
Disable WDS/TFTP and iSCSI Target where unused and restrict infrastructure services through network segmentation. Test the August updates against domain services and critical applications, but do not delay remediation of highly exposed systems.
Adobe Critical Security Updates
Adobe Commerce / Magento. CVE-2026-71362
CVE-2026-71362 can allow an unauthenticated attacker to interfere with customer sessions and gain elevated access to sensitive resources. Exploitation attempts were reported shortly after disclosure.
Required Response
Install the corresponding isolated Adobe patch.
Invalidate active customer and administrator sessions.
Review newly created administrator accounts.
Inspect customer-account and order changes.
Rotate integration and payment-related API credentials where compromise is suspected.
Adobe ColdFusion. CVE-2026-48362
CVE-2026-48362 is an unauthenticated operating-system command-injection vulnerability with a CVSS score of 10.0. Successful exploitation may result in arbitrary code execution.
The same ColdFusion security release also addresses additional Critical vulnerabilities involving evaluation injection, authorisation, memory corruption and security-control bypass.
Internet-facing ColdFusion deployments should therefore be patched as a priority.
Enterprise and Application Security Watch
SAP Commerce Cloud. CVE-2026-58231
A maximum-severity authorisation vulnerability affects the SAP Commerce Cloud Data Hub Adapter. An unauthenticated attacker may submit malicious input and potentially achieve remote code execution.
Upgrade to SAP Commerce Cloud 2211.55, 2211-jdk21.17 or later. Until the update is applied, restrict /datahubadapter/import/** to trusted Data Hub addresses.
GitLab. CVE-2026-19478
Self-managed GitLab CE/EE installations are vulnerable to unauthenticated modification or deletion of public projects and user data through a GraphQL directive.
Corrected versions are 18.11.11, 19.0.8, 19.1.6 and 19.2.4. GitLab.com and GitLab Dedicated were already patched.
No active exploitation was reported at the assessment cut-off, but self-managed environments should be upgraded promptly.
WordPress Forminator. CVE-2026-15748
Forminator Forms versions through 1.56.1 allow an unauthenticated attacker to upload potentially executable PHP files. Successful exploitation may result in complete WordPress-site compromise.
Update to version 1.56.2 or later, review recent uploads and search web directories for unexpected PHP files.
macOS Screen Sharing Exposure
CVE-2026-65400 allows a network attacker to authenticate to macOS Screen Sharing without valid credentials. The highest risk applies to systems with Screen Sharing enabled and TCP port 5900 exposed.
Required Response
Deploy the applicable macOS update.
Disable Screen Sharing where not required.
Block TCP 5900 at internet and untrusted-network boundaries.
Review remote-screen-sharing events and newly created accounts.
Investigate unexpected cryptocurrency-mining or persistence activity.
OT/ICS Security Watch
CISA published a substantial group of industrial control system advisories on 13 August. Priority systems include:
AVEVA Enterprise SCADA, with unsafe deserialisation that may result in code execution;
Siemens Siveillance Video, with remote-code-execution exposure affecting video-management servers;
Johnson Controls Airwall, with authentication bypass, arbitrary file access and exposure of protected resources;
Siemens Desigo controllers, with denial of service through malformed BACnet traffic;
ANDRITZ HIPASE, with potential device-data access and workstation compromise;
Hitachi Energy APM Edge, affected by Dirty Frag vulnerabilities impacting confidentiality, integrity and availability.
OT and ICS environments should follow approved change procedures. Where immediate patching is not operationally feasible, organizations should restrict remote access, isolate affected systems and increase monitoring.
What Deserves Attention This Week?
Analytics and Business Data
Priority systems:
Metabase.
Primary actions:
upgrade immediately;
revoke active sessions;
review administrator accounts and API keys;
rotate connected-database credentials;
review queries, exports and data-warehouse logs.
Remote Access and Network Security
Priority systems:
Cisco ASA / FTD;
internet-facing VPN infrastructure.
Primary actions:
apply Cisco hotfixes;
identify exposed VPN listeners;
review crashes and reloads;
test high-availability failover;
maintain independent emergency administrative access.
Windows Infrastructure
Priority systems:
Windows endpoints;
DNS Server;
WDS;
DHCP;
QUIC;
iSCSI;
HPC Pack.
