Infosec News Nuggets — August 14, 2026
Brief
vCenter Flaw Exploited Just Five Days After Disclosure
A critical directory-traversal flaw in VMware vCenter’s Syslog server, rated CVSS 9. 8, was already being exploited within five days of Broadcom’s disclosure, with researchers tracing 361 victim IP addresses across 47 countries.
The attacker deployed an open-source reverse shell tool to maintain access to compromised systems, and while Broadcom has released patches, defenders are warned that patching alone won’t remove intruders who got in before the fix was applied.
Hackers leverage new Microsoft SharePoint exploit in attacks
A proof-of-concept exploit for a critical SharePoint authentication bypass flaw was weaponized within a day of its publication, letting unauthenticated attackers impersonate site users or administrators to access files and modify data.
