Cyber Risk Brief: 3 - 9 August 2026
CRB-2010 August 2026Sovereign GRC Intel18 min read
Disclaimer:This brief is governance commentary for leadership and risk teams, not incident notification, public attribution, legal advice, or quantitative risk analysis. Threat prioritization, framework mappings, attribution, and risk-zone groupings are informational only. Validate all technical claims against vendor advisories and internal telemetry before operational response.
Threat Intelligence Summary
Six CISA KEV clocks landed in this window, five of them already passed at publication. IBM Langflow CVE-2026-9198 (T1, Immediate) is a second Langflow KEV distinct from CVE-2026-0770, due 7 August and passed, with public PoCs on default deployments; the same 4 August drop also listed Apache Tomcat CVE-2026-34486 (KEV due 7 August, EPSS 81.16%), folded into T1 rather than carried as a ninth card. N-able N-central CVE-2026-18577 (T2, Immediate) is an authentication bypass after an incomplete fix of CVE-2026-18556, KEV due 6 August and passed, with CCCS AV26-769 and attackers reported reaching managed systems; CISA separately KEV-listed the predecessor CVE-2026-18556 on 4 August, due 7 August, so one product carries two federal clocks. JetBrains TeamCity CVE-2026-63077 (T3, Immediate) escalates the 3 August card from no confirmed in-the-wild exploitation to CISA KEV due 8 August, already passed. Progress Kemp LoadMaster CVE-2026-8037 (T4, Immediate) escalates the 6 July card to KEV due 10 August with EPSS 99.31% after 792 reported attempts. Metabase unauthenticated SQL injection (T5, Immediate, GHSA-vwf4-m7j8-wcjf) carries a vendor CVSS 10.0 with no NVD record, active exploitation, confirmed data theft at Framework and Tally, and no CVE at source time. INC ransomware chaining SonicWall SMA1000 CVE-2026-15409 / CVE-2026-15410 (T6, Immediate, continuity from 20 July on a KEV pair whose 17 July deadline is long passed), TrueConf installer trojanization by Head Mare delivering PhantomCore and PhantomGraph (T7, 7 days), and Atlassian Rovo data exfiltration where Atlassian closed the Varonis URL-parameter route on 8 July but the PromptArmor prompt-injection route has no confirmed fix (T8, Post-incident) close the register.
Threat Register: 10/08/2026
| Threat | |||||
|---|---|---|---|---|---|
| T1 | IBM Langflow Unauthenticated Remote Code Execution (CVE-2026-9198) CVE-2026-9198 is a code-injection flaw in IBM Langflow that lets an unauthenticated attacker execute code on default deployments by chaining two API endpoints to bypass login (CVSS 3.1 9.8, EPSS 0.17053). CISA added it to KEV on 4 August 2026 with remediation due 7 August 2026. IBM disclosed the flaw and shipped a fix the same day, 17 July 2026: Langflow OSS 1.0.0 through 1.10.0 are affected and 1.10.1 or later is fixed, with 1.11.2 current. Fully functional public proof-of-concept exploits circulated in late July. This is distinct from the earlier Langflow KEV entry CVE-2026-0770 covered in prior briefs. | 9.8 | 17.05% | Critical | Immediate |
| T2 | N-able N-central Authentication Bypass (CVE-2026-18577) CVE-2026-18577 is an authentication bypass in N-able N-central that yields administrative account takeover on hosted and on-premises servers (CVSS 4.0 8.2, EPSS 0.04103). It follows an incomplete fix for CVE-2026-18556, which CISA added to KEV in its own right on 4 August 2026 with remediation due 7 August 2026. CISA added CVE-2026-18577 to KEV a day earlier, on 3 August 2026, with remediation due 6 August 2026. N-able shipped Hotfix 1 (build 2026.3.1.7) on 2 August and Hotfix 2 (build 2026.3.1.10) on 6 August; Hotfix 2 supersedes Hotfix 1 and N-able states it is required even where Hotfix 1 was already applied. Attackers have reached managed systems and persisted after the first fix. CCCS AV26-769, updated 7 August, lists versions prior to 2026.3.1.10 as affected. | 8.2v4.0 | 4.10% | Critical | Immediate |
| T3 | JetBrains TeamCity Unauthenticated RCE — KEV Escalation (CVE-2026-63077) CVE-2026-63077 remains an unauthenticated remote code execution flaw against all TeamCity On-Premises versions via the agent polling protocol (CVSS 3.1 9.8, EPSS 0.01010). Distinct from the 3 August brief, where JetBrains reported no evidence of exploitation and the card carried a 7-day SLA: CISA added the CVE to KEV on 5 August 2026 with remediation due 8 August 2026 and confirmed active exploitation. Fixes remain 2025.11.7 and 2026.1.3. | 9.8 | 1.01% | Critical | Immediate |
