Critical Isolated-vm Vulnerability Leads to RCE on Host
2026-08-21T13:23:59Z•e2bc7008a05a5e95795392637dbb5433f40344825e4d064cc849370a71871e55
CVE-2026-73570AtlassianCISADahuaHead-MareIP-camerasMLflowMicrosoft-Entra-IDNorth-KoreaPhantomCoreSplunkTrueConfZimbraactive-exploitationcloud-securitycredential-theftpatch-managementremote-code-executionsandbox-escapesupply-chain-attackzero-day
What happened
SecurityWeek RSS digest covering active exploitation, critical vulnerabilities, supply-chain compromise, cloud credential theft, and major security patch releases. Notable items include an isolated-vm type-confusion flaw enabling V8 sandbox escape and host-process RCE, a poisoned Rust arrayref release linked to North Korean operators, exploited Microsoft Entra ID and TrueConf vulnerabilities, active exploitation of Zimbra CVE-2026-73570, Operation CameraSwarm compromising approximately 14,000 Dahua cameras, and MLflow exploitation to access internal endpoints and steal cloud credentials.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityweek
- Record identifier
- e2bc7008a05a5e95795392637dbb5433f40344825e4d064cc849370a71871e55
- Enrichment time
- 2026-08-21T13:23:59Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.