August 10, 2026
Command View
Verification cutoff
Verification cutoff: August 10, 2026, 14:43 UTC
Today’s edition is dominated by threats to systems that sit between attackers and consequential infrastructure: operational-technology (OT) controllers, remote-monitoring and management platforms, application-delivery controllers, remote-access appliances, and data-management systems carrying reusable credentials into other environments.
The most consequential current development remains the campaign against internet-exposed water-sector programmable logic controllers (PLCs): the FBI and EPA say utilities in at least seven U.S. states have reported incidents since July 27, with effects including loss of monitoring or control, loss of pressure, flooding, and at least one case involving altered PLC project files. At the enterprise edge, CISA on August 7 added the unauthenticated Progress Kemp LoadMaster command-injection flaw CVE-2026-8037 to the Known Exploited Vulnerabilities (KEV) catalog, with a federal remediation deadline of August 10.
The N-able N-central incident also requires a stronger response than the previous edition conveyed. N-able now requires on-premises customers to install 2026.3.1.10 / Hotfix 2, even where the August 2 hotfix was already installed. Its investigation found attackers used compromised N-central infrastructure to reach managed endpoints through Take Control and then registered Cloudflare Tunnel services on those endpoints, providing persistence after N-central access was revoked.
Priority posture
- RED: Internet-exposed Rockwell Automation/Allen-Bradley MicroLogix 1100 and 1400 PLCs in the U.S. water and wastewater sector are being actively manipulated, with confirmed operational effects.
- RED: Progress Kemp LoadMaster CVE-2026-8037 is now CISA KEV-listed; exposed, API-enabled vulnerable systems permit pre-authentication operating-system command execution.
- RED: N-able N-central CVE-2026-18577 was exploited as a zero-day and enabled downstream access and persistence inside customer-managed environments; current vendor-required remediation is Hotfix 2 / 2026.3.1.10.
- RED: SonicWall SMA1000 CVE-2026-15409 and CVE-2026-15410 are both confirmed exploited. Technical analysis establishes a path from unauthenticated external access to internal appliance services and then root command execution.
- RED: Metabase has confirmed active exploitation of a CVSS 10.0 unauthenticated SQL-injection vulnerability that can yield Metabase administrator access and expose credentials for connected databases.
- RED: Suisun City, California remains in incident response after malicious software compromised municipal IT and affected 911 routing, police/fire dispatch, records, and other city functions.
- AMBER: CERT Polska’s newly disclosed investigation of the December 2025 energy attack shows attackers entered an OT environment through a misconfigured private cellular Access Point Name (APN), shutting down a steam turbine and process-water treatment system.
Today’s decisions
- RED — Water/OT operators: Remove PLCs from direct internet exposure; validate running PLC project files and ladder logic against known-good copies before locking controllers into run mode; preserve evidence from modems, human-machine interfaces (HMIs), engineering workstations, and gateways.
- RED — Edge/application-delivery teams: Identify LoadMaster systems with API access enabled and running GA 7.2.63.1 or earlier or LTSF 7.2.54.17 or earlier; upgrade and investigate exposed appliances rather than treating CISA’s August 10 deadline as a patch-only exercise.
- RED — MSP/RMM owners: Upgrade on-premises N-central to 2026.3.1.10 and hunt managed endpoints for unauthorized services, Cloudflare Tunnel activity, unexpected Take Control sessions, administrator changes, and the vendor-published indicators. Do not accept a clean N-able IOC scan as proof of non-compromise.
- RED — Remote-access/security appliance teams: Patch affected SMA1000 appliances and conduct forensic review. Where SonicWall indicators are present, follow vendor guidance to re-image or redeploy the appliance, change user and administrator passwords, and reset TOTP tokens.
- RED — Data-platform owners: Patch vulnerable Metabase instances; where the reset-password endpoint was publicly accessible, invalidate sessions, audit administrator and API-key changes, rotate credentials for connected databases, and review warehouse access.
- AMBER — OT/telecom architecture owners: Validate private APN isolation rather than assuming that “private” cellular addressing prevents device-to-device reachability. Test whether arbitrary subscribers inside the APN can communicate with one another or reach OT assets.
