Security NEXT•August 19, 2026•🇯🇵Translated from Japanese

CISA Adds Four Exploited Vulnerabilities to KEV Catalog Including Critical macOS Authentication Bypass

The US Cybersecurity and Infrastructure Security Agency (CISA) added four vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog on August 18, 2026, after confirming active exploitation in the wild.

Among the newly listed issues is CVE-2026-65400 affecting Apple macOS. The flaw stems from improper authentication handling in the Screen Sharing feature and permits attackers to bypass authentication over the network even without valid credentials.

Apple released patches for the vulnerability on August 6 in macOS Tahoe 26.6.1, macOS Sequoia 15.7.9, and macOS Sonoma 14.8.9. CISA assigned the vulnerability a CVSS v3.1 base score of 9.8 and classified it as Critical.

The remaining three vulnerabilities impact Microsoft SharePoint and VMware vCenter along with additional unspecified products. All four entries were added because real-world attacks have been observed.

CISA has directed all US federal civilian agencies to remediate the listed vulnerabilities within three days of the catalog update.

Related articles

Habr•Vulnerabilities & Exploits

Dissecting CVE-2026-83557 in jackson-databind: Why Not Every CVE Requires Immediate Panic

A detailed analysis of CVE-2026-83557 reveals that the vulnerability in jackson-databind affects only a narrow set of configurations involving polymorphic deserialization with the Comparable base type. The flaw stems from an incomplete denylist in DefaultBaseTypeLimitingValidator, which overlooks java.lang.Comparable when the MapperFeature.BLOCK_UNSAFE_POLYMORPHIC_BASE_TYPES flag is explicitly enabled. Researchers constructed working proof-of-concept exploits showing that an attacker can instantiate classes such as java.io.File, but only when the property is declared as Comparable<?> and the protective flag is active. The issue impacts versions 2.11 through 2.22.1, yet the CVSS score of 5.6 reflects its moderate real-world risk because most applications lack the required Comparable-typed polymorphic fields. Patching introduces its own trade-off by blocking legitimate Comparable subclasses, forcing developers to implement custom BasicPolymorphicTypeValidator allowlists. The case highlights how dependency scanners often flag CVEs without considering application-specific configuration and DTO structures.

Security NEXT•Vulnerabilities & Exploits

Multiple Critical Vulnerabilities Found in Citrix NetScaler ADC and Gateway, Two Actively Exploited

Cloud Software Group disclosed eight vulnerabilities affecting NetScaler ADC and NetScaler Gateway products on September 27, 2026. Two of the issues, CVE-2026-88771 and CVE-2026-88772, have already been confirmed as exploited in the wild, prompting urgent remediation advice. CVE-2026-88771 stems from insufficient input validation and allows unauthenticated remote code execution across all default configurations. CVE-2026-88772 involves a memory overflow that can lead to code execution or denial of service when DTLS is enabled, which occurs by default on VPN vServers. The remaining six vulnerabilities cover code execution, denial of service, and HTTP request smuggling risks, with the advisory rated Critical overall. Organizations are urged to apply patches immediately and investigate potential breaches.

Habr•Vulnerabilities & Exploits

YApi Abandoned Since 2022: Fork Yapix Exposes Forgable Project Tokens and Critical Sandbox Flaws

YApi, a widely used open-source API documentation and mocking platform with 27.7k GitHub stars, has received no updates since its 1.12 release in November 2022. The project accumulated 1,629 open issues, including an unaddressed remote code execution report via mock scripts. Security researcher Perruer created the Yapix fork to address broken dependencies, Node.js 22 incompatibility with deprecated crypto.createCipher, and 244 known vulnerabilities in production dependencies. Analysis revealed that project tokens could be forged by any user because the default passsalt key was a hardcoded five-character string published on GitHub. The original implementation used vm2 and Node vm for script execution, both of which are unsafe, allowing arbitrary server-side code execution. Yapix migrates to isolated-vm with strict memory and time limits, replaces SHA-1 password hashing with scrypt, and blocks MongoDB operator injection in API parameters.

Habr•Vulnerabilities & Exploits

Researchers Bypass RP2350 Secure Debug Lock with Laser Fault Injection and Photon Emission Microscopy

Security researchers have demonstrated a hardware attack that restores Secure Debug access on the RP2350 microcontroller revision A4 despite permanent OTP fuses disabling it. Using photon emission microscopy they first located the exact physical bits of the DEBUGEN register, then applied precisely timed 980 nm laser pulses to flip two critical bits and re-enable the Mem-AP ports. The attack requires decapping the chip from the backside and laboratory equipment costing around $250,000, but succeeds in seconds once calibrated. It bypasses the CRIT1.DEBUG_DISABLE fuse, TrustZone restrictions, and glitch detectors by resetting the device before firmware can re-lock the OTP page. The technique was developed against the updated A4 silicon released after the first Raspberry Pi Hacking Challenge. The work highlights that even heavily hardened microcontrollers remain vulnerable to sophisticated physical attacks when an attacker has direct silicon access.