Executive assessment
Today's brief leads with Still active: New cPanel Critical Flaw Could Let Hosting Customers Run SQL as Database Root. All 10 selected findings retain their own technical scope, action, observed status, and evidence limits.
Finding 01 — Still active: New cPanel Critical Flaw Could Let Hosting Customers Run SQL as Database Root
Coverage status: First reported 2026-08-05; ongoing coverage.
What changed: cPanel has patched a flaw that let an authenticated hosting customer execute SQL in the databases root context, crossing the privilege boundary between a cPanel account and the servers administrative database identity. It shipped in a targeted security release that closes two other routes past account boundaries.
Technical evidence: CVE-2026-58048; CVSS v4.0 9.4; weakness ['CWE-89']; technical confidence High.
Why it matters: The Critical priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.
Observed status: Observed in-the-wild exploitation status is unknown.
Action: Map CVE-2026-58048 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
Evidence limits: exploitation status unknown
fixed version or patch state unknown
affected product not structured
[Evidence source: thehackernews.com](<https://thehackernews.com/2026/08/new-cpanel-critical-flaw-could-let.html>)
Finding 02 — A flaw was found in the Linux kernel in versions before 5.12. The value of internal.ndata, in the KVM API, is mapped to an array index.
What changed: A flaw was found in the Linux kernel in versions before 5.12. The value of internal.ndata, in the KVM API, is mapped to an array index, which can be updated by a user process at anytime which could lead to an out-of-bounds write.
Technical evidence: CVE-2021-3501; CVSS v3.1 7.1; weakness ['CWE-787']; technical confidence High.
Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.
Observed status: Observed in-the-wild exploitation status is unknown.
Action: Map CVE-2021-3501 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
Evidence limits: exploitation status unknown
fixed version or patch state unknown
affected product not structured
[Evidence source: nvd.nist.gov](<https://nvd.nist.gov/vuln/detail/CVE-2021-3501>)
Finding 03 — A flaw was found in the Nosy driver in the Linux kernel. This issue allows a device to be inserted twice into a doubly-linked list.
What changed: A flaw was found in the Nosy driver in the Linux kernel. This issue allows a device to be inserted twice into a doubly-linked list, leading to a use-after-free when one of these devices is removed.
Technical evidence: CVE-2021-3483; CVSS v3.1 7.8; weakness ['CWE-416']; technical confidence High.
Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.
Observed status: Observed in-the-wild exploitation status is unknown.
Action: Map CVE-2021-3483 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
Evidence limits: exploitation status unknown
fixed version or patch state unknown
affected product not structured
[Evidence source: nvd.nist.gov](<https://nvd.nist.gov/vuln/detail/CVE-2021-3483>)
Finding 04 — A vulnerability was found in the pfkey_register function in net/key/af_key.c in the Linux kernel.
What changed: A vulnerability was found in the pfkey_register function in net/key/af_key.c in the Linux kernel. This flaw allows a local, unprivileged user to gain access to kernel memory, leading to a system crash or a leak of internal kernel information.
Technical evidence: CVE-2022-1353; CVSS v3.1 7.1; weakness ['CWE-200']; technical confidence High.
Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.
Observed status: Observed in-the-wild exploitation status is unknown.
Action: Map CVE-2022-1353 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
Evidence limits: exploitation status unknown
fixed version or patch state unknown
affected product not structured
[Evidence source: nvd.nist.gov](<https://nvd.nist.gov/vuln/detail/CVE-2022-1353>)
Finding 05 — New OVSwrap Linux Kernel Flaw Lets Local Users Gain Root via Open vSwitch
What changed: A memory corruption flaw in the Linux kernels Open vSwitch datapath gives ordinary local users a path to root on a broad set of default-configured distributions, and a public exploit ships with pre-built records for roughly 800 kernel builds. The vulnerability, tracked as CVE-2026-64531 (CVSS score: 7.8) and codenamed OVSwrap by its discoverer, was disclosed by security researcher Asim CVE coverage: CVE-2026-64531.
Technical evidence: CVE-2026-64531; CVSS v3.1 7.8; technical confidence High.
Why it matters: Public exploit code is available, so weaponisation is low-effort; prioritise exposure validation and patching ahead of routine cycles.
Observed status: Observed in-the-wild exploitation status is unknown.
