If you just remember one thing from this briefing…
Three widely deployed platforms went from patch to mass exploitation in under a week.
VMware vCenter, SharePoint and Windows IKE were each added to the exploited-vulnerability catalogue on 18
August, vCenter alone compromised at 361 organisations within five days of its fix. Ask your team this
week: what is our actual time from vendor patch to deployed fix, measured, not assumed.
Priority18 Aug
vCenter, SharePoint and Windows IKE hit by mass exploitation within days of each patch
CISA catalogued four flaws on 18 August: a VMware vCenter Syslog path-traversal (CVE-2026-59310) giving
root code execution, exploited at 361 organisations in 47 countries within five days of Broadcom's fix; a
SharePoint JWT auth bypass (CVE-2026-55040); and a Windows IKE double-free (CVE-2026-33824), pre-auth over
UDP 500/4500.
So what: a monthly patch window no longer protects internet-facing vCenter,
SharePoint or IKE VPN endpoints. Treat all three as compromised until patched and checked.
Priority11 Aug
Cisco ASA and FTD SSL VPN flaw exploited for unauthenticated denial of service
CISA added CVE-2026-20349 after confirming exploitation of a heap-inspection flaw in Cisco ASA and FTD
Remote Access SSL VPN. A single crafted, unauthenticated HTTP request forces the device to reload.
Federal agencies were ordered to patch by 14 August.
So what: ASA and FTD carry VPN and site-to-site links across airport and airline
networks. An unpatched unit can be knocked offline remotely, at will, with no credentials.
Watch10 Aug
UAE reports third critical-infrastructure campaign of 2026, aviation among the targets
The UAE Cybersecurity Council said it had detected and contained coordinated intrusion attempts against
aviation, energy and education networks, involving phishing and account takeover. No disruption was
confirmed. It is the third disclosed sector-wide campaign this year, after finance in July.
So what: Gulf aviation is a live, repeated target. European operators sharing
suppliers with Gulf carriers should ask if the same tooling reached them.
WatchEarly Aug
GNSS spoofing over the Baltic now degrades navigation for most transiting aircraft
Lithuania's regulator confirmed Kaliningrad spoofing infrastructure grew from three to 36 transmitters in
fifteen months, its radius now reaching Estonia, Latvia, Poland, Finland and Sweden. Over eastern Latvia
in early August, roughly three in four aircraft flagged degraded GNSS integrity.
So what: spoofing, not jamming, is now the dominant failure mode. Confirm
documented holdover for every ground system with a GNSS timing dependency.