[REVISION HISTORY]
Software vulnerability exploits & patch response, 2026
Updated 10 times since CLSTR started tracking revisions of this situation.
What changed
2026-09-03 15:14 UTC → 2026-09-06 16:08 UTC ·
added
removed
The wave of exploitation observed in July 2026 continued into August, with significant impacts on government infrastructure and core operating systems. In Switzerland, the breach of federal SharePoint servers was further detailed. Unknown actors exploited CVE-2026-56164 and CVE-2026-50522 to access the Federal Office for Information Technology and Telecommunication (BIT) servers. The breach, detected on 28 July 2026, resulted in the compromise of approximately 200 user and technical accounts. In response, the Swiss government isolated the servers, disconnected them from the internet, and initiated a full environment rebuild. While BIT is working with Microsoft and the Federal Office for Cybersecurity (BACS) on forensics, officials stated that no confidential or sensitive personal data is believed to have been stored on the platform, and no evidence of dark web exfiltration has been found. Simultaneously, Microsoft’s August security updates addressed 398 vulnerabilities, including 62 critical flaws. A notable active exploit, CVE-2026-68820, targets a use-after-free error in the Windows Ancillary Function Driver for WinSock (afd.sys). New disclosures in mid-August highlighted further critical risks. Oasis Security identified CVE-2026-41679, a CVSS 10.0 vulnerability in the Paperclip orchestration platform. Researchers also identified an unauthenticated RCE chain in Microsoft SharePoint, combining a JWT authentication-bypass (CVE-2026-55040) with a flaw in Business Connectivity Services (CVE-2026-63520). Further research uncovered complex chains targeting the Windows kernel and hypervisor, dubbed ‘Download More RAM,’ which can bypass Virtualization-Based Security (VBS). Additionally, a vulnerability in Microsoft System Center Configuration Manager (SCCM) allows remote code execution via an authorization issue and a path traversal flaw known as ‘CabSlip.’ In late August, Microsoft addressed CVE-2026-50522 in SharePoint, involving untrusted data deserialization. Concurrently, Microsoft disclosed a critical remote code execution (RCE) vulnerability in Entra ID, tracked as CVE-2026-69836. In early September 2026, new critical vulnerabilities emerged.
Versions
- 2026-09-06 16:08 UTC Software vulnerability exploits & patch response, 2026
- 2026-09-03 15:14 UTC Software vulnerability exploits & patch response, 2026
- 2026-08-25 06:07 UTC Software vulnerability exploits & patch response, 2026
- 2026-08-23 01:21 UTC Software vulnerability exploits & patch response, 2026
- 2026-08-22 15:21 UTC Software vulnerability exploits & patch response, 2026
- 2026-08-21 04:44 UTC Software vulnerability exploits & patch response, 2026
- 2026-08-17 12:06 UTC Software vulnerability exploits & patch response, 2026
- 2026-08-12 11:19 UTC Software vulnerability exploits & patch response, 2026
- 2026-08-12 06:28 UTC Software vulnerability exploits & patch response, 2026
- 2026-08-08 08:34 UTC Software vulnerability exploits & patch response, 2026
- 2026-07-30 23:16 UTC Software vulnerability exploits & patch response, July 2026
Only revisions since CLSTR began indexing content versions appear here. Select a version to see what changed compared to the one before it.