Trustity Threat Briefing
Trustity Threat Briefing - Week of 2026-08-10
Week of 2026-08-10
This week, we highlight critical vulnerabilities affecting various enterprise applications and systems, particularly those that could lead to unauthorized access or denial of service. Key vulnerabilities include a heap inspection flaw in Cisco Secure Firewall and a use-after-free vulnerability in Microsoft Windows. Additionally, several applications such as Metabase and JetBrains TeamCity are affected by vulnerabilities that could allow remote code execution or SQL injection, posing significant risks to data integrity and system availability. Immediate attention is recommended to mitigate these threats.
What to watch
CVE-2026-20349CVE-2026-20349
Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) contain a heap inspection vulnerability that could allow an unauthenticated, remote attacker to cause the device to reload unexpectedly, resulting in a denial of service (DoS) condition.
CVE-2026-68820CVE-2026-68820
Microsoft Windows Ancillary Function Driver for WinSock contains a use-after-free vulnerability that allows an authorized attacker to elevate privileges locally.
CVE-2026-72898CVE-2026-72898
Metabase contains a SQL Injection vulnerability that allows an unauthenticated remote attacker to inject arbitrary SQL into the Metabase application database, potentially granting administrator access.
CVE-2026-63077CVE-2026-63077
JetBrains TeamCity contains a deserialization of untrusted data vulnerability that could allow unauthenticated remote code execution via the agent polling protocol.
CVE-2026-18556CVE-2026-18556
N-able N-central contains an authentication bypass using an alternate path or channel that allows for authentication bypass.
Sources
Public cyber threat intelligence for awareness. Not a substitute for incident response or a formal security assessment.
