August 25, 2026 | Jonathan Brown

Command View


Verification cutoff

15:07 UTC, August 25, 2026. This edition centers on confirmed exploitation of Oracle and Zimbra products; observed exploitation attempts against miniOrange and GitLab; and high-consequence identity, broadband-edge, application-framework, connected-mobility, cloud-credential and package-infrastructure risks. Every CVE identifier, affected-version boundary, fixed release, severity statement, exploitation claim, quantity, date and attribution retained below was checked against an originating vendor, government, coordination-center or original-research source. Statements about the absence of public exploitation or victim reporting are bounded to this cutoff and do not establish absence of undisclosed activity.

Priority posture

  • RED: CISA has confirmed exploitation of Oracle CVE-2026-21962. CERT Polska has confirmed active exploitation of Zimbra CVE-2026-73570. DigitalOcean detected and blocked an attempted miniOrange SAML administrator takeover after the attacker obtained an administrator session cookie, and watchTowr reported GitLab CVE-2026-19478 exploit attempts reaching its honeypots. These systems require remediation, evidence preservation and compromise assessment.
  • AMBER: Keycloak CVE-2026-18963 enables unauthenticated account takeover, but no authoritative source reviewed by the cutoff confirmed exploitation in the wild. Calix CVE-2026-75501 has public technical detail and proof-of-concept material without vendor confirmation or a published fix. Spring for GraphQL has a conditional remote-code-execution path. Kaspersky documented malicious use of DoFun automotive head-unit update infrastructure, and Truffle Security reported thousands of still-authenticating AWS access keys.
  • WATCH: Spring AI CVE-2026-59318 can dispatch a tool not advertised to the current request under documented conditions, but Spring rates it Medium and reports no active exploitation. OX Security found npm packages being used to host fake verification pages on trusted package mirrors; installation alone is not compromise, and the live redirect observed during the research led to legitimate ChatGPT rather than an active phishing payload.
  • CONTEXT: Trust position matters more than a flat severity score. Web proxy plug-ins, mail servers, SAML integrations, source-code systems, identity providers, software updaters, cloud credentials and AI tool dispatchers can extend an initial failure into downstream accounts, data, builds, devices or services.

Today’s decisions

  • RED — Oracle Fusion Middleware owners and incident response: Identify every Oracle HTTP Server and WebLogic Server Proxy Plug-in deployment, including Apache and Microsoft IIS front ends; apply the January 2026 Critical Patch Update for the installed release; preserve proxy and web logs; and investigate unauthorized data access or modification. Do not report remote code execution unless separate evidence establishes it.
  • RED — Mail platform owners and incident response: Upgrade qualifying Zimbra installations to 10.1.20 or later and perform the CERT Polska hunt across Zimbra logs, application directories and temporary storage. The federal remediation date has passed, but that compliance date applies to covered federal civilian agencies rather than every organization.
  • RED — Web identity and WordPress owners: Determine the exact miniOrange edition before comparing version numbers, install a build that closes both SAML flaws, invalidate privileged sessions and investigate unexplained administrator authentication. Paid editions may require manual upload because the WordPress dashboard can fail to offer the cross-line update.
  • RED — GitLab and software-delivery owners: Upgrade affected self-managed GitLab instances, preserve GraphQL and audit telemetry, and validate public-project, repository, membership and deletion history against independent trusted records. Honeypot exploit traffic does not prove production compromise, but patching alone cannot prove repository integrity.
  • AMBER — Identity and access management: Upgrade upstream Keycloak to 26.7.2 or apply the appropriate fixed Red Hat build. If remediation cannot be completed immediately, disable Forgot password in every realm and review reset-credential events, privileged-user changes and sessions issued after suspicious resets.
  • AMBER — Network, application and cloud owners: Block WAN access to TCP port 5000 on affected Calix gateways; patch Spring for GraphQL and Spring AI according to their separate fixed-release lines; disable exposed AWS access keys before creating replacements; and investigate credential use from the first known exposure date.