Primary actions:
deploy August security updates;
prioritise highly trusted and exposed systems;
disable unused services;
hunt for suspicious privilege escalation.
AI and Development Infrastructure
Priority systems:
Ray;
GitLab;
AI development workstations.
Primary actions:
upgrade Ray;
restrict local development services;
review exposed ports and job history;
rotate potentially exposed cloud and AI-provider credentials;
upgrade self-managed GitLab.
Public-facing Applications
Priority systems:
Adobe Commerce;
Adobe ColdFusion;
SAP Commerce Cloud;
WordPress Forminator.
Primary actions:
apply vendor updates;
review sessions and administrator accounts;
inspect unexpected file uploads;
rotate integration credentials where exposure cannot be excluded.
Recommended Management Actions
Immediate Actions (0–7 Days)
Identify whether Metabase, Cisco ASA/FTD Remote Access SSL VPN, vulnerable Windows systems, Ray, Adobe Commerce, ColdFusion, SAP Commerce Cloud, GitLab or Forminator are present in the environment.
Patch and investigate internet-accessible Metabase instances immediately.
Apply Cisco ASA/FTD hotfixes and verify VPN resilience and emergency administrative access.
Deploy Microsoft August security updates to critical Windows endpoints and infrastructure servers.
Upgrade Ray to version 2.52.0 or later and remove unnecessary exposure of development interfaces.
Patch Adobe Commerce and internet-facing ColdFusion deployments.
Remove public access to unnecessary administrative, analytics and AI-development interfaces.
Actions Within 30 Days
Review administrative accounts, sessions and credentials associated with Metabase, Adobe, Ray and GitLab environments.
Validate network segmentation around analytics, VPN, development and infrastructure services.
Review Windows DNS, WDS, DHCP, iSCSI and QUIC exposure across the estate.
Upgrade self-managed GitLab, Forminator and affected SAP Commerce Cloud components.
Validate external attack-surface inventory for exposed ports 443, 5900 and 8265.
Close or formally document unresolved remediation exceptions.
Strategic Actions (Within 90 Days)
Reduce unnecessary public exposure of administrative, analytics and development interfaces.
Integrate AI/ML development platforms into vulnerability management and continuous monitoring.
Improve visibility of externally reachable Windows infrastructure services.
Review business-continuity dependencies on VPN and remote-access infrastructure.
Strengthen session, credential and API-key lifecycle management for analytics and commerce platforms.
Review OT/ICS remediation procedures and compensating controls for systems that cannot be patched immediately.
Enterprise Exposure Assessment
Security teams should prioritise systems based on four factors.
1. Active Exploitation
Metabase, Cisco ASA/FTD, Windows AFD and Ray have confirmed active exploitation and are included in the CISA Known Exploited Vulnerabilities Catalog.
Confirmed exploitation should immediately increase remediation priority.
2. External Accessibility
Internet-facing analytics platforms, VPN services, development interfaces, remote-screen-sharing services and application servers require the highest attention.
A vulnerable internal system and an externally accessible administrative or data platform do not represent the same operational risk.
3. Business Role
The operational role of the affected technology should influence response priority.
Compromise of Metabase may expose business data and connected databases.
Disruption of Cisco ASA/FTD may affect remote work and emergency access.
Windows privilege escalation can convert limited access into full endpoint control.
Compromise of Ray may expose development infrastructure, cloud credentials and AI services.
4. Recovery Readiness
Organizations should confirm that critical platforms can be restored safely.
Recovery planning should include tested backups, high-availability and failover for VPN services, validated database backups and review of exposed sessions, credentials and API keys.
Ongoing Security Controls
Beyond the immediate remediation cycle, security teams should:
maintain an accurate inventory of internet-facing applications, VPN services and development interfaces;
map business-critical platforms to their owners and dependent services;
validate remediation through authenticated scanning and configuration review;
monitor privileged access, session creation and administrative changes;
conduct threat hunting when confirmed exploitation overlaps with external exposure;
monitor analytics and commerce platforms for abnormal data access and export activity;
include AI/ML development environments in vulnerability and credential-management programmes;
test backup restoration, high availability and failover for critical infrastructure;
report unresolved remediation exceptions and accepted risks to management.
Questions for Leadership
Boards and executive teams should ask:
Do we operate any of the technologies covered in this report?
Which affected systems were accessible from the internet while vulnerable?
Have all actively exploited vulnerabilities been patched or isolated?
Have internet-facing Metabase instances been investigated for compromise?
Can remote operations continue if primary VPN infrastructure becomes unavailable?
Have critical Windows infrastructure services received the August security updates?
Are AI and development environments exposing services or credentials unnecessarily?
Have potentially exposed sessions, API keys and database credentials been revoked or rotated?
Can critical services be restored from validated backups or fail over to alternative infrastructure?
Which remediation exceptions remain open, and who has accepted the associated risk?
ISO 27001 Alignment
The actions described in this report support several areas of an Information Security Management System (ISMS) aligned with ISO/IEC 27001, including:
asset inventory and ownership;
vulnerability management;
secure configuration;
identity and access management;
logging and monitoring;
incident response;
network security;
application and development security;
backup and recovery;
business continuity;
risk treatment and management review.
Evidence should be retained for every remediation activity. Confirmation that an update has been installed is not sufficient on its own. Organizations should preserve version records, vulnerability scan results, compromise-assessment outcomes, session and credential reviews, and recovery or failover validation.
ISO 9001 Alignment
The response activities described in this report also support quality-management principles under ISO 9001 by promoting:
clearly defined ownership;
controlled change management;
documented evidence;
corrective actions;
validation of remediation outcomes;
management review;
continual improvement.
The objective is not simply to deploy updates but to demonstrate that remediation has successfully reduced operational risk.
Need Help Assessing Your Exposure?
If your organization operates any of the technologies covered in this report, identifying them is only the first step.
The next step is understanding:
whether vulnerable systems were exposed before remediation;
whether indicators of attempted or successful compromise exist;
whether active sessions, credentials or API keys require revocation or rotation;
whether business data or connected systems may have been affected;
which systems should be prioritised according to operational impact.
DIAMATIX helps organizations assess exposure, validate remediation and strengthen continuous monitoring through expert-led Security Operations Center as a Service (SOCaaS), Managed Detection and Response as a Service (MDRaaS) and Incident Response services.
Contact our team to discuss your environment.
Conclusion
This week’s findings combine three significant risk patterns: compromise of security and remote-access infrastructure, compromise of business-data platforms, and increased targeting of development and AI environments.
Metabase represents the most significant direct data-compromise scenario because successful exploitation may provide administrator access, connected-database credentials and access to business information. Internet-facing vulnerable instances should therefore be investigated, not merely updated.
Cisco ASA and FTD require immediate attention because disruption of Remote Access SSL VPN services can affect remote operations and incident-response access. Windows environments also require rapid remediation due to the actively exploited AFD privilege-escalation vulnerability and the broader group of critical unauthenticated remote-code-execution issues included in the August Microsoft release.
Ray demonstrates that development infrastructure can be exposed even when a service is not intentionally published to the internet. Local development dashboards, browser behaviour and DNS rebinding protections should therefore form part of the security review.
Across Metabase, Cisco ASA/FTD, Windows AFD and Ray, the appropriate response is not limited to patching. Organizations should document compromise assessments, revoke exposed sessions, rotate relevant credentials, review logs and validate downstream systems and data access.
The objective is to establish, with evidence, that exposure has been reduced, compromise has been investigated and critical business services remain reliable.
Sources
ThreatScope Weekly Research
CISA Known Exploited Vulnerabilities additions, August 12–18, 2026
Official Metabase Security Advisory
Cisco Security Advisory
Microsoft August 2026 Security Update analysis
Ray Security Advisory
Adobe Commerce Security Bulletin APSB26-92
Adobe ColdFusion Security Bulletin APSB26-90
SAP August Security Patch Day
GitLab Critical Patch Release
Wordfence technical advisory for Forminator
Apple Security Advisory
CISA ICS Advisories
AVEVA Enterprise SCADA advisory
Siemens Siveillance Video advisory
Johnson Controls Airwall advisory
Methodology
This report is based on open-source threat intelligence and vulnerability intelligence, prioritising confirmed exploitation, CISA KEV status, vendor advisories, external exposure and business criticality.
Applicability should always be validated against the organization’s actual asset inventory, deployed software versions and configuration.
The report does not, by itself, confirm the presence or absence of compromise.
Trusted · Innovative · Vigilant






