- ## Þjóðarleysa Þjóðarleysa á 13. ágúst 2026 er meðgild á algengum, kritískum veikleikum sem krefjast augljósar uppfærslu á kerfisstjórnun og aukinni, áherslumálaðri átökum. **Í virkri nýtingu** er staðfest fyrir fjölmörg kritískar veikleika, t.d. kritískan NGINX RCE veikleika (CVE-2026-42945) og Microsoft Exchange XSS veikleika (CVE-2026-42897). **LiteLLM PyPI aðfangakeðja átök** hefur aukast, nú skýrt að hafa áhrif á yfir 2.100 fyrirtækjum. Auk þess, nýtt átak á **pólska kraftkerfi** sýnir kritískt riska fyrir OT netkerfi á meðal annars með eignarþjónustu (APN) og aðgengi á eftirfarandi netkerfi. ## ⚠️ Þarf augljós aðgerð
- *Kritísk NGINX veikleika er í virkri nýtingu fyrir RCE** Heap biðminnisskrun (CVE-2026-42945, CVSS 8.1) í NGINX's `ngx_http_rewrite_module` leyfir óauðkenndar fjarkeyrslu kóða eða þjónustuneitun. Í virkri nýtingu og sönnun á virkni er skýrt.
- *CVE:** CVE-2026-42945 (CVSS: 8.1)
- *Staða:** Í virkri nýtingu
- *Veikar útgáfur:** NGINX Open Source útgáfur 1.0.0 til 1.24.x
- *Lagfært í:** Ekki tilgreint í heimildum — skoðið tilkynningu framleiðanda
- *Tímabundin lausn:** Ekkert nefnt í heimildum
- *Heimild:** [BSI Þýskaland: [NEU] [hoch] NGINX: Mehrere Schwachstellen](https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-2798)
- *Microsoft Exchange Server XSS veikleika er í virkri nýtingu** Kritísk cross-site scripting veikleika (CVE-2026-42897, CVSS 8.1) í Microsoft Exchange Server leyfir að hægt sé að keyra óskýrða JavaScript með óskýrðum póstum, sem leiðir til aðgerða án auðkenningar.
- *CVE:** CVE-2026-42897 (CVSS: 8.1)
- *Staða:** Í virkri nýtingu
- *Veikar útgáfur:** Microsoft Exchange Server 2016, 2019 og Subscription Edition (ekkert útgáfur nefnd)
- *Lagfært í:** Uppfærslur í júní 2026
- *Tímabundin lausn:** Ekkert nefnt í heimildum
- *Heimild:** [Help Net Security: Laundry Bear’s new Microsoft Exchange attack triggers on email open (CVE-2026-42](https://www.helpnetsecurity.com/?p=380088)
- *Ivanti EPM veikleikar eru í virkri nýtingu, CISA krefst uppfærslu** Fjölmörg Ivanti Endpoint Manager (EPM) veikleikar, t.d. CVE-2026-1603 (CVSS 8.6) og CVE-2026-1340 (CVSS 9.8), eru í virkri nýtingu, sem leyfir að hægt sé að skila auðkenni og keyra kóða fjarlægð.
- *CVE:** CVE-2026-1603 (CVSS: 8.6), CVE-2026-1340 (CVSS: 9.8)
- *Staða:** Í virkri nýtingu
- *Veikar útgáfur:** Ivanti EPM útgáfur fyrir 2024; Ivanti EPMM útgáfur fyrir 12.7.0.0
- *Lagfært í:** Uppfærslur tilbúar frá Ivanti
- *Tímabundin lausn:** Ekkert nefnt í heimildum
- *Heimild:** [SC Media: Federal agencies ordered to patch Ivanti EPMM zero-day in 3 days](https://www.scworld.com/news/federal-agencies-ordered-to-patch-ivanti-epmm-zero-day-in-3-days)
- *Adobe ColdFusion fjölmörg kritískar RCE veikleikar** Adobe hefur uppfært yfir 55 kritískar veikleikar í ColdFusion, með fjölmörgum CVSS 10.0 veikleikum sem leyfa fjarkeyrslu kóða og réttindaaukning. Fjölmörg eru í CISA's KEV katalogi.
