CyberNews: 18/08/2026 Edition
Today’s roundup
Summary
CISA has added CVE-2025-62593 (CVSS 9.4), a critical RCE in Ray AI compute engine, to its KEV catalog due to active exploitation via DNS rebinding; federal agencies must patch by August 20.
GitLab patched CVE-2026-19478 (CVSS 9.4), a critical GraphQL flaw allowing unauthenticated attackers to modify or delete public projects on self-managed instances.
The "SANDCLOCK" supply-chain attack on LiteLLM exposed credentials across 2,038 GitHub repositories, impacting over 2,500 organizations in tech, finance, and healthcare sectors.
CISA confirmed that ransomware gangs are actively exploiting a high-severity Windows Task Host vulnerability, previously identified in April.
CVE-2026-54121, or "Certighost," allows a standard domain user to escalate privileges and turn an Enterprise Certificate Authority into a Domain Controller.
A critical RCE (CVE-2026-15748, CVSS 9.8) in the Forminator Forms WordPress plugin allows unauthenticated arbitrary code execution via malicious PHP uploads.
Fortinet detailed Evooo1Bot, a Mirai-based Linux botnet with encrypted C2, SSH brute-force, credential sniffing, SOCKS5 proxies, and an exploit arsenal targeting 18 CVEs.
Poland is investigating a data breach at MyDr healthcare software, potentially impacting 19 million people, with the company having remediated the cause.
Want to dig deeper?
Vulnerabilities
| CVE-2025-62593 | Critical |
| CVE-2026-19478 | Critical |
| CVE-2026-54121 | High |
| CVE-2026-15748 | High |