Threat and Resilience Ledger


RED — Web and application middleware | Global — Oracle proxy plug-in flaw enters CISA KEV

CISA added CVE-2026-21962 to the Known Exploited Vulnerabilities Catalog on August 24. Oracle’s January 2026 risk matrix identifies an improper-access-control vulnerability in Oracle HTTP Server and the WebLogic Server Proxy Plug-in for Apache HTTP Server and Microsoft IIS. It is remotely exploitable over HTTP without authentication or user interaction and carries an Oracle CVSS 3.1 score of 10.0. Supported affected releases are 12.2.1.4.0, 14.1.1.0.0 and 14.1.2.0.0, but Oracle’s Note 1 limits the affected IIS plug-in to 12.2.1.4.0. Oracle states that exploitation can permit unauthorized reading, creation, deletion or modification of accessible data and assigns no availability impact; the public advisory does not claim remote code execution. Covered federal civilian agencies have an August 27 remediation date. Operators should apply the appropriate January 2026 CPU patch through Oracle’s release-specific patch documentation, preserve front-end and proxy telemetry, and investigate unexplained data access or modification.

Evidence: Confirmed vulnerability and confirmed exploitation; public exploit-chain and victim details are absent.
Attribution: Unknown.
Confidence: High.
Uncertainty: Actor, victim scope, exploit path, indicators and post-exploitation behavior remain undisclosed.
Sources: CISA — “CISA Adds One Known Exploited Vulnerability to Catalog,” August 24, 2026; Oracle — “Oracle Critical Patch Update Advisory — January 2026,” initial release January 20, 2026, current revision February 2, 2026.

RED — Email and collaboration | Global — Zimbra command injection remains under active exploitation

CERT Polska reported active exploitation of CVE-2026-73570 on August 17. Zimbra Collaboration Suite before 10.1.20 is affected when the optional zimbra-snmp package is installed, SNMP notifications are enabled and the swatchdog service is running; CERT Polska notes that swatchdog is enabled by default. A remote unauthenticated attacker can send crafted SMTP requests that execute operating-system commands as the zimbra user. The CNA score is CVSS 8.9, while NVD had not assigned an independent score by the cutoff. CISA added the flaw to KEV on August 21 with an August 24 date for covered federal civilian agencies. Operators should upgrade to 10.1.20 or later and review the previous 30 days of /var/log/zimbra.log for suspicious Service status change entries, along with files created by the zimbra user in /opt/zimbra/jetty/webapps/, /opt/zimbra/jetty_base/webapps/ and /tmp/.

Evidence: Confirmed vulnerability and confirmed active exploitation.
Attribution: Unknown.
Confidence: High.
Uncertainty: Public sources do not identify the actor, victim count, campaign objective or complete post-exploitation chain.
Sources: CERT Polska — “Aktywnie wykorzystywana podatność w Zimbra Collaboration Suite,” August 17, 2026; CISA — “CISA Adds One Known Exploited Vulnerability to Catalog,” August 21, 2026; Zimbra — “Zimbra Security Advisories,” accessed August 25, 2026.

RED — Federated identity and web administration | Global — miniOrange SAML bypasses reach administrator sessions

Patchstack and DigitalOcean disclosed on August 21 that CVE-2026-61979 and CVE-2026-15981 affect miniOrange SAML 2.0 Single Sign On editions for WordPress. CVE-2026-61979 is a signature-algorithm-confusion flaw scored CVSS 8.1; CVE-2026-15981 treats an OpenSSL error return as successful verification and is scored 9.8. Both can let an unauthenticated attacker forge a SAML assertion and authenticate as an existing user, including an administrator. DigitalOcean detected and blocked an anomalous administrator session attempt on August 16; its analysis states that the attacker had already obtained an administrator session cookie, while a trusted-network restriction prevented subsequent administrator-panel operations. Scanning from multiple addresses appeared opportunistic, and no actor was named. To close both CVEs, the joint vendor matrix identifies minimum fixed builds of Free 5.4.5; Premium Single Site 13.0.4; Standard Single Site 17.0.6; Premium, Enterprise and All-Inclusive Multisite 20.2.8; Enterprise and All-Inclusive Single Site 26.0.3; VIP Single Site 32.0.8; and VIP Multisite 35.0.7. Operators must identify the edition, update, invalidate privileged sessions and investigate administrator authentication and account changes.

