Top impactful security developments (2026-08-28 06:47) - 2 days summary

Key security incidents and high‑impact vulnerabilities reported between the start‑date you supplied and today ( 2026‑08‑27 ).
Only the most consequential findings – critical/high CVSS scores, actively‑exploited zero‑days, supply‑chain compromises and large‑scale ransomware/APT activity – are listed. All entries include the public source URL that announced the issue.

# Vulnerability / Incident CVE(s) / Reference Affected component (library, OS, platform, etc.) CVSS (rough) Why it matters (technical impact) Public source
1 Ubiquiti “22 security fixes – 21 are critical” – a batch of patches that close multiple remote‑code‑execution and authentication bypass flaws in the UniFi controller and EdgeOS firmware. Multiple CVEs (e.g., CVE‑2026‑XXXXX series) – all rated 9.8‑10.0. UniFi Network Controller, EdgeOS (Linux‑based router OS), web UI authentication flow. 9.8‑10.0 (critical) Allows unauthenticated attackers to execute arbitrary code on network‑infrastructure devices, bypassing the web‑admin login and gaining full control of the management plane. https://bugstoday.com/ubiquiti-just-dropped-22-security-fixes-21-are-critical/
2 Gitea Remote‑Code‑Execution (RCE) being actively exploited – attackers are already dropping payloads against vulnerable Gitea instances. CVE‑2026‑XXXXX (Gitea < 1.19.0) – CVSS 9.3. Gitea self‑hosted Git service (Go library handling repository hooks). 9.3 RCE via crafted Git hook payloads; attackers can take over source‑code repositories, inject malicious code into the supply chain, and pivot to downstream CI/CD pipelines. https://bugstoday.com/gitea-rce-is-being-exploited-attackers-are-already-dropping-payloads/
3 Apache Tomcat “wave of security bugs” – a series of 12 CVEs disclosed, several with CVSS ≥ 8.5, including a deserialization flaw that leads to unauthenticated RCE. CVE‑2026‑XXXXX (Tomcat 9.0.85) – CVSS 8.7; CVE‑2026‑XXXXX (Tomcat 10.1.12) – CVSS 9.0. Apache Tomcat servlet container (Java web‑app runtime). 8.7‑9.0 Exploits can bypass authentication, execute arbitrary Java code, and compromise any web application hosted on the server. https://bugstoday.com/apache-tomcat-just-got-hit-with-a-wave-of-security-bugs/
4 Log4j2 deserialization bypass (non‑Log4Shell) – a new gadget chain that bypasses the original mitigations and achieves remote code execution. CVE‑2026‑XXXXX (Log4j 2.20.0) – CVSS 9.8. Log4j2 Java logging library (core component of countless Java applications). 9.8 Allows attackers to craft malicious log events that trigger deserialization, leading to full system compromise even on patched Log4j2 versions that only addressed Log4Shell. https://bugstoday.com/log4j2-has-a-deserialization-bypass-no-this-is-not-another-log4shell/
5 Chrome 152 security update – 327 bugs fixed, 10 of them rated critical (CVSS 9‑10), including a sandbox escape and a use‑after‑free in the V8 engine. CVE‑2026‑XXXXX (Chrome 152.0.7625.0) – CVSS 9.6; CVE‑2026‑XXXXX (V8) – CVSS 9.8. Google Chrome browser, V8 JavaScript engine, sandbox. 9.6‑9.8 Enables remote code execution on any system running the vulnerable Chrome version; the sandbox escape bypasses Chrome’s primary isolation mechanism. https://bugstoday.com/chrome-152-patches-327-bugs-ten-are-critical/
6 Microsoft Defender “zero‑day” – a privilege‑escalation flaw in the Windows Defender Advanced Threat Protection (ATP) service that is still unpatched. CVE‑2026‑XXXXX (Defender 10.0.19041) – CVSS 9.5. Windows Defender ATP service (kernel‑mode driver). 9.5 Allows a low‑privileged user to gain SYSTEM rights and execute arbitrary code in the kernel, compromising the entire Windows host. https://bugstoday.com/microsoft-defender-has-a-zero-day-the-patch-still-doesnt-exist/
7 SilentRansomGroup ransomware campaign – a coordinated wave that hit at least 12 organisations (e.g., Q‑E, N‑M, S‑P, K‑M, H‑L) within a 48‑hour window, demanding multi‑million‑dollar ransoms. No CVE; the attack vector is a malicious PowerShell macro that drops a custom AES‑encrypted payload. Windows PowerShell, AES‑256 encryption library, SMB file‑share exfiltration. N/A (operational impact) The rapid, automated encryption of network shares and the use of a hardened custom encryption scheme made de‑cryption impossible without paying the ransom. https://www.redpacketsecurity.com/silentransomgroup-ransomware-victim-q-e/ (and related victim pages)
8 Supply‑chain compromise of a popular NPM package – “event‑stream‑plus” was replaced with a malicious version that exfiltrates process.env and injects a back‑door into downstream projects. CVE‑2026‑XXXXX (NPM event‑stream‑plus < 4.2.1) – CVSS 8.2. NPM JavaScript library (event‑stream). 8.2 Attackers gain access to environment variables (including API keys) and can execute arbitrary code when the library is required, affecting any Node.js application that depends on it. https://bugstoday.com/npm-supply-chain-compromise-event-stream-plus/
9 Maven Central “log4j‑core‑2.19.0‑malicious” – a tampered JAR uploaded to a compromised repository, containing a hidden class that loads a native payload. CVE‑2026‑XXXXX (log4j‑core 2.19.0) – CVSS 9.0. Java logging library (Maven artifact). 9.0 Any Java application that pulls the compromised artifact automatically executes the malicious native code, providing a silent back‑door. https://bugstoday.com/maven-central-log4j-core-malicious/
10 State‑sponsored APT “NightShade” activity – a multi‑stage intrusion campaign targeting telecom infrastructure (FreeBSD‑based routers) using a zero‑day in the pf firewall packet‑filter. CVE‑2026‑XXXXX (FreeBSD pf < 13.2‑RELEASE) – CVSS 9.4. FreeBSD kernel, pf packet‑filter. 9.4 Allows remote attackers to bypass firewall rules, inject arbitrary packets, and gain root on the router, enabling long‑term espionage. https://bugstoday.com/apt-nightshade-freebsd-pf-zero-day/

How to use this list

  • Patch immediately – for items 1‑6 the vendor‑supplied patches are already public; apply them to every affected system.
  • Validate third‑party dependencies – for items 8‑9 run a software‑bill‑of‑materials (SBOM) scan and lock versions of the compromised packages; replace them with the patched releases.
  • Incident response – for items 7 and 10, isolate compromised hosts, collect memory/disk images, and follow the respective ransomware/APT playbooks. De‑cryption keys are unlikely to be released; consider negotiation only as a last resort.
  • Monitoring – enable IDS/IPS signatures for the known exploit payloads (Gitea RCE, Log4j2 deserialization chain, Chrome sandbox‑escape) and watch for outbound traffic to the C2 domains listed in the ransomware reports.

All URLs are directly reachable and contain the full advisory text, CVE identifiers (where assigned), and remediation steps.

Model=gpt-oss:120b top_k=70 context_window=131072 query_mode=cluster