Action: Map CVE-2026-64531 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
Evidence limits: exploitation status unknown
fixed version or patch state unknown
affected product not structured
[Evidence source: thehackernews.com](<https://thehackernews.com/2026/08/new-ovswrap-linux-kernel-flaw-lets.html>)
Finding 06 — Nuxt route rules silently dropped for mixed-case paths, bypassing appMiddleware auth gates (incomplete fix for CVE-2026-53721)
What changed: Nuxt route rules silently dropped for mixed-case paths, bypassing appMiddleware auth gates (incomplete fix for CVE-2026-53721) CVE coverage: CVE-2026-71315, CVE-2026-53721.
Technical evidence: CVE-2026-71315; CVSS v3.1 8.2; weakness ['CWE-178', 'CWE-863']; technical confidence High.
Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.
Observed status: Observed in-the-wild exploitation status is unknown.
Action: Map CVE-2026-71315 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
Evidence limits: exploitation status unknown
fixed version or patch state unknown
affected product not structured
[Evidence source: github.com](<https://github.com/advisories/GHSA-hxvh-4h3w-prp9>)
Finding 07 — Over 400 NPM Packages Infected in ChainDrop Supply Chain Attack
What changed: The malware was designed to steal and exfiltrate secrets, and to propagate itself via stolen NPM and GitHub credentials.
Why it matters: The cited reporting affects widely deployed technology, so exposure validation and source verification need explicit ownership.
Observed status: Observed in-the-wild exploitation status is unknown.
Action: Review the cited source, validate exposure of the affected technology in owned environments, apply available vendor guidance, and retain evidence of the exposure decision.
Evidence limits: grounded severity unavailable
exploitation status unknown
fixed version or patch state unknown
affected product not structured
[Evidence source: www.securityweek.com](<https://www.securityweek.com/over-400-npm-packages-infected-in-chaindrop-supply-chain-attack/>)
Finding 08 — QuickFox Supply Chain Attack Delivers FDMTP Backdoor via Trojanized Windows Installer
What changed: Cybersecurity researchers have disclosed what has been described as a "long-standing supply chain attack" on QuickFox, a virtual private network (VPN) and network acceleration tool designed for overseas Chinese users. According to Fortinet FortiGuard Labs, the supply chain attack has been ongoing since at least August 2025 and involves a trojanized version of the application to deliver FDMTP, a
Why it matters: The cited reporting affects widely deployed technology, so exposure validation and source verification need explicit ownership.
Observed status: Observed in-the-wild exploitation status is unknown.
Action: Review the cited source, validate exposure of the affected technology in owned environments, apply available vendor guidance, and retain evidence of the exposure decision.
Evidence limits: grounded severity unavailable
exploitation status unknown
fixed version or patch state unknown
affected product not structured
[Evidence source: thehackernews.com](<https://thehackernews.com/2026/08/quickfox-supply-chain-attack-delivers.html>)
Finding 09 — Shai-Hulud strikes again: CHAINDROP worm hits 400+ npm packages
What changed: Elastic Security Labs identified the return of Shai-Hulud. Attackers compromised the keyv maintainer and deployed CHAINDROP, a worm that uses stolen npm credentials to backdoor co-owned packages totaling over 1.3 billion monthly downloads.
Why it matters: The cited reporting affects widely deployed technology, so exposure validation and source verification need explicit ownership.
Observed status: Observed in-the-wild exploitation status is unknown.
Action: Review the cited source, validate exposure of the affected technology in owned environments, apply available vendor guidance, and retain evidence of the exposure decision.
Evidence limits: grounded severity unavailable
exploitation status unknown
fixed version or patch state unknown
affected product not structured
[Evidence source: www.elastic.co](<https://www.elastic.co/security-labs/shai-hulud-chaindrop-npm-supply-chain>)
Finding 10 — Still active: Hugging Face Diffusers Flaws Could Let Model Repositories Execute Arbitrary Code
Coverage status: First reported 2026-08-04; ongoing coverage.
What changed: Three high-severity security flaws have been disclosed in Hugging Faces Diffusers library that could allow crafted model repositories to stealthily execute arbitrary code on machines that load it, opening the artificial intelligence (AI) supply chain to security risk.
Why it matters: The cited reporting affects widely deployed technology, so exposure validation and source verification need explicit ownership.
Observed status: Observed in-the-wild exploitation status is unknown.
Action: Review the cited source, validate exposure of the affected technology in owned environments, apply available vendor guidance, and retain evidence of the exposure decision.
Evidence limits: grounded severity unavailable
exploitation status unknown
fixed version or patch state unknown
affected product not structured
[Evidence source: thehackernews.com](<https://thehackernews.com/2026/08/hugging-face-diffusers-flaws-could-let.html>)