Threat and Resilience Ledger
RED — Water/Operational Technology | North America — Internet-exposed PLC campaign is producing physical-process disruption
The FBI and EPA warned on July 30 that malicious cyber actors have been remotely accessing internet-facing Rockwell Automation/Allen-Bradley MicroLogix 1100 and 1400 PLCs used by U.S. water and wastewater utilities. Since July 27, utilities in at least seven states had reported incidents to the FBI. Attackers changed controller IP addresses and passwords, causing loss of monitoring and, in some cases, loss of equipment function. Reported operational effects include loss of pressure and flooding; at least one organization found modified PLC project files after discovering ladder-logic discrepancies at several sites. The agencies also identified similarities in third-party-supplied network configurations across multiple victims, raising the possibility that common deployment patterns are multiplying exposure. Operators should remove direct inbound internet exposure, broker remote access through controlled gateways, secure cellular modems, restrict controller communications with access-control lists, validate project files and logic against trusted versions, and preserve the capability for safe manual operation.
Evidence: confirmed.
Attribution: unknown.
Confidence: high.
Uncertainty: The FBI/EPA advisory does not publicly identify the victims, provide case-level attribution, or establish how many additional exposed utilities have been accessed without visible operational effects.
Sources: FBI and EPA — “Malicious Cyber Actors Targeting Water and Wastewater Sector Internet-Facing Programmable Logic Controllers, Causing Operational Disruptions,” July 30, 2026.
RED — Application Delivery / Network Edge | Global — LoadMaster pre-authentication RCE enters CISA KEV with remediation due today
CISA added CVE-2026-8037 affecting Progress Kemp LoadMaster to KEV on August 7 and set August 10, 2026 as the federal remediation deadline. The vulnerability is a CVSS 9.6 operating-system command-injection flaw reachable through the /accessv2 API endpoint when API access is enabled; successful exploitation permits an unauthenticated attacker to execute arbitrary commands on the appliance. Progress identifies fixed releases LMOS 7.2.63.2 and 7.2.54.18; affected branches are GA 7.2.63.1 and earlier and LTSF 7.2.54.17 and earlier. Public proof-of-concept material appeared June 29, and eSentire observed exploitation attempts beginning that day. Importantly, eSentire states that the attempts it personally observed were unsuccessful and produced no post-compromise activity; CISA’s subsequent KEV addition supplies the stronger evidence that exploitation has occurred elsewhere. Internet-facing LoadMasters with the vulnerable API configuration should therefore be patched and investigated as potential edge footholds.
Evidence: confirmed.
Attribution: unknown.
Confidence: high.
Uncertainty: CISA has not publicly disclosed the victim count, observed post-exploitation behavior, or evidence underlying the KEV determination.
Sources: CISA — “CISA Adds One Known Exploited Vulnerability to Catalog,” August 7, 2026; Progress — “LoadMaster Vulnerabilities,” updated August 5, 2026; eSentire — “Progress Kemp LoadMaster Vulnerability Targeted (CVE-2026-8037),” June 30, 2026.
RED — MSP / Remote Management | Global — N-central CVE-2026-18577 requires Hotfix 2 and downstream persistence hunting
N-able’s August 6 investigation update materially changes the response requirements for CVE-2026-18577, the N-central authentication-bypass vulnerability discovered after active zero-day exploitation on July 31. N-able initially released build 2026.3.1.7 on August 2, but now explicitly requires on-premises deployments to upgrade to 2026.3.1.10 / Hotfix 2, which supersedes Hotfix 1 with additional hardening. CISA added CVE-2026-18577 to KEV on August 3. More importantly, N-able has documented the attack path: after remotely obtaining N-central administrative access, attackers used Take Control to connect to systems managed by N-central and registered a Cloudflare Tunnel as a new service on those downstream devices. That provided access persistence even after the attacker’s N-central access was revoked. N-able reports a limited number of identified customers but says its investigation is ongoing. A clean result from N-able’s IOC service template explicitly does not prove an environment was unaffected. The response boundary must therefore extend across customer endpoints, identities, services, remote-control events, logs, and credentials—not end at the N-central server.
Evidence: confirmed.
Attribution: unknown.
Confidence: high.
Uncertainty: The complete victim population, attacker dwell time, additional persistence methods, downstream credential exposure, and full attacker infrastructure remain under investigation.
Sources: N-able — “N-central Security Update – August 6, 2026,” August 6, 2026; CISA — “CISA Adds One Known Exploited Vulnerability to Catalog,” August 3, 2026.