Evidence: Confirmed vulnerabilities, confirmed end-to-end reproduction and observed attempted exploitation that produced an administrator session cookie.
Attribution: Unknown; the observed scanning was assessed as opportunistic rather than targeted.
Confidence: High.
Uncertainty: The number of successfully compromised sites and the full duration of the exploitation activity are unknown.
Sources: Patchstack and DigitalOcean — “One slug, seven editions: the miniOrange SAML SSO bug that let anyone log in as your WordPress admin,” August 21, 2026; CVE Program — CVE-2026-61979 and CVE-2026-15981 records, accessed August 25, 2026.

RED — Source control and software delivery | Global — GitLab exploit attempts follow emergency patch

GitLab released versions 18.11.11, 19.0.8, 19.1.6 and 19.2.4 on August 17 to fix CVE-2026-19478, a CVSS 9.4 GraphQL code-injection vulnerability. Under specific conditions, an unauthenticated remote attacker can modify or delete public projects and user data. Affected self-managed Community and Enterprise Edition ranges are 18.2 before 18.11.11, 19.0 before 19.0.8, 19.1 before 19.1.6 and 19.2 before 19.2.4. GitLab.com and GitLab Dedicated were already patched by GitLab. WatchTowr subsequently reported exploit attempts reaching its honeypots and reproduced the vulnerable behavior, but no reviewed source confirms successful compromise of a production victim. Self-managed operators should upgrade, preserve GraphQL, reverse-proxy, application and audit logs, and verify project, repository, membership and deletion state against trusted backups and independent records.

Evidence: Confirmed vulnerability and affected versions; demonstrated exploitability; reported in-the-wild exploitation attempts against honeypots.
Attribution: Unknown.
Confidence: High for the vulnerability and attempt telemetry; moderate for the unknown extent of real-world compromise.
Uncertainty: Successful production compromise, victim count, actor identity and vendor-issued indicators remain unconfirmed.
Sources: GitLab — “GitLab Critical Patch Release: 19.2.4, 19.1.6, 19.0.8, 18.11.11,” August 17, 2026; watchTowr — public alert reporting honeypot exploitation attempts against CVE-2026-19478, August 19, 2026.

AMBER — Identity control plane | Global — Keycloak password-reset flaw enables unauthenticated takeover

Red Hat issued fixed Red Hat Build of Keycloak 26.4.15 and 26.6.6 packages on August 18, and the Keycloak project announced upstream 26.7.2 on August 19. CVE-2026-18963 is caused by improper state validation in the reset-credentials flow, allowing a remote unauthenticated attacker to bypass the required email-verification link and set new credentials for a target user. Red Hat rates the flaw Critical at CVSS 9.1 and states that successful exploitation can provide full account control without user interaction. Customers should use the applicable Red Hat erratum for package or image updates. The public notices do not state a dependable lower affected-version boundary. No authoritative source reviewed by the cutoff confirmed active exploitation, and claims of a working public exploit could not be positively validated. Operators should patch or temporarily disable Forgot password in every realm, then review credential-reset events and sessions associated with high-value accounts.

Evidence: Confirmed vulnerability and fixes; no confirmed in-the-wild exploitation by the cutoff.
Attribution: Not applicable to the vulnerability; no attack activity is attributed.
Confidence: High for mechanics, severity and remediation; moderate for the full affected-version floor because the public upstream notice does not define it.
Uncertainty: The prevalence of exposed vulnerable realms and the existence of a reliably working public exploit remain unconfirmed.
Sources: Red Hat — “CVE-2026-18963,” accessed August 25, 2026; Red Hat security advisories RHSA-2026:56519 and RHSA-2026:56520 for 26.4.15, and RHSA-2026:56523 and RHSA-2026:56524 for 26.6.6, issued August 18, 2026; Keycloak — “Keycloak 26.7.2 released,” August 19, 2026.

