421
CVEs patched in August 2026 Patch Tuesday, Microsoft's largest single monthly release of the year
9.8
CVSS score of CVE-2026-62878, the unauthenticated wormable Windows DNS Server RCE included in the August 11 release
8 of 14
SharePoint vulnerabilities CISA has flagged since 2021 that have been used directly in ransomware attacks
1.1 million
Records stolen from Lumenis by ShinyHunters ransomware this week, including customer PII and 176 GB of internal data

SponsoredHorizon3.ai

Proactive Security for the AI Era

NodeZero continuously and autonomously pentests infrastructure, identity, cloud, and now web applications, chaining weaknesses across every domain the way real attackers do. Every finding ships with replayable proof showing exploitable business impact, not theoretical risk.

See NodeZero WebApp in action

A wormable Windows DNS Server flaw rated CVSS 9.8 and a SharePoint deserialization vulnerability actively used in ransomware attacks are the two most urgent patches from the August 11, 2026 Patch Tuesday release, a 421-CVE drop that is the largest single Microsoft security release of the year.

CVE-2026-62878 is a stack-based buffer overflow in the Windows DNS Server service. An unauthenticated remote attacker sends a crafted DNS query that overflows a fixed-size stack buffer, overwrites the return address, and executes arbitrary code at SYSTEM privilege. Active Directory domain controllers run the DNS role by default, placing every enterprise using standard AD architecture in the direct blast radius. The wormable designation means a single compromised DNS server can propagate the exploit to every other exposed DNS server on the network without additional attacker interaction.

CVE-2026-45659 is the SharePoint deserialization flaw ransomware groups have been actively exploiting since early July 2026. A low-privileged attacker authenticates to SharePoint, submits a crafted serialization payload, achieves code execution as the IIS service account, and steals machine keys that produce persistent, token-based access surviving password resets. Resecurity documented an attack chain where operators moved from initial SharePoint access to domain controller compromise in under six hours using this exact technique. CISA added CVE-2026-45659 to its Known Exploited Vulnerabilities catalog with a three-day federal remediation deadline.

Three additional threats round out today's Monday Intel Drop: pre-authentication customer account hijacking in Adobe Commerce via CVE-2026-71362, a Cisco Secure Firewall heap inspection vulnerability on the CISA KEV list (CVE-2026-20349), and confirmed data exfiltration by Cl0p targeting Shell and by ShinyHunters targeting Lumenis with 1.1 million records stolen. Full remediation priority list and detection rules follow.

How Does CVE-2026-62878 Windows DNS Server Wormable RCE Work?

CVE-2026-62878 is a stack-based buffer overflow in dns.exe, the Windows DNS Server service process. A remote unauthenticated attacker sends a crafted DNS query containing a payload sized to overflow a fixed-size stack buffer in the DNS response-processing code path. The overflow overwrites the saved return address with attacker-controlled shellcode that executes at the privilege level of the DNS Server service, which runs as SYSTEM on Windows Server. No credentials are required. No user interaction is required. The attack is effective against any host listening on UDP or TCP port 53 with the DNS Server role active.

Security Affairs described CVE-2026-62878 as "a good ol' fashioned stack-based buffer overflow" and noted that a compromised DNS server running on a domain controller provides a direct path into Active Directory services including authentication, name resolution, and Group Policy distribution for the entire domain. The wormable designation confirms that an exploit can scan for and attack other reachable DNS servers autonomously, without additional human direction.

Affected systems include Windows Server 2025, Windows Server 2022, and Windows Server 2019 with the DNS Server role active. Standard Active Directory deployments place the DNS role on every domain controller, which means the highest-value servers in most enterprise environments are directly exposed.

Apply the fix from CVE-2026-62878 advisory: KB5121003 on Windows Server 2025 and KB5120249 on Windows Server 2022 and 2019 via Windows Update, WSUS, or direct MSU deployment. This cumulative update also resolves the Lazarus Group-exploited CVE-2026-68820 zero-day -- full details on that nation-state campaign are in the Lazarus FudModule 3.1 deep dive.

No confirmed exploitation of CVE-2026-62878 has been publicly reported as of August 17. Historical patterns with DNS server vulnerabilities show functional exploits typically emerge one to three weeks after patch release.