RED — Remote Access / Security Appliances | Global — SMA1000 flaws provide a demonstrated path from the internet to root
SonicWall confirms active exploitation of CVE-2026-15409, a CVSS 10.0 server-side request forgery (SSRF) flaw, and CVE-2026-15410, a CVSS 7.2 remote-code-execution/privilege-escalation flaw affecting specified SMA1000 12.4.3 and 12.5.0 builds. Rapid7 observed targeted zero-day exploitation of internet-facing appliances before disclosure. Its technical analysis shows why the pair is especially dangerous: CVE-2026-15409 allows an unauthenticated attacker to use the /wsproxy feature as a TCP tunnel into localhost-only appliance services, including the control service on port 8188; CVE-2026-15410 can then abuse the remove_hotfix workflow to execute attacker-controlled code as root. Rapid7 demonstrated the resulting chain from external unauthenticated reachability to privileged appliance execution. SonicWall confirms both vulnerabilities are exploited in the wild, but public vendor evidence does not establish that every observed intrusion used the complete two-CVE chain; that distinction should be preserved. Fixed releases are 12.4.3-03453 or later and 12.5.0-02835 or later. SonicWall directs compromised customers to re-image/redeploy affected appliances and reset credentials and TOTP tokens.
Evidence: confirmed exploitation; exploit chain demonstrated.
Attribution: unknown.
Confidence: high.
Uncertainty: Public reporting does not establish how consistently attackers chained CVE-2026-15409 with CVE-2026-15410 during real intrusions, nor the total number of compromised appliances.
Sources: SonicWall — “Product Notice: SMA 1000 Series affected by Multiple Vulnerabilities,” July 14, updated July 15, 2026; Rapid7 — “Rapid7 MDR Team Discovers New SonicWall SMA1000 Zero Days being Actively Exploited (CVE-2026-15409, CVE-2026-15410),” July 2026.
RED — Data / Administrative Platforms | Global — Metabase confirms exploitation of unauthenticated SQL injection leading to administrator access
Metabase on August 6 disclosed GHSA-vwf4-m7j8-wcjf, a CVSS 10.0 vulnerability for which no CVE had been assigned by the verification cutoff. An unauthenticated remote attacker can inject SQL into the Metabase application database and potentially obtain administrator access. From there, Metabase says an attacker could alter configuration, obtain stored credentials for connected databases, read data available through those connections, and export data. Metabase explicitly confirms active exploitation. Patched releases are x.58.24, x.59.21, x.60.17, x.61.11, x.62.9, and x.63.5. Where immediate upgrade is impossible, Metabase recommends blocking /api/session/reset_password; if that endpoint had been publicly reachable, post-patch actions include invalidating sessions, reviewing API keys and administrator changes, rotating credentials for connected databases, and examining warehouse and Metabase query logs.
Evidence: confirmed.
Attribution: unknown.
Confidence: high.
Uncertainty: Metabase has not publicly established the overall victim population, attacker identity, or how extensively compromised instances were used to pivot into connected databases.
Sources: Metabase — “SQL injection using an unauthenticated endpoint leading to admin access,” GitHub Security Advisory GHSA-vwf4-m7j8-wcjf, August 6, 2026.
RED — Municipal / Public Safety | North America — Suisun City emergency continues after malware compromises public-safety IT
Suisun City, California declared a state of emergency on August 8 after malicious software infected and compromised municipal IT systems at approximately 05:45 local time on August 7. The city states that the incident affected 911 routing, police and fire dispatch, records, and city services. Officials shut down the entire IT network both to contain the threat and preserve evidence for a federal investigation. Emergency operations remain active through continuity arrangements—including use of the Solano County dispatch center—but online city services and internal operations were still unavailable in the city’s latest public statement. The FBI, Department of Homeland Security, California Office of Emergency Services, and regional partners are involved. The city has not publicly identified the malware family, initial access vector, attacker, or whether data was exfiltrated, so the incident should not be described as ransomware without additional evidence.
Evidence: confirmed.
Attribution: unknown.
Confidence: high.
Uncertainty: Initial access, persistence, data theft, malware family, restoration timeline, and attacker objective remain undisclosed.
