Australia & New Zealand face surge in critical flaws
Fri, 14th Aug 2026 (Today)
Recorded Future's Insikt Group has identified 85 high-impact vulnerabilities that organisations in Australia and New Zealand should prioritise for remediation, a 44% increase from the previous month.
In its July assessment, 36 of the vulnerabilities received a Very Critical risk score. All 85 were either actively exploited or operationally weaponised during the month and affected products from 61 vendors.
Microsoft accounted for about 12% of the listed vulnerabilities. The rest were spread across enterprise software, security products, network infrastructure, developer tools and cloud platforms, pointing to broad exposure rather than concentration in a single supplier or product category.
A notable part of the report was the age of some flaws. Fourteen of the 85 vulnerabilities were at least five years old, and the oldest was about 18 years old, suggesting attackers continue to find opportunities in systems where patching has been delayed or missed altogether.
The research also found that exploitation can begin almost immediately after public disclosure. In the fastest observed case, less than a day passed between a vulnerability becoming public and reported exploitation.
Old flaws persist
The continued use of older vulnerabilities suggests many organisations still struggle with basic patch management, especially across legacy systems and internet-exposed devices. For security teams, that creates a double challenge: responding quickly to newly disclosed flaws while reducing backlogs tied to older weaknesses.
Remote code execution featured heavily in the findings. Fifty-seven of the 85 vulnerabilities allowed attackers to run code on affected systems, including flaws linked to Microsoft, Fortinet, Langflow, ServiceNow, WordPress and Joomla environments, as well as internet-facing security appliances and embedded network devices.
Publicly available exploit material remains another risk factor. Insikt Group identified proof-of-concept exploits and scanners for 60 of the 85 vulnerabilities, making it easier for attackers to test and exploit weaknesses at scale.
China-linked activity
The report highlighted activity tied to China-linked actors, particularly the use of edge infrastructure as relay capacity. This reflects interest in compromising internet-facing devices and repurposing them to support broader operations.
One example involved UAT-7810, which was described as exploiting CVE-2020-22653, CVE-2020-22658 and CVE-2023-25717 to compromise Ruckus devices and expand the LapDogs operational relay box network. The compromised devices were then used as relay infrastructure after initial access.
Another campaign, Dysphoria, was also cited for repurposing compromised devices. According to the report, infected hosts were used to proxy traffic and hide back-end command-and-control infrastructure.
The focus on relay networks matters because it shows attackers using breached infrastructure not only to gain access to a victim but also to support other operations. Edge devices, embedded systems and poorly maintained networking equipment can become useful assets in campaigns that require persistence, obfuscation and broad geographic distribution.
Email systems targeted
Email, document and collaboration platforms also featured in the findings, with several campaigns using them for espionage or to deliver malicious software. The report described a series of operations targeting communications and document workflows, which often hold sensitive information and provide routes for follow-on activity.
Cloud Atlas was said to have used malicious Office documents to exploit CVE-2018-0802 and deliver CloudAtlasGo. In a separate case, UNK_MassTraction was described as exploiting CVE-2024-42009 in Roundcube and using IceCube during post-exploitation, before the malware attempted to exploit CVE-2025-49113.
The research also pointed to CL-STA-1114's abuse of CVE-2025-66376 and TA488's exploitation of CVE-2026-42897 to deploy OWAReaper. Separately, an Armoured Likho campaign was described as using a malicious shortcut to abuse CVE-2025-9491, execute obfuscated PowerShell and deploy BusySnake Stealer.
Beyond office and email software, known flaws in IoT and embedded devices were used by the Dysphoria botnet to build distributed denial-of-service and relay infrastructure. The report also cited JADEPUFFER and Cl0p as targeting exposed AI and product lifecycle platforms for encryption, data theft and extortion.
The breadth of the listed vulnerabilities, from collaboration tools to edge devices and cloud-linked platforms, underscores how threat actors are mixing older methods with newer targets. For organisations in Australia and New Zealand, the findings present a risk picture shaped by both the speed of exploitation and the persistence of long-known weaknesses across internet-facing systems.