AMBER — Residential broadband edge | Global — Calix gateway exposes WAN-side NAT control

CERT/CC published CVE-2026-75501 on August 21 for the Calix GS7 XGS model GS5239XG. The CVE record marks firmware through EXOS 6.6.47 as affected, while the CERT/CC note specifically documents EXOS 6.6.47. The device exposes the MiniUPnPd 2.3.7 WANIPConnection SOAP service on the public WAN interface at TCP port 5000 without authentication. Crafted requests can add, delete or enumerate NAT port mappings or query the external address, allowing exposure of internal services through attacker-created forwarding rules. The researcher published technical detail and proof-of-concept material and assigned CVSS 9.1, but CERT/CC and NVD had not assigned an authoritative score by the cutoff. CERT/CC could not reach Calix, published no vendor statement and listed no vendor patch. Providers should disable WAN-side UPnP or filter inbound TCP port 5000 and coordinate with Calix; customers without administrative control should contact their service provider.

Evidence: Confirmed CERT/CC vulnerability record and public proof of concept; not vendor-confirmed.
Attribution: Not applicable; no malicious activity is attributed.
Confidence: High for the documented model, service and attack capability; moderate for scope across earlier firmware builds.
Uncertainty: Calix’s assessment, a supported fixed release, fleet prevalence and active exploitation are unknown.
Sources: CERT/CC — “VU#756733 — Calix GS7 XGS GS5239XG residential router contains missing authentication vulnerability,” August 21, 2026; Brian Khan Quintana — “The router in my living room was taking orders from strangers,” August 21, 2026; CVE Program — CVE-2026-75501 record, August 21, 2026.

AMBER — Application frameworks | Global — Spring for GraphQL has a conditional RCE path

Spring disclosed CVE-2026-59285 on August 20 and rates it High. Spring for GraphQL 2.0.0 through 2.0.4 is vulnerable to unsafe deserialization only when all documented conditions are present: Spring for GraphQL is in use; Jackson 2.x performs JSON deserialization; the application exposes a paginated Connection field; and specific usable classes exist on the classpath. A crafted GraphQL request can then lead to remote code execution. Fixed releases are open-source 2.0.5 and Enterprise Support 2.0.4.1. Spring’s advisory does not report active exploitation. Application owners should patch and verify the complete dependency, classpath and schema preconditions rather than either universalizing the RCE claim or dismissing the issue on package version alone.

Evidence: Confirmed vendor advisory; exploitation is conditional on the complete documented configuration.
Attribution: Not applicable.
Confidence: High.
Uncertainty: Public sources do not quantify how many deployments meet all preconditions or identify real-world exploitation.
Sources: Spring — “Spring for GraphQL Unsafe Deserialization in pagination support,” August 20, 2026.

WATCH — AI application authorization | Global — Spring AI may dispatch an unadvertised tool

Spring disclosed CVE-2026-59318 on August 20 and rates it Medium. In Spring AI’s tool-calling support, a per-request tool list is advertised to the model but is not fully enforced when a tool call is dispatched. Under documented conditions, prompt injection can cause invocation of a tool not advertised to the current request, creating a potential privilege-escalation path when the application treats that list as an authorization control. Affected releases are 2.0.0, 1.1.0 through 1.1.8 and 1.0.0 through 1.0.9. Fixed releases are open-source 2.0.1 and Enterprise Support 2.0.0.1, 1.1.9 and 1.0.10. Spring reports no active exploitation. Operators should patch and enforce identity, authorization and policy checks at the tool-execution layer independently of prompts and model-visible tool lists.

Evidence: Confirmed vendor advisory; no confirmed exploitation.
Attribution: Not applicable.
Confidence: High.
Uncertainty: The number of applications relying on the advertised tool list as a security boundary is unknown.
Sources: Spring — “DefaultToolCallingManager Global Resolver Fallback Allows Unadvertised Tool Dispatch via Prompt Injection,” August 20, 2026.

