Tech Blog

everyWAN Blog

Technology, cybersecurity and IT trends that matter

Deep Analysis
Cybersecurity
IT Trends
Filter by:
Archivo de oficina con cajas y carpetas apiladas en estanterías metálicas bajo luz natural
5 min read

They are not old bugs: they are old classes of bug. We ran the numbers on CISA's catalogue

We downloaded CISA's Known Exploited Vulnerabilities catalogue and counted its 1,685 entries. Of the 201 added in 2026, 123 carry an identifier from this same year and the median gap is zero: what is old is not the individual bug but the class. We measured that too, using the file's own cwes field: CWE-20, improper input validation, tops the catalogue with 118 entries, followed by command injection and out-of-bounds write. And something turned up that we were not looking for: on 10 June directive BOD 26-04 revoked BOD 22-01, and since then 81% of what goes in arrives with a three-day deadline instead of the previous 23%.

Cuarto de impresión de una oficina con una multifunción, cajas de papel y un servidor en una estantería metálica
9 min read

PaperCut: the print server runs as SYSTEM, and nearly half the measured estate has no patch

On 27 August PaperCut confirmed active exploitation of PaperCut NG and MF. The identifiers landed the next day: CVE-2026-81578 (CVSS 8.8) and CVE-2026-82078 (CVSS 9.4), chained into unauthenticated remote code execution. Huntress watched one intrusion last under two minutes, and in their proof of concept the code executes as SYSTEM. The figure that orders everything else: 47% of the 2,500 installations Huntress tracks are on version 23 or older, for which no patch exists. What happened hour by hour, why Thursday's patch did not hold on Friday, and today's notice that turns one of the indicators into a false positive.

Puerta de acero de una sala de servidores sujeta abierta con una cuña, con un rack visible al fondo
5 min read

The bulletin said "denial of service". The exploit gives root: NetScaler CVE-2026-8452

Citrix shipped the patch on 30 June and described it as a denial of service; the CVSS vector on that same entry already showed high confidentiality impact and no privileges required. On 14 August, 45 days later, the exploit that gives unauthenticated root went public, and attacks followed within days: CISA set a 29 August deadline. How to check whether you are patched without knocking the box over (513 bytes, error 43549) and why the patch does not evict whoever already got in.

Fotocopiadora multifunción de oficina con la puerta de tóner abierta y la bandeja de papel a medio sacar
7 min read

August's patch broke printing in WPF apps: the three ways out, with the maths done

The 11 August .NET Framework cumulative update breaks printing and PDF export in WPF applications using Calibri, Cambria, Constantia and Corbel: <code>System.IO.FileFormatException</code> on a font Windows itself installs. Microsoft acknowledged it on the 24th, thirteen days later, and the interim workaround switches off the overflow protection that same patch had just added. We looked at what exactly it turns off, why the decision should be per application rather than per fleet, and which of the three ways out costs least in each case.

Aparato de red de 1U extraído sobre sus guías en un rack de sala técnica, con cable de consola conectado y un carro de servicio al lado
9 min read

NetScaler CVE-2026-19490: your version doesn't tell you whether you're exposed

On 19 August Citrix published an authentication bypass scoring 9.3 out of 10 in NetScaler ADC and Gateway. Being affected does not depend on your version alone: it depends on what you have configured, and older builds need fewer conditions. How to actually answer the question, why a pre-authentication flaw leaves your MFA out of the path, and what we do in the window before the first exploit lands.

Armario de red mural abierto en una oficina, con panel de parcheo, dos conmutadores de rack y un mazo de latiguillos peinado sobre el raíl lateral
9 min read

A CVE is no longer one bug: Cisco has changed the unit of measurement

On 19 August Cisco published two advisories carrying five CVEs scored 10.0 between them. They are not five bugs: each identifier groups an entire class of bugs and carries the score of the worst one in the bag. Across the four hardening advisories we reviewed the mitigation line says the same thing, "none." This is not a complaint about Cisco: it is that the unit you count vulnerabilities in has changed size, and your inventory has not noticed.

Sala de archivo de una oficina con estanterías metálicas llenas de cajas de cartón y carpetas, y una caja abierta sobre una mesa de trabajo
7 min read

"The column was encrypted": pgcrypto was storing cleartext and nobody noticed

On 13 August PostgreSQL closed 28 CVEs in one go. One of them is not a buffer overflow: when OpenSSL rejected the requested cipher, pgcrypto never checked the answer and wrote the value into your "encrypted" column with a trivial XOR. Neither the INSERT nor the SELECT failed. What triggers it, why the day it broke was not the day the code was written, and which version you are really running if you install from Debian rather than PGDG.

Chasis de servidor de almacenamiento extraído sobre sus guías en un pasillo de datacenter, con dos filas de discos de 3,5 pulgadas en bandejas metálicas y un destornillador apoyado en el borde
7 min read

Ceph patches four CVEs: the package closes three, the fourth is on you

On 19 August Ceph shipped Squid 19.2.6 and Tentacle 20.2.4 tagged [URGENT]. One of the four flaws is not fixed by installing anything: it forces you to rotate every CephX key in the cluster, ten manual steps, and it leaves the cluster in HEALTH_ERR in the meantime. What is inside each CVE, why anyone holding a "mon allow r" key could read your OSD LUKS passphrases, and what we found today in Proxmox's Ceph repository.

Armario de comunicaciones de pared en una sala técnica, con un servidor de rack, un pequeño cortafuegos y un panel de parcheo con latiguillos naranjas y grises
7 min read

"Exploitation Less Likely": 126 days in the queue for CVE-2026-33824

Microsoft patched the Windows IPsec VPN flaw on 14 April with the label "Exploitation Less Likely". CISA added it to its exploited catalogue on 18 August. Between those dates sit 126 days, a Unit 42 report, and a vendor page that still has not been corrected. Our own count across Microsoft's 24 KEV entries this year, and which mitigation you cannot apply if your VPN carries remote workers.