- *CVE:** Fjölmörg, t.d. CVE-2026-48282, CVE-2026-48316, CVE-2026-48315 (CVSS: Ekki tilgreint)
- *Staða:** Í virkri nýtingu
- *Veikar útgáfur:** ColdFusion 2023 og 2025 fyrir ákveðnar uppfærslur
- *Lagfært í:** Uppfærslur tilbúar frá Adobe
- *Tímabundin lausn:** Ekkert nefnt í heimildum
- *Heimild:** [The Hacker News: Adobe Patches Three CVSS 10.0 ColdFusion and Campaign Classic Flaws](https://thehackernews.com/2026/08/adobe-patches-three-cvss-100-coldfusion.html)
- *IBM WebSphere kritískar veikleikar í auðkenningu og RCE** Fjölmörg kritískar veikleikar í IBM WebSphere Application Server og Liberty leyfa fjarlægðar aðgengi, keyrslu kóða og þjónustuneitun.
- *CVE:** Ekki tilgreint í heimildum — skoðið tilkynningu framleiðanda
- *Staða:** Birt
- *Veikar útgáfur:** Útgáfur fyrir 9.0.5.29 og 8.5.5.31
- *Lagfært í:** Uppfærslur tilbúar frá IBM
- *Tímabundin lausn:** Ekkert nefnt í heimildum
- *Heimild:** [BSI Þýskaland: [NEU] [hoch] IBM WebSphere Application Server und Application Server Liberty: Me](https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-2564) ## 🔍 Átöksháttur
- *🏢 Pólska kraftkerfi átaka með eignarþjónustu (APN) og Fortinet kerfi:** Átökendur hafðu áhrif á pólska kraftkerfi með því að fyrst nota aðgengi á Fortinet kerfi, síðan nota aðgengi á eignarþjónustu (APN) sem skjóðaða veg í operatískum netkerfi (OT). Þetta sýnir nýjan átaksháttur sem áhrifar á kritískar náttúrukerfi.
- *Lazarus Group notar Windows zero-day:** Norður-Kóreanska Lazarus Group notar CVE-2026-68820, Windows réttindaaukninga zero-day, í áherslumálaðum átökum á vörnarmáli með óskýrðum starfsmannsáætlunum og trojanuðum PDF skjölum sem lúr.
- *Gunra gíslatökuhugbúnað notar þekktar veikleikar:** Gunra gíslatökuhugbúnað notar þekktar veikleikar í Fortinet (CVE-2025-24472) og Schneider Electric (CVE-2024-55591) kerfum fyrir fyrstu aðgengi og MFA framhjáhlaup.
- *Kali365 netveiðarplattform býr til MFA:** Phishing-as-a-service (PhaaS) plattform kallar Kali365 er aðgengi Microsoft 365 notendum með því að sækja OAuth token með netveiðar, sem leyfir framhjáhlaup MFA án að hafa aðgang að lykilorðum.
- *LiteLLM PyPI aðfangakeðja átök hefur aukast:** Það óskýrða aðgengi á LiteLLM Python pakkanum (útgáfur 1.82.7 og 1.82.8) hefur aukast, með nýjum tilföllum sem sýna að yfir 2.100 fyrirtækjum hafa áhrif. Átak, sem hefur upprun áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður áður á
## Executive Summary The threat landscape on August 13, 2026, is characterized by widespread, critical vulnerabilities requiring immediate patching across core enterprise infrastructure and a surge in sophisticated, targeted attacks. **Active exploitation** is confirmed for multiple high-profile vulnerabilities, including a critical NGINX RCE flaw (CVE-2026-42945) and a Microsoft Exchange XSS vulnerability (CVE-2026-42897). The **LiteLLM PyPI supply chain attack** has escalated, now reported to have impacted over 2,100 organizations. Additionally, a novel attack on a **Polish power plant** demonstrates the critical risk of OT network compromise via private cellular networks (APNs) and compromised edge devices.