AMBER — Connected mobility and update integrity | Global — DoFun head-unit updater distributed malware

Kaspersky reported on August 21 that, while monitoring Android threats in June, it identified a multi-stage malware chain delivered through built-in update functionality on multiple models of DoFun Android automotive head units. The legitimate TWCore application received MQTT instructions through infrastructure under cardoor.cn and could install applications not already present. Attackers used that channel to deliver the JarService dropper, later loaders and payloads supporting advertising fraud and a reverse-proxy botnet. Kaspersky attributes the activity to MoYu Group with high confidence based on naming patterns and infrastructure overlap with the BADBOX ecosystem. Kaspersky says DoFun reported fixing the distribution-security issues after notification, but no public affected-model list, firmware boundary, fixed build, victim count or independent validation is available. The research does not establish compromise of safety-critical vehicle-control systems. Fleet and automotive suppliers should verify updater authorization and signing, inventory unexpected applications and isolate suspect infotainment systems from credentials and business networks.

Evidence: Confirmed by Kaspersky telemetry and malware analysis; vendor remediation is reported through Kaspersky rather than a public DoFun advisory.
Attribution: Kaspersky high-confidence assessment linking the campaign to MoYu Group; no government attribution.
Confidence: High for the observed infection chain; moderate for attribution and remediation status.
Uncertainty: Affected models, firmware, geography, infection count and completeness of the reported fix remain unknown.
Sources: Kaspersky Securelist — “The invisible passenger in your car,” August 21, 2026; Kaspersky — “Kaspersky discovers a malware campaign targeting car head units,” August 21, 2026.

AMBER — Cloud identity and secrets | Global — Thousands of leaked AWS keys still authenticate

Truffle Security reported on August 19 that it reverified 10,616 complete AWS access-key pairs on August 10 and found 9,308, or approximately 88 percent, still authenticating. Of 817 keys it classified as business-linked, 768 provided full control: 526 root keys and 242 IAM-user keys with AdministratorAccess. The researchers also identified 130 live root keys on AWS Organizations management accounts. The study used read-only identity and metadata calls and published no key material or account identifiers. These counts establish live exposure, not proof that each key was maliciously used or that every associated account was compromised. Affected organizations should disable exposed keys immediately, remove root access keys, investigate CloudTrail and resource activity from the earliest known exposure, invalidate or constrain derived temporary sessions where necessary, and replace long-lived credentials with roles or other temporary credentials.

Evidence: Original research with exact aggregate counts and a disclosed methodology; malicious use is not established.
Attribution: Not applicable to the exposures.
Confidence: Moderate to high; the measurements are detailed but cannot be independently reproduced from public key material for ethical reasons.
Uncertainty: The number of keys already abused, the accuracy of every ownership classification and the number remediated after notification are unknown.
Sources: Truffle Security — “768 Leaked Corporate AWS Keys Held Full Admin Rights,” August 19, 2026; AWS — “Manage access keys for IAM users” and “What to Do If You Inadvertently Expose an AWS Access Key,” accessed August 25, 2026.

WATCH — Package infrastructure and phishing | Global — npm mirrors host fake verification pages

OX Security reported on August 25 that it found 24 npm packages containing the same fake Cloudflare verification page, typically drawing 50 to 300 weekly downloads before removal. The packages were used as hosting objects because unpkg, Yarn, npmmirror, Tencent and other services render mirrored package files on trusted domains. Early samples redirected through a typosquatted Microsoft domain; later samples used the legitimate api.keyval.org service to retrieve an encrypted, operator-changeable destination. At the time of OX Security’s research, the live destination was legitimate ChatGPT, not an active credential-theft or command-execution page. Downloading or installing the packages does not itself execute malware; risk begins when a user opens the rendered HTML and is redirected into a malicious flow. Defenders should flag direct HTML requests to package-mirror domains, preserve redirect-chain telemetry and avoid labeling package installation alone as compromise.

