Key take‑aways from the August 27 2026 Cyber Threat Intelligence brief
| Item | What happened | Impact |
|---|---|---|
| CVE‑2026‑77991 | Joomla Event Manager <5.0.1 allows an admin to write arbitrary files (incl. PHP) → privileged remote code execution. | Severity 9.4 (CRITICAL) |
| CVE‑2026‑59270 | Spring Security’s embedded UnboundID LDAP server auto‑registers a hard‑coded admin credential and listens on all interfaces. | Severity 9.4 (CRITICAL) – Affects Spring Security 5.7‑7.1 (multiple sub‑versions). |
| CVE‑2026‑47877 | Default consent page of Spring Security Authorization Server renders unescaped user data → XSS. | Severity 8.2 (High) – Affects Spring Security 7.1 and 7.0.x. |
| CISA KEV update (Aug 26‑27) | Six actively exploited CVEs were added to the Known Exploited Vulnerabilities catalog. Included are CVE‑2019‑1068 (Citrix NetScaler RCE) and recent CVEs 2026‑8452, 2022‑0995, 2021‑23758, 2015‑5287, 2015‑3246. | Highlights confirmed exploitation |