Wednesday, September 2, 2026
banner

The week of August 10–16, 2026 produced a patching queue that reaches from internet-facing Macs and VPN appliances to collaboration clients, browsers, and privileged Windows drivers. The most urgent item is not simply the vulnerability with the highest score. It is the issue for which exploitation has been observed and exposure is easy to verify: CVE-2026-65400 in macOS Screen Sharing.

This security week in review organizes the work as fix now → investigate → reduce repeat exposure. Use it as a Monday handoff for endpoint, network, vulnerability-management, and incident-response teams.

Fix now

Patch exposed macOS Screen Sharing systems

Apple fixed CVE-2026-65400 in macOS Tahoe 26.6.1, Sequoia 15.7.9, and Sonoma 14.8.9. The flaw can allow a network attacker to authenticate to Screen Sharing without valid credentials. On August 12, the Netherlands’ NCSC updated its advisory to say that public proof-of-concept code was available and active exploitation had been observed on multiple systems with TCP port 5900 exposed to the internet. In every incident reported to the agency, the attacker obtained root access and installed a Monero miner.

Inventory Macs with Screen Sharing or Remote Management enabled, confirm whether port 5900 is reachable from untrusted networks, and deploy the applicable update. If immediate patching is impossible, remove public exposure and disable the service until the system can be updated.

Apply the August Windows security updates

Microsoft released its August security updates on August 11. One item deserves priority because CISA added it to the Known Exploited Vulnerabilities catalog: CVE-2026-68820, a use-after-free flaw in the Windows Ancillary Function Driver for WinSock. Treat it as a post-compromise privilege-escalation path. Updating closes the vulnerability, but high-value systems also need a review for signs that a low-privileged foothold became SYSTEM before the patch arrived.

Update Zoom, Chrome, and affected ASUS utilities

Zoom’s ZSB-26015 bulletin addresses memory-safety problems in the annotation function. CVE-2026-53413 is a high-severity out-of-bounds write that could let a meeting participant execute code on another participant’s client. Organizations should update managed Zoom clients and verify the running build, not only the deployment job.

Google released Chrome 151.0.7922.137/.138 for Windows and macOS and 151.0.7922.137 for Linux. The release fixes five high-severity use-after-free vulnerabilities affecting V8, TabStrip, Extensions, HTML, and Blink. Google did not state that these bugs were being exploited, but browser reach and the memory-corruption class justify rapid rollout.

ASUS disclosed CVE-2026-8917 in GPU Tweak III, GPU Tweak II, AI Suite 3, and a related VGAdll component. The vulnerable driver interface can allow a local attacker to write to an arbitrary memory address and potentially escalate privileges. Inventory the utilities, deploy vendor-fixed builds, and remove them from systems that do not need them.

Investigate

Check the August 11 CISA KEV additions

CISA added three vulnerabilities with evidence of exploitation:

  • CVE-2026-20349 in Cisco ASA and FTD.
  • CVE-2026-68820 in the Windows Ancillary Function Driver for WinSock.
  • CVE-2026-72898 in Metabase.

Build an asset list for all three. For externally reachable Cisco and Metabase systems, record exposure, current version, patch status, and the earliest reliable log timestamp. For Windows, prioritize systems where attackers could already have low-privileged code execution. A patch-complete dashboard is not an incident-response conclusion.

Read the Gunra advisory as an intrusion playbook

A joint advisory from the FBI, CISA, NSA, DC3, the U.S. Secret Service, and South Korea’s KNPA describes Gunra ransomware as a ransomware-as-a-service operation using double extortion. Observed access paths include known flaws in internet-facing firewalls and VPN gateways, weak or default credentials, stolen session information, and modified authentication logic that enabled an attacker-selected one-time password.

Gunra affiliates used tools such as Impacket, RClone, FileZilla, AnyDesk, Mimikatz, and 7-Zip. These programs can be legitimate, so a filename alone is not proof of compromise. Hunt for unexpected execution context, unusual parent processes, late-night administrative activity, credential dumping, large archive creation, cloud-storage exfiltration, shadow-copy deletion, and lateral movement over SMB or RDP.

Reduce repeat exposure

  1. Remove direct administrative exposure. Screen Sharing, VPN management, Metabase, and device administration should not be reachable from the public internet unless the architecture explicitly requires and protects it.
  2. Verify patches by running version. Deployment success, package download, and actual execution of the fixed build are different states.
  3. Protect the authentication path. MFA is necessary, but session theft and tampering with authentication components can bypass a nominally protected login.
  4. Keep immutable recovery copies. The Gunra advisory emphasizes offline, segmented, tested backups because attackers may target both primary and disaster-recovery infrastructure.
  5. Preserve evidence before cleanup. Collect logs and volatile indicators before rotating credentials, removing tools, or rebuilding systems.

Monday handoff

Priority Owner Proof of completion
macOS CVE-2026-65400 Endpoint and network teams Fixed OS version; no public port 5900 exposure
August Windows updates Endpoint management Installed update, reboot completed, high-value hosts reviewed
CISA KEV triage Vulnerability management Asset matches, exposure, patch and investigation status
Zoom and Chrome Application management Running fixed versions on managed devices
ASUS utilities Endpoint engineering Inventory, patched or removed vulnerable components
Gunra readiness Incident response Hunts completed; immutable restore test passed

Sources

banner
Choose your TOTP token

Newsletter

Subscribe our Newsletter for new blog posts & tips. Let's stay updated!

banner

Leave a Comment

This website uses cookies to improve your experience. We'll assume you're ok with this, but you can opt-out if you wish. Accept