Evidence: Confirmed original research and package artifacts; no confirmed victim count or active payload at the final observed destination.
Attribution: Unknown.
Confidence: High for the infrastructure-abuse mechanism; low for realized victim impact.
Uncertainty: Mirror retention, subsequent redirect changes and successful phishing outcomes are unknown.
Sources: OX Security — “ClickFix Phishing Pages Discovered in 24 npm Packages,” August 25, 2026.

Defensive Posture Changes


Inventory enabling conditions, not merely product names

Oracle exposure can reside on an Apache or IIS tier rather than the WebLogic back end. Zimbra requires an optional package and specific notification state. miniOrange uses seven independently versioned editions under one WordPress slug, while Spring for GraphQL requires a particular schema, deserializer and classpath combination. Asset and vulnerability systems must record components, roles, editions, configurations and dependency paths; a product-level hit alone is not sufficient for either escalation or dismissal.

Make integrity validation part of remediation

The Oracle, miniOrange and GitLab cases can affect data or trusted administrative state without necessarily leaving a conventional malware artifact. After patching, compare repositories, projects, membership, SAML sessions, administrator changes and accessible data against independent records. Where exploitation or attempted exploitation occurred, version compliance establishes that a known path is closed; it does not establish that the system or the objects it controls remain trustworthy.

Treat credential exposure as an incident, not a rotation ticket

An exposed AWS key may have created temporary sessions, roles, resources or persistence before the key was disabled. Similarly, a Keycloak reset or miniOrange SAML bypass can issue sessions that survive the vulnerable transaction. Disable the exposed credential first, investigate activity, invalidate dependent access where supported, restore required access through new trusted credentials and verify that no alternate access path remains.

Enforce authorization outside automated channels

The DoFun and Spring AI cases expose the same control failure in different forms: an automated channel was permitted to take consequential action without a sufficiently independent enforcement boundary. Software updaters require cryptographic provenance and constrained authorization for every delivered object. AI tool dispatch requires server-side identity, policy and argument validation for every call, regardless of which tools a model was told were available.

Preserve evidence before high-risk edge changes

Oracle proxy plug-ins, Zimbra mail servers, GitLab instances and Calix gateways may lose volatile or short-retention telemetry during upgrades, restarts or provider-driven changes. Capture relevant configuration, logs, process state and network evidence when operationally safe before remediation. Evidence collection must not become an excuse to delay containment on an exposed actively exploited system, but neither should emergency patching erase the only available record of prior compromise.

Regional and Sector Pulse


North America — RED

The clearest region-specific fact is regulatory rather than victimological: CISA set August 27 for covered federal civilian agencies to remediate Oracle CVE-2026-21962, while the August 24 date for Zimbra CVE-2026-73570 has passed. Those dates do not apply universally to private operators, and neither catalog entry establishes a North American victim concentration. Government, healthcare, telecommunications and regulated enterprises using the affected middleware should nevertheless treat the KEV status as an immediate compromise-assessment trigger.

Europe — WATCH

CERT Polska is the authoritative public source confirming active Zimbra exploitation, but its advisory does not disclose Polish or wider European victim concentration. European operators should use the technical hunt guidance without converting the reporting organization’s location into a claim about campaign geography. No reliable regional victim distribution is public for the GitLab, miniOrange or Keycloak issues.

Global identity and software delivery — RED

miniOrange, GitLab and Keycloak sit directly on authentication or software-authority boundaries. Their exposure is global because the affected products are deployable worldwide, not because a global victim set has been confirmed. The immediate defensive question is whether an organization can prove the integrity of sessions, privileged identities, public projects and repository state after the vulnerable period.

Broadband and connected mobility — AMBER

Calix CVE-2026-75501 concerns a specific residential gateway model and WAN-exposed service; it does not establish compromise of carrier cores or other Calix products. Kaspersky’s DoFun reporting establishes update-chain abuse across multiple head-unit models but does not publish geography, affected firmware or safety-system effects. Telecom providers, fleets and automotive suppliers should prioritize inventory and isolation while resisting unsupported claims of carrier-scale or vehicle-control compromise.