How Ransomware Groups Are Weaponizing SharePoint CVE-2026-45659

CVE-2026-45659 is a deserialization of untrusted data flaw in Microsoft SharePoint Server. Deserialization vulnerabilities occur when an application reconstructs attacker-supplied data back into executable .NET objects without validating the object type or content. The architectural root cause creates broad attack surface because the vulnerable code path handles routine SharePoint operations, making patch testing time-consuming and creating long deployment windows during which ransomware groups operate freely.

The documented attack chain begins with low-privilege SharePoint credentials obtained through phishing or credential stuffing. The attacker authenticates to the SharePoint web frontend and sends a crafted HTTP POST request to a SharePoint endpoint that processes serialized .NET objects. The server's deserialization routine reconstructs the malicious payload and executes the embedded code as the w3wp.exe IIS worker process, which runs as the SharePoint application pool service account -- a high-privilege domain account in most deployments.

From that initial code execution, attackers extract the IIS machine keys stored in the SharePoint application configuration. Machine keys allow signing arbitrary authentication tokens, which the attacker uses to forge persistent session cookies that bypass all authentication checks and survive password resets on the compromised account. Resecurity's analysis of the July 2026 SharePoint attack wave documented a case where operators moved from initial SharePoint access to domain controller compromise in under six hours using this exact machine key forgery technique.

CISA confirmed active ransomware exploitation and added CVE-2026-45659 to the Known Exploited Vulnerabilities catalog with a three-day federal remediation deadline. Of 14 SharePoint vulnerabilities CISA has flagged since 2021, eight have been exploited directly in ransomware attacks. Apply the SharePoint Server cumulative update for your version immediately. Hunt for unexpected file writes in the SharePoint layouts directories as evidence of prior webshell deployment.

Subscribe to unlock Indicators of Compromise

Free subscribers unlock full IOC lists, Sigma detection rules, remediation steps, and every daily briefing.

Free daily briefing

Briefings like this, every morning before 9am.

Threat intel, active CVEs, and campaign alerts, distilled for practitioners. 50,000+ subscribers. No noise.

Adobe Commerce CVE-2026-71362 and Cisco Firewall CVE-2026-20349: Patch Before End of Day

Two additional CISA-flagged vulnerabilities require action today.

CVE-2026-71362 is an incorrect authorization vulnerability in Adobe Commerce, Commerce B2B, and Magento Open Source. An unauthenticated attacker can switch a store visitor's session to any registered customer account without credentials, gaining access to order history, saved payment methods, shipping addresses, and all personal account data. Sansec, an ecommerce security research firm, reported active exploitation attempts in its WAF telemetry before Adobe released the August 2026 security update. No account, administrator access, or user interaction is required to trigger the attack -- an attacker browsing the storefront can hijack any customer session in a single request. Apply the isolated patch files for your branch from Adobe security advisory APSB26-92 before the store accepts customer traffic this week.

CVE-2026-20349 is a heap inspection vulnerability in Cisco Secure Firewall ASA and FTD software that CISA added to its Known Exploited Vulnerabilities catalog on August 11, 2026, confirming active in-the-wild exploitation. The flaw can expose sensitive memory contents including cryptographic material and session tokens that enable follow-on attacks. Cisco ASA and FTD appliances manage perimeter access for enterprise, government, and critical infrastructure networks globally. Apply the vendor advisory fix immediately. Treat any perimeter firewall that may have been exposed to active exploitation as potentially compromised and conduct a full configuration audit before treating it as a trusted network boundary.

The 2024 ArcaneDoor campaign demonstrated how nation-state actors compromise Cisco perimeter devices to maintain long-term invisible persistence in government networks -- the Cisco ASA ArcaneDoor breakdown provides the full attack pattern.

Cl0p and ShinyHunters: Active Data Exfiltration Campaigns This Week

Two ransomware and extortion groups confirmed active data exfiltration operations this week against large enterprise targets.

