VORANT. Threat Intelligence Sign in Get the full feed

ANSSI Flags Actively Exploited Flaws in GitLab, Zimbra, VMware

severe vulnerability technologyinfrastructure

French CERT-FR's weekly bulletin highlights critical, actively-exploited vulnerabilities in GitLab, Zimbra, VMware vCenter, Apple macOS, TrueConf, MLflow, SPIP and more, plus dozens of high-severity CVSS 9+ issues in Cisco, Oracle and Splunk products.

CERT-FR's weekly activity bulletin (week 34, 2026) summarizes the most significant vulnerabilities disclosed between 17-23 August 2026. Several are confirmed as actively exploited in the wild, including a data-integrity flaw in GitLab CE/EE (CVE-2026-19478, CVSS 9.4), a remote code execution and security-bypass issue in Synacor Zimbra Collaboration (CVE-2026-73570, CVSS 8.9), a critical VMware vCenter Server RCE (CVE-2026-59310, CVSS 9.8) already listed in CISA's KEV catalog, an Apple macOS security-bypass flaw (CVE-2026-65400), two TrueConf Server RCEs (CVE-2026-72530/72529), and an MLflow security-bypass vulnerability (CVE-2026-64849). SPIP CMS also received three critical patches in recent weeks, with the vendor confirming in-the-wild exploitation attempts against CVE-2026-77806 and public proof-of-concept code available; CERT-FR urges migration to SPIP 4.4.21.

Beyond confirmed exploitation, the bulletin catalogs an unusually dense cluster of maximum-severity (CVSS 9.6-10) advisories with no confirmed in-the-wild activity yet: eight Cisco Secure Workload and Crosswork vulnerabilities (several rated CVSS 10, covering RCE, SQLi, and security-bypass), six Oracle Weblogic/PeopleSoft/Database Server RCEs from the August critical patch update, and four Splunk Enterprise/MCP Server vulnerabilities affecting confidentiality, integrity, and remote code execution. A Google Chrome RCE (CVE-2026-76036) and additional exploited issues in WordPress Elementor Pro and n8n (with public exploit code available for the latter) round out the list. CERT-FR reiterates that this digest does not replace full review of individual advisories and that all listed vulnerabilities should be risk-assessed and patched according to organizational exposure.

For defenders, the priority items are the vulnerabilities marked as actively exploited or KEV-listed (GitLab, Zimbra, VMware vCenter, Apple macOS, TrueConf, MLflow, SPIP) since these represent live attacker interest; the remaining CVSS 9+ Cisco, Oracle, and Splunk advisories should be scheduled for prompt patching given their severity even absent confirmed exploitation.

Mentioned in this report

Vulnerabilities CVE-2026-19478templatedCVE-2026-20030CVE-2026-20231CVE-2026-20315CVE-2026-20317CVE-2026-20318CVE-2026-20357CVE-2026-20358CVE-2026-20359CVE-2026-32475templatedCVE-2026-33696CVE-2026-59310KEVCVE-2026-60672CVE-2026-60696CVE-2026-60698CVE-2026-60702CVE-2026-60821CVE-2026-60977CVE-2026-64849KEVCVE-2026-65400KEVCVE-2026-66738CVE-2026-71063CVE-2026-71064CVE-2026-71102CVE-2026-72529KEVCVE-2026-72530KEVCVE-2026-73570KEVCVE-2026-76036CVE-2026-76310CVE-2026-76311CVE-2026-76312CVE-2026-76404CVE-2026-77647weaponizedCVE-2026-77806templated

Source reporting: https://www.cert.ssi.gouv.fr/actualite/CERTFR-2026-ACT-036

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free