Cloud and application development — AMBER

The AWS study, Spring advisories and npm mirror research affect globally distributed development and cloud environments. The AWS counts measure live credentials rather than confirmed malicious use; the Spring flaws require version and configuration analysis; and the npm packages functioned as web-hosting infrastructure rather than import-time malware. These distinctions should determine incident classification and prevent both underreaction and false compromise declarations.

Vulnerability and Supplier Watchlist


Oracle HTTP Server and WebLogic Server Proxy Plug-in

Issue: CVE-2026-21962, improper access control with confirmed exploitation.
Affected scope: 12.2.1.4.0, 14.1.1.0.0 and 14.1.2.0.0 for the identified Apache component; IIS plug-in affected at 12.2.1.4.0 only.
Fixed release: Apply the January 2026 CPU patch for the installed supported release through Oracle’s patch-availability documentation.
Severity: Oracle CVSS 10.0; CISA KEV.
Status: RED — confirmed exploitation and Tier-0-adjacent middleware exposure.

Zimbra Collaboration Suite

Issue: CVE-2026-73570, unauthenticated operating-system command injection through SMTP and SNMP notification processing.
Affected scope: Before 10.1.20 when zimbra-snmp is installed and SNMP notifications are enabled.
Fixed release: 10.1.20.
Severity: CNA CVSS 8.9; CISA KEV.
Status: RED — confirmed active exploitation.

miniOrange SAML 2.0 Single Sign On for WordPress

Issue: CVE-2026-61979 and CVE-2026-15981, unauthenticated SAML authentication bypasses.
Affected scope: Seven independently versioned Free, Premium, Standard, Enterprise, All-Inclusive and VIP single-site or multisite editions; compare the installed edition with the vendor matrix.
Fixed release: To close both flaws: 5.4.5, 13.0.4, 17.0.6, 20.2.8, 26.0.3, 32.0.8 or 35.0.7 according to edition.
Severity: CVSS 8.1 and 9.8.
Status: RED — observed attempted exploitation produced an administrator session cookie.

GitLab Community Edition and Enterprise Edition

Issue: CVE-2026-19478, unauthenticated GraphQL code injection affecting public projects and user data.
Affected scope: 18.2 before 18.11.11; 19.0 before 19.0.8; 19.1 before 19.1.6; 19.2 before 19.2.4.
Fixed release: 18.11.11, 19.0.8, 19.1.6 and 19.2.4.
Severity: GitLab CVSS 9.4.
Status: RED — exploit attempts observed against honeypots; production compromise unconfirmed.

Keycloak

Issue: CVE-2026-18963, unauthenticated reset-credentials flow bypass enabling account takeover.
Affected scope: The public upstream notice does not define a dependable lower version boundary; unpatched supported streams require vendor-specific assessment.
Fixed release: Upstream 26.7.2; Red Hat Build of Keycloak 26.4.15 and 26.6.6 streams, using the applicable Red Hat erratum.
Severity: Red Hat CVSS 9.1, Critical.
Status: AMBER — high-consequence identity exposure without confirmed active exploitation.

Calix GS7 XGS GS5239XG

Issue: CVE-2026-75501, unauthenticated WAN-side UPnP control of NAT mappings.
Affected scope: CVE record lists firmware through EXOS 6.6.47; CERT/CC specifically documents EXOS 6.6.47 on the GS5239XG.
Fixed release: None published by cutoff; disable UPnP or filter inbound TCP port 5000.
Severity: Researcher-assigned CVSS 9.1; no CERT/CC or NVD score by cutoff.
Status: AMBER — public proof of concept, no vendor statement and no confirmed exploitation.

Spring for GraphQL

Issue: CVE-2026-59285, conditional unsafe deserialization leading to remote code execution.
Affected scope: 2.0.0 through 2.0.4 when every documented framework, Jackson, pagination and classpath precondition is present.
Fixed release: Open-source 2.0.5; Enterprise Support 2.0.4.1.
Severity: Spring rating High.
Status: AMBER — serious conditional RCE without confirmed exploitation.

