Daily Cyber Threat Intel Brief — 2026-08-09
Generated: 2026-08-09 08:00:23 UTC
Executive summary
Priority technology watch items
- Information published.
- Information published.
- Information published.
- Information published.
Newly exploited vulnerabilities / CVE watch
Ransomware and extortion trend notes
Malware / infrastructure / abuse feed highlights
IOC highlights
| Type | Value | Context | Source |
| cve | `CVE-2026-34502` | CVE-2026-34502 Apache Portable Runtime Utility: Heap buffer overflow in APR memcached clie | Microsoft Security Response Center RSS |
| cve | `CVE-2026-34501` | CVE-2026-34501 Apache Portable Runtime Utility: Heap buffer overflow in APR redis client | Microsoft Security Response Center RSS |
| cve | `CVE-2026-34191` | CVE-2026-34191 Apache Portable Runtime Utility: SQL Injection in apr_dbd_oracle | Microsoft Security Response Center RSS |
| cve | `CVE-2025-49506` | CVE-2025-49506 Apache Portable Runtime Utility: apr_password_validate() vulnerable to timi | Microsoft Security Response Center RSS |
| cve | `CVE-2026-64584` | CVE-2026-64584 usb: gadget: f_midi: cancel pending IN work before freeing the midi object | Microsoft Security Response Center RSS |
| cve | `CVE-2026-64583` | CVE-2026-64583 usb: gadget: udc: bdc: free IRQ and drain func_wake_notify before teardown | Microsoft Security Response Center RSS |
| cve | `CVE-2026-64590` | CVE-2026-64590 dma-buf/udmabuf: skip redundant cpu sync to fix cacheline EEXIST warning | Microsoft Security Response Center RSS |
| cve | `CVE-2026-64577` | CVE-2026-64577 gtp: check skb_pull_data() return in gtp1u_send_echo_resp() | Microsoft Security Response Center RSS |
| cve | `CVE-2026-64567` | CVE-2026-64567 btrfs: reject free space cache with more entries than pages | Microsoft Security Response Center RSS |
| cve | `CVE-2026-64569` | CVE-2026-64569 mpls: fix NULL deref in mpls_valid_fib_dump_req() on CONFIG_INET=n | Microsoft Security Response Center RSS |
| cve | `CVE-2026-64572` | CVE-2026-64572 ipv4: fib: free fib_alias with kfree_rcu() on insert error path | Microsoft Security Response Center RSS |
| cve | `CVE-2026-64576` | CVE-2026-64576 nexthop: initialize extack in nh_res_bucket_migrate() | Microsoft Security Response Center RSS |
| cve | `CVE-2026-64571` | CVE-2026-64571 wifi: p54: validate RX frame length in p54_rx_eeprom_readback() | Microsoft Security Response Center RSS |
| cve | `CVE-2026-64562` | CVE-2026-64562 KVM: nVMX: Hide shadow VMCS right after VMCLEAR | Microsoft Security Response Center RSS |
| cve | `CVE-2026-64564` | CVE-2026-64564 sctp: don't free the ASCONF's own transport in DEL-IP processing | Microsoft Security Response Center RSS |
| cve | `CVE-2026-64561` | CVE-2026-64561 KVM: x86: Check for invalid/obsolete root *after* making MMU pages availabl | Microsoft Security Response Center RSS |
| cve | `CVE-2026-18839` | CVE-2026-18839 Popt-devel: popt-static: size_t underflow in singleoptionhelp | Microsoft Security Response Center RSS |
| cve | `CVE-2026-71227` | CVE-2026-71227 Libkcapi: infinite loop denial of service in libkcapi _kcapi_aio_read_all() | Microsoft Security Response Center RSS |
| cve | `CVE-2026-71226` | CVE-2026-71226 Libkcapi: memory corruption via uncanceled aio requests on error in libkcap | Microsoft Security Response Center RSS |
| cve | `CVE-2026-71225` | CVE-2026-71225 Libkcapi: iv reuse in libkcapi one-shot symmetric cipher chunking causes ci | Microsoft Security Response Center RSS |
| cve | `CVE-2026-54876` | CVE-2026-54876 Client-Side Memory Leak in OCSP Response Checking | Microsoft Security Response Center RSS |
| cve | `CVE-2026-68082` | CVE-2026-68082 libceph: fix two unsafe bare decodes in decode_lockers() | Microsoft Security Response Center RSS |
| cve | `CVE-2026-68081` | CVE-2026-68081 KVM: nVMX: Put vmcs12 pages if nested VM-Enter fails due to invalid guest s | Microsoft Security Response Center RSS |
| cve | `CVE-2026-47243` | CVE-2026-47243 Kata guest escape: runtime-rs guest-root to host-root escape via virtiofs | Microsoft Security Response Center RSS |
| cve | `CVE-2026-64676` | CVE-2026-64676 Kata Containers: Unauthorized mem-agent ttRPC methods let an untrusted host | Microsoft Security Response Center RSS |
| cve | `CVE-2026-55995` | CVE-2026-55995 Double-free in the iSNS attribute decoder in open-iscsi | Microsoft Security Response Center RSS |
| cve | `CVE-2026-44944` | CVE-2026-44944 iscsiuio control-socket authentication bypass in open-iscsi | Microsoft Security Response Center RSS |
| cve | `CVE-2026-44943` | CVE-2026-44943 remote limited file-write as root via discovery in open-iscsi | Microsoft Security Response Center RSS |
| cve | `CVE-2026-6879` | CVE-2026-6879 Quadratic Behavior in xml.etree.ElementPath Index Predicates | Microsoft Security Response Center RSS |
| cve | `CVE-2026-32597` | CVE-2026-32597 PyJWT accepts unknown `crit` header extensions (RFC 7515 §4.1.11 MUST viola | Microsoft Security Response Center RSS |