Today’s Field Note

Two edge-facing bugs are already being turned against people, and both sit in the boxes you use to keep others out. QUIRSO reports active exploitation of CVE-2026-59310, the 9.8 directory-traversal RCE in Broadcom VMware vCenter, giving attackers persistent remote access to the thing that controls your entire virtual estate. Cisco confirms CVE-2026-20349 in ASA and FTD is being used in the wild to crash firewalls remotely without authentication, so treat it as a live availability threat, not a theoretical one. Meanwhile Microsoft’s August load buries one that matters: CVE-2026-68820, a use-after-free in afd.sys already exploited for SYSTEM. Ignore the 400-CVE headline and patch the three things attackers are actually touching.

Today’s Action

  • Patch VMware vCenter for CVE-2026-59310 now, then hunt for traversal-based access and unexpected persistence, since exploitation predates your patch window.
  • Apply Cisco’s ASA and FTD fix for CVE-2026-20349; if you cannot patch immediately, watch for repeated device crashes and restrict HTTP-facing management exposure.
  • Deploy August’s Windows updates prioritizing CVE-2026-68820 (afd.sys) on internet-adjacent and high-value hosts first.
  • Segregate and monitor vCenter and firewall management interfaces so they are not reachable from general network space or the internet.
  • Note the ShieldBreak PoC (CVE-2026-50656 bypass) and SharePoint CVE-2026-55040; confirm your Defender and SharePoint builds are current before those move from PoC to payload.

Resources

Verified links for the CVEs mentioned above: official advisories, and a live search for public detection rules if any exist yet.

Patch the three they’re touching, not the four hundred they’re not.

More: Issues · Field Notes · RTFM


Daily field notes, weekly Issues. Follow @itsalreadywhen or subscribe via RSS.