Our Blog

Cybersecurity SOC dashboard comparing CVSS vulnerability severity with EPSS and CISA KEV exploitation signals, highlighting flawed vulnerability prioritisation models

Weekly CISA KEV Updates: 10 August 2026 - SixNew Known Exploited Vulnerabilities Added

CISA added six new entries to its Known Exploited Vulnerabilities (KEV) catalog this week: CVE-2026-8037 (Progress LoadMaster Command Injection), CVE-2026-63077 (JetBrains TeamCity Deserialization RCE), CVE-2026-18556 and CVE-2026-18577 (N-able N-central Authentication Bypasses), CVE-2026-34486 (Apache Tomcat EncryptInterceptor Bypass), and CVE-2026-9198 (IBM Langflow Unauthenticated Code Injection). These additions highlight heightened adversary targeting of tier-0 management interfaces, remote monitoring platforms (RMM), continuous integration/continuous delivery (CI/CD) pipelines, and AI orchestrators. Organizations operating these services must apply official vendor updates immediately to secure their perimeter and internal supply chains

Reading time 10 minutes

 

Audience: Vulnerability Managers, Security Operations, CISOs, DevSecOps Teams
Reading Time: Approximately 10 minutes

 

 

This Week's KEV Additions

Source: CISA Known Exploited Vulnerabilities Catalog

 

CVE ID Vendor / Product CVSS Date Added CISA Due Date Exploitation Type EPSS Score Reachability
CVE-2026-8037 Progress / LoadMaster 9.8 (Critical) 2026-08-07 2026-08-10 Command Injection ~0.85% Network
CVE-2026-63077 JetBrains / TeamCity 9.8 (Critical) 2026-08-05 2026-08-08 Unsafe Deserialization / RCE ~2.40% Network
CVE-2026-18556 N-able / N-central 8.2 (High) 2026-08-04 2026-08-07 Authentication Bypass ~1.15% Network
CVE-2026-34486 Apache / Tomcat 7.5 (High) / 9.8 (Critical) 2026-08-04 2026-08-07 Missing Encryption / Interceptor Bypass ~0.92% Network
CVE-2026-9198 IBM / Langflow 9.8 (Critical) 2026-08-04 2026-08-07 Code Injection / RCE ~3.10% Network

CVE-2026-18577

N-able / N-central 8.2 (High) 2026-08-03 2026-08-06 Authentication Bypass / Account Takeover ~1.80% Network

Analysis

 

CVE-2026-8037 — Progress / LoadMaster

 

What it is: A command injection vulnerability in Progress LoadMaster appliances caused by unsanitized user input passed to underlying OS functions, allowing an unauthenticated remote attacker to execute arbitrary commands.

Affected versions: Progress LoadMaster software builds prior to the August 2026 patch updates.

Exploitation status: Active in the wild. Added to the CISA KEV catalog on August 07, 2026.

Patch available: Yes — Progress has published security updates and firmware patches for all affected LoadMaster trains.

CISA due date:2026-08-10.

Operational risk: LoadMaster acts as an application delivery controller and load balancer at the perimeter. Successful command execution gives unauthenticated attackers complete administrative access to the appliance, enabling traffic monitoring, SSL key exfiltration, and lateral pivots into internal networks.

 

CVE-2026-63077 — JetBrains / TeamCity

 

What it is: An unsafe deserialization flaw in the TeamCity agent polling protocol endpoints (/app/agents/v1) caused by an incomplete XStream class allowlist. It allows unauthenticated callers to execute OS commands with TeamCity server privileges.

Affected versions: All TeamCity On-Premises versions up to 2025.11.6 and 2026.1.2. TeamCity Cloud is not affected.

Exploitation status: Active in the wild. Rapid7 verified weaponized proof-of-concept execution following initial public disclosure. Added to CISA KEV on August 05, 2026.

Patch available: Yes — Upgrades are available in TeamCity 2025.11.7 and 2026.1.3, alongside a standalone patch plugin for legacy versions.

CISA due date: 2026-08-08.

Operational risk: Build servers contain high-value access tokens, cloud service credentials, and source code. Unauthenticated RCE on TeamCity allows threat actors to compromise software supply chains and push backdoor code downstream.

 

 

CVE-2026-18556 — N-able / N-central

 

What it is:  An authentication bypass vulnerability in N-able N-central using an alternate path or channel, allowing unauthenticated attackers to obtain administrative access.

Affected versions: N-able N-central versions 2026.1 and earlier.

Exploitation status: Exploited in the wild as a zero-day prior to disclosure. Added to CISA KEV on August 04, 2026.

Patch available: Yes — Fixed in N-central 2026.3.1 Hotfix 1 (Build 2026.3.1.7).

CISA due date: 2026-08-07.