| T4 | Progress Kemp LoadMaster Command Injection (CVE-2026-8037) CVE-2026-8037 is a critical command-injection flaw in Progress Kemp LoadMaster (CVSS 3.1 9.6, EPSS 0.99311). Distinct from the 6 July brief, which recorded exploitation attempts: CISA added it to KEV on 7 August 2026 with remediation due 10 August 2026 after 792 reported exploit attempts. EPSS at 0.99311 is the highest exploitation probability in this register. | 9.6 | 99.31% | Critical | Immediate |
| T5 | Metabase Unauthenticated SQL Injection Zero-Day Metabase disclosed an unauthenticated SQL injection in 0.58 / 1.58 and above (0.x is the open-source line, 1.x the Enterprise line of the same release) that grants administrator access to a customer instance. The vendor rates it Critical at CVSS 10.0 and confirms active exploitation. It is tracked as GitHub Security Advisory GHSA-vwf4-m7j8-wcjf; no CVE identifier was assigned at source time, so the 10.0 is a vendor score with no NVD record behind it. Framework and Tally disclosed data theft. LexisNexis has stated its own service disruption is unrelated to this zero-day and stems from a different third-party incident, so it is not an impacted customer of this flaw. Cloud tenants were patched by the vendor; self-hosted installs must upgrade manually. | 10.0vendor | — | Critical | Immediate |
| T6 | SonicWall SMA1000 Flaws Exploited by INC Ransomware INC ransomware is reported as the dominant actor chaining SonicWall Secure Mobile Access (SMA) 1000 series flaws disclosed earlier — CVE-2026-15409 (CVSS 3.1 10.0, EPSS 0.78440) and CVE-2026-15410 (CVSS 3.1 7.2, EPSS 0.76347), both CISA KEV since 14 July 2026 with a 17 July deadline that has already passed, covered in the 20 July brief — for root access, data theft, and encryption. Distinct from that earlier zero-day disclosure card: this week's sources establish INC as the primary ransomware operator exploiting the pair at scale. Scores shown are for CVE-2026-15409, the governing flaw of the pair. | 10.0 | 78.44% | Critical | Immediate |
| T7 | TrueConf Installer Trojanization by Head Mare The Head Mare hacktivist group has been exploiting vulnerabilities in unpatched TrueConf video-conferencing servers to replace client installers with malicious versions that deliver the PhantomCore and PhantomGraph backdoors, per Kaspersky research reported by BleepingComputer. The server flaws are tracked as KLCERT-26-057 and KLCERT-26-058 under Kaspersky's own identifiers rather than CVE numbers. Reported targeting is Russian organizations in instrumentation, electronics, transport, energy, IT and software development, which makes this primarily a supply-chain and counterparty-exposure question for readers outside that footprint. | — | — | High | 7 days |
| T8 | Atlassian Rovo AI One-Click Data Exfiltration Two research firms independently found ways to make Atlassian's Rovo assistant collect Jira, Confluence, or SharePoint data a signed-in user can access and send it to an outside server. Varonis Threat Labs reported a URL-parameter route (RovoBlast), which SecurityWeek describes as a critical one-click vulnerability and which Atlassian fixed server-side on 8 July 2026. PromptArmor reported an indirect prompt-injection route through uploaded file content, disclosed 23 May 2026; The Hacker News found no confirmation of a fix as of 8 August 2026. The closed route is the one with a patch; the open route is the one you have to govern. | — | — | High | Post-incident |
| Select a row for narrative, affected systems, remediation, and sources. | |||||
Reading the columns: Severity is Sovereign's own classification, not a CVSS band. Critical means an unauthenticated or widely reachable flaw with plausible widespread exploitation absent compensating controls; High means exploitation needs authenticated access, specialized tooling, or a material control deficiency. A CVSS of 8.2 can therefore sit under a Critical rating, and does here on T2. The CVSS column mixes scoring systems, so each non-standard score carries a tag: unlabelled scores are CVSS 3.1 base scores from NVD, v4.0 marks a CVSS 4.0 score, and vendor marks a vendor-assigned score with no CVE and no NVD record. Scores from different versions are not directly comparable; sort on EPSS or KEV status when ranking work.
