A Perfect 10 With a Three-Day Deadline (08/25/2026)

August 25, 2026
A Perfect 10 With a Three-Day Deadline (08/25/2026)
Key Intel / TL;DR
  • CVE-2026-21962 scores 10.0 against Oracle HTTP Server and the WebLogic Server Proxy Plug-in, was patched in January, and reached CISA's exploited catalog on August 24 with an August 27 deadline.
  • Oasis Security showed a malicious webpage can reach the unauthenticated Ollama API behind NVIDIA NemoClaw through DNS rebinding and write hidden instructions into the model itself.
  • Norway's national login and digital signature services have been under DDoS since 03:38 CEST Monday, the third attack on the same agency since June.
  • Shadowserver counted 274 compromised Zimbra instances on August 22 against roughly 8,200 still unpatched.
  • ANY.RUN tracked the Mirage2FA phishing service across 4,532 organization email domains, stealing session cookies rather than defeating the second factor.

The Oracle timeline is the part to sit with. A maximum-severity flaw was patched in January, honeypots picked up exploitation attempts in February, and the federal directive to fix it arrived on August 24 with a deadline of August 27. Seven months of public exploitation preceded a three-day window to remediate, which tells you the deadline is measuring urgency rather than difficulty.

Top 5 Critical Security Alerts

1. A Perfect 10 in Oracle With a Three-Day Federal Deadline

CVE-2026-21962 is an improper access control flaw scoring 10.0 in Oracle HTTP Server and the Oracle WebLogic Server Proxy Plug-in, letting an unauthenticated attacker with network access create, delete, or modify critical data. Oracle patched it in January, CloudSEK honeypots captured exploitation attempts alongside older WebLogic flaws, and CISA added it to the Known Exploited Vulnerabilities catalog on August 24 under Binding Operational Directive 26-04 with a remediation deadline of August 27. The Hacker News

Operator Note: The Register’s framing on this is the one to carry into your own program, which is that you could have applied all 1,449 patches in the last cycle and still been hit, because attackers are increasingly exploiting how the product is meant to work rather than a coding defect in it. Check whether the proxy plug-in is in your estate at all, since it tends to sit in front of things rather than being inventoried as a thing. The Register

2. A Webpage Can Poison the Model Behind NVIDIA NemoClaw

Oasis Security disclosed that NemoClaw starts Ollama bound to all interfaces on port 11434 with no authentication, and that its Host header and CORS protections can both be bypassed when the bind address is not loopback. An attacker-controlled webpage using DNS rebinding then reaches the local API as same-origin and calls the create endpoint to rewrite the model’s chat template, planting instructions that persist across every conversation and survive the agent’s own system prompt. There is no CVE. Version 0.0.35 fixed macOS and Linux, Windows and WSL got a warning instead in 0.0.34, and 0.0.106 from August 10 refuses to start against a non-loopback backend. The Hacker News

Operator Note: The persistence is what separates this from ordinary prompt injection, because the instruction lives in the model artifact rather than in a conversation you can clear. Anyone running a local agent stack has quietly created an unauthenticated service on their workstation, and the browser sitting on the same machine is the thing that reaches it. Dark Reading

3. Norway’s National Login Service Is Under Sustained DDoS

A distributed denial of service attack against the Norwegian Digitalisation Agency and its operations provider began at 03:38 CEST on Monday, disrupting public-service logins, electronic identities and signatures, secure digital mail, government forms, and data exchange between agencies. ID-porten and eSignering remained partially unreachable as other systems stabilized, and downstream services including Altinn and Skattetaten were affected. No data compromise has been identified, and this is the third such attack on the agency since June. BleepingComputer

Operator Note: Availability is the control nobody tabletops. A national identity service going dark takes every service that depends on it with it, and none of those downstream systems were breached. If your business has consolidated authentication onto one provider, you have the same shape of exposure and probably no plan that starts with the provider being up but unreachable. The Record

4. Zimbra Compromises Reach 274 With 8,200 Still Unpatched

Shadowserver scans on August 22 identified 274 compromised instances of CVE-2026-73570, the command injection flaw in the SNMP monitoring component that allows unauthenticated remote code execution when SNMP notifications are enabled. Synacor shipped the fix in ZCS 10.1.20 on July 20, CERT Polska flagged in-the-wild targeting on August 21, and roughly 8,200 instances remain unpatched. BleepingComputer

Operator Note: We carried this on August 20 as under exploitation and again on August 24 when the federal directive landed, and the compromise count is the number that closes the loop. Five weeks separated the patch from the first confirmed targeting, which is the actual window most organizations had and did not use.

5. Mirage2FA Steals the Session Instead of Beating the Factor

ANY.RUN tracked the commercial Mirage2FA phishing service across 4,532 unique organization email domains from 2024 to 2026, with the United States accounting for 63.7% of victims and technology, manufacturing, and education among the most targeted sectors. The kit abuses legitimate Microsoft 365 login flows to capture passwords and session cookies, giving the operator an authenticated session without ever defeating the second factor. The Hacker News

Operator Note: Every awareness program in the country still teaches multi-factor authentication as the thing that stops phishing, and this is the second campaign this month where the answer is that the attacker never attacked the factor. The detection that matters is session anomaly rather than login anomaly, because the login looked correct and was.

Additional Security Alerts

Threat Intelligence

  • The US sanctioned Mabna Institute operators as the UK power plant intrusion surfaced: Treasury named Iranian actors behind critical infrastructure intrusions, days after the reporting we carried yesterday. The Record
  • TeamT5 says AI tooling has more than doubled Chinese state-backed attack volume: The claim is about throughput rather than capability, which is the more useful measure. The Decoder
  • ZeroTokens gives phishing operators live control of victim sessions across 53 financial brands: Real-time steering rather than a static kit. Infosecurity Magazine

Security Breaches & Incidents

  • Benefits platform Paylogix says attackers stole financial and health data on tens of thousands: A third-party processor holding both categories at once. The Record
  • Hospital operator Nutex Health confirms data exfiltration: BleepingComputer
  • Police across 22 countries identified 263 suspects and arrested 58: Enforcement against networks coordinated by African crime groups. BleepingComputer

Vulnerabilities & Exploits

  • Attackers are forging SAML responses against the miniOrange WordPress plugin to log in as administrators: Two unauthenticated bypasses, already under attempted exploitation. The Hacker News
  • Australia warns of active exploitation against a critical TeamCity flaw: Build servers hold credentials to everything they deploy to. Infosecurity Magazine
  • 24 npm packages are hosting fake Cloudflare CAPTCHA pages through unpkg mirrors: The registry as free phishing infrastructure, with no malicious code in the package itself. The Hacker News

The Axe Report is a daily briefing from Grab The Axe. Need help assessing your organization’s security posture? Take our free Human Attack Surface Score assessment.

Distribute Intel
Chris Armour
Director of Information Security
Chris Armour
The Breaker & Builder.

Operating on the philosophy that 'you can't build a secure system if you don't know how to break it,' Chris leads our engineering division. A top 1% National Cyber League competitor, he hardens our digital infrastructure against the very exploits he has mastered.

View Profile →
Press & Media

Media Inquiries

For expert commentary, interview requests, or high-res assets regarding this announcement, initialize the terminal.

Initialize Terminal

Initiate
Deployment.

Whether you need a full adversarial facility audit or an executive resilience protocol for your leadership team.

Secure the Facility (Assessments)
Secure the Mind (Coaching/Speaking)