Cybersecurity Bulletin

Emerging Vulnerabilities and Cyber Threats | 10-16 August 2026

8/18/2026
Emerging Vulnerabilities and Cyber Threats

The global cybersecurity landscape continues to evolve as organizations face critical software vulnerabilities, sophisticated ransomware operations and targeted cyberattacks against governments and critical infrastructure. For businesses across the UAE, Middle East and global markets, effective vulnerability management, cyber threat intelligence and incident response remain essential to strengthening cyber resilience and protecting critical systems.

Critical Vulnerabilities Require Immediate Attention

Several vulnerabilities require assessment by cybersecurity teams. CVE-2026-13739, affecting Commvault Command Center, involves a Server-Side Request Forgery (SSRF) vulnerability that could create security risks for affected environments.

Two significant SAP vulnerabilities also require attention. CVE-2026-58231 affects the SAP Commerce Cloud Data Hub Adapter and involves improper authorization with potential remote code execution. CVE-2026-34265 is a memory corruption vulnerability affecting SAP NetWeaver Application Server ABAP, specifically involving DIAG protocol parsing.

180826 bulletin 

Organizations using affected technologies should review the relevant vendor security advisories, identify potentially exposed systems and prioritize remediation according to business criticality, exposure and organizational risk.

Ransomware and Targeted Cyber Campaigns

Cyber threat activity continues to demonstrate a focus on governments, telecommunications providers and critical infrastructure. Taiwan government agencies have reportedly been targeted in an AI-assisted cyber campaign, highlighting the increasing role of artificial intelligence in modern cyber operations.

Meanwhile, Gunra ransomware is emerging as a Ransomware-as-a-Service (RaaS) threat associated with attacks against organizations worldwide, including critical infrastructure. The PATCHCORD campaign has also drawn attention for activity targeting Afghan telecommunications and critical infrastructure across South Asia.

Major Cybersecurity News

Recent developments include a taxpayer-data breach involving the French Finance Ministry and DGFiP, alongside reported cybersecurity-related developments involving Philips.

Additionally, CISA has warned about a critical Metabase SQL injection vulnerability that could allow unauthenticated attackers to gain administrative access, reinforcing the importance of timely vulnerability identification, patching and remediation.

For organizations across the UAE and wider Middle East, these developments emphasize the importance of continuous security monitoring, proactive patch management, cyber threat intelligence and tested incident response procedures. Staying informed about emerging vulnerabilities, ransomware and attack campaigns can help organizations identify cyber risks earlier, protect critical assets and respond effectively to evolving threats.

Dawn Thomas
Dawn Thomas
Senior Partner - Governance Risk & Compliance
shahnawaz.sheik@crowe.ae
Shahnawaz Sheik
Director – Cyber Threat Management

For Cybersecurity and Cyber Threat Management consulting,
Call / WA +971 52 373 4662 |
[email protected]