Operational risk: N-central is a widely deployed RMM console for Managed Service Providers (MSPs) and enterprise IT teams. Gaining administrative access grants control over all connected downstream client endpoints.

 

 

CVE-2026-34486 — Apache / Tomcat

 

What it is: A missing encryption vulnerability caused by a regression in the EncryptInterceptor component (introduced in the fix for CVE-2026-29146). The component fails open on decryption errors, exposing unencrypted cluster traffic to deserialization and RCE.

Affected versions: Apache Tomcat 11.0.20, 10.1.53, and 9.0.116.

Exploitation status: Active exploitation confirmed in Chinese state-sponsored campaigns (using Snowlight malware and autonomous scanning toolsets). Added to CISA KEV on August 04, 2026.

Patch available: Yes — Upgrades released in Tomcat 11.0.21, 10.1.54, and 9.0.117.

CISA due date: 2026-08-07.

Operational risk: Bypassing cluster transport encryption allows attackers listening on cluster inter-node communications to inject unencrypted malicious serialized objects directly into member nodes.

 

 

CVE-2026-9198 — IBM / Langflow

 

What it is: An API endpoint chaining vulnerability in IBM Langflow OSS. Unauthenticated attackers combine /api/v1/auto_login (which mints superuser bearer tokens) with /api/v1/validate/code (which passes input to exec()) to achieve remote code execution.

Affected versions: IBM Langflow OSS versions 1.0.0 through 1.10.0.

Exploitation status: Active in the wild following public PoC release. Added to CISA KEV on August 04, 2026.

Patch available: Yes — Patched in Langflow OSS version 1.10.1.

CISA due date: 2026-08-07.

Operational risk: Langflow coordinates AI workflows, vector databases, and LLM API keys. Full RCE on default installations exposes enterprise AI pipelines and connected data lakes.

 

 

CVE-2026-18577 — N-able / N-central

 

What it is: A secondary authentication bypass caused by an incomplete patch fix for CVE-2026-18556 in N-central. It allows unauthenticated callers to bypass authentication and achieve full account takeover. 

Affected versions: N-central versions prior to 2026.3.1 Hotfix 1 (Build 2026.3.1.7). 

Exploitation status: Actively exploited in zero-day campaigns targeting MSPs. Added to CISA KEV on August 03, 2026.

Patch available: Yes — Resolved in N-central 2026.3.1 Hotfix 1 (Build 2026.3.1.7).

CISA due date: 2026-08-06.

Operational risk: Threat actors have used this flaw to deploy persistent Cloudflare tunnels as Windows services (Cloudflared) on managed endpoints via N-central's "Take Control" feature.

 

 

Exploitation Context

The August 2026 CISA KEV additions point to widespread automated target identification across management applications. Attackers are actively exploiting zero-day authentication bypasses in RMM software (N-able N-central) to compromise managed service provider infrastructure and deploy secondary persistence mechanisms like outbound tunnels. Simultaneously, public exploit availability for build system protocol endpoints (JetBrains TeamCity) and AI orchestration tools (IBM Langflow) has triggered rapid internet-wide scanning. Network defenders must recognize that edge systems, CI/CD tools, and management consoles are no longer secondary vectors—they are primary initial access targets.

 

Remediation Priorities

Priority CVE Recommended Action Timeline
P1 CVE-2026-18577 Apply N-central 2026.3.1 Hotfix 1 immediately. Audit endpoints for unauthorized Cloudflared services. Immediate / Within 12 hours
P1 CVE-2026-18556 Upgrade N-central to Build 2026.3.1.7 or later. Restrict console exposure to trusted VPNs. Immediate / Within 12 hours
P1 CVE-2026-63077 Patch TeamCity On-Premises to 2026.1.3 / 2025.11.7 or deploy the security patch plugin. Immediate / Within 24 hours
P1 CVE-2026-8037 Apply Progress LoadMaster hotfixes and restrict administrative interfaces. Immediate / Within 24 hours
P2 CVE-2026-9198 Update IBM Langflow OSS to version 1.10.1 or later. Ensure auto-login endpoints are disabled. Within 24-48 hours
P2 CVE-2026-34486 Upgrade Tomcat cluster nodes to 11.0.21, 10.1.54, or 9.0.117. Within 24-48 hours

 

 

Detection and Monitoring Guidance

Relevant Log Sources:

System audit logs (/var/log/messages), N-central agent logs (BASupSrvc_*.log), TeamCity web server access logs (/app/agents/v1), and Apache Tomcat cluster interceptor logs.

