STRATQUAD
CYBER THREAT INTELLIGENCE BRIEF
Daily Brief · 26 August 2026 · 24h windowRISKHIGH
StratQuad CTI Daily Brief, 26 August 2026

Compiled from 52 monitored sources · 404 articles reviewed

Today’s Briefing

CVE-2026-68820, an actively exploited Windows vulnerability, entered CISA's KEV catalog yesterday with remediation timelines under BOD 26-04 now running from three to fourteen days depending on risk classification. CVE-2026-60004 in Gitea also joined KEV; the flaw permits code injection via a malicious patch to the diffpatch endpoint, allowing repository contributors to plant Git hooks and execute commands as the service account. Six critical Azure and Entra ID vulnerabilities appeared on the watchlist today, including remote code execution via deserialisation in Entra ID (CVE-2026-69836) and SSRF privilege escalation in the same product (CVE-2026-69851), though none are yet reported exploited. Google published research on STOCKSTAY, a new intelligence collection tool attributed to Turla. NHS Digital issued CC-4835 covering CVE-2026-65400, an authentication bypass in macOS Screen Sharing that permits unauthenticated network access to the service.

Top Stories

  1. CVE-2026-68820 is in KEV. Here Is What CISA BOD 26-04 Actually Requires Now
  2. CISA Adds One Known Exploited Vulnerability to Catalog
  3. Bendix EC80 Brake ECU
  4. CC-4835 - Exploitation of Critical Authentication Bypass Vulnerability in macOS Screen Sharing
  5. ToxicPanda 2.0 can take over your Android phone and banking apps

Full brief available to subscribers

The complete operator brief — action items with patch deadlines, the vulnerability appendix and named actor activity — goes out by email each morning. Subscribe free to receive it.

All briefs