When the Hypervisor Is the Target: An August 2026 UK SME Threat Briefing
Two weeks into August 2026 and the July pattern holds. A critical VMware vCenter flaw disclosed on 29 July is under active exploitation, DEF CON 34 produced a reproducible attack on AI agents and an on-prem SharePoint auth bypass has a public exploit. A practical briefing for UK SMEs.
Two weeks into August 2026 and the pattern from July has not changed. Infrastructure is being exploited faster than many teams patch, and the research world is showing exactly how AI agents fit into an attack chain. Three items belong on a UK SME list this month: a critical VMware vCenter flaw disclosed at the end of July and now under active exploitation, a reproducible attack on AI agents demonstrated at DEF CON 34, and an on-premises SharePoint authentication bypass that has a public exploit and plenty of unpatched farms.
This is a briefing. Skip to the sections that apply to your stack.
1. VMware vCenter CVE-2026-59310: patch, then hunt
On 29 July 2026 Broadcom published VMSA-2026-0006, covering CVE-2026-59310, a directory-traversal flaw in the vCenter Syslog server (CVSS 9.8). An unauthenticated attacker with network access can write files outside the intended directory and achieve arbitrary code execution on the appliance. No credentials, no user interaction. Broadcom shipped it alongside CVE-2026-59309, a companion authentication bypass in the VMware Directory Service (VMDir, the identity backbone behind vCenter single sign-on), also CVSS 9.8. There is no workaround for either. Patching is the only remediation.
Why this is an August problem, not a July one: incident responders observed live exploitation from 3 August, five days after disclosure, with compromises catalogued across dozens of countries inside the first week and a half. Reporting describes a suspected APT establishing persistence with reverse SSH once it lands on the appliance. That is the uncomfortable part for SMEs. If your vCenter was reachable and unpatched during the first half of August, patching now closes the door but does not evict anyone already inside.
Patch to at least
Post-patch hunt (if the appliance was network-reachable while unpatched)
If you find persistence, treat the appliance as compromised: isolate, preserve evidence, rebuild from a known-good image and rotate SSO, service-account and linked credentials. A vCenter takeover is a path to every VM it manages.
Practical note: keep vCenter management off the public internet entirely. Restrict it to a management VLAN reachable only from jump hosts. That does not fix the CVE but it shrinks the blast radius while you schedule the patch.
2. DEF CON 34: "Ghostjacking" shows where agentic AI breaks
At DEF CON 34 in early August, Tenet Security presented Ghostjacking, a reproducible attack on AI coding and operations agents. The mechanism is short. An attacker plants a crafted line in a security log. An AI agent tasked with reviewing yesterday's blocked events reads that line, treats it as an instruction and is steered into issuing an outbound action. In the demonstrated chain that was a DNS record change and an API request with a credential attached. Tenet reported the attack succeeded nine times out of ten against one popular coding agent under a default configuration. This is published research with a reproduced result, not a campaign seen in the wild, and it should be read that way. Separately, the researchers reported a sandbox-escape issue to the vendor, which confirmed and patched it before the talk.
Why it matters for SMEs adopting agents: the failure is not the model "being tricked". It is that the agent's tool layer had the authority to change DNS while running a task whose scope was only "read the logs". The fix is the guardrail this blog has argued for since the spring. Scope each agent's tool permissions to its task, deny by default and require human approval for anything that changes DNS, credentials, money or customer-visible state. A log-review agent should be able to read logs and nothing else.
If you are running or piloting agentic automation, three concrete checks this month:
This lines up with the NCSC's guidance on managing the cyber risk of agentic AI: use safeguards, sandboxing and active oversight so autonomous systems deliver value without unintended action.
3. SharePoint CVE-2026-55040: on-prem, again
July's briefing flagged one on-premises SharePoint flaw. Here is another that deserves attention now. CVE-2026-55040 (CVSS 9.1) is an authentication bypass in the JWT token-validation pipeline of on-premises SharePoint Server. Because several token-validation settings are off by default, an unauthenticated attacker who knows a target user's identifier (SID or UPN, typically `user@domain`) can forge a bearer token and act as that user, including a site administrator. It was disclosed on 14 July 2026 with a public proof-of-concept, so the barrier to exploitation is low and unpatched farms should be treated as high risk.
Confirm you are at least on
SharePoint Online is not affected. If the farm was internet-reachable while unpatched, patch, then hunt for forged-token activity and rotate ASP.NET machine keys to invalidate any ViewState or web-shell persistence. An authentication bypass is also a natural second-stage tool once an attacker has any foothold, so internal-only farms should still be patched this week.
The pattern behind August
None of these needed a novel technique to hurt an SME. A hypervisor left reachable, an agent given more authority than its task, a patch not yet applied. The common thread with July is speed. The window between disclosure and mass exploitation keeps shrinking, so "we patch monthly" is no longer a safe default for internet-facing infrastructure.
What UK SMEs should do this month
Pick the items relevant to your stack and put a date next to each:
How fractional teams help
We confirm what is exposed, patch and hunt vCenter and SharePoint, take management interfaces off public IP space and put least-privilege guardrails around any AI agents you are piloting so a log-review task cannot change your DNS. We wire a KEV-triggered patch rhythm into your monthly operations so a flaw disclosed at the end of one month is not your incident at the start of the next.
Further reading
Topics Covered
Ready to Transform Your IT Operations?
Get expert guidance from our fractional IT specialists. We'll help you implement the strategies discussed in this article and accelerate your digital transformation journey.
About the Author
Nimbul Systems Team
Our experienced team of fractional IT specialists brings over 35 years of combined expertise in DevOps automation, cloud engineering and digital transformation.
Continue Reading
DevOps Automation: The Complete Guide for UK SMEs
Discover practical strategies and tools that UK SMEs can implement to accelerate development.
Read Article →Cloud Migration Strategy: A UK Business Guide
Navigate cloud migration complexity with this practical guide.
Read Article →