Customer Security Newsletter - August 2026

Welcome to the August 2026 edition of the MEDITECH Customer Security Newsletter. This month, we provide critical updates on vulnerabilities added to federal catalogs and strategic intelligence on threat actors targeting essential infrastructure. Our goal is to provide you with actionable information and resources to strengthen your organization's security posture. This data has been gleaned from the review of public records on file with CISA, H-ISAC and Health Sector Cybersecurity Coordination Center (HC3) alerts. Please note the Talk To Us section, as we would like to tailor future editions of the newsletter to address specific concerns.


Known Exploited Vulnerabilities

Between July 9, 2026 and August 5, 2026, CISA added 26 its "Known Exploited Vulnerabilities" catalog based on definitive evidence of active exploitation in the wild.

CVE-2026-63077JetBrains TeamCityDeserialization of Untrusted Data (Remote Code Execution)
CVE-2026-9198IBM LangflowCode Injection (Remote Code Execution)
CVE-2026-34486Apache TomcatMissing Encryption of Sensitive Data
CVE-2026-18556N-able N-centralAuthentication Bypass Using an Alternate Path or Channel
CVE-2026-18577N-able N-centralAuthentication Bypass Using an Alternate Path or Channel
CVE-2026-20316Cisco Secure Firewall Management Center (FMC)Use of Hard-coded Password
CVE-2026-16812Arista VeloCloud Orchestrator On-PremOS Command Injection
CVE-2025-68686Fortinet FortiOSExposure of Sensitive Information to an Unauthorized Actor
CVE-2026-50522Microsoft SharePoint ServerDeserialization of Untrusted Data (Remote Code Execution)
CVE-2026-16232Check Point SmartConsoleImproper Authentication (Authentication Bypass)
CVE-2021-27137DD-WRTStack-Based Buffer Overflow
CVE-2026-0770LangflowInclusion of Functionality from Untrusted Control Sphere (Remote Code Execution)
CVE-2026-63030WordPress CoreInterpretation Conflict (SQL Injection / Remote Code Execution)
CVE-2026-60137WordPress CoreSQL Injection
CVE-2026-39808Fortinet FortiSandboxOS Command Injection
CVE-2026-25089Fortinet FortiSandboxOS Command Injection
CVE-2026-58644Microsoft SharePoint ServerDeserialization of Untrusted Data (Remote Code Execution)
CVE-2023-4346KNX Association KNX ProtocolConnection Authorization Option 1 Overly Restrictive Account Lockout Mechanism
CVE-2026-46817Oracle E-Business SuiteImproper Privilege Management
CVE-2026-15410SonicWall SMA1000 Series AppliancesCode Injection (Command Injection)
CVE-2026-15409SonicWall SMA1000 Series AppliancesServer-Side Request Forgery (SSRF)
CVE-2026-56164Microsoft SharePoint ServerMissing Authentication for Critical Function (Remote Code Execution)
CVE-2026-56155Microsoft Active Directory Federation Services (AD FS)Insufficient Granularity of Access Control
CVE-2008-4128Cisco IOSCross-Site Request Forgery (CSRF)
CVE-2026-48939iCagendaUnrestricted Upload of File with Dangerous Type (Arbitrary PHP RCE)
CVE-2026-56291Balbooa FormsUnrestricted Upload of File with Dangerous Type (Arbitrary File Upload RCE)

Threat Actor Spotlight: Rhysida Ransomware Group

First observed in May 2023, Rhysida is an opportunistic Ransomware-as-a-Service (RaaS) and double-extortion group that has emerged as a severe threat to the Healthcare and Public Health (HPH) sector. Operating as a profit-driven syndicate, the group deceitfully frames itself on its dark web leak portal as a "cybersecurity team" offering network auditing services, while systematically conducting high-impact ransomware attacks against health systems, medical service providers, and critical infrastructure globally.

  • Initial Access & Persistence: Rhysida primarily gains initial entry through targeted phishing campaigns, compromised corporate VPN credentials, and exposed external remote infrastructure (such as Remote Desktop Protocol). Threat actors have also been observed exploiting unpatched vulnerabilities in internet-facing tools—such as Zerologon (CVE-2020-1472)—to escalate privileges and establish persistence across target environments.
  • Living-off-the-Land & Extortion: Once inside a network, Rhysida operators rely heavily on "Living-off-the-Land" (LotL) tactics and legitimate administrative utilities—including PowerShell, AnyDesk, PuTTY, secretsdump, and ntdsutil—to map Active Directory structures, harvest domain credentials, and quietly exfiltrate sensitive patient and operational records. Prior to encryption, the group frequently clears Windows event logs to hinder detection. They then deploy a 64-bit payload that locks files using a 4096-bit RSA key with ChaCha20 encryption, appends .rhysida extensions, and leaves embedded PDF ransom notes demanding Bitcoin payments under threat of publicly releasing exfiltrated patient data.
  • Proactive Defense: Defending against Rhysida requires enforcing mandatory phishing-resistant multi-factor authentication (MFA) across all remote access points and email services, strictly controlling or blocking unmonitored remote access software, and maintaining rigorous patch management for external-facing devices. Organizations must also ensure isolated, immutable offline backups and apply principle-of-least-privilege access controls across domain infrastructure.

News

Mitigating Supply Chain Risks: CISA’s New Framework for Open-Source Software

Recognizing the widespread reliance on open-source software within government networks, this CISA announcement introduces a new guide to help federal agencies securely evaluate, adopt, and contribute to open-source solutions and AI models while actively mitigating supply chain risks.

Addressing the Weakest Link in Healthcare Cybersecurity

On July 29, 2026, H-ISAC linked an article highlighting a critical vulnerability in the medical sector's digital defenses; this article explores recent Health-ISAC data revealing that post-attack recovery is the weakest link in healthcare cybersecurity, and urges organizations to elevate disaster recovery investments to a board-level priority.


Additional Resources


Talk to us!

We at MEDITECH would love to hear your feedback about this newsletter and we’d like to know what is on your mind. Is there something you would like us to address?

We also have a question for you that is important to us. What are your largest concerns or security hopes for 2026?

Please let us know by contacting us !

Until next time, stay alert out there!