This Week in Cybersecurity: Zero-Days, Ransomware, & Nation-States – August 3-9, 2026

Microsoft disclosed an actively exploited zero-day vulnerability in Exchange Server, CVE-2026-42897, allowing unauthenticated attackers to execute arbitrary JavaScript, as reported by the OpenVPN Blog. Simultaneously, Cisco patched CVE-2026-20182, a maximum-severity authentication bypass in its SD-WAN products, which a sophisticated operator, UAT-8616, actively exploited. This period saw a convergence of threats including new zero-day exploits by ransomware groups and nation-state targeting of critical infrastructure and traveler data.

1. Critical Zero-Days Impact Microsoft Exchange and Cisco SD-WAN

Microsoft and Cisco disclosed actively exploited zero-day vulnerabilities this period, demanding urgent action from IT professionals. Microsoft revealed an actively exploited zero-day, CVE-2026-42897, affecting Exchange Server as reported by the OpenVPN Blog. This vulnerability permits unauthenticated attackers to execute arbitrary JavaScript. While this initially suggests client-side impact, an unauthenticated flaw on a mail server often presents a significant gateway to remote code execution or internal network reconnaissance through crafted emails or web requests. CISA recognized the severity, adding CVE-2026-42897 to its Known Exploited Vulnerabilities (KEV) catalog with a federal remediation deadline of May 29, 2026. Organizations running on-premises Exchange instances must prioritize immediate patching to prevent potential server compromise and lateral movement within their environments. Even if direct RCE isn't immediately evident, the ability to execute arbitrary code without authentication is a critical vector.

Concurrently, Cisco patched a maximum-severity authentication bypass, CVE-2026-20182, in its SD-WAN products, as detailed by the OpenVPN Blog. This flaw is actively exploited by a sophisticated operator identified as UAT-8616, OpenVPN Blog confirmed. An authentication bypass on core network infrastructure like SD-WAN allows an attacker to gain administrative access without valid credentials, effectively granting full control over affected devices. Such comprehensive access enables UAT-8616 to intercept, redirect, or disrupt network traffic, posing severe risks to network integrity, data confidentiality, and availability. Immediately apply Cisco’s provided patches to all affected SD-WAN deployments. Security teams should also conduct thorough log reviews for any anomalous access attempts or configuration changes prior to patching and actively monitor for post-patch network anomalies to detect persistent compromise. While Cisco has addressed the flaw, discovering an advanced persistent threat like UAT-8616 means incident responders need to go beyond simple patching.

2. Inc Ransomware Exploits SonicWall SMA Zero-Days

The Inc ransomware-as-a-service (RaaS) group has been observed actively exploiting two zero-day vulnerabilities in SonicWall Secure Mobile Access (SMA) 1000 Series appliances, per F5 Labs. This marks a significant escalation for the Inc group, moving from opportunistic targeting to sophisticated zero-day exploitation. The vulnerabilities include a critical server-side request forgery (SSRF) flaw, CVE-2026-15409, which carries a CVSS score of 10.0. This means it can be exploited remotely without authentication, leading to maximum impact. The second vulnerability is a high-severity code injection flaw, CVE-2026-15410, rated at CVSS 7.2. Chaining these two vulnerabilities grants attackers root-level remote code execution on the appliances, F5 Labs reports.

Successful exploitation of these flaws provides Inc ransomware operators with a direct entry point into victims' networks, bypassing traditional perimeter defenses. SonicWall SMA devices are commonly used for secure remote access, making them prime targets for initial access brokers and ransomware groups. Once root access is achieved, attackers can deploy ransomware, exfiltrate sensitive data, or establish persistent backdoors for future operations. Organizations using SonicWall SMA 1000 Series appliances must immediately apply all available patches and configuration updates released by SonicWall. Beyond patching, security teams should isolate these devices from internal networks as much as possible, enable multi-factor authentication for all remote access, and meticulously review logs for any indicators of compromise (IOCs) such as unusual process execution, new user accounts, or outbound connections to suspicious IPs. Given the CVSS 10.0 rating, an unpatched device is essentially an open door for sophisticated ransomware operations.

