# Threat Intel Brief — August 26, 2026

TL;DR

  • Critical Oracle WebLogic flaw (CVE-2026-21962, CVSS 10.0) actively exploited; CISA mandates federal patching by August 27.
  • Zimbra RCE vulnerability under active exploitation with 270+ confirmed compromises; CISA orders 3-day remediation for federal agencies.
  • Keycloak authentication bypass (CVE-2026-18963, CVSS 9.1) allows unauthenticated account takeover via password reset manipulation.
  • Mirage2FA phishing campaign compromised 4,500+ US/EU organizations through Microsoft 365 session hijacking, bypassing MFA.
  • China-nexus Operation QUICSILVER targets Myanmar government with QUICAgent backdoor; concurrent Mustang Panda activity observed.

Critical Threats

Oracle WebLogic Server Exploitation (CVE-2026-21962)

What happened: CISA added CVE-2026-21962 to its Known Exploited Vulnerabilities catalog following confirmed active exploitation since February 2026. The maximum-severity flaw (CVSS 10.0) affects Oracle HTTP Server and WebLogic Server Proxy Plug-in, allowing unauthenticated remote attackers to access, create, delete, or modify critical data via HTTP. GreyNoise and CloudSEK observed attacks from IP 193.24.123[.]42, with threat actors chaining this vulnerability alongside older WebLogic flaws (CVE-2020-14882, CVE-2020-2551, CVE-2017-10271).

Impact: Complete compromise of accessible data on internet-facing WebLogic deployments. Federal agencies face mandatory remediation deadline of August 27, 2026. High risk for financial services, telecommunications, and government networks globally where WebLogic remains widely deployed.

Recommendations:

  • Apply Oracle Critical Patch Update from January 2026 immediately to all WebLogic and Oracle HTTP Server instances
  • Block inbound traffic from 193.24.123[.]42 and review logs for compromise indicators
  • Restrict HTTP access to WebLogic servers to trusted sources only; remove public internet exposure where possible

Zimbra Collaboration Suite Remote Code Execution

What happened: CISA issued emergency directive requiring federal agencies to patch an actively exploited Zimbra vulnerability within three days. The unauthenticated RCE flaw enables command injection via SNMP monitoring components when SNMP notifications are enabled. Shadowserver identified 270+ compromised instances; CERT Polska flagged active exploitation on August 17. Over 12,000 Zimbra servers remain exposed online.

Impact: Attackers execute arbitrary OS commands as the Zimbra user by sending crafted SMTP requests. Historical targeting by APT28, APT29, and Winter Vivern for credential theft and espionage. Hundreds of millions of users globally rely on ZCS, including government agencies and enterprises.

Recommendations:

  • Upgrade Zimbra Collaboration Suite to version 10.1.20 or later immediately (released July 20, 2026)
  • Review /opt/zimbra/jetty/webapps/, /opt/zimbra/jetty_base/webapps/, and /tmp/ for suspicious files created by 'zimbra' user
  • Disable SNMP notifications as temporary mitigation if immediate patching is not possible
  • Monitor SMTP traffic for anomalous requests targeting SNMP notification processing

Keycloak Account Takeover Vulnerability (CVE-2026-18963)

What happened: Red Hat and the Keycloak project patched a critical authentication bypass (CVSS 9.1) allowing unauthenticated remote attackers to take over any user account, including administrators, by forcing password resets. The flaw exploits improper state validation in the reset-credentials flow, bypassing email token requirements. Affects upstream Keycloak versions prior to 26.7.2 and Red Hat builds prior to 26.4.15/26.6.6.

Impact: Complete account takeover without authentication or user interaction. Organizations using Keycloak as SSO/IAM gateway face cascading compromise of all downstream applications. No evidence of active exploitation as of August 24, but proof-of-concept details are public.

Recommendations:

  • Update upstream Keycloak to 26.7.2 or Red Hat builds to 26.4.15/26.6.6 immediately
  • Disable 'Forgot password' functionality in all realms if immediate patching is not possible
  • Review authentication logs for anomalous password reset activity or direct reset-credentials endpoint requests
  • Force password resets for privileged accounts after patching to ensure no prior compromise

miniOrange SAML Plugin Authentication Bypass

What happened: Attackers are actively exploiting two critical authentication bypass vulnerabilities in the miniOrange SAML 2.0 Single Sign On WordPress plugin. CVE-2026-61979 (CVSS 8.1) and CVE-2026-15981 (CVSS 9.8) allow unauthenticated attackers to forge SAML responses and gain WordPress administrator access. Scanning activity observed from six IP addresses across Europe, Africa, and the United States since August 16. DigitalOcean blocked anomalous admin sessions created via exploit chains.