## ⚠️ Immediate Action Required * **Critical NGINX Flaw Actively Exploited for RCE** A heap buffer overflow (CVE-2026-42945, CVSS 8.1) in NGINX's `ngx_http_rewrite_module` allows unauthenticated remote code execution or denial of service. Active exploitation and proof-of-concept code are reported. * **CVE:** CVE-2026-42945 (CVSS: 8.1) * **Status:** Active exploitation detected * **Vulnerable:** NGINX Open Source versions 1.0.0 through 1.24.x * **Fixed:** Not specified in source — check vendor advisory * **Workaround:** None mentioned in source * **Reference:** [BSI Germany: [NEU] [hoch] NGINX: Mehrere Schwachstellen](https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-2798)
* **Microsoft Exchange Server XSS Vulnerability Exploited** A critical cross-site scripting vulnerability (CVE-2026-42897, CVSS 8.1) in Microsoft Exchange Server allows attackers to execute arbitrary JavaScript via malicious emails, leading to spoofing and code execution without authentication. * **CVE:** CVE-2026-42897 (CVSS: 8.1) * **Status:** Active exploitation detected * **Vulnerable:** Microsoft Exchange Server 2016, 2019, and Subscription Edition (specific versions not listed) * **Fixed:** Patches included in June 2026 security updates * **Workaround:** None mentioned in source * **Reference:** [Help Net Security: Laundry Bear’s new Microsoft Exchange attack triggers on email open (CVE-2026-42](https://www.helpnetsecurity.com/?p=380088)
* **Ivanti EPM Vulnerabilities Under Active Attack, CISA Mandates Patching** Multiple Ivanti Endpoint Manager (EPM) vulnerabilities, including CVE-2026-1603 (CVSS 8.6) and CVE-2026-1340 (CVSS 9.8), are being actively exploited, allowing credential leaks and remote code execution. * **CVE:** CVE-2026-1603 (CVSS: 8.6), CVE-2026-1340 (CVSS: 9.8) * **Status:** Active exploitation detected * **Vulnerable:** Ivanti EPM versions prior to 2024; Ivanti EPMM versions prior to 12.7.0.0 * **Fixed:** Patches available from Ivanti * **Workaround:** None mentioned in source * **Reference:** [SC Media: Federal agencies ordered to patch Ivanti EPMM zero-day in 3 days](https://www.scworld.com/news/federal-agencies-ordered-to-patch-ivanti-epmm-zero-day-in-3-days)
* **Adobe ColdFusion Multiple Critical RCE Vulnerabilities** Adobe has patched over 55 critical vulnerabilities in ColdFusion, including multiple CVSS 10.0-rated flaws enabling remote code execution and privilege escalation. Several are listed on CISA's KEV catalog. * **CVE:** Multiple, including CVE-2026-48282, CVE-2026-48316, CVE-2026-48315 (CVSS: Not specified) * **Status:** Active exploitation detected * **Vulnerable:** ColdFusion 2023 and 2025 prior to specific updates * **Fixed:** Patches available from Adobe * **Workaround:** None mentioned in source * **Reference:** [The Hacker News: Adobe Patches Three CVSS 10.0 ColdFusion and Campaign Classic Flaws](https://thehackernews.com/2026/08/adobe-patches-three-cvss-100-coldfusion.html)
* **IBM WebSphere Critical Security Bypass and RCE Flaws** Multiple critical vulnerabilities in IBM WebSphere Application Server and Liberty allow remote attackers to bypass security controls, execute arbitrary code, and cause denial of service. * **CVE:** Not specified in source — check vendor advisory * **Status:** Disclosed * **Vulnerable:** Versions prior to 9.0.5.29 and 8.5.5.31 * **Fixed:** Patches available from IBM * **Workaround:** None mentioned in source * **Reference:** [BSI Germany: [NEU] [hoch] IBM WebSphere Application Server und Application Server Liberty: Me](https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-2564)
## 🔍 Threat Activity * **🏢 Polish CHP Plant Breached via Private APN and Fortinet Device:** Attackers compromised a Polish combined heat and power plant by first exploiting a Fortinet device, then using a compromised private cellular network (APN) as a stealthy tunnel for lateral movement into the operational technology (OT) network. This highlights a novel attack vector targeting critical infrastructure. * **Lazarus Group Exploits Windows Zero-Day:** The North Korean Lazarus Group is exploiting CVE-2026-68820, a Windows privilege escalation zero-day, in targeted attacks against the defense sector using fake job offers and trojanized PDFs as lures. * **Gunra Ransomware Leverages Known Flaws:** The Gunra ransomware operation is exploiting known vulnerabilities in Fortinet (CVE-2025-24472) and Schneider Electric (CVE-2024-55591) devices for initial network access and MFA bypass. * **Kali365 Phishing Kit Bypasses MFA:** A phishing-as-a-service (PhaaS) platform named Kali365 is actively targeting Microsoft 365 users by stealing OAuth tokens via device code phishing, effectively bypassing multi-factor authentication without stealing passwords. * **LiteLLM PyPI Supply Chain Attack Escalates:** The malicious compromise of the LiteLLM Python package (versions 1.82.7 and 1.82.8) has escalated, with new reports indicating over 2,100 organizations impacted. The attack, which originated from a poisoned CI/CD pipeline (Trivy scanner), harvested developer credentials at scale.
