August 4, 2026
- Unpatched NTLM leak via the Windows
search:URI handler — no CVE, no fix. Huntress details a coercion primitive functionally identical to CVE-2026-33829 but closed without a CVE, with arguably higher real-world risk; mitigations include blocking outbound SMB, enforcing SMB signing, disabling NTLM, and monitoring URI-handler activity (Huntress). · Vulnerabilities & Exploits
in Attackers Seize N-central RMM Servers After N-able's Second Fix Falls Short