Strategic context
Six federal clocks on control planes, five already missed
- CISA added six CVEs to KEV between 3 and 9 August, every one of them on a control plane: N-central CVE-2026-18577 (3 August, due 6 August), N-central CVE-2026-18556 (4 August, due 7 August), Apache Tomcat CVE-2026-34486 (4 August, due 7 August), IBM Langflow CVE-2026-9198 (4 August, due 7 August), JetBrains TeamCity CVE-2026-63077 (5 August, due 8 August), and Progress Kemp LoadMaster CVE-2026-8037 (7 August, due 10 August). Five deadlines had passed before this brief published.
- IBM Langflow CVE-2026-9198 (T1) is a distinct KEV from last month's Langflow CVE-2026-0770, against default deployments with public PoCs. N-able N-central CVE-2026-18577 (T2) follows an incomplete fix of CVE-2026-18556, and CISA then KEV-listed that predecessor CVE the following day: one product, two federal clocks, one day apart. CCCS AV26-769 is on the record, and reporting says attackers reached managed systems after the first hotfix.
- JetBrains TeamCity CVE-2026-63077 (T3) is the material update from the 3 August brief: then no confirmed in-the-wild exploitation and a seven-day SLA; now CISA KEV with active exploitation and due 8 August, already passed. Progress Kemp LoadMaster CVE-2026-8037 (T4) is the material update from the 6 July brief: then exploit-attempt telemetry; now KEV due 10 August with EPSS 99.31% after 792 reported attempts.
- Ask which of RMM, CI/CD, AI-agent tooling, application servers, and load-balancer management sit inside the emergency patch register with named owners. Five of six clocks in this set have already closed; the sixth closes on publish day. An older one is still open behind T6: the SonicWall SMA1000 pair has been KEV-listed since 14 July with a 17 July deadline.
Patched once is not patched for the product family
- N-central's incomplete first fix left a second authentication-bypass path to administrative takeover. CISA made the point federally: it KEV-listed the successor CVE-2026-18577 on 3 August and the incompletely fixed predecessor CVE-2026-18556 on 4 August, so the register needs two rows and two deadlines, not one. Organizations that applied only the initial remediation may already be past initial access on the RMM that manages their fleet. The vendor then superseded its own fix: Hotfix 1 (build 2026.3.1.7, 2 August) was replaced by Hotfix 2 (build 2026.3.1.10, 6 August), which N-able says is required even where Hotfix 1 was already applied. Build 2026.3.1.10 is the floor for on-premises; hosted NCOD tenants received the vendor mitigation.
- Langflow owners who closed CVE-2026-0770 and stepped down emergency posture face a second, separately due KEV on the same product family. TeamCity owners who deferred the 3 August card now face a federal deadline that has already passed on unchanged fixed versions 2025.11.7 and 2026.1.3.
- Decide whether product-family ownership stays in the ring after the first advisory closes, and whether incomplete-fix advisories reopen tickets automatically rather than waiting for a second KEV letter.
Analytics and AI assistants inherited production blast radius
- Metabase (T5) disclosed unauthenticated SQL injection at vendor CVSS 10.0 with active exploitation, tracked as GHSA-vwf4-m7j8-wcjf with no CVE at source time, so there is no NVD base score and no EPSS behind that 10.0. Framework and Tally disclosed confirmed data theft, Framework losing names, emails, login IPs, billing and shipping details and business tax identifiers, Tally losing email addresses and one-way password hashes. LexisNexis has since stated its own disruption is unrelated to this zero-day and stems from a separate third-party incident. Self-hosted installs must upgrade manually while Cloud tenants were vendor-patched. A BI tool holding live database credentials is a vault with a login page.
- Atlassian Rovo (T8) can be steered to collect Jira, Confluence, or SharePoint data within the signed-in user's permissions and send it outside. Two firms found it independently: Varonis Threat Labs reported the URL-parameter route (RovoBlast), which SecurityWeek describes as a critical one-click path and which Atlassian fixed server-side on 8 July; PromptArmor reported indirect prompt injection through uploaded file content, disclosed 23 May, with no confirmed fix as of 8 August per The Hacker News. The vendor patched what a patch could reach. The open route is content-borne and belongs to your access controls, not Atlassian's release notes.
- Decide whether BI platforms and AI assistants with user-scoped access inherit the same internet-exposure, least-privilege, and emergency patch rules as customer-facing applications.