Caja fuerte pequeña de oficina abierta sobre una repisa, con dos sobres, un juego de llaves y una memoria USB dentro
5 min read

Cloning the repository is not a GitLab backup

On 17 August GitLab shipped four out-of-band releases for a flaw that lets an unauthenticated user modify or delete public projects. The usual answer — "we have the code cloned everywhere" — is true, and it is the part you are least likely to lose. What a clone actually carries, what lives only on the server, why the secrets file is not inside the backup, and why the June fix, the one with no CVE, explains the problem better.

Varios miniordenadores en una bandeja de rack conectados a un panel de parcheo: máquinas pequeñas alojadas y accesibles desde la red
5 min read

They came in on port 5900 and left with root: the miner was the least of it

In mid-August the Dutch cyber security centre warned that the macOS Screen Sharing flaw is being exploited on Macs with port 5900 open to the internet, and that in every reported case the attacker got root and left a Monero miner behind. Apple had already shipped the patch on 6 August. What exactly breaks in CVE-2026-65400, why classic hardening did not cover this hole, and the list almost no company has: what listens from outside.

Un parquímetro con el indicador EXPIRED en rojo y un coche todavía aparcado detrás: la fecha ha pasado y no ha cambiado nada visible
9 min read

Proxmox VE 8 goes end of life in August: Debian will keep patching you, the hypervisor will not

Proxmox's official table says 2026-08 and does not give a day. What tends to fall outside the headline is that Debian 12's extended support runs to June 2028 through the usual channel, so apt will keep installing real patches on an unsupported node. What exactly freezes, how to check it, the order of the upgrade to 9.2, and why forcing it in August can be worse than being late.

Sala de reuniones vacía con las sillas recogidas: en agosto la alerta salta igual, pero la sala donde se decide está cerrada
5 min read

Three days to patch, and the third one lands on a Saturday

Since CISA changed its deadlines on 10 June, 42 of the 48 vulnerabilities it has added come with three days to fix them. We counted the weekdays over the catalog file itself: not a single 2026 entry was published on a Saturday or Sunday, and thirteen of those three-day deadlines expire exactly there. In August, with half the staff away, the bottleneck is who signs off that a server can be isolated at three in the morning.

Pasillo de un archivo lleno de cajas y carpetas: el SharePoint local de una empresa guarda sus documentos igual, y desde el 14 de julio ya no recibe arreglos
5 min read

Your SharePoint 2016 got its last patch on 14 July

CVE-2026-55040 lets an attacker with no credentials impersonate any user or administrator of an on-premises SharePoint. Microsoft fixed it on 14 July 2026: exactly the day SharePoint Server 2016 and 2019 went out of support. The proof of concept went public on 12 August and was seen in use the same day, but KEVintel's sensors date the first attempt to 19 July, twenty-four days earlier. Why asking whether it should have been published is the wrong argument, and what to check today on a server that will not receive any more fixes.

Tipos de imprenta de madera: PostScript nació para hablar con impresoras y sigue vivo dentro de las bibliotecas que procesan imágenes
7 min read

It was called .png and inside it was PostScript: the WordPress 7.0.4 flaw

On 12 August WordPress shipped 7.0.4 with a single fix: CVE-2026-65640, remote code execution by uploading a file that announces itself as an image and is PostScript inside. The patch reaches back to the 4.7 branch, from December 2016. For it to affect you two conditions have to hold at once, and the first one is not yours to decide. Why validating the extension does not validate what you think, what "requires Author role" really means, and how to check it in ten minutes.

Pasillo de un centro de datos: cuando el concentrador de VPN se reinicia, el acceso remoto de toda la empresa se queda fuera
9 min read

The Cisco flaw that steals nothing: it just reboots the door your people come in through

On 11 August Cisco published an advisory for ASA and Secure Firewall Threat Defense: an HTTP request against the remote access SSL VPN service makes the device reload. The CVSS vector reads C:N/I:N/A:H —nothing is leaked, nothing is altered— and two hours and twenty minutes later it was already in CISA's KEV catalog with a 14 August due date. Three days. What to check on the device, why the patch costs exactly what the attack costs, and when this does not concern you.

Cronómetro deportivo: los cinco días entre el aviso VMSA-2026-0006 y las primeras conexiones de vCenter comprometidos a la infraestructura del atacante
9 min read

The vCenter advisory said there was no known exploitation. It held for five days

Broadcom published VMSA-2026-0006 on 29 July with no information suggesting exploitation, and that is how we quoted it here the next day. On 3 August the first compromised vCenters started connecting to attacker infrastructure, and on 12 August QUIRSO published the count: 361 victim IP addresses across 47 countries. What those numbers mean, what they do not, and the question that decides whether this concerns you: who can open a connection to your vCenter.

Sala de centralita telefónica con operadoras conectando llamadas: el servicio que resuelve nombres y por el que pasa todo el mundo
5 min read

The DNS server you have to patch is your domain controller

CVE-2026-62878 scores 9.8: a stack-based buffer overflow in Windows DNS, no authentication and no user interaction. Microsoft's bulletin lists sixteen affected products and all sixteen require a reboot. In many of the networks we come across, that machine is also the one validating everybody's passwords, which is why it hasn't been rebooted in months — sometimes years. What the bulletin actually says, what goes down while it boots, and the checks we run before the window.

Subscribe to our newsletter

To receive IT stories, everyWAN news and exclusive subscriber offers, sign up to our mailing list

Minorisa de Sistemas Informaticos y Gestión S.L. © 2026
everyWAN
everyWAN