Impact: Complete WordPress site takeover without valid credentials. Affects 10,000+ free installs and 30,000 paid customers using the plugin for SAML-based SSO with Microsoft Entra ID, Okta, Google Workspace, or OneLogin. Paid editions lack dashboard update notifications, leaving many sites unpatched despite July 2026 fixes.

Recommendations:

  • Upgrade miniOrange SAML SSO plugin immediately: Free 5.4.5+, Premium single-site 13.0.4+, Standard 17.06+, multisite/enterprise versions per vendor guidance
  • Manually verify paid edition versions via plugin settings—WordPress dashboard does not show update warnings
  • Review WordPress administrator accounts created since July 2026 for unauthorized entries
  • Monitor for suspicious admin sessions from unexpected geographic locations

Threat Actor Activity

Operation QUICSILVER: China-Nexus Espionage Against Myanmar

A China-nexus threat actor is conducting cyber espionage against Myanmar's government and IT sectors using the QUICAgent Go backdoor. The campaign employs graduation ceremony invitation lures impersonating Myanmar's Information Technology and Cyber Security Department. Multi-stage infection chains abuse ftp.exe (LOLBAS technique) and implement sandbox evasion via random delays and SHA-256 hashing. C2 infrastructure is dynamically retrieved via Cloudflare Workers, with QUIC over UDP port 443 for communications. The disclosure coincides with Mustang Panda deploying updated COOLCLIENT backdoors with kernel-mode capabilities across Myanmar, Mongolia, Pakistan, and Russia, suggesting coordinated China-nexus collection efforts.

UAT-10147: AI-Assisted Global Server Compromise Campaign

Chinese-speaking cybercrime group UAT-10147 is targeting Windows and Linux web servers globally using AI-powered tools (PentestGPT, DeepAudit) to automate exploitation at scale. The group deploys SPECTRE malware with EDR bypass capabilities and Linux rootkit functionality, primarily targeting education, media, technology, and gaming sectors. Victims are concentrated in Brazil, Bolivia, China, Canada, and Vietnam. The actor exploits known vulnerabilities including CVE-2022-27925 (Zimbra), CVE-2021-23758 (AjaxPro), CVE-2019-18935 (Telerik UI), and multiple Linux privilege escalation flaws (CVE-2022-0995, CVE-2021-3156, CVE-2022-0847). Target lists of ~170,000 URLs indicate mass exploitation for SEO fraud and data theft.

Mirage2FA: Large-Scale Microsoft 365 Phishing Campaign

The Mirage2FA phishing-as-a-service campaign has targeted approximately 4,500 US and EU companies from 2024 to 2026, abusing Microsoft 365 login flows to bypass two-factor authentication. The commercial toolkit uses adversary-in-the-middle (AiTM) techniques to harvest credentials and session cookies, enabling attackers to hijack authenticated sessions. ANY.RUN research indicates 48% of targeted email addresses were potentially compromised, with 63.7% of victims US-based. Primary targets include technology, manufacturing, and education sectors.

Iranian Cyber Actors: U.S. Sanctions Under Operation Economic Outcast

The U.S. Treasury sanctioned five Iranian cyber actors affiliated with Iran's Ministry of Intelligence and Security (MOIS) for targeting U.S. critical infrastructure since late 2023. The individuals—Behzad Mesri, Mojtaba Ghal'eh-Kuhi, Keyvan Fayyaz Ghareh Blagh, Saber Shahbazi Balujeh, and Mohammad Reza Kadkhoda'i—are linked to the Tehran-based Mabna Institute. Operations include network compromise of energy companies, defense contractors, healthcare institutions, telecommunications providers, and water utilities across 12+ U.S. states. TRM Labs identified approximately $16.8 million in cryptocurrency transactions across 30 wallets between 2018-2026. Recent campaigns include spear-phishing FBI Director Kash Patel's personal email and a 4-day U.K. power plant shutdown.

Geopolitical Context

Norway Government Infrastructure Under Sustained DDoS Attack

Norway's shared government digital infrastructure (Digitaliseringsdirektoratet) has been disrupted by distributed denial-of-service attacks since August 23, 2026—the third such incident in three months. Affected services include ID-porten (public login), electronic signatures, secure government communications, and inter-agency data exchange. Norwegian media speculate potential Russian involvement, though no official attribution has been issued. The attacks impact tax administration (Skatteetaten) and business-government communications (Altinn), with no data breach or system compromise confirmed.