Edge appliances and trusted update paths still feed campaigns
- INC ransomware (T6) is reported as the dominant actor chaining SonicWall SMA1000 CVE-2026-15409 (CVSS 10.0, EPSS 78.44%) and CVE-2026-15410 (CVSS 7.2, EPSS 76.35%), first covered on 20 July and CISA KEV-listed since 14 July with a 17 July deadline that is long passed. The technical defects are continuity; the new fact is a named ransomware operator treating unpatched SMA1000 estates as extortion inventory. Vendor hotfixes exist, so this is an overdue patch item carrying the highest CVSS in the register, not a governance-only card.
- Head Mare (T7), a hacktivist group, exploited unpatched TrueConf servers to replace client installers with unsigned builds delivering the PhantomCore and PhantomGraph backdoors, per Kaspersky. Users who update through the corporate portal install the attacker's payload under the vendor brand. The server flaws carry Kaspersky identifiers KLCERT-26-057 and KLCERT-26-058 rather than CVE numbers. Reported targeting is Russian industry, so for most readers here the exposure is a counterparty one: staff joining meetings on someone else's compromised server are offered the same trojanized client.
- Post-patch compromise assumptions for the disclosure-to-campaign interval, and signed-update attestation under your control, belong in the risk register beside the CVE field.
Threat Actor Profiling
Two threats carry named attribution: INC ransomware as the dominant actor chaining SonicWall SMA1000 flaws (T6, per CyberScoop, SecurityWeek, and The Hacker News) and Head Mare for TrueConf installer trojanization (T7, per BleepingComputer). Langflow (T1), N-central (T2), TeamCity (T3), Kemp (T4), and Metabase (T5) have confirmed exploitation or attempt volume without a public actor name. Atlassian Rovo (T8) is research-documented by two firms independently, Varonis Threat Labs (RovoBlast) and PromptArmor, without a named operator in retrieved reporting. MITRE technique codes are shown as hover-to-define abbreviations.
| Threats | Actor | Sectors | MITRE tradecraft | Kill chain |
|---|---|---|---|---|
| T1 | Unattributed (active exploitation confirmed by CISA; public PoCs reported late July) | Any organization running internet-reachable IBM Langflow, AI agent platform operators | Unauthenticated attackers chain two Langflow API endpoints to bypass login and execute code on default deployments. Public proof-of-concept exploits circulated in late July 2026. Distinct from the earlier Langflow KEV entry CVE-2026-0770. | |
| T2 | Unattributed (exploitation confirmed by N-able and CISA; attackers reached managed systems after incomplete first fix) | Managed service providers, Organizations hosting N-central on-premises or as hosted tenants | Authentication bypass yields administrative takeover on N-central after an incomplete remediation of CVE-2026-18556, which CISA KEV-listed in its own right on 4 August with a 7 August deadline. Reporting describes persistence including Cloudflared services and anomalous svchost.exe paths under user Documents, with access extending to managed endpoints behind the RMM. | |
| T3 | Unattributed (active exploitation confirmed by CISA; material update from 3 August brief) | Software development, Any organization running TeamCity On-Premises | The agent polling protocol accepts unauthenticated requests, yielding remote code execution on a build host that holds signing keys and deployment credentials. Fixed builds remain 2025.11.7 and 2026.1.3; the change from the prior brief is KEV listing and confirmed exploitation, not a new defect. | |
| T4 | Unattributed (792 reported exploit attempts; CISA KEV; material update from 6 July brief) | Any organization running Progress Kemp LoadMaster | Command injection against Kemp LoadMaster management and edge surfaces. EPSS 0.99311 is the highest exploitation probability in this register. KEVIntel telemetry records 792 attempts over 41 days from 65 unique IP addresses across 18 countries, last seen 4 August 2026. Continuity from July exploit-attempt reporting to a 10 August KEV deadline. | |
| T5 | Unattributed (active exploitation confirmed by Metabase; confirmed data theft at Framework and Tally; LexisNexis disruption stated by LexisNexis to be unrelated) | Organizations running Metabase Cloud or self-hosted Metabase 1.58+, Analytics and BI estates holding live database credentials | Unauthenticated SQL injection grants administrator access to the Metabase instance, exposing connected data stores. Workaround path centres on blocking /api/session/reset_password; hunt pattern includes POST reset_password returning 400 followed by successful GET /api/user/current. No CVE assigned at source time. | |
| T6 | INC ransomware (dominant actor chaining SonicWall SMA1000 flaws per CyberScoop, SecurityWeek, and The Hacker News) | Organizations with SonicWall SMA 1000 series edge VPN appliances | Operators chain previously disclosed SMA1000 flaws CVE-2026-15409 (SSRF, CVSS 10.0) and CVE-2026-15410 (post-authentication code injection, CVSS 7.2) from the 20 July brief for root access, data theft, and encryption. Both have been on CISA KEV since 14 July with a 17 July deadline. No new CVE is assigned for the ransomware campaign itself. | |