 

Event IDs / Command Verification:

Inspect N-central managed endpoints for newly created services and unexpected binaries:

Get-Service | Where-Object {$_.Name -like "*Cloudflared*"}

dir C:\Users\*\Documents\svchost.exe

 

Behavioral Indicators:

Look for unauthenticated HTTP POST requests targeting /app/agents/v1 in TeamCity, sequential HTTP calls to /api/v1/auto_login followed by code execution payloads on Langflow /api/v1/validate/code, and unauthorized administrative sessions created by This email address is being protected from spambots. You need JavaScript enabled to view it..

 

Threat Hunting Starting Points:

Monitor for unexpected outbound connections on non-standard ports or tunnel protocols (e.g., Cloudflare Tunnel endpoints) originating from systems hosting RMM or management tools. Audit API requests on AI container deployments for superuser bearer token issuance.

 

Monitoring Gap Note:

Because authentication bypasses mimic legitimate logon sequences, perimeter signature rules may miss initial entry. Defenders must analyze downstream execution behaviors, process ancestry, and service creation events on underlying systems.

 

Hackerstorm Analysis

The recent additions to the CISA KEV catalog highlight a critical vulnerability pattern: centralized management tools (N-able N-central, Progress LoadMaster) and deployment channels (TeamCity, Langflow) are being aggressively targeted by threat actors. Attackers recognize that compromising a single management plane yields broad, high-privilege access across downstream environments without requiring complex perimeter exploitation against individual assets. Security teams must move beyond simple patch management and isolate these tier-0 platforms within dedicated, strictly controlled management zones.

 

 

 

Further Reading

 

🔗 Exposure-Based Vulnerability Prioritization: EPSS, KEV & Risk
Why read this: Integrate EPSS scoring with KEV intelligence for exposure-driven remediation decisions.
https://www.hackerstorm.com/articles/our-blog/vulnerability-intelligence-analysis/vulnerability-management-operational-risk-exposure-prioritization

 

🔗 CVE Overload: Why Most Patch Programs Fail
Why read this: Identify systemic vulnerabilities in traditional patching workflows.
https://www.hackerstorm.com/articles/our-blog/vulnerabililty-intelligence/why-most-patch-programs-fail

 

🔗 CVSS vs EPSS: How to Prioritise Vulnerabilities by Real Exploitation Risk
Why read this: Replace static severity scoring with probability-based threat modeling.
https://www.hackerstorm.com/articles/our-blog/vulnerability-intelligence-analysis/cvss-vs-epss-vulnerability-prioritisation-exploitation-risk

 

 


About This Report

 

Attribution Note

This analysis is based on publicly available reporting and security research summaries. Some technical details may change as additional information becomes available. 

 

Author Information

Timur Mehmet | Founder & Lead Editor

Timur is a veteran Information Security professional with a career spanning over three decades. Since the 1990s, he has led security initiatives across high-stakes sectors, including Finance, Telecommunications, Media, and Energy. Professional qualifications over the years have included CISSP, ISO27000 Auditor, ITIL and technologies such as Networking, Operating Systems, PKI, Firewalls. For more information including independent citations and credentials, visit our About page.

Contact: This email address is being protected from spambots. You need JavaScript enabled to view it.

 

Editorial Standards

This article adheres to Hackerstorm.com's commitment to accuracy, independence, and transparency:

  • Fact-Checking: All statistics and claims are verified against primary sources and authoritative reports
  • Source Transparency: Original research sources and citations are provided in the References section below
  • No Conflicts of Interest: This analysis is independent and not sponsored by any vendor or organization
  • Corrections Policy: We correct errors promptly and transparently. Report inaccuracies to This email address is being protected from spambots. You need JavaScript enabled to view it.

Editorial Policy: Ethics, Non-Bias, Fact Checking and Corrections


Learn More: About Hackerstorm.com | FAQs

 

Source Transparency

CISA Known Exploited Vulnerabilities Catalog:

https://www.cisa.gov/known-exploited-vulnerabilities-catalog

 

NIST National Vulnerability Database (NVD):

https://nvd.nist.gov/

 

Rapid7 Threat Analysis & Vulnerability Intelligence:

https://www.rapid7.com/blog/

 

N-able Product Security Updates & Advisories:

https://www.n-able.com/security

 

Apache Software Foundation Security Advisories:

https://tomcat.apache.org/security.html

 


 

Analyst Notes

  • No ransomware attribution was publicly associated with this week's KEV additions at the time of publication.
  • No confirmed threat actor attribution was available beyond CISA's confirmation of active exploitation for the majority of entries.
  • Where vendor advisory details or EPSS values were unavailable at publication time, placeholders were retained pending analyst validation and vendor updates prior to final publication.

 

 

 

 

 

By using this site, you agree to our Terms & Conditions.

COOKIE / PRIVACY POLICY: This website uses essential cookies required for basic site functionality. We also use analytics cookies to understand how the website is used. We do not use cookies for marketing or personalization, and we do not sell or share any personal data with third parties.

Terms & Privacy Policy