Cl0p ransomware claimed responsibility for exfiltrating sensitive internal data from Shell, the multinational energy and petrochemical company operating across more than 70 countries. Shell launched a formal investigation following the Cl0p claim. Cl0p's established playbook involves bulk data exfiltration without deploying encryption, followed by publication of stolen files on the group's leak site when ransom negotiations fail, typically 30 to 60 days after the initial breach. The group has previously targeted organizations through exploited managed file transfer platforms and enterprise software vulnerabilities. Organizations that supply products or services to Shell, operate joint ventures with Shell entities, or share data through integrated systems should assess what data may be within scope of the breach and review contractual breach notification obligations.

ShinyHunters ransomware targeted Lumenis, an Israeli medical device and aesthetic laser technology company, and claimed to have stolen 1.1 million records totaling 176 gigabytes of internal data. The stolen data includes customer and employee personally identifiable information. Lumenis customers and employees should monitor for credential stuffing attempts against any accounts sharing email addresses or passwords with Lumenis-connected services and enable multi-factor authentication immediately on all such accounts.

Neither the Cl0p/Shell breach nor the Lumenis breach has produced specific network infrastructure indicators of compromise as of August 17. The Cl0p group typically releases a partial data sample alongside the victim claim as verification before the 60-day publication deadline.

Ransomware gangs have begun abusing a high-severity Microsoft SharePoint remote code execution vulnerability. All organizations running SharePoint Server are strongly urged to apply the update immediately.

CISA, August 2026 SharePoint Exploitation Advisory

Sigma and WAF Detection Rules for CVE-2026-45659 SharePoint RCE

No CVE-specific Sigma rule targeting CVE-2026-45659's deserialization payload exists yet in the SigmaHQ library -- the vulnerability was added to the CISA KEV list this week and community rules for specific deserialization CVEs typically lag by two to four weeks. The two rules below target the post-exploitation behavior that is consistent across SharePoint deserialization attacks: webshell strings in web server access logs and suspicious file writes to the SharePoint layouts directory, which is where attackers drop webshells after achieving code execution.

Both rules require different telemetry sources. The webshell strings rule operates on web server access logs (IIS logs for Windows SharePoint deployments). The SharePoint layouts file write rule requires Windows file event telemetry from Sysmon event ID 11 (FileCreate) with process image logging. Enable Sysmon with at minimum FileCreate events filtered to the SharePoint Web Server Extensions directory paths before deploying this rule.

Deploy in detection mode and validate against known-good SharePoint administrative operations before switching to blocking mode.

The WAF rules below target CVE-2026-45659 at the HTTP layer -- the deserialization payload arrives as a POST body to SharePoint layout endpoints. Deploy all four platform rules in log/count mode first to baseline legitimate SharePoint traffic before switching to block mode. The ModSecurity rule is OWASP CRS compatible at rule ID 926045659 and includes rate-limiting counters per source IP.

Subscribe to unlock Sigma Detection Rules

Free subscribers unlock full IOC lists, Sigma detection rules, remediation steps, and every daily briefing.

Subscribe to unlock WAF Detection Rules

Free subscribers unlock full IOC lists, Sigma detection rules, remediation steps, and every daily briefing.

5-Step Patch Priority for August 17: What to Fix First This Week

Five actions, ranked by exploitation urgency, close the majority of today's critical exposure. Execute them in order before Friday.

Apply official patch →msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62878

Subscribe to unlock Remediation & Mitigation steps

Free subscribers unlock full IOC lists, Sigma detection rules, remediation steps, and every daily briefing.

Why August 2026 Patch Tuesday Critical Vulnerabilities Demand Same-Week Action

The August 2026 Patch Tuesday release is notable for four converging factors that make delayed patching unusually dangerous.

First, the wormable classification of CVE-2026-62878 means standard patch deployment timelines are inappropriate. A wormable DNS vulnerability on domain controllers does not wait for the next maintenance window. Every day of exposure is a day where a single network-adjacent exploit turns into organization-wide DNS compromise.

Second, CISA's three-day federal deadline for CVE-2026-45659 is the strongest signal the agency can send about active ransomware exploitation in production environments. Federal deadlines are not the relevant metric for private organizations, but the three-day window reflects confirmed incidents where ransomware operators moved from initial SharePoint access to data exfiltration in hours, not days.