3. CISA Adds SharePoint and FortiSandbox Flaws to KEV Catalog

CISA added three actively exploited vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog on July 16, 2026, as reported by F5 Labs. The inclusion in the KEV catalog signifies that these vulnerabilities are under active exploitation and pose a material risk to federal agencies, implying the same for private sector organizations. One critical flaw is CVE-2026-58644, a deserialization vulnerability in Microsoft SharePoint Server with a CVSS score of 9.8. This flaw allows network-based remote code execution with Site Owner privileges. While it requires Site Owner privileges, which might limit its reach in highly segmented internal networks, the high impact of RCE on a critical collaboration platform like SharePoint makes it extremely dangerous for data integrity and confidentiality. Attackers who gain access to even a single Site Owner account could pivot to full control over affected SharePoint instances.

The other two vulnerabilities added by CISA are OS command injection flaws affecting various versions of Fortinet FortiSandbox, identified as CVE-2026-25089, each with a CVSS score of 9.1. These vulnerabilities could allow an attacker to execute arbitrary commands on the underlying operating system of the sandbox appliance. FortiSandbox products are designed to detect and analyze advanced threats, so a compromise of the sandbox itself could allow attackers to bypass security controls, gather intelligence on an organization's defenses, or even use the appliance as a pivot point for further attacks. Security teams should prioritize patching all affected SharePoint Server and FortiSandbox instances immediately, following vendor advisories. For SharePoint, reviewing Site Owner access and implementing least privilege principles is essential. For FortiSandbox, ensure it operates in a highly isolated network segment and monitor for unusual outbound connections or system activity to mitigate the risks associated with CVE-2026-25089.

4. Iran-Linked Cyberattacks Target U.S. Water Systems

U.S. intelligence agencies attribute coordinated cyberattacks on over 30 municipal water systems in Minnesota to Iran, as reported by TIME. This marks a concerning escalation in nation-state activity targeting critical infrastructure within the United States. The attackers remotely accessed industrial control systems (ICS), changed administrator passwords, and caused tangible operational disruptions. These disruptions included incidents of flooding and significant pressure loss within the affected water systems, demonstrating the potential for real-world physical impact from cyber-attacks. Such attacks not only pose a direct threat to public health and safety but also erode public trust in essential services.

In response to these incidents, CISA issued urgent advisories urging water and wastewater systems across the nation to implement immediate security enhancements. Key recommendations include disconnecting Programmable Logic Controllers (PLCs) and other operational technology (OT) devices from direct internet access. Furthermore, CISA stressed the importance of changing all default passwords on any internet-connected devices or systems within these environments. Organizations managing critical infrastructure, particularly water and wastewater facilities, must conduct comprehensive security audits of their OT networks. Implementing strict network segmentation, enforcing multi-factor authentication for all remote access, and establishing immutable, tested incident response plans tailored to OT environments are no longer optional. This campaign by Iran highlights the escalating risks faced by operational technology.

5. Russian Hackers Hijack Hotel Wi-Fi to Steal Microsoft 365 Tokens

Microsoft Threat Intelligence identified a campaign, dubbed CaptiveCrunch, by the Russian SVR-linked group Midnight Blizzard (Storm-2945), as detailed by Security Affairs. This group, known for its persistent and stealthy espionage activities, has been manipulating DNS and hijacking hotel Wi-Fi portals since early May 2026, Security Affairs confirmed. Their primary objective is to steal Microsoft 365 tokens from travelers, particularly those in high-value positions, to gain unauthorized access to sensitive information from compromised accounts. This method effectively turns public Wi-Fi networks into an advanced phishing and credential harvesting mechanism. By controlling the DNS resolution or redirecting users through malicious captive portals, Storm-2945 can intercept authentication attempts and steal session tokens without the user necessarily realizing they’ve been compromised.

The implications of this campaign are far-reaching, especially for business travelers who frequently rely on hotel Wi-Fi for work. Compromised Microsoft 365 tokens can grant attackers persistent access to emails, documents, and other cloud resources, leading to corporate espionage, data exfiltration, and further network infiltration. Organizations must educate their employees, especially frequent travelers, about the risks of public Wi-Fi. Mandating the use of corporate VPNs for all work-related activities when using public networks is crucial. Additionally, enforcing device posture checks before allowing access to internal resources, requiring hardware-backed multi-factor authentication (MFA), and regularly reviewing Microsoft 365 audit logs for unusual sign-in locations or activity patterns can help detect and mitigate compromise from CaptiveCrunch. This campaign highlights the enduring threat from SVR-backed groups targeting individuals for strategic intelligence.