Global Law Enforcement Operation Targets African Cybercrime Networks

Operation Jackal IV, coordinated by INTERPOL across 22 countries between November 2025 and June 2026, resulted in 58 arrests and identification of 263 suspects linked to West African cybercrime networks, particularly the Black Axe syndicate. The operation targeted romance scams, cryptocurrency fraud, business email compromise, and sextortion campaigns. Arrests occurred in Argentina (17), South Africa (39), Romania (11), and Italy (1), with $2.67 million seized in South Africa and 257 bank accounts blocked. The campaign follows Operation Red Card 2.0 (651 arrests) and Operation First Light 2026 (5,811 arrests, $293 million seized).

Recommended Actions

Immediate (0-24 hours)

  • Patch Oracle WebLogic Server to address CVE-2026-21962 (CVSS 10.0) on all internet-facing instances; federal agencies must comply by August 27
  • Upgrade Zimbra Collaboration Suite to version 10.1.20 or disable SNMP notifications as emergency mitigation
  • Update Keycloak to version 26.7.2 (upstream) or Red Hat builds 26.4.15/26.6.6; disable 'Forgot password' feature if patching is delayed
  • Upgrade miniOrange SAML plugin on all WordPress installations; manually verify paid edition versions as dashboard notifications are absent

Within 24-72 hours

  • Audit WordPress administrator accounts created since July 2026 for unauthorized entries; review SAML authentication logs for anomalies
  • Hunt for UAT-10147 indicators: certutil.exe abuse, EfsPotato privilege escalation tools, suspicious Defender exclusion modifications, and outbound connections to Alibaba Nacos
  • Review Zimbra service logs for unexpected restarts; check /opt/zimbra/ directories for suspicious files created by 'zimbra' user in the last 30 days
  • Monitor for FTP-based dead drop resolver activity: block outbound FTP connections (port 21) to non-business-critical servers; alert on anomalous FTP traffic from workstations

This week

  • Implement phishing-resistant MFA (FIDO2/WebAuthn) to defend against Mirage2FA-style session hijacking attacks on Microsoft 365 environments
  • Deploy behavioral analytics for Microsoft 365 session anomalies including impossible travel, unusual SSO access patterns, and session token reuse from multiple IP addresses
  • Strengthen email security controls against spear-phishing campaigns, particularly for high-value personnel; enforce number matching or FIDO2-based MFA instead of push notifications
  • Review PostgreSQL instances for critical RCE vulnerability; apply latest security patches immediately (CVE: see source)
  • Assess Calix GS7 XGS router deployments (CVE-2026-75501); disable UPnP via admin interface or contact ISP to request deactivation

Watch List

  • NVIDIA NemoClaw DNS rebinding vulnerability: Upgrade to v0.0.35 on macOS/Linux; Windows/WSL remain vulnerable with no patch available
  • Marimo notebook code injection (CVE-2026-75149): Update to version 0.23.15+ if opening notebooks from untrusted sources
  • Microsoft .NET Framework August 2026 updates: Breaking WPF printing and PDF export functionality; workaround disables security protections
  • Calix GS7 XGS routers: Unpatched UPnP exposure on WAN (CVE-2026-75501) allows unauthenticated NAT bypass; vendor unresponsive
  • npm package mirrors abuse: 24 malicious packages hosting fake Cloudflare CAPTCHA phishing pages via unpkg.com; block HTML file access to npm mirrors
  • AnonyMousKIT PhaaS: Voice AI agents targeting iPhone passcode theft via Apple Support impersonation; 168 reseller brands across 506 domains
  • E4del and PINHOLE RATs: Novel FTP banner dead drop resolver technique; Spanish-language phishing lures delivering Node.js and Electron-based backdoors

Sources

  • CISA Known Exploited Vulnerabilities Catalog
  • BleepingComputer
  • The Hacker News
  • CERT.BE (Belgium)
  • GreyNoise, CloudSEK, Shadowserver Foundation
  • Red Hat Product Security
  • ANY.RUN Research
  • SOCRadar Threat Intelligence
  • McAfee Labs
  • U.S. Department of the Treasury (OFAC)
  • INTERPOL

---

*This brief covers threats observed through August 26, 2026. Organizations should prioritize patching of actively exploited vulnerabilities (CVE-2026-21962, CVE-2026-18963, CVE-2026-61979, CVE-2026-15981) and implement phishing-resistant authentication controls to defend against credential harvesting campaigns.*