Sources: City of Suisun City — “Suisun City Council Declares State of Emergency,” August 8, 2026.
AMBER — Energy / OT Connectivity | Europe — Polish destructive attack exposes private-APN trust failure
CERT Polska on August 8 disclosed a previously unreported component of the destructive December 29, 2025 attack on Poland’s energy sector. Alongside attacks against 30 wind and solar installations and a large combined heat-and-power plant, attackers struck a smaller CHP facility supplying heat to approximately 50,000 residents. The attack shut down a steam turbine and the water-treatment system used to produce process water, interrupting cogeneration; rapid operator action limited the outage and prevented loss of heat to consumers. CERT Polska reconstructed an attack path into the OT network through a private cellular APN whose configuration allowed arbitrary devices inside that supposedly private network to communicate with one another. CERT Polska says its survey work found similar configurations common in Poland and believes they are widely used elsewhere. The incident is historical, not evidence of an ongoing August compromise, but the newly disclosed access path warrants immediate review of cellular OT architectures because “private APN” cannot be treated as equivalent to segmentation or peer isolation.
Evidence: confirmed.
Attribution: public assessment.
Confidence: high.
Uncertainty: The prevalence of equally exploitable APN configurations outside Poland and the degree to which mobile-network providers expose comparable peer-to-peer paths remain unresolved.
Sources: CERT Polska — “Follow-Up Report of the December 2025 Energy Sector Incident,” August 8, 2026.
Defensive Posture Changes
Patching a control plane does not evict its downstream footholds
The N-central incident provides unusually clear evidence for a rule that should apply across RMM, identity, VPN, edge, and management infrastructure: repairing the original control plane is not incident closure. N-able documented persistence on endpoints that remained usable after N-central access was revoked. The investigation boundary must therefore follow every privilege and management relationship the compromised platform controlled.
For N-central specifically, defenders should correlate Take Control history with endpoint service creation, outbound Cloudflare-related connectivity, administrator changes, credential use, and endpoint telemetry. Evidence should be preserved before aggressive cleanup. Where attacker access to privileged credentials cannot be excluded, rotate them after affected systems have been brought back under trusted control.
The same principle applies to Metabase: patching the application does not invalidate stolen sessions, API keys, or database credentials. Likewise, SonicWall explicitly recommends appliance re-imaging or redeployment when compromise indicators are found rather than assuming a firmware update restores trust.
Treat PLC logic and configuration as integrity-critical evidence
The FBI/EPA water alert moves the defensive problem beyond “protect the password.” Attackers have manipulated controller addressing and authentication configuration, and at least one victim reported modified project files and ladder-logic discrepancies. Defenders should therefore baseline and integrity-check not only firmware but the control program itself, reusable logic, I/O configuration, controller mode, and relevant HMI and engineering-workstation state. Backups must be validated before restoration; an intact-looking backup containing malicious logic is not a recovery point.
Where safety allows, engineering and security personnel should jointly compare running logic with an independently trusted engineering copy. Changes should be understood operationally before controllers are placed into modes that lock the current project into service.
Private transport is not segmentation
The Polish energy investigation and the FBI/EPA warning intersect in an important way. Cellular connectivity is increasingly used for geographically distributed OT, but a private APN, private address range, VPN, or carrier-managed service is only a transport and access mechanism. It must not substitute for explicit authorization boundaries.
CERT Polska found that arbitrary devices within the affected private APN could communicate with one another. FBI/EPA guidance separately calls for secured cellular modems, logging, controlled gateways, and isolated architectures for remote OT access. Defenders should test actual reachability rather than infer isolation from the provider’s product name or topology diagram.
Edge appliances should be investigated as hosts, not black boxes
Load balancers, VPN appliances, and remote-access gateways routinely receive less host-level monitoring than general-purpose servers even though compromise places attackers at a privileged network boundary. CVE-2026-8037 and the SMA1000 campaign reinforce the need to preserve and inspect appliance logs, configuration history, authentication activity, unexpected outbound connectivity, and changes to local services.
Where the vendor recommends rebuilding the appliance after confirmed compromise—as SonicWall does—restoration from configuration backups must also account for whether those backups could preserve attacker-modified state.
