# ANSSI Flags Actively Exploited Flaws in GitLab, Zimbra, VMware

Published: 2026-08-24 · Severity: severe · Sectors: technology, infrastructure
Canonical: https://vorant.io/reports/0bbf391a-7a45-597e-8ba2-5db74954eef9/anssi-flags-actively-exploited-flaws-in-gitlab-zimbra-vmware

> French CERT-FR's weekly bulletin highlights critical, actively-exploited vulnerabilities in GitLab, Zimbra, VMware vCenter, Apple macOS, TrueConf, MLflow, SPIP and more, plus dozens of high-severity CVSS 9+ issues in Cisco, Oracle and Splunk products.

CERT-FR's weekly activity bulletin (week 34, 2026) summarizes the most significant vulnerabilities disclosed between 17-23 August 2026. Several are confirmed as actively exploited in the wild, including a data-integrity flaw in GitLab CE/EE (CVE-2026-19478, CVSS 9.4), a remote code execution and security-bypass issue in Synacor Zimbra Collaboration (CVE-2026-73570, CVSS 8.9), a critical VMware vCenter Server RCE (CVE-2026-59310, CVSS 9.8) already listed in CISA's KEV catalog, an Apple macOS security-bypass flaw (CVE-2026-65400), two TrueConf Server RCEs (CVE-2026-72530/72529), and an MLflow security-bypass vulnerability (CVE-2026-64849). SPIP CMS also received three critical patches in recent weeks, with the vendor confirming in-the-wild exploitation attempts against CVE-2026-77806 and public proof-of-concept code available; CERT-FR urges migration to SPIP 4.4.21.

Beyond confirmed exploitation, the bulletin catalogs an unusually dense cluster of maximum-severity (CVSS 9.6-10) advisories with no confirmed in-the-wild activity yet: eight Cisco Secure Workload and Crosswork vulnerabilities (several rated CVSS 10, covering RCE, SQLi, and security-bypass), six Oracle Weblogic/PeopleSoft/Database Server RCEs from the August critical patch update, and four Splunk Enterprise/MCP Server vulnerabilities affecting confidentiality, integrity, and remote code execution. A Google Chrome RCE (CVE-2026-76036) and additional exploited issues in WordPress Elementor Pro and n8n (with public exploit code available for the latter) round out the list. CERT-FR reiterates that this digest does not replace full review of individual advisories and that all listed vulnerabilities should be risk-assessed and patched according to organizational exposure.

For defenders, the priority items are the vulnerabilities marked as actively exploited or KEV-listed (GitLab, Zimbra, VMware vCenter, Apple macOS, TrueConf, MLflow, SPIP) since these represent live attacker interest; the remaining CVSS 9+ Cisco, Oracle, and Splunk advisories should be scheduled for prompt patching given their severity even absent confirmed exploitation.

## Mentioned in this report

- Vulnerabilities: CVE-2026-19478 (templated), CVE-2026-20030, CVE-2026-20231, CVE-2026-20315, CVE-2026-20317, CVE-2026-20318, CVE-2026-20357, CVE-2026-20358, CVE-2026-20359, CVE-2026-32475 (templated), CVE-2026-33696, CVE-2026-59310 (KEV), CVE-2026-60672, CVE-2026-60696, CVE-2026-60698, CVE-2026-60702, CVE-2026-60821, CVE-2026-60977, CVE-2026-64849 (KEV), CVE-2026-65400 (KEV), CVE-2026-66738, CVE-2026-71063, CVE-2026-71064, CVE-2026-71102, CVE-2026-72529 (KEV), CVE-2026-72530 (KEV), CVE-2026-73570 (KEV), CVE-2026-76036, CVE-2026-76310, CVE-2026-76311, CVE-2026-76312, CVE-2026-76404, CVE-2026-77647 (weaponized), CVE-2026-77806 (templated)

Source reporting: https://www.cert.ssi.gouv.fr/actualite/CERTFR-2026-ACT-036

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/0bbf391a-7a45-597e-8ba2-5db74954eef9/anssi-flags-actively-exploited-flaws-in-gitlab-zimbra-vmware.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