Third, the concentration of critical patches touching identity infrastructure -- Active Directory Certificate Services (CVE-2026-62818), DNS Server (CVE-2026-62878), and SharePoint (CVE-2026-45659) -- means unpatched organizations face a situation where multiple independent attack paths can produce domain-level compromise. Patching any one without patching the others leaves compounding risk.

Fourth, the Cl0p and ShinyHunters campaigns demonstrate that enterprise-scale data exfiltration is ongoing alongside vulnerability exploitation. Organizations focused exclusively on perimeter patching may miss active lateral movement by threat actors who entered through a different vector.

Apply the five patches above before Friday. Schedule a Monday morning review of patch deployment status across DNS servers, SharePoint farms, Cisco perimeter devices, and Adobe Commerce instances to confirm coverage before the week ends.

The bottom line

August 2026 Patch Tuesday critical vulnerabilities include a CVSS 9.8 wormable DNS RCE (CVE-2026-62878) and a SharePoint deserialization flaw ransomware groups are actively exploiting (CVE-2026-45659). Three additional high-priority patches cover Adobe Commerce session hijacking (CVE-2026-71362), Cisco Secure Firewall exploitation (CVE-2026-20349), and Active Directory Certificate Services RCE (CVE-2026-62818). Apply KB5121003 or KB5120249 to all DNS Server hosts today, patch SharePoint and Adobe Commerce before end of day, and audit any Shell-affiliated vendor connections for potential Cl0p supply chain exposure.

This analysis is generic. create a free account to score threats like this against your own stack.

Frequently asked questions

What is CVE-2026-62878?

CVE-2026-62878 is a stack-based buffer overflow in the Windows DNS Server service that allows an unauthenticated remote attacker to execute arbitrary code on any server running the DNS role. A crafted DNS query packet overflows a fixed-size stack buffer, overwriting the return address with attacker-controlled shellcode that runs at SYSTEM privilege. The flaw carries a CVSS score of 9.8 and is classified as wormable, meaning a single exploit can self-propagate to other exposed DNS servers without additional attacker interaction. Microsoft patched it on August 11, 2026, via KB5121003 for Windows Server 2025 and KB5120249 for Windows Server 2022 and 2019.

Is CVE-2026-62878 being exploited in the wild?

No confirmed exploitation of CVE-2026-62878 has been reported as of August 17, 2026. The flaw is not on the CISA Known Exploited Vulnerabilities list. However, the CVSS 9.8 score, wormable designation, and ubiquitous deployment of Windows DNS Server on Active Directory domain controllers make this a highest-priority patch. Historical patterns show working exploits for DNS server vulnerabilities typically emerge one to three weeks after patch release, as researchers reverse-engineer the fix. This week is the critical patching window.

How are ransomware groups exploiting SharePoint CVE-2026-45659?

CVE-2026-45659 is a deserialization of untrusted data vulnerability in SharePoint Server. Attackers obtain low-privilege SharePoint credentials via phishing or credential stuffing, authenticate to the SharePoint web application, and submit a crafted HTTP POST containing a malicious serialized .NET object. SharePoint deserializes the payload and executes embedded code as the IIS application pool service account. Attackers then steal IIS machine keys, which allow forging authentication tokens for persistent, session-independent access. Resecurity documented a case where attackers moved from initial SharePoint access to domain controller compromise in under six hours using this chain.

What is the CISA deadline for SharePoint CVE-2026-45659?

CISA added CVE-2026-45659 to its Known Exploited Vulnerabilities catalog with a three-day remediation deadline for federal civilian executive branch agencies, making the federal deadline this week. The three-day window reflects confirmed ransomware exploitation in production environments. Non-federal organizations are not bound by CISA deadlines, but eight of the fourteen SharePoint flaws CISA has flagged since 2021 have been directly exploited in ransomware attacks. Treat this as an emergency patch for any on-premise SharePoint Server installation regardless of federal affiliation.

How do I know if Adobe Commerce CVE-2026-71362 affects my store?

CVE-2026-71362 affects all currently supported Adobe Commerce, Commerce B2B, and Magento Open Source release lines that have not applied the August 2026 security update. The flaw allows an unauthenticated attacker to switch a visitor session to any customer account without credentials, giving access to order history, saved payment methods, and personal data. Check your version in the admin panel. If it predates the August 2026 security release for your branch, apply the isolated patch files from Adobe security advisory APSB26-92 before the store accepts customer traffic.

What is Cisco Secure Firewall CVE-2026-20349?

CVE-2026-20349 is a heap inspection vulnerability in Cisco ASA and FTD firewall software that CISA added to the Known Exploited Vulnerabilities catalog on August 11, 2026, confirming active exploitation. The flaw can expose sensitive memory contents including cryptographic material. Cisco ASA and FTD devices manage perimeter access for thousands of enterprise, government, and critical infrastructure networks. Any organization running these appliances should apply the Cisco advisory fix immediately. Treat perimeter firewalls that may have been reached by an active exploit as potentially compromised and conduct a full configuration audit.

What data did Cl0p steal from Shell?

Cl0p claimed responsibility for exfiltrating sensitive internal data from Shell, the multinational energy and petrochemical company, which has launched a formal investigation. The specific data categories have not been confirmed publicly as of August 17, 2026. Cl0p's established pattern is bulk data theft followed by publication on its leak site 30 to 60 days after the attack when ransom demands are not met. Organizations that supply services to Shell, share data through joint ventures, or operate connected infrastructure should assess potential data exposure and review contractual breach notification obligations.

Which five patches are most urgent from Patch Tuesday August 2026?

Patch in this order. First, apply KB5121003 or KB5120249 to all Windows DNS Server instances, especially domain controllers, for CVE-2026-62878 (CVSS 9.8, wormable). Second, apply the SharePoint cumulative update for CVE-2026-45659, which ransomware groups are actively exploiting. Third, apply Adobe security advisory APSB26-92 for Adobe Commerce and Magento for CVE-2026-71362. Fourth, update Cisco ASA and FTD for CVE-2026-20349 per the Cisco advisory. Fifth, apply the August 2026 cumulative update to Active Directory Certificate Services servers for CVE-2026-62818 (critical RCE), which provides domain-level compromise capability.

Sources & references

  1. BleepingComputer, Microsoft August 2026 Patch Tuesday fixes 400 flaws, 3 zero-days
  2. Security Affairs, Microsoft Patch Tuesday for August 2026 Fixed a Zero-Day and Wormable RCE
  3. CISA, Adds Three Known Exploited Vulnerabilities to Catalog, August 11 2026
  4. BleepingComputer, CISA Microsoft SharePoint flaw now exploited in ransomware attacks
  5. The Hacker News, SharePoint RCE CVE-2026-45659 Added to CISA KEV After Active Exploitation
  6. CISA Known Exploited Vulnerabilities Catalog
  7. BleepingComputer, Hackers exploit critical Adobe Commerce flaw to hijack customer accounts
  8. WindowsForum, CVE-2026-62878 Patch Windows DNS Server RCE Flaw

Free resources

25
Free download

Critical CVE Reference Card 2025–2026

25 actively exploited vulnerabilities with CVSS scores, exploit status, and patch availability. Print it, pin it, share it with your SOC team.

No spam. Unsubscribe anytime.

Free download

Ransomware Incident Response Playbook

Step-by-step 24-hour IR checklist covering detection, containment, eradication, and recovery. Built for SOC teams, IR leads, and CISOs.

No spam. Unsubscribe anytime.

Free newsletter

Get threat intel before your inbox does.

50,000+ security professionals read Decryption Digest for early warnings on zero-days, ransomware, and nation-state campaigns. Free, daily, no spam.

Unsubscribe anytime. We never sell your data.

Eric Bang
Author

Founder & Cybersecurity Evangelist, Decryption Digest

Cybersecurity professional with expertise in threat intelligence, vulnerability research, and enterprise security. Covers zero-days, ransomware, and nation-state operations for 50,000+ security professionals every morning.

Giveaway: InfoSec World 2026 All Access Pass ($3,895 value)

Details →
Daily Briefing

Subscribe to enter the giveaway

Every subscriber is automatically entered. You also get daily threat intel every morning: zero-days, ransomware, and nation-state campaigns. Free. No spam.

Already subscribed? You're already entered.

Giveaway

Win a $3,895 InfoSec World 2026 pass.