Continuity plans must prove that the physical mission survives the IT outage
Suisun City maintained emergency response by shifting dispatch operations rather than waiting for the primary IT environment to recover. Water-sector operators have similarly depended on manual capability during PLC disruption. Critical-infrastructure recovery plans should therefore be tested around the mission function—dispatching responders, maintaining pressure, controlling treatment, producing heat—not merely restoration of servers.
Regional and Sector Pulse
RED — North America | Water and wastewater
The strongest region-specific critical-infrastructure warning is the FBI/EPA campaign against water and wastewater PLCs. The verified public floor is at least seven states, not higher figures circulating through secondary reporting. Confirmed effects already cross the threshold from scanning or opportunistic access into operational interference: equipment visibility and function have been lost, pressure loss and flooding have occurred, and controller project files have been modified.
RED — North America | Municipal government and public safety
Suisun City demonstrates how compromise of conventional municipal IT can immediately reach emergency-service operations even without demonstrated OT involvement. The continuing use of alternate dispatch arrangements is evidence of resilience, but also evidence that the primary environment has not yet returned to normal trusted operation.
AMBER — Europe | Energy and telecom-dependent OT
The newly disclosed Polish CHP incident changes architecture assumptions beyond the original December attack. The important development is not merely another victim but a previously undocumented private-APN route into OT, followed by destructive action against generation-support processes. Organizations using similar carrier-based architectures should regard private-APN isolation as a property to verify, not an assumption.
RED — Global product exposure | Management and edge systems
N-central, LoadMaster, SMA1000, and Metabase exposure is global rather than evidence of a region-specific campaign. Their common characteristic is leverage: each sits at a point from which successful compromise can reach systems, identities, applications, data, or networks beyond the initially vulnerable host.
Vulnerability and Supplier Watchlist
Progress Kemp LoadMaster
Issue: CVE-2026-8037 — unauthenticated operating-system command injection / remote code execution through the API interface.
Affected scope: GA 7.2.63.1 and earlier; LTSF 7.2.54.17 and earlier. Exploit path is reachable through /accessv2 when API access is enabled.
Fixed release: LMOS 7.2.63.2; LMOS 7.2.54.18.
Severity: CVSS 9.6.
Status: RED — CISA KEV-listed August 7 with August 10 federal remediation deadline; public PoC and exploitation activity exist.
N-able N-central
Issue: CVE-2026-18577 — authentication bypass enabling remote administrative access; exploited as a zero-day.
Affected scope: N-able states the original vulnerability affected all N-central versions; attacker exploitation occurred against systems prior to 2026.3.1.7. On-premises deployments are now subject to the subsequent Hotfix 2 requirement.
Fixed release: 2026.3.1.10 / Hotfix 2 is the current vendor-required release, superseding 2026.3.1.7 / Hotfix 1 with additional hardening. Hosted environments have been mitigated by N-able.
Severity: CISA Known Exploited Vulnerability; remote administrative compromise with demonstrated downstream endpoint access.
Status: RED — confirmed zero-day exploitation, CISA KEV listing, and demonstrated persistence on managed endpoints via Cloudflare Tunnel services.
SonicWall SMA1000
Issue: CVE-2026-15409 — SSRF permitting unauthenticated access to localhost-only services; CVE-2026-15410 — root-level operating-system command execution through an internal control-service workflow.
Affected scope: SMA1000 6210, 7210, 8200v and CMS on listed 12.4.3 and 12.5.0 hotfix builds. SonicWall identifies affected builds as 12.4.3-03245, 12.4.3-03387, 12.4.3-03434, 12.5.0-02283, 12.5.0-02624, and 12.5.0-02800.
Fixed release: 12.4.3-03453 or later; 12.5.0-02835 or later.
Severity: CVE-2026-15409 CVSS 10.0 Critical; CVE-2026-15410 CVSS 7.2 High.
Status: RED — both vulnerabilities are confirmed exploited; Rapid7 demonstrated how the first can expose internal services and the second can convert that access into root execution.
Metabase
Issue: GHSA-vwf4-m7j8-wcjf — unauthenticated SQL injection into the Metabase application database leading potentially to administrator access. No CVE assigned by cutoff.
Affected scope: documented affected ranges span x.58 through x.63 branches; operators should follow Metabase’s precise advisory ranges rather than infer safety from major-version numbers alone.
Fixed release: x.58.24; x.59.21; x.60.17; x.61.11; x.62.9; x.63.5.