## 📋 Patches & Updates * **🏢 Zoom Patches Critical Zero-Click RCE Flaws ("Zoomsday"):** Zoom has released patches for critical zero-click remote code execution vulnerabilities (CVE-2026-53413, CVE-2026-53414, CVE-2026-53415) in its annotation feature. Attackers could compromise meeting participants without any user interaction. * **Microsoft Edge Multiple Critical Vulnerabilities:** Critical vulnerabilities in Microsoft Edge (versions prior to 146.0.7680.75) allow remote code execution and information disclosure. Patches are available via updates to the latest version. * **Google Chrome Zero-Day (CVE-2026-2441) Patched:** Google has released Chrome version 145 to address an actively exploited zero-day vulnerability (CVE-2026-2441) that allowed remote code execution. * **ClamAV Denial of Service Vulnerabilities:** Multiple high-severity Denial of Service vulnerabilities in ClamAV (e.g., CVE-2026-20348) affect various versions and downstream products, including Cisco Secure Endpoint Connector. Patches are available. * **MongoDB Multiple Critical Vulnerabilities:** MongoDB has released patches for multiple critical vulnerabilities allowing remote code execution, information disclosure, and denial of service. Users of affected versions are at high risk.
## Today's Priorities 1. **Patch NGINX and Microsoft Exchange Immediately:** Prioritize patching for NGINX (CVE-2026-42945) and Microsoft Exchange Server (CVE-2026-42897) due to confirmed active exploitation. 2. **Review and Patch Ivanti EPM/EPMM:** Verify your Ivanti Endpoint Manager and Endpoint Manager Mobile versions against the advisories for CVE-2026-1603 and CVE-2026-1340. CISA has mandated a short patching deadline for federal agencies, indicating high risk. 3. **Audit Python Development Environments:** If your organization uses the LiteLLM Python package, scan for versions 1.82.7 and 1.82.8, remove them, and rotate all credentials that may have been exposed on affected developer systems. 4. **Assess OT Network Segmentation:** Review the security of private cellular networks (APNs) and the segmentation between IT and OT networks, in light of the Polish power plant attack. Ensure edge security devices (e.g., Fortinet) are fully patched.
## 🔗 References
- [BSI Germany: [NEU] [hoch] NGINX: Mehrere Schwachstellen](https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-2798)
- [Help Net Security: Laundry Bear’s new Microsoft Exchange attack triggers on email open (CVE-2026-42](https://www.helpnetsecurity.com/?p=380088)
- [The Hacker News: Malicious LiteLLM Releases Tied to Trivy Hack May Have Exposed 2,100+ Organizati](https://thehackernews.com/2026/08/malicious-litellm-releases-tied-to.html)
- [SC Media: Attackers breach Polish CHP plant using private APN and Fortinet device](https://www.scworld.com/brief/attackers-breach-polish-chp-plant-using-private-apn-and-fortinet-device)
- [SC Media: Federal agencies ordered to patch Ivanti EPMM zero-day in 3 days](https://www.scworld.com/news/federal-agencies-ordered-to-patch-ivanti-epmm-zero-day-in-3-days)