Progress LoadMaster Command Injection Vulnerability

🚨SEVERITY: CRITICAL β€” CVSS 9.6Security Advisory

TL;DR πŸ“Œ

  • Progress LoadMaster contains a command injection vulnerability that allows an un-authenticated attacker to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in multiple command endpoints.
  • Highest CVSS: 9.6 (Critical).
  • Listed in CISA KEV (2026-08-07) β€” this is being exploited in the wild.
  • Check the advisory for fixed releases β€” remediation detail is in the vendor link below.
  • CVEs: CVE-2026-8037.

What it is

CVE-2026-8037 is a command injection vulnerability in Progress LoadMaster, the vendor’s load balancer/ADC appliance. The flaw sits in multiple command endpoints where input is not properly sanitised before being passed through to the underlying system.

[]

Cisco Catalyst SD-WAN Software Security Hardening Release: August 2026

🚨SEVERITY: CRITICAL β€” CVSS 9.9Security Advisory

TL;DR πŸ“Œ

  • As part of Cisco’s ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. These vulnerabilities were found during internal testing and are not known to be actively exploited. To…
  • Highest CVSS: 9.9 (Critical).
  • Fix available β€” see the first fixed release below.
  • CVEs: CVE-2026-20303, CVE-2026-20304, CVE-2026-20310.

What it is

As part of Cisco’s ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities.

[]

Cisco IOS XE Software Security Hardening Release: August 2026

🚨SEVERITY: CRITICAL β€” CVSS 9.8Security Advisory

TL;DR πŸ“Œ

  • As part of Cisco’s ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. These vulnerabilities were found during internal testing and are not known to be actively exploited. To…
  • Highest CVSS: 9.8 (Critical).
  • Fix available β€” see the first fixed release below.
  • CVEs: CVE-2026-20267, CVE-2026-20268, CVE-2026-20269.

What it is

This advisory covers seven CVEs found by Cisco’s own IOS XE engineering team during an internal security review, rather than through external reporting. Cisco has grouped the underlying bugs by CWE class and issued one CVE ID per class: CVE-2026-20267 (improper access control, CWE-284), CVE-2026-20268 (memory buffer bounds issues, CWE-119), CVE-2026-20269 (resource lifetime handling, CWE-664), CVE-2026-20270 (incorrect calculation, CWE-682), CVE-2026-20271 (control flow issues such as race conditions or uncontrolled recursion, CWE-691), CVE-2026-20272 (improper neutralisation of special elements, CWE-74, i.e. injection), and CVE-2026-20273 (improper input validation, CWE-20).

[]

Cisco Secure Firewall Management Center Software Authentication Bypass Vulnerability

🚨SEVERITY: CRITICAL β€” CVSS 10.0Security Advisory

TL;DR πŸ“Œ

  • A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to bypass authentication and execute script files on an affected device to obtain root access to the underlying operating system. This vulnerability is due to an improper system process that is created at boot time.…
  • Highest CVSS: 10.0 (Critical).
  • Check the advisory for fixed releases β€” remediation detail is in the vendor link below.
  • CVEs: CVE-2026-20079.

What it is

CVE-2026-20079 is an authentication bypass in the web interface of Cisco Secure Firewall Management Center (FMC) Software. It carries a CVSS score of 10.0 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H) β€” network-exploitable, no privileges, no user interaction, and full impact on confidentiality, integrity and availability.

[]

JetBrains TeamCity Deserialization of Untrusted Data Vulnerability

🚨SEVERITY: CRITICAL β€” CVSS 9.8Security Advisory

TL;DR πŸ“Œ

  • JetBrains TeamCity contains a deserialization of untrusted data vulnerability that could allow unauthenticated remote code execution via the agent polling protocol.
  • Highest CVSS: 9.8 (Critical).
  • Listed in CISA KEV (2026-08-05) β€” this is being exploited in the wild.
  • Check the advisory for fixed releases β€” remediation detail is in the vendor link below.
  • CVEs: CVE-2026-63077.

What it is

CVE-2026-63077 is a deserialisation of untrusted data vulnerability in JetBrains TeamCity. It sits in the agent polling protocol, which handles communication between TeamCity build agents and the server.