Severity: CVSS 10.0 Critical.
Status: RED — Metabase confirms active exploitation; compromise can expose credentials for connected databases and expand beyond the application itself.
Rockwell Automation / Allen-Bradley MicroLogix 1100 and 1400
Issue: Active malicious access and configuration manipulation of internet-facing PLCs; this campaign is not principally a newly disclosed CVE issue.
Affected scope: Internet-exposed MicroLogix 1100 and 1400 devices observed by the FBI in U.S. water and wastewater environments; similar defensive considerations apply to other exposed PLCs.
Fixed release: Not applicable. Reduce exposure through architecture and access control; end-of-life equipment should be replaced or isolated.
Severity: Operational consequence already demonstrated.
Status: RED — confirmed multi-state activity has caused loss of monitoring/control, pressure loss, flooding, and altered PLC project files.
Outlook and Uncertainty
Next 24 hours
Watch for CISA or Progress publication of additional exploitation detail, indicators, or victim information for CVE-2026-8037 following today’s federal remediation deadline.
N-able’s investigation remains active. Additional endpoint indicators, attacker infrastructure, persistence mechanisms, or changes to Hotfix guidance would directly change MSP and downstream-customer response priorities.
Metabase remains a candidate for rapid defensive escalation if a CVE is assigned, CISA adds the issue to KEV, public exploitation tooling appears, or victim reporting demonstrates widespread compromise of connected database credentials.
Water-sector defenders should watch for an updated FBI/EPA victim count, case-level indicators, confirmed actor attribution, evidence of additional PLC families being targeted, or more serious physical effects. The current public record already establishes operational interference but does not publicly attribute the seven-state activity.
Suisun City’s recovery should be watched for clarification of the malware family, entry vector, persistence, data exposure, and criteria used before reconnecting municipal and public-safety systems.
What is not known
The principal gaps are consequential:
- The FBI and EPA have not publicly attributed the seven-state water-sector activity or identified the affected utilities.
- CISA has not disclosed the exploitation evidence behind the LoadMaster KEV addition or the number of affected organizations.
- N-able has not publicly defined the full number of compromised downstream endpoints or ruled out persistence mechanisms beyond the disclosed Cloudflare Tunnel services.
- Public SonicWall reporting does not prove that every observed SMA1000 compromise used the full CVE-2026-15409 → CVE-2026-15410 chain, even though the chain is technically demonstrated and both flaws are exploited.
- Metabase has not disclosed a complete exploitation timeline, victim count, attacker identity, or the number of connected databases reached from compromised instances.
- Suisun City has not disclosed its initial access vector, malware family, exfiltration status, or attacker.
- CERT Polska’s private-APN findings establish a dangerous architecture pattern but do not establish how many comparable networks outside Poland are presently exploitable.
Absence of a public victim count, persistence indicator, attribution, or confirmed lateral movement is not evidence that these elements are absent.
Trigger for escalation
The following evidence should immediately change response priorities:
- Water/OT: manipulation of treatment or safety logic, chemical dosing, interlocks, pump sequencing, or other control functions capable of creating direct public-health or equipment-safety consequences.
- LoadMaster: confirmed successful post-exploitation activity in critical-infrastructure, government, defense, telecom, cloud, or MSP environments; persistence or credential theft from the appliance; publication of reliable mass-exploitation telemetry.
- N-central: discovery of additional downstream persistence, credential theft, broad customer-to-customer propagation, or compromise surviving 2026.3.1.10 remediation.
- SMA1000: evidence of broad automated exploitation, new persistence, lateral movement from appliances into critical environments, or additional root-level attack paths.
- Metabase: confirmed reuse of stolen database credentials against production systems, exploitation across significant critical-infrastructure deployments, or broadly available reliable exploit automation.
- Private APN / OT: discovery of the Polish access pattern in additional energy, water, transport, telecom, or industrial networks, particularly where peer reachability crosses customer or facility boundaries.
- Municipal systems: evidence that the Suisun compromise persists into recovery, affected public-safety data integrity, or reached systems capable of changing physical operations.
Jonathan Brown is a cybersecurity researcher and investigative journalist at bordercybergroup.com.
If you would like to support our work — useful, well-researched, ad-free cybersecurity intelligence — subscribe, comment, or buy us a coffee! Thanks.
Member discussion: