Jump to the main content block

【Vulnerability Alert】CISA Added 9 Known Exploited Vulnerabilities to the KEV Catalog (2026/08/17-2026/08/23)

publish date : 2026-09-04 update date : 2026-09-04

Source: Ministry of education information & communication security contingency platform

"" "" ""

Publication Number TACERT-ANA-2026082804084040 Publication Time 2026-08-28 16:03:40
Incident Type ANA-Vulnerability Alert Discovery Time 2026-08-28 16:03:40
Impact Level Low  
[Subject]
【Vulnerability Alert】CISA Added 9 Known Exploited Vulnerabilities to the KEV Catalog (2026/08/17-2026/08/23)
[Content]

Forwarded from TWCERTCC Cybersecurity Alert TWCERTCC-200-202608-00000018

【CVE-2025-62593】Ray-Project Ray Code Injection Vulnerability (CVSS v3.1: 8.8)
【Whether exploited by ransomware: Unknown】Ray-Project Ray contains a code injection vulnerability that may lead to remote code execution. This vulnerability can be exploited through Firefox and Safari.

【CVE-2026-33824】Microsoft Internet Key Exchange (IKE) Service Extensions Double Free Vulnerability (CVSS v3.1: 9.8)
【Whether exploited by ransomware: Unknown】Microsoft Internet Key Exchange (IKE) Service Extensions contain a Double Free vulnerability that may lead to remote code execution.

【CVE-2026-59310】Broadcom VMware vCenter Path Traversal Vulnerability (CVSS v3.1: 9.8)
【Whether exploited by ransomware: Unknown】Broadcom VMware vCenter contains a Path Traversal vulnerability that may allow a threat actor with network access to vCenter to execute arbitrary code.

【CVE-2026-55040】Microsoft SharePoint Weak Authentication Vulnerability (CVSS v3.1: 9.1)
【Whether exploited by ransomware: Unknown】Microsoft SharePoint contains a Weak Authentication vulnerability that may allow an unauthorized attacker to bypass security features over a network.

【CVE-2026-65400】Apple macOS Improper Authentication Vulnerability (CVSS v3.1: 9.8)
【Whether exploited by ransomware: Unknown】Apple macOS contains an Improper Authentication vulnerability that may allow an attacker on the network to pass Screen Sharing authentication without valid credentials.

【CVE-2026-64849】MLflow Server-Side Request Forgery Vulnerability (CVSS v3.1: 9.3)
【Whether exploited by ransomware: Unknown】MLflow contains a Server-Side Request Forgery vulnerability that may allow an attacker to access internal or cloud metadata services and obtain response_status and response_body.

【CVE-2026-72530】TrueConf Server Code Injection Vulnerability (CVSS v3.1: 9.0)
【Whether exploited by ransomware: Unknown】TrueConf Server contains a Code Injection vulnerability that may allow an unauthorized remote attacker with network access through port 4307/TCP to use a specially crafted script to escape the isolation environment and execute arbitrary code on the host system.

【CVE-2026-72529】TrueConf Server Missing Authentication for Critical Function Vulnerability (CVSS v3.1: 9.8)
【Whether exploited by ransomware: Unknown】TrueConf Server contains a Missing Authentication for Critical Function vulnerability that may allow an unauthorized remote attacker with network access through port 4307/TCP to execute arbitrary scripts.

【CVE-2026-73570】Zimbra Collaboration Suite (ZCS) OS Command Injection Vulnerability (CVSS v3.1: 8.9)
【Whether exploited by ransomware: Unknown】Zimbra Collaboration Suite (ZCS) contains an OS Command Injection vulnerability that may allow an unauthenticated attacker to send specially crafted SMTP requests and execute arbitrary operating system commands as the Zimbra user.

Information Sharing Level: WHITE (the intelligence content is information that may be publicly disclosed)

[Affected Platform]

【CVE-2025-62593】Please refer to the affected versions listed by the official vendor https://github.com/ray-project/ray/security/advisories/GHSA-q279-jhrf-cc6v

【CVE-2026-33824】Please refer to the affected versions listed by the official vendor https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-33824

【CVE-2026-59310】Please refer to the affected versions listed by the official vendor https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/38017

【CVE-2026-55040】Please refer to the affected versions listed by the official vendor https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55040

【CVE-2026-65400】Please refer to the affected versions listed by the official vendor https://support.apple.com/en-us/100100

【CVE-2026-64849】Please refer to the affected versions listed by the official vendor https://github.com/mlflow/mlflow/security/advisories/GHSA-7gwp-5pfp-969j

【CVE-2026-72530】Please refer to the affected versions listed by the official vendor https://trueconf.com/blog/news/security-fixes-updates-and-advisories

【CVE-2026-72529】Please refer to the affected versions listed by the official vendor https://trueconf.com/blog/news/security-fixes-updates-and-advisories

【CVE-2026-73570】Please refer to the affected versions listed by the official vendor https://wiki.zimbra.com/wiki/Zimbra_Security_Advisories

[Recommended Actions]

【CVE-2025-62593】The official vendor has released a remediation update for the vulnerability. Please update to the relevant version https://github.com/ray-project/ray/security/advisories/GHSA-q279-jhrf-cc6v

【CVE-2026-33824】The official vendor has released a remediation update for the vulnerability. Please update to the relevant version https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-33824

【CVE-2026-59310】The official vendor has released a remediation update for the vulnerability. Please update to the relevant version https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/38017

【CVE-2026-55040】The official vendor has released a remediation update for the vulnerability. Please update to the relevant version https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55040

【CVE-2026-65400】The official vendor has released a remediation update for the vulnerability. Please update to the relevant version https://support.apple.com/en-us/100100

【CVE-2026-64849】The official vendor has released a remediation update for the vulnerability. Please update to the relevant version https://github.com/mlflow/mlflow/security/advisories/GHSA-7gwp-5pfp-969j

【CVE-2026-72530】The official vendor has released a remediation update for the vulnerability. Please update to the relevant version https://trueconf.com/blog/news/security-fixes-updates-and-advisories

【CVE-2026-72529】The official vendor has released a remediation update for the vulnerability. Please update to the relevant version https://trueconf.com/blog/news/security-fixes-updates-and-advisories

【CVE-2026-73570】The official vendor has released a remediation update for the vulnerability. Please update to the relevant version https://wiki.zimbra.com/wiki/Zimbra_Security_Advisories

[Reference]

(This notification is for informational purposes only and does not constitute a cybersecurity incident).
If you have questions or suggestions regarding this notification, please feel free to contact us.
Ministry of education information & communication security contingency platform
Website: https://info.cert.tanet.edu.tw/
Phone: +886-7-5250211
Internet Phone: 98400000
E-Mail: service@cert.tanet.edu.tw
Organizer: Computer Center
Click Num: