(TLP CLEAR) Weekly Vulnerabilities to Prioritize – August 27, 2026
Created: Thursday, August 27, 2026 - 15:14
Categories: Cybersecurity, Security Preparedness
The below vulnerabilities have been identified by WaterISAC analysts as important for water and wastewater utilities to prioritize in their vulnerability management efforts. WaterISAC shares critical vulnerabilities that affect widely used products and may be under active exploitation. WaterISAC draws additional awareness in alerts and advisories when vulnerabilities are confirmed to be impacting, or have a high likelihood of impacting, water and wastewater utilities. Members are encouraged to regularly review these vulnerabilities, many of which are often included in CISA’s Known Exploited Vulnerabilities (KEV) Catalog.
Citrix NetScaler ADC and NetScaler Gateway Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability
CVSS v4.0: 8.8
CVEs: CVE-2026-8452
Description: Memory overflow vulnerability NetScaler ADC and NetScaler Gateway leading to unpredictable or erroneous behavior and Denial of Service if the appliance is configured as a Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server. CISA added this vulnerabilities to its Known Exploited Vulnerability Catalog.
Source: https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX696604
ownCloud Improper Authentication Vulnerability
CVSS v3.1: 9.8
CVEs: CVE-2023-49105
Description: An issue was discovered in ownCloud owncloud/core before 10.13.1. An attacker can access, modify, or delete any file without authentication if the username of a victim is known, and the victim has no signing-key configured. This occurs because pre-signed URLs can be accepted even when no signing-key is configured for the owner of the files. The earliest affected version is 10.6.0. CISA added this vulnerabilities to its Known Exploited Vulnerability Catalog.
Source: https://owncloud.com/security-advisories/webdav-api-authentication-bypass-using-pre-signed-urls/
Linux Kernel Unspecified Vulnerability
CVSS v3.1: 7.8
CVEs: CVE-2026-53362
Description: This vulnerability has been resolved in the Linux kernel. CISA added this vulnerabilities to its Known Exploited Vulnerability Catalog.
Source: https://www.cve.org/CVERecord?id=CVE-2026-53362
JFrog Artifactory Improper Limitation of a Pathname to a Restricted Directory Vulnerability
CVSS v3.1: 5.3
CVEs: CVE-2026-66384
Description: An authenticated user may write data outside the intended Docker cache path under specific remote-repository conditions. CISA added this vulnerabilities to its Known Exploited Vulnerability Catalog.
Source: https://docs.jfrog.com/releases/docs/jfrog-security-advisories
Microsoft SQL Server Remote Code Execution Vulnerability
CVSS v3.1: N/A
CVEs: CVE-2019-1068
Description: A remote code execution vulnerability exists in Microsoft SQL Server when it incorrectly handles processing of internal functions, aka ‘Microsoft SQL Server Remote Code Execution Vulnerability’. CISA added this vulnerabilities to its Known Exploited Vulnerability Catalog.
Source: https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2019-1068
Zimbra Collaboration Suite (ZCS) OS Command Injection Vulnerability
CVSS v3.1: 8.9
CVEs: CVE-2026-73570
Description: A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp package is installed and SNMP notifications are enabled. Due to improper sanitization of untrusted input during SNMP notification processing, an unauthenticated attacker can send specially crafted SMTP requests that may result in execution of arbitrary operating system commands as the Zimbra user. This issue is fixed in version 3.15.0. CISA added this vulnerabilities to its Known Exploited Vulnerability Catalog.
Source: https://wiki.zimbra.com/wiki/Zimbra_Security_Advisories
TrueConf Server Missing Authentication for Critical Function Vulnerability
CVSS v4.0: 9.3
CVEs: CVE-2026-72529
Description: A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to 5.3.9, 5.4.X to 5.4.9, 5.5.X to 5.5.5, and earlier could execute an arbitrary script by calling an undocumented function. CISA added this vulnerabilities to its Known Exploited Vulnerability Catalog.
Source: https://ics-cert.kaspersky.com/advisories/2026/08/11/trueconf-server-missing-authentication-for-critical-function/
TrueConf Server Code Injection Vulnerability
CVSS v4.0: 9.5
CVEs: CVE-2026-72530
Description: A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to 5.3.9, 5.4.X to 5.4.9, 5.5.X to 5.5.5, and earlier could use a specially crafted script to break out of the isolated environment and execute arbitrary code on the host system. CISA added this vulnerabilities to its Known Exploited Vulnerability Catalog.
Source: https://ics-cert.kaspersky.com/advisories/2026/08/11/trueconf-server-breakout-from-isolated-environment/