[]

Apache Tomcat Missing Encryption of Sensitive Data Vulnerability

🚨SEVERITY: HIGH β€” CVSS 7.5Security Advisory

TL;DR πŸ“Œ

  • Apache Tomcat contains a missing encryption of sensitive data vulnerability that allows the bypass of the EncryptInterceptor. This vulnerability can be chained with CVE‑2025‑24813.
  • Highest CVSS: 7.5 (High).
  • Listed in CISA KEV (2026-08-04) β€” this is being exploited in the wild.
  • Check the advisory for fixed releases β€” remediation detail is in the vendor link below.
  • CVEs: CVE-2026-34486.

What it is

Apache Tomcat contains a missing encryption of sensitive data vulnerability that allows the bypass of the EncryptInterceptor. This vulnerability can be chained with CVE‑2025‑24813.

[]

IBM Langflow Code Injection Vulnerability

🚨SEVERITY: CRITICAL β€” CVSS 9.8Security Advisory

TL;DR πŸ“Œ

  • Langflow contains a code injection vulnerability that allows unauthenticated attackers to achieve full remote code execution on default Langflow deployments.
  • Highest CVSS: 9.8 (Critical).
  • Listed in CISA KEV (2026-08-04) β€” this is being exploited in the wild.
  • Check the advisory for fixed releases β€” remediation detail is in the vendor link below.
  • CVEs: CVE-2026-9198.

What it is

CVE-2026-9198 is a code injection vulnerability in IBM Langflow. It allows an unauthenticated attacker to achieve full remote code execution on a default Langflow deployment.

[]

N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability

🚨SEVERITY: HIGH β€” CVSS 7.4Security Advisory

TL;DR πŸ“Œ

  • N-able N-central contains an authentication bypass using an alternate path or channel that allows for authentication bypass.
  • Highest CVSS: 7.4 (High).
  • Listed in CISA KEV (2026-08-04) β€” this is being exploited in the wild.
  • Check the advisory for fixed releases β€” remediation detail is in the vendor link below.
  • CVEs: CVE-2026-18556.

What it is

CVE-2026-18556 is an authentication bypass in N-able N-central, achieved by reaching the application through an alternate path or channel that skips the normal authentication check. The CVSS vector indicates this is exploitable over the network without authentication or user interaction, though attack complexity is rated high.

[]

N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability

🚨SEVERITY: HIGH β€” CVSS 8.1Security Advisory

TL;DR πŸ“Œ

  • N-able N-central contains an authentication bypass using an alternate path or channel allows for authentication bypass and account takeover in N-central. This vulnerability is the result of an incomplete patch for CVE-2026-18556.
  • Highest CVSS: 8.1 (High).
  • Listed in CISA KEV (2026-08-03) β€” this is being exploited in the wild.
  • Check the advisory for fixed releases β€” remediation detail is in the vendor link below.
  • CVEs: CVE-2026-18577.

What it is

N-able N-central contains an authentication bypass using an alternate path or channel allows for authentication bypass and account takeover in N-central. This vulnerability is the result of an incomplete patch for CVE-2026-18556.

[]

Cisco Catalyst Center Virtual Appliance Privilege Escalation Vulnerability

🚨 SEVERITY: HIGH β€” CVSS 8.8 Security Advisory

TL;DR πŸ“Œ

A privilege escalation vulnerability has been identified in the Cisco Catalyst Center Virtual Appliance, allowing authenticated attackers to elevate their privileges to Administrator. The highest CVSS score for this vulnerability is 8.8, categorized as High severity. No workarounds are available, but fixed software releases are provided.

What happened πŸ•΅οΈβ€β™‚οΈ

A vulnerability in the Cisco Catalyst Center Virtual Appliance could allow an authenticated, remote attacker to elevate their privileges to Administrator on an affected system. This issue arises from insufficient validation of user-supplied input. An attacker with valid credentials for a user account with at least the Observer role could exploit this vulnerability by sending a crafted HTTP request, potentially allowing unauthorized modifications to the system.

[]