Spring AI

Issue: CVE-2026-59318, dispatch of a tool not advertised to the current request under documented conditions.
Affected scope: 2.0.0; 1.1.0 through 1.1.8; 1.0.0 through 1.0.9.
Fixed release: Open-source 2.0.1; Enterprise Support 2.0.0.1, 1.1.9 and 1.0.10.
Severity: Spring rating Medium.
Status: WATCH — authorization-design concern without confirmed exploitation.

DoFun automotive head-unit update chain

Issue: Legitimate TWCore update functionality was abused to install a multi-stage Android malware chain.
Affected scope: Multiple DoFun-powered head-unit models; public model, firmware and victim boundaries are unavailable.
Fixed release: DoFun reportedly corrected the distribution issue; no public fixed build was available by cutoff.
Severity: Confirmed supplier and update-channel compromise; no CVSS score or safety-control impact established.
Status: AMBER — active malware distribution with incomplete scope and remediation detail.

Outlook and Uncertainty


Next 24 hours

The highest-value collection targets are technical or victim disclosures for Oracle CVE-2026-21962; confirmation of successful production compromise involving GitLab CVE-2026-19478; authoritative evidence that Keycloak CVE-2026-18963 has entered active exploitation; further miniOrange indicators or victim reporting; and a Calix vendor statement or fixed firmware. Defenders should also watch for revised Spring advisories, validated DoFun model and firmware scope, changes to the npm redirect infrastructure and removal or rotation of the AWS credentials described by Truffle Security.

Inventory discrepancies are likely to remain operationally important even if no new campaign data emerges. Commercial miniOrange editions, Oracle plug-ins installed on front ends, optional Zimbra components, transitive Spring dependencies and provider-managed Calix gateways can all evade a first-pass product inventory. Reconciliation of actual deployed components and configurations should continue independently of public news flow.

What is not known

Oracle’s public record does not identify actors, victims, indicators, exploit mechanics or post-exploitation behavior. Zimbra victim count and campaign attribution remain unknown. GitLab exploit attempts are confirmed at honeypots, but successful production compromise is not. The public Keycloak notices do not define a complete lower affected-version boundary, and a reliably working public exploit was not positively validated. Calix has not publicly confirmed the issue or supplied a fix.

Kaspersky does not publish the affected DoFun models, firmware releases, countries or infection count, and its reported vendor remediation cannot be independently validated from a DoFun advisory. Truffle Security’s study measures authenticating credentials rather than malicious use. OX Security’s research demonstrates redirectable phishing infrastructure, but its final observed destination was benign and no successful compromise count is available. Absence of public reporting on any of these points is not evidence of absence.

Trigger for escalation

Escalate Keycloak to RED upon authoritative confirmation of in-the-wild account takeover. Escalate Calix if a provider or incident responder confirms unauthorized NAT-rule manipulation, broad scanning or exploitation at scale. Escalate Spring for GraphQL if credible telemetry shows the complete documented RCE preconditions being exploited in operational environments, and escalate Spring AI if unauthorized tool execution is confirmed against production systems.

For Oracle, Zimbra, miniOrange and GitLab, any unexplained data modification, administrator session, project deletion, service-state change, web shell, credential creation or persistence artifact should trigger full incident-response containment rather than a patch-only workflow. Escalate the DoFun case if evidence reaches safety-relevant vehicle networks or establishes a materially larger verified infection base. Escalate the npm activity if the configurable redirect begins delivering credential theft or command-execution instructions, and treat any unauthorized AWS API activity tied to a published key as confirmed cloud compromise.


Jonathan Brown is a cybersecurity researcher and investigative journalist at bordercybergroup.com.

If you would like to support our work — useful, well-researched, ad-free cybersecurity intelligence — subscribe, comment, or buy us a coffee! Thanks.

© 2026 Border Cyber Group. All rights reserved.