- ## Öfugt samanfletting Þjóðarhættulegar birtir á 13. ágúst 2026 eru stjórnaðar af **breiddu, í virkri nýtingu veikleikum** í grunnþjónustu fyrirtækja. Þarf að taka áherslu á **VMware vCenter** (CVE-2026-59310), sem er nýtt á heimsvísu innan daga eftir birtingu, og **WordPress "wp2shell"** RCE-þátt, sem er í massa nýtingu. Aðfangakeðja-áráðstöður **LiteLLM** hafa vaxið, nú kynnt að hafa áhrif á yfir 2.100 fyrirtæki. Auk þess, sýnilegar netveiðarhópar eins og **Kali365** eru vel að framkvæma MFA til að skemmta Microsoft 365 notanda, sem lýsir mikilli hættu við að fá aðgang að auðkenningum. ## ⚠️ Þarf að taka áherslu á augnablik
- *🏢 VMware vCenter/ESXi er í virkri nýtingu fyrir fjarveit** Þjófnendur notar CVE-2026-59310 til að fá aðgang að vCenter kerfum. Nýting hefur verið skoðuð í 47 landum innan fimm daga eftir birtingu, sem sýnir hraða í nýtingu.
- *CVE:** CVE-2026-59310 (CVSS: Ekki tilgreint)
- *Staða:** Í virkri nýtingu
- *Veikar útgáfur:** Ekki tilgreint í heimildum — skoðið tilkynningu framleiðanda
- *Lagfært í:** Ekki tilgreint í heimildum — skoðið tilkynningu framleiðanda
- *Tímabundin lausn:** Ekkert nefnt í heimildum
- *Heimild:** [Infosecurity Magazine: vCenter veikleiki nýtt innan fimm daga eftir birtingu](https://www.infosecurity-magazine.com/news/vcenter-cve-2026-59310-exploited/)
- *WordPress Core "wp2shell" óþýðingaræður fjarkeyrslu kóða** Kritískur veikleikshópur í WordPress kerfi leyfir óþýðingaræður fjarkeyrslu kóða með REST API og SQL-injúksföllum. Opinberar hagnýtingar eru til staðar, sem leiðir til breiddu nýtingu.
- *CVE:** CVE-2026-63030, CVE-2026-60137 (CVSS: Ekki tilgreint)
- *Staða:** Í virkri nýtingu, sönnun á virkni (PoC) tiltækt
- *Veikar útgáfur:** WordPress 6.9.0-6.9.4, 7.0.0-7.0.1
- *Lagfært í:** WordPress 6.9.5, 7.0.2
- *Tímabundin lausn:** Ekkert nefnt í heimildum
- *Heimild:** [FortiGuard Outbreak Alerts: WP2Shell RCE](https://fortiguard.fortinet.com/outbreak-alert/wp2shell-rce)
- *🏢 Fortinet FortiWeb auðkenningarframhjáhlaup** Fjölmörg kritískir veikleikar í Fortinet FortiWeb leyfa óþýðingaræður aðgang að kerfi, keyrslu kóða eða þjónustuneitun.
- *CVE:** Fjölmörg (CVSS: Allt að 9.8)
- *Staða:** Birt
- *Veikar útgáfur:** Útgáfur fyrir 8.0.4 og 7.6.7
- *Lagfært í:** FortiWeb 8.0.4, 7.6.7
- *Tímabundin lausn:** Ekkert nefnt í heimildum
- *Heimild:** [BSI Germany: [NEU] [hoch] Fortinet FortiWeb: Mehrere Schwachstellen ermöglichen Umgehen von S](https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-2810)
- *Lazarus Group notar Windows núll-daga veikleika (CVE-2026-68820)** North Korean Lazarus APT notar Windows réttindaaukning núll-daga veikleika (CVE-2026-68820) í ákveðnum áráðstöðum á vörnarmáli, með ósönnu starfsmannsáætlun sem hætta.
- *CVE:** CVE-2026-68820 (CVSS: Ekki tilgreint)
- *Staða:** Í virkri nýtingu
- *Veikar útgáfur:** Ekki tilgreint í heimildum — skoðið tilkynningu framleiðanda
- *Lagfært í:** Uppfærð af Microsoft; CISA hefur beðið um uppfærslu.
- *Tímabundin lausn:** Ekkert nefnt í heimildum
- *Heimild:** [The Hacker News: Lazarus notar Windows núll-daga veikleika til að fá SYSTEM aðgang og setja innbrot](https://thehackernews.com/2026/08/lazarus-exploits-windows-zero-day-to.html) ## 🔍 Þjóðarhættulegar aðgerðir
- *Gunra gíslatökuhugbúnaður notar Fortinet og Schneider veikleika:** Gunra gíslatökuhugbúnaður notar veikleika í Fortinet (FortiOS, FortiProxy) og Schneider Electric (PowerLogic P5) tækin til að fá fyrstu aðgang að netinu og framhjá MFA, ákveðin á vörnarmáli.
- *Kali365 netveiðarhópar framhjá MFA:** Þýðingarhópur sem heitir Kali365 er á að framkvæma MFA með að fá OAuth aðgangslykli með netveiðum, sem gefur aðgang án að nota lykilorð.
- *LiteLLM aðfangakeðja-áráðstöður breiddast:** Þýðingarhópurinn LiteLLM Python pakka, sem hefur verið áhrif á 2.100 fyrirtæki, hefur leitt til aðgangs að auðkenningum úr útvega kerfum. ## 📋 Uppfærslur og uppfærslur
- *🏢 Palo Alto PAN-OS:** Fjölmörg kritískir veikleikar leyfa RCE, þjónustuneitun og aðgang að upplýsingum hafa verið lagaðir. Þau eru ávöxtuð á PAN-OS 12.1 og eldri.
- *🏢 Microsoft Defender "RoguePlanet":** Microsoft hefur lagað CVE-2026-50656, núll-daga réttindaaukning veikleika í Defender fyrir Windows 10/11, sem var í virkri nýtingu.
- *Zoom "Zoomsday" núll-daga fjarkeyrslu kóða:** Zoom hefur gefið út uppfærslur fyrir kritískar núll-daga fjarkeyrslu kóða (CVE-2026-53413-15) í annaðhliðarþátt sem getur leyft einum deiluþátttakanda að skemmta annan.
- *Adobe ColdFusion:** Adobe hefur lagað yfir 55 kritískar veikleikar, með fjölmörgum með CVSS 10.0 stig, í ColdFusion 2023 og 2025. Sumar eru í virkri nýtingu.
- *Progress MOVEit:** Kritískar auðkenningarframhjáhlaup og aðrar veikleikar (CVE-2026-4670, CVE-2026-5174) hafa verið lagaðir í MOVEit Automation og Transfer. Athugið: Það er tengt fyrri MOVEit Transfer atburðum. Kerfi sem eru uppfærð eru aðeins fyrir eldri vandamál, en geta ennþá verið veikar — skoðið núverandi uppfærslu. ## Daglegar áætlanir 1. **Uppfæra VMware vCenter/ESXi á augnablik.** Athugaðu að kerfi eru uppfærð með uppfærslum fyrir CVE-2026-59310, vegna hraðar og breiddar nýtingar. 2. **Uppfæra öll WordPress kerfi til 6.9.5/7.0.4 eða nýrra** til að minnka nýtingu "wp2shell" RCE-þátt. 3. **Skoðaðu Fortinet FortiWeb útgáfur** fyrir 8.0.4/7.6.7 og skrifaðu uppfærslur til að laga kritískar auðkenningarframhjáhlaup. 4. **Athugaðu útvega kerfi og CI/CD aðferðir** fyrir veikar LiteLLM pakka (útgáfur 1.82.7, 1.82.8) og breyta öllum aðgengslslykli. ## 🔗 Heimildir - [Infosecurity Magazine: vCenter veikleiki nýtt innan fimm daga eftir birtingu](https://www.infosecurity-magazine.com/news/vcenter-cve-2026-59310-exploited/) - [FortiGuard Outbreak Alerts: WP2Shell RCE](https://fortiguard.fortinet.com/outbreak-alert/wp2shell-rce) - [BSI Germany: [NEU] [hoch] Fortinet FortiWeb: Mehrere Schwachstellen ermöglichen Umgehen von S](https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-2810) - [The Hacker News: Kali365 notar Microsoft auðkenningu gegn Bandaríkisfyrirtækjum: Nýja fyrirtækja](https://thehackernews.com/2026/08/kali365-weaponizes-microsoft.html) - [The Hacker News: Þýðingarhópur LiteLLM útgáfur tengd Trivy hættu geta verið að aðgengja 2.100+ fyrirtæki](https://thehackernews.com/2026/08/malicious-litellm-releases-tied-to.html)
## Executive Summary The threat landscape on August 13, 2026, is dominated by **widespread, active exploitation of critical vulnerabilities** in foundational enterprise software. Immediate attention is required for **VMware vCenter** (CVE-2026-59310), which is being exploited globally within days of disclosure, and the **WordPress "wp2shell"** RCE chain, which is seeing mass exploitation. The **LiteLLM supply chain attack** has escalated, now confirmed to impact over 2,100 organizations. Additionally, sophisticated phishing campaigns like **Kali365** are successfully bypassing MFA to compromise Microsoft 365 accounts, representing a significant credential theft risk.
## ⚠️ Immediate Action Required
* **🏢 VMware vCenter/ESXi Actively Exploited for Remote Access** Attackers are exploiting CVE-2026-59310 to gain persistent remote access to VMware vCenter servers. Exploitation has been observed in 47 countries within five days of disclosure, indicating rapid weaponization. * **CVE:** CVE-2026-59310 (CVSS: Not specified) * **Status:** Active exploitation detected * **Vulnerable:** Not specified in source — check vendor advisory * **Fixed:** Not specified in source — check vendor advisory * **Workaround:** None mentioned in source * **Reference:** [Infosecurity Magazine: vCenter Flaw Exploited Just Five Days After Disclosure](https://www.infosecurity-magazine.com/news/vcenter-cve-2026-59310-exploited/)
* **WordPress Core "wp2shell" Unauthenticated RCE** A critical vulnerability chain in WordPress core allows unauthenticated remote code execution via REST API and SQL injection flaws. Public exploits are available, leading to widespread exploitation. * **CVE:** CVE-2026-63030, CVE-2026-60137 (CVSS: Not specified) * **Status:** Active exploitation detected, Proof of Concept available * **Vulnerable:** WordPress 6.9.0-6.9.4, 7.0.0-7.0.1 * **Fixed:** WordPress 6.9.5, 7.0.2 * **Workaround:** None mentioned in source * **Reference:** [FortiGuard Outbreak Alerts: WP2Shell RCE](https://fortiguard.fortinet.com/outbreak-alert/wp2shell-rce)
* **🏢 Fortinet FortiWeb Security Control Bypass** Multiple critical vulnerabilities in Fortinet FortiWeb allow unauthenticated attackers to bypass security controls, execute code, or cause denial of service. * **CVE:** Multiple (CVSS: Up to 9.8) * **Status:** Disclosed * **Vulnerable:** Versions prior to 8.0.4 and 7.6.7 * **Fixed:** FortiWeb 8.0.4, 7.6.7 * **Workaround:** None mentioned in source * **Reference:** [BSI Germany: [NEU] [hoch] Fortinet FortiWeb: Mehrere Schwachstellen ermöglichen Umgehen von S](https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-2810)
* **Lazarus Group Exploits Windows Zero-Day (CVE-2026-68820)** The North Korean Lazarus APT is exploiting a Windows privilege escalation zero-day (CVE-2026-68820) in targeted attacks against the defense sector, using fake job offers as a lure. * **CVE:** CVE-2026-68820 (CVSS: Not specified) * **Status:** Active exploitation detected * **Vulnerable:** Not specified in source — check vendor advisory * **Fixed:** Patched by Microsoft; CISA has mandated patching. * **Workaround:** None mentioned in source * **Reference:** [The Hacker News: Lazarus Exploits Windows Zero-Day to Gain SYSTEM Access and Deploy Backdoor](https://thehackernews.com/2026/08/lazarus-exploits-windows-zero-day-to.html)