What to Watch Next Week

Next week, anticipate further fallout from the Microsoft Exchange and Cisco SD-WAN zero-days; more organizations will discover potential compromise from UAT-8616 and other threat actors. We'll also be monitoring for any new information regarding the Inc ransomware campaign exploiting SonicWall SMA vulnerabilities, particularly if more indicators of compromise emerge. Keep an eye on the second Tuesday of the month for the typical patch cycle from major vendors, which could include fixes for any new zero-days disclosed during this period. For active campaigns, the CaptiveCrunch activity by Midnight Blizzard remains a significant concern; expect continued efforts by Microsoft Threat Intelligence to track its evolution and potential new targets, requiring vigilance from travelers and security teams alike.

Data at a Glance

Story Type Severity / Scale Status Source
Microsoft Exchange / Cisco SD-WAN Zero-Days Zero-Day Exploitation CVE-2026-42897 (Unauthenticated JS Execution), CVE-2026-20182 (Max-Severity Auth Bypass) Actively Exploited by UAT-8616 OpenVPN Blog
Inc Ransomware Exploits SonicWall SMA Zero-Days Ransomware / Zero-Day Exploitation CVE-2026-15409 (CVSS 10.0), CVE-2026-15410 (CVSS 7.2) Actively Exploited F5 Labs
CISA Adds SharePoint & FortiSandbox Flaws to KEV Actively Exploited Vulnerabilities CVE-2026-58644 (CVSS 9.8), CVE-2026-25089 (CVSS 9.1) KEV Cataloged F5 Labs
Iran-Linked Attacks on U.S. Water Systems Nation-State / Critical Infrastructure Attack Over 30 Municipal Water Systems Targeted Active Disruptions TIME
Russian Hackers Hijack Hotel Wi-Fi for Microsoft 365 Tokens Nation-State / Espionage Microsoft 365 Token Theft Active since early May 2026 Security Affairs

The CVEDaily Take

This week’s incidents show a dangerous trend: ransomware groups are not waiting for public disclosures, and nation-states are directly targeting operational technology. The fact that CVE-2026-15409, a perfect 10.0 CVSS score vulnerability, is being exploited by a ransomware group like Inc RaaS suggests that their exploit development capabilities are accelerating beyond what many organizations can defend against. We believe that many organizations are still underestimating the speed at which threat actors integrate newly discovered zero-days into their operations. It’s no longer enough to patch quickly; security teams need to hunt for exploitation pre-patch.

How are you prioritizing patching efforts for high-CVSS zero-days like CVE-2026-15409 while simultaneously checking for signs of prior compromise on your SonicWall SMA devices?

FAQ

What happened in cybersecurity this week?
This week in cybersecurity saw critical zero-day vulnerabilities in Microsoft Exchange and Cisco SD-WAN actively exploited. The Inc ransomware group leveraged new zero-days in SonicWall SMA appliances, and CISA added significant flaws in SharePoint and FortiSandbox to its KEV catalog. Additionally, Iran-linked cyberattacks targeted over 30 U.S. municipal water systems, while Russian hackers from Midnight Blizzard engaged in widespread hotel Wi-Fi hijacking to steal Microsoft 365 tokens from travelers.

What was the biggest cyber attack this week?
The biggest cyber attack this week arguably involved the coordinated Iran-linked cyberattacks on over 30 municipal water systems in Minnesota. These attacks, attributed by U.S. intelligence agencies and reported by TIME, directly impacted critical infrastructure, leading to operational disruptions like flooding and pressure loss, posing a tangible threat to public safety and essential services.

What is the risk of CVE-2026-15409 impacting SonicWall SMA devices?
CVE-2026-15409 is a critical server-side request forgery (SSRF) vulnerability in SonicWall Secure Mobile Access (SMA) 1000 Series appliances, carrying a maximum CVSS score of 10.0. This means it can be exploited remotely and without authentication, allowing attackers, specifically the Inc ransomware group, to achieve root-level remote code execution when chained with CVE-2026-15410. The risk is immediate and severe, potentially leading to full network compromise, ransomware deployment, and data exfiltration from organizations using these devices for remote access.