Welcome to the August 2026 edition of the MEDITECH Customer Security Newsletter. This month, we provide critical updates on vulnerabilities added to federal catalogs and strategic intelligence on threat actors targeting essential infrastructure. Our goal is to provide you with actionable information and resources to strengthen your organization's security posture. This data has been gleaned from the review of public records on file with CISA, H-ISAC and Health Sector Cybersecurity Coordination Center (HC3) alerts. Please note the Talk To Us section, as we would like to tailor future editions of the newsletter to address specific concerns.
Known Exploited Vulnerabilities
Between July 9, 2026 and August 5, 2026, CISA added 26 its "Known Exploited Vulnerabilities" catalog based on definitive evidence of active exploitation in the wild.
| CVE-2026-63077 | JetBrains TeamCity | Deserialization of Untrusted Data (Remote Code Execution) |
|---|---|---|
| CVE-2026-9198 | IBM Langflow | Code Injection (Remote Code Execution) |
| CVE-2026-34486 | Apache Tomcat | Missing Encryption of Sensitive Data |
| CVE-2026-18556 | N-able N-central | Authentication Bypass Using an Alternate Path or Channel |
| CVE-2026-18577 | N-able N-central | Authentication Bypass Using an Alternate Path or Channel |
| CVE-2026-20316 | Cisco Secure Firewall Management Center (FMC) | Use of Hard-coded Password |
| CVE-2026-16812 | Arista VeloCloud Orchestrator On-Prem | OS Command Injection |
| CVE-2025-68686 | Fortinet FortiOS | Exposure of Sensitive Information to an Unauthorized Actor |
| CVE-2026-50522 | Microsoft SharePoint Server | Deserialization of Untrusted Data (Remote Code Execution) |
| CVE-2026-16232 | Check Point SmartConsole | Improper Authentication (Authentication Bypass) |
| CVE-2021-27137 | DD-WRT | Stack-Based Buffer Overflow |
| CVE-2026-0770 | Langflow | Inclusion of Functionality from Untrusted Control Sphere (Remote Code Execution) |
| CVE-2026-63030 | WordPress Core | Interpretation Conflict (SQL Injection / Remote Code Execution) |
| CVE-2026-60137 | WordPress Core | SQL Injection |
| CVE-2026-39808 | Fortinet FortiSandbox | OS Command Injection |
| CVE-2026-25089 | Fortinet FortiSandbox | OS Command Injection |
| CVE-2026-58644 | Microsoft SharePoint Server | Deserialization of Untrusted Data (Remote Code Execution) |
| CVE-2023-4346 | KNX Association KNX Protocol | Connection Authorization Option 1 Overly Restrictive Account Lockout Mechanism |
| CVE-2026-46817 | Oracle E-Business Suite | Improper Privilege Management |
| CVE-2026-15410 | SonicWall SMA1000 Series Appliances | Code Injection (Command Injection) |
| CVE-2026-15409 | SonicWall SMA1000 Series Appliances | Server-Side Request Forgery (SSRF) |
| CVE-2026-56164 | Microsoft SharePoint Server | Missing Authentication for Critical Function (Remote Code Execution) |
| CVE-2026-56155 | Microsoft Active Directory Federation Services (AD FS) | Insufficient Granularity of Access Control |
| CVE-2008-4128 | Cisco IOS | Cross-Site Request Forgery (CSRF) |
| CVE-2026-48939 | iCagenda | Unrestricted Upload of File with Dangerous Type (Arbitrary PHP RCE) |
| CVE-2026-56291 | Balbooa Forms | Unrestricted Upload of File with Dangerous Type (Arbitrary File Upload RCE) |
Threat Actor Spotlight: Rhysida Ransomware Group
First observed in May 2023, Rhysida is an opportunistic Ransomware-as-a-Service (RaaS) and double-extortion group that has emerged as a severe threat to the Healthcare and Public Health (HPH) sector. Operating as a profit-driven syndicate, the group deceitfully frames itself on its dark web leak portal as a "cybersecurity team" offering network auditing services, while systematically conducting high-impact ransomware attacks against health systems, medical service providers, and critical infrastructure globally.
- Initial Access & Persistence: Rhysida primarily gains initial entry through targeted phishing campaigns, compromised corporate VPN credentials, and exposed external remote infrastructure (such as Remote Desktop Protocol). Threat actors have also been observed exploiting unpatched vulnerabilities in internet-facing tools—such as Zerologon (CVE-2020-1472)—to escalate privileges and establish persistence across target environments.
- Living-off-the-Land & Extortion: Once inside a network, Rhysida operators rely heavily on "Living-off-the-Land" (LotL) tactics and legitimate administrative utilities—including PowerShell, AnyDesk, PuTTY, secretsdump, and ntdsutil—to map Active Directory structures, harvest domain credentials, and quietly exfiltrate sensitive patient and operational records. Prior to encryption, the group frequently clears Windows event logs to hinder detection. They then deploy a 64-bit payload that locks files using a 4096-bit RSA key with ChaCha20 encryption, appends .rhysida extensions, and leaves embedded PDF ransom notes demanding Bitcoin payments under threat of publicly releasing exfiltrated patient data.
- Proactive Defense: Defending against Rhysida requires enforcing mandatory phishing-resistant multi-factor authentication (MFA) across all remote access points and email services, strictly controlling or blocking unmonitored remote access software, and maintaining rigorous patch management for external-facing devices. Organizations must also ensure isolated, immutable offline backups and apply principle-of-least-privilege access controls across domain infrastructure.
News
Mitigating Supply Chain Risks: CISA’s New Framework for Open-Source Software
Recognizing the widespread reliance on open-source software within government networks, this CISA announcement introduces a new guide to help federal agencies securely evaluate, adopt, and contribute to open-source solutions and AI models while actively mitigating supply chain risks.
Addressing the Weakest Link in Healthcare Cybersecurity
On July 29, 2026, H-ISAC linked an article highlighting a critical vulnerability in the medical sector's digital defenses; this article explores recent Health-ISAC data revealing that post-attack recovery is the weakest link in healthcare cybersecurity, and urges organizations to elevate disaster recovery investments to a board-level priority.
Additional Resources
- HHS 405(d) Aligning Health Care Industry Security Approaches - The 405(d) Program and Task Group is a collaborative effort between industry and the federal government, which aims to raise awareness, provide vetted cybersecurity practices, and move healthcare organizations towards consistency in mitigating the current most pertinent cybersecurity threats to the sector. Their website provides the latest resources and information as well as an opportunity for involvement.
- Helpful resources CISA has provided can be found on the following pages:
Talk to us!
We at MEDITECH would love to hear your feedback about this newsletter and we’d like to know what is on your mind. Is there something you would like us to address?
We also have a question for you that is important to us. What are your largest concerns or security hopes for 2026?
Please let us know by contacting us !
Until next time, stay alert out there!