## 🔍 Threat Activity * **Gunra Ransomware Leverages Fortinet & Schneider Flaws:** The Gunra ransomware operation is exploiting vulnerabilities in Fortinet (FortiOS, FortiProxy) and Schneider Electric (PowerLogic P5) devices to gain initial network access and bypass MFA, targeting critical infrastructure. * **Kali365 Phishing Kit Bypasses MFA:** A sophisticated Phishing-as-a-Service (PhaaS) platform named Kali365 is targeting Microsoft 365 accounts by stealing OAuth tokens via device code phishing, granting persistent access without needing passwords. * **LiteLLM Supply Chain Attack Impact Widens:** The malicious compromise of the LiteLLM Python package, originating from a poisoned CI/CD pipeline, has impacted over 2,100 organizations, leading to credential theft from developer systems.
## 📋 Patches & Updates * **🏢 Palo Alto PAN-OS:** Multiple critical vulnerabilities allowing RCE, DoS, and information disclosure have been patched. Affected versions include PAN-OS 12.1 and earlier. * **🏢 Microsoft Defender "RoguePlanet":** Microsoft has patched CVE-2026-50656, a zero-day local privilege escalation flaw in Defender for Windows 10/11 that was actively exploited. * **Zoom "Zoomsday" Zero-Click RCE:** Zoom has released patches for critical zero-click RCE vulnerabilities (CVE-2026-53413-15) in its annotation feature that could allow one meeting participant to compromise another. * **Adobe ColdFusion:** Adobe has patched over 55 critical vulnerabilities, including several with CVSS 10.0 scores, in ColdFusion 2023 and 2025. Some are under active exploitation. * **Progress MOVEit:** Critical authentication bypass and other vulnerabilities (CVE-2026-4670, CVE-2026-5174) have been patched in MOVEit Automation and Transfer. Note: Related to previous MOVEit Transfer incidents. Systems patched only for earlier issues may still be vulnerable — verify current patch level.
## Today's Priorities 1. **Patch VMware vCenter/ESXi immediately.** Verify systems are updated to versions patched for CVE-2026-59310, given its rapid, global exploitation. 2. **Update all WordPress instances to 6.9.5/7.0.4 or later** to mitigate the actively exploited "wp2shell" RCE chain. 3. **Review Fortinet FortiWeb deployments** for versions prior to 8.0.4/7.6.7 and apply updates to address critical security control bypass flaws. 4. **Audit developer environments and CI/CD pipelines** for the compromised LiteLLM packages (versions 1.82.7, 1.82.8) and rotate any exposed credentials.
## 🔗 References
- [Infosecurity Magazine: vCenter Flaw Exploited Just Five Days After Disclosure](https://www.infosecurity-magazine.com/news/vcenter-cve-2026-59310-exploited/)
- [FortiGuard Outbreak Alerts: WP2Shell RCE](https://fortiguard.fortinet.com/outbreak-alert/wp2shell-rce)
- [BSI Germany: [NEU] [hoch] Fortinet FortiWeb: Mehrere Schwachstellen ermöglichen Umgehen von S](https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-2810)
- [The Hacker News: Kali365 Weaponizes Microsoft Authentication Against US Companies: New Enterprise](https://thehackernews.com/2026/08/kali365-weaponizes-microsoft.html)
- [The Hacker News: Malicious LiteLLM Releases Tied to Trivy Hack May Have Exposed 2,100+ Organizati](https://thehackernews.com/2026/08/malicious-litellm-releases-tied-to.html)