| T7 | Head Mare, hacktivist group (Kaspersky research via BleepingComputer) | Organizations running internet-reachable TrueConf video-conferencing servers | Unpatched TrueConf servers are compromised through KLCERT-26-057 and KLCERT-26-058 and client installers replaced with unsigned builds delivering PhantomCore (reconnaissance, LSASS credential theft, C2) and PhantomGraph (SysExcSvc.dll and SysReadSvc.dll, tasked over a Microsoft OneDrive account). Subsequent client downloads through the trusted portal install attacker payloads under the vendor brand. The flaws carry Kaspersky identifiers rather than CVE numbers. | |
| T8 | Unattributed (two independent research findings: Varonis Threat Labs as RovoBlast, and PromptArmor; no named operator in retrieved reporting) | Atlassian Cloud tenants with Rovo connected to Jira, Confluence, or SharePoint | Attacker-controlled instructions cause Rovo to collect content within the signed-in user's permissions and send it to an outside server. Route 1 (Varonis Threat Labs, RovoBlast) abuses a URL parameter and is the critical one-click path SecurityWeek describes; Atlassian fixed it server-side on 8 July 2026. Route 2 (PromptArmor) is indirect prompt injection carried inside uploaded file content, disclosed 23 May 2026 with no confirmed fix as of 8 August 2026. |
▶Table methodology & sourcing notes
- CVSS, EPSS and CISA KEV status for scored CVEs were re-derived independently from NVD 2.0, FIRST EPSS and the CISA KEV catalogue on 10 August 2026 via scripts/verify-cve.py. Unlike the 3 August brief, this window's Sheet correctly flagged KEV on Langflow, TeamCity, N-central and LoadMaster; scores were still re-verified rather than taken from Hermes alone. Metabase (T5), TrueConf (T7) and Rovo (T8) carry no CVE in retrieved reporting: T5's 10.0 is the vendor's own score with no NVD record, and T7 and T8 carry no score at all. SonicWall (T6) is a campaign continuity card on CVE-2026-15409 / CVE-2026-15410 from the 20 July brief rather than a new CVE, and is scored here on CVE-2026-15409 as the governing flaw of the pair, which remains KEV-listed from 14 July with a 17 July deadline. TeamCity (T3) and Kemp (T4) are material updates from prior briefs (3 August and 6 July respectively); Langflow CVE-2026-9198 is distinct from CVE-2026-0770. CISA added six CVEs to KEV between 3 and 9 August: the four carried as register rows plus N-central CVE-2026-18556, the incompletely fixed predecessor behind T2, and Apache Tomcat CVE-2026-34486, both of which are carried inside T2 and T1 rather than as separate rows. EPSS is a daily-moving score; all values here are the 10 August 2026 pull.
Control Deficiency & Framework Mapping
| Threat | Control gaps | ISO 27001 | NIST CSF 2.0 | CIS Controls | Privacy Act / PIPEDA | ITSG-33 | OSFI B-13 | ISO 42001 |
|---|---|---|---|---|---|---|---|---|
T1IBM Langflow Unauthenticated Remote Code Execution (CVE-2026-9198) |
| , , , , | , , , | , , , | — | , , , | , | , |
T2N-able N-central Authentication Bypass (CVE-2026-18577) |
| , , , , , | , , , , | , , , , | — | , , , , , , | , , | — |
T3JetBrains TeamCity Unauthenticated RCE — KEV Escalation (CVE-2026-63077) |
| , , , , | , , , , | , , , | — | , , , , | , , | — |
T4Progress Kemp LoadMaster Command Injection (CVE-2026-8037) |
| , , , , | , , , | , , , | — | , , , , | , , | — |
T5Metabase Unauthenticated SQL Injection Zero-Day |
| , , , , , | , , , , | , , , , | , | , , , , , | , , | — |
T6SonicWall SMA1000 Flaws Exploited by INC Ransomware |
| , , , , , | , , , , | , , , , | , | , , , , | , , | — |
T7TrueConf Installer Trojanization by Head Mare |
| , , , , | , , , , | , , , , | — | , , , | , | — |
T8Atlassian Rovo AI One-Click Data Exfiltration |
| , , , , | , , , | , , | , | , , , | , , | , , |
Privacy Act / PIPEDA & OSFI: No entry in this register is itself a confirmed Canadian personal-data breach notification trigger. Metabase (T5) is the primary assessment point: confirmed customer impacts are Framework customer PII and Tally email and password hashes, which map to Schedule 1, Principle 4.7 safeguards and, where your footprint holds Canadian personal information, PIPEDA s.10.1 reporting analysis. LexisNexis is excluded from this assessment: it has stated its disruption is unrelated to this zero-day and caused by a separate third-party incident. SonicWall INC ransomware (T6) and Rovo-assisted exfiltration of Jira, Confluence or SharePoint content (T8) raise the same Principle 4.7 / 4.1.3 questions when personal information sits behind those systems. OSFI B-13 patch, access-control and third-party expectations apply to federally regulated financial institutions running the RMM, CI/CD and edge appliances in T1–T4 and T6. Assess all of it against your own data map and regulatory footprint.
Risk Triage
Threats are assigned to primary zones based on their dominant organizational risk characteristic. A threat may appear in a secondary zone when it presents a materially distinct compounding risk dimension.
Active exploitation or weaponized capability with immediate organizational exposure if unaddressed.
- T1Langflow CVE-2026-9198: KEV due 7 Aug, already passed
Unauthenticated RCE on default deployments with public PoCs; distinct from CVE-2026-0770. Upgrade to 1.10.1 or later (1.11.2 current) — the fix shipped 17 July, twenty-one days before the deadline passed — remove internet exposure, and hunt PoC-era scanning since late July.
- T2N-central CVE-2026-18577: KEV due 6 Aug, incomplete fix chain
Admin takeover after incomplete remediation of CVE-2026-18556, which CISA KEV-listed separately on 4 August with a 7 August deadline; attackers reached managed systems. Upgrade to 2026.3.1.10 (Hotfix 2 supersedes the 2026.3.1.7 hotfix), close both clocks, hunt IoCs, track CCCS AV26-769.
- T3TeamCity CVE-2026-63077: KEV escalation from 3 Aug brief
Moved from no confirmed ITW to CISA KEV due 8 August (passed). Upgrade to 2025.11.7 or 2026.1.3 and rotate signing keys if exposure cannot be ruled out.
- T4Kemp CVE-2026-8037: EPSS 99.31%, KEV due 10 Aug
Highest EPSS in the register after 792 attempts logged from 65 IPs across 18 countries; continuity from the 6 July card. Patch immediately, remove management interfaces from the public internet, and segment the adjacent networks the NVD vector (AV:A) puts in scope.
- T6SonicWall SMA1000 CVE-2026-15409: CVSS 10.0, KEV due 17 Jul, long passed
Highest CVSS in the register with EPSS 78.44%, now under active INC ransomware exploitation. Hotfixes have been available since July; confirm builds 12.4.3-03453 / 12.5.0-02835 or successor.
Confirmed campaign or large-scale exposure with direct impact on organizations or their data.
- T5Metabase SQLi zero-day: named customer data theft
Vendor CVSS 10.0 with no NVD record, under active exploitation; confirmed data theft at Framework and Tally. LexisNexis has stated its disruption is unrelated to this flaw. Upgrade self-hosted builds and rotate connected database credentials.
- T6INC ransomware on SonicWall SMA1000 CVE-2026-15409 / 15410
Named dominant operator chaining the SMA1000 flaws for root access, theft and encryption, with credential, session and TOTP seed theft reported. Also carried in Exposure Velocity: the pair is KEV-listed with a passed deadline. Confirm hotfixes and hunt from 22 June, when exploitation began as a zero-day.
- T2N-central: attackers reached managed systems after first fix
Incomplete remediation left a second bypass path; reporting describes persistence and reach into managed endpoints behind the RMM.
Structural control deficiencies revealed by the week's threats, independent of any single exploit.
- T7TrueConf: trusted installer path became the delivery channel
Head Mare replaced client installers on compromised servers with unsigned builds carrying PhantomCore and PhantomGraph. Verify signatures and checksums, and remove public download endpoints that are not required.
- T8Rovo: AI assistant inherits full user read scope
One-click or prompt-controlled exfiltration of Jira, Confluence or SharePoint data. Atlassian fixed the Varonis URL-parameter route; the PromptArmor prompt-injection route is unfixed and can only be constrained by scope and access controls.
- T5Metabase: BI vault outside crown-jewel inventory
Live database credentials behind an unauthenticated admin path. Waiting for a CVE number delayed action after vendor confirmation of exploitation.
Cross-cutting pattern requiring board-level awareness and programme-level response.
- T1 · T2 · T3 · T4Six KEV clocks on control planes; five already missed
N-central CVE-2026-18577 due 6 Aug, its predecessor CVE-2026-18556 due 7 Aug, Apache Tomcat CVE-2026-34486 due 7 Aug, Langflow due 7 Aug and TeamCity due 8 Aug have all passed; Kemp is due 10 Aug. RMM, CI/CD, AI-agent tooling, application servers and load-balancer management need permanent Immediate-lane ownership, not letter-driven triage.
- T1 · T3 · T4 · T6Continuity is a reopen rule, not a status footnote
Langflow CVE-2026-9198 is distinct from CVE-2026-0770; TeamCity escalates the 3 August card to KEV; Kemp escalates the 6 July card; SonicWall CVE-2026-15409 / 15410 returns as an INC campaign. Decide what automatically reopens a closed ticket.
- T5 · T8Assistants and analytics inherited production blast radius
Metabase held live database credentials; Rovo inherits the signed-in user's Jira and Confluence scope. Both need crown-jewel classification and least-privilege defaults before the next integration ships.
Remediation Actions
Consolidated actions across all eight threats, organized by time horizon. T-badges indicate which threat each action addresses.
0 – 24 hours
Immediate response
- T1Upgrade Langflow to 1.10.1 or later, ideally current 1.11.2 — the vendor fix has been available since 17 July. Remove internet exposure from management and API endpoints and record the 7 August KEV deadline as missed where unmet. Treat as a separate ticket from CVE-2026-0770.
- T1Patch Apache Tomcat CVE-2026-34486 where Tomcat is in scope. It is KEV-listed from the same 4 August drop with a 7 August deadline and EPSS 81.16%, so it belongs in this lane rather than the weekly change window: upgrade 11.0.20 to 11.0.21, 10.1.53 to 10.1.54, or 9.0.116 to 9.0.117.
- T2Upgrade on-premises N-central to build 2026.3.1.10 (Hotfix 2, 6 August). Hotfix 1 build 2026.3.1.7 is superseded and needs a second change window even where already applied; confirm hosted NCOD tenants received the vendor mitigation. Hunt N-able IoCs and rotate RMM admin credentials. Record both KEV deadlines as missed where unmet: CVE-2026-18577 due 6 August and predecessor CVE-2026-18556 due 7 August.
- T3Upgrade TeamCity to 2025.11.7 or 2026.1.3 if not already done from the 3 August brief; install the security patch plugin where upgrade is blocked. Remove internet-facing access. Record the 8 August KEV deadline as missed where unmet.
- T4Apply Progress Kemp LoadMaster patches for CVE-2026-8037 immediately, remove management interfaces from the public internet, and meet or document exception against the 10 August KEV deadline.
- T5Upgrade self-hosted Metabase to the fixed build for your branch — 0.58.24, 0.59.21, 0.60.17, 0.61.11, 0.62.9 or 0.63.5, per branch rather than a range. Until patched, block /api/session/reset_password. Revoke sessions and rotate connected database credentials.
- T6Confirm SMA1000 appliances are on hotfix builds 12.4.3-03453 / 12.5.0-02835 or successor. CVE-2026-15409 and CVE-2026-15410 have been KEV-listed since 14 July with a 17 July deadline that is long passed, and INC ransomware is now exploiting the pair.
7 days
Short-term hardening
- T1Hunt for PoC-era scanning and post-exploitation on Langflow hosts since late July.
- T2Assume managed endpoints behind a compromised N-central may be reached; review agent-side persistence and track CCCS AV26-769 to closure.
- T3Rotate signing keys and deployment credentials if TeamCity exposure cannot be ruled out for the window between disclosure and KEV.
- T4Hunt for exploitation attempts against LoadMaster since early July and cross-check CCCS Progress advisory AV26-552, updated 7 August to record the CISA KEV addition.
- T6Hunt INC ransomware IoCs and residual access on SMA1000 estates from 22 June onward, three weeks before the hotfix, and rotate VPN credentials plus re-enrol MFA where TOTP seed theft cannot be ruled out.
- T7Patch TrueConf servers for KLCERT-26-057 / -058, validate installer signatures and hashes before distribution, and hunt endpoints that installed clients during the exposure window for PhantomCore and PhantomGraph, including staff who joined meetings on counterparty-hosted servers.
- T8Confirm the Varonis URL-parameter route is closed in your tenant, then treat the PromptArmor prompt-injection route as open: restrict which apps and user groups can use Rovo, restrict its access to crown-jewel spaces, and constrain untrusted uploaded content in Rovo-readable spaces.
14 – 30 days
Programme remediation
- T1T2T3Name owners for Langflow, N-central and TeamCity end to end, and define the reopen rule when a briefed critical moves to KEV or a second advisory lands on the same product family.
- T4T6Place load-balancer and edge VPN management planes permanently in the Immediate remediation lane, independent of monthly change windows.
- T5Add BI tools with live database credentials to crown-jewel inventory with the same internet-exposure and patch SLAs as customer-facing applications.
- T7Require signed-update attestation under organizational control before collaboration-suite installers reach user devices.
- T8Treat AI assistant integrations as data processors in the asset inventory and default them to least-privilege project scopes.
Ongoing
Structural controls
- T1T2Incomplete-fix advisories, second KEV listings on the same product family, and superseded vendor builds all reopen tickets automatically; 'patched' is not binary until the follow-on advisory and the current build both close.
- T3T4T6Continuity cards (TeamCity from 3 Aug, Kemp from 6 Jul, SonicWall CVE-2026-15409 / 15410 from 20 Jul) update the threat-actor and exploitation fields, not only the CVE field.
- T5T8Analytics platforms and AI assistants with user-scoped access inherit production blast radius; classify them before integration, not after breach reporting.
- T7Vendor update portals are not a control until content integrity is verified under your attestation.
Provenance
Intelligence Sources
- BleepingComputer ↗CISA warns of hackers exploiting Langflow, N-central, Apache Tomcat flaws
- The Hacker News ↗CISA Flags Langflow RCE, Tomcat, and N-central Flaws as Actively Exploited
- NVD ↗CVE-2026-9198
- BleepingComputer ↗N-able warns of N-central auth bypass flaw exploited in attacks
- The Hacker News ↗CISA Adds Exploited N-able N-central Flaw to KEV After Customer Compromises
- The Hacker News ↗N-able Issues N-central Hotfix 2 as Attackers Reach Managed Systems and Persist
- CCCS ↗AV26-769: N-able security advisory
- NVD ↗CVE-2026-18577
- NVD ↗CVE-2026-18556 (predecessor, separately KEV-listed)
- SecurityWeek ↗Hackers Start Exploiting Recent JetBrains TeamCity Vulnerability
- The Hacker News ↗CISA Flags TeamCity CVE-2026-63077 RCE Flaw Under Active Exploitation in the Wild
- NVD ↗CVE-2026-63077
- The Hacker News ↗Progress Kemp LoadMaster Flaw Hits CISA KEV After 792 Reported Exploit Attempts
- CCCS ↗AV26-552: Progress security advisory (5 June 2026, updated 7 August 2026 for the CISA KEV addition)
- NVD ↗CVE-2026-8037
- BleepingComputer ↗Metabase SQLi zero-day exploited in customer data-theft attacks
- The Hacker News ↗Metabase Zero-Day Exploited in Wild Allows Admin Access Without Authentication
- CyberScoop ↗Prolific ransomware group behind SonicWall zero-day attacks
- SecurityWeek ↗Recent SonicWall Vulnerabilities Exploited in Ransomware Attacks
- The Hacker News ↗INC Ransomware Emerges as Dominant Actor Exploiting SonicWall SMA 1000 Flaws
- NVD ↗CVE-2026-15409 (governing flaw of the pair)
- BleepingComputer ↗Hackers breach TrueConf to trojanize client installers with backdoors
- SecurityWeek ↗Critical One-Click Vulnerability in Atlassian’s Rovo AI Exposed Enterprise Data
- The Hacker News ↗Atlassian Rovo Can Be Tricked Into Sending Jira and Confluence Data to Attackers
Cadence
Published weekly. Each issue distills the week's most material threats from primary security reporting and vendor advisories, cross-referenced against authoritative sources (CVE/NVD, CISA KEV, and MITRE ATT&CK) and mapped to the compliance obligations that govern your response. Use Subscribe or Share on any issue to join the distribution list.
See how this week's threats map to your control gaps.
Book a briefing →