Critical Isolated-vm Vulnerability Leads to RCE on Host

2026-08-21T13:23:59Ze2bc7008a05a5e95795392637dbb5433f40344825e4d064cc849370a71871e55
CVE-2026-73570AtlassianCISADahuaHead-MareIP-camerasMLflowMicrosoft-Entra-IDNorth-KoreaPhantomCoreSplunkTrueConfZimbraactive-exploitationcloud-securitycredential-theftpatch-managementremote-code-executionsandbox-escapesupply-chain-attackzero-day

What happened

SecurityWeek RSS digest covering active exploitation, critical vulnerabilities, supply-chain compromise, cloud credential theft, and major security patch releases. Notable items include an isolated-vm type-confusion flaw enabling V8 sandbox escape and host-process RCE, a poisoned Rust arrayref release linked to North Korean operators, exploited Microsoft Entra ID and TrueConf vulnerabilities, active exploitation of Zimbra CVE-2026-73570, Operation CameraSwarm compromising approximately 14,000 Dahua cameras, and MLflow exploitation to access internal endpoints and steal cloud credentials.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityweek
Record identifier
e2bc7008a05a5e95795392637dbb5433f40344825e4d064cc849370a71871e55
Enrichment time
2026-08-21T13:23:59Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Critical Isolated-vm Vulnerability Leads to RCE on Host · Baitaphish