// INTEL.DIGEST

Morning briefing, Sunday Aug 30, 2026

Aug 30

On-demand Morning run. The new enterprise-Microsoft list is the actual news this slot: CISA spent last week putting on-prem SharePoint authentication bypass and a seven-year-old SQL Server remote-code-execution bug on the Known Exploited Vulnerabilities catalog. McKesson and Boston Scientific are unchanged overnight — still the live large-provider incidents, still no Sunday restoration or materiality update.

CISA adds on-prem SharePoint authentication bypass to KEV as last-week chain coverage lands

CVE-2026-55040 is a weak-authentication flaw in on-premises Microsoft SharePoint Server (Subscription Edition, 2019, and Enterprise Server 2016). Microsoft scores it CVSS 9.1 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N). FIRST EPSS as of 30 Aug 2026 is 0.40. CISA added it to the Known Exploited Vulnerabilities catalog on 18 Aug 2026, with a federal due date of 21 Aug 2026. SharePoint Online is not listed as affected.

On 25 Aug 2026, Censys published an exposure advisory covering this bug together with a separate SharePoint remote-code-execution issue disclosed in August. That second CVE does not meet this briefing’s EPSS cutoff and is not treated as a qualifying item here. Microsoft has published July and August security updates for the on-premises builds. Unpatched internet-facing SharePoint farms remain the priority.

Sources: CISA KEV alert, 18 Aug 2026; Microsoft Security Update Guide, CVE-2026-55040; Censys advisory, 25 Aug 2026; NVD, CVE-2026-55040.

CISA confirms exploitation of 2019 Microsoft SQL Server RCE; federal due date was yesterday

CVE-2019-1068 is a remote-code-execution vulnerability in Microsoft SQL Server when the engine incorrectly handles internal functions. NVD scores it CVSS 8.8 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H). FIRST EPSS as of 30 Aug 2026 is 0.53. Affected products listed by NVD include SQL Server 2014 (SP2/SP3), SQL Server 2016, and SQL Server 2017.

CISA added the CVE to the Known Exploited Vulnerabilities catalog on 26 Aug 2026, citing evidence of active exploitation, and set a Binding Operational Directive 26-04 due date of 29 Aug 2026 — Saturday, now passed. CISA’s KEV note says a successful exploit can run code in the context of the SQL Server Database Engine service account. Microsoft’s original advisory and patches remain the remediation path; this is a catch-up for unpatched 2014–2017 instances, not a new 2026 Patch Tuesday bug.

Sources: CISA KEV alert, 26 Aug 2026; NVD, CVE-2019-1068; Microsoft advisory, CVE-2019-1068.

McKesson: Saturday customer note still in force — distribution up, investigation early

McKesson’s 29 Aug 2026 customer page still says the company is serving customers across all lines of business, accepting orders, and shipping from distribution centers. That is the last official operational statement as of this Sunday morning slot. The 28 Aug 2026 Form 8-K remains the legal disclosure: the company discovered a cybersecurity incident on 25 Aug 2026 involving unauthorized access to third-party applications and data exfiltration; the investigation is early; McKesson has not determined the incident is material.

ShinyHunters’ claims — Okta vishing into Salesforce and Snowflake, roughly 1 TB over 21–25 Aug, about 284 million patient-related records (a raw record count, not unique patients), and a $55,236,150 ransom after McKesson allegedly did not negotiate — are still attacker statements. McKesson has not confirmed the actor, the applications, or the data types. No Sunday update replaced Saturday’s picture.

Sources: McKesson Customer Cybersecurity Information Center; BleepingComputer, 28 Aug 2026.

Boston Scientific: no Sunday update; Saturday 4:55 p.m. ET note still the last word

Boston Scientific’s newsroom has not posted a 30 Aug update. The 29 Aug 2026, 4:55 p.m. ET statement is still current: investigation ongoing with CrowdStrike and other third parties; no impact indicated to cloud-based systems and applications; unauthorized activity limited to certain on-premise systems. Manufacturing, order processing, and shipping remain disrupted, with no full-restoration timeline. EDI and GHX orders can be queued. New remote-monitoring activations for some cardiac devices remain affected; existing remote monitoring and device function were reported unimpacted in the 28 Aug product note.

Sources: Boston Scientific incident updates.

VMware vCenter CVE-2026-59310 remains KEV; no newer Sunday exploitation report

CVE-2026-59310 is a directory-traversal issue in the VMware vCenter Syslog server. Broadcom/VMware scores it CVSS 9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). FIRST EPSS as of 30 Aug 2026 is 0.46. CISA added it to KEV on 18 Aug 2026 (federal due date 21 Aug 2026). Affected products include vCenter 7.0/8.0/9.0/9.1 trains as listed in VMSA-2026-0006; Broadcom states there is no workaround. Nothing published overnight changes that patch-and-hunt picture.

Sources: NVD, CVE-2026-59310; CISA KEV alert, 18 Aug 2026; Broadcom VMSA-2026-0006.