August 8, 2026
Command View
Verification cutoff
This edition is verified through August 8, 2026, at 12:31 UTC. It prioritizes exploitation, service disruption, and supplier or control-plane weaknesses that can cross administrative, network, server, cloud, CI/CD, or operational-technology trust boundaries.
Priority posture
RED means active exploitation, a confirmed operational effect, or a control-plane exposure requiring immediate containment and recovery validation. AMBER means high-consequence exposure or public exploit material without confirmed broad exploitation. WATCH means a credible defensive or regulatory change that needs tracking. CONTEXT changes planning assumptions without establishing a current compromise.
The lead decision is to treat internet-reachable TeamCity, N-central, VeloCloud Orchestrator, Secure FMC, and SonicWall SMA1000 systems as compromise-assessment candidates, not ordinary patch tickets. The same discipline applies to exposed PLCs and untrusted router firmware.
Today’s decisions
- RED | CI/CD and MSP owners: identify internet-reachable TeamCity and N-central systems, preserve evidence, and move to fixed builds or the vendor hotfix path.
- RED | Network and remote-access owners: validate Cisco FMC, VeloCloud Orchestrator, and SonicWall SMA1000 exposure and downstream device integrity.
- RED | OT owners: remove direct internet paths to PLCs and validate running logic before changing controller mode or restoring backups.
- AMBER | Platform owners: map Cisco IOS XE, Apache Traffic Server, Zbtlink, and VMware exposure to critical services and maintenance windows.
Threat and Resilience Ledger
RED — CI/CD and software supply chain | Global — TeamCity exploitation is now confirmed
JetBrains reported active and attempted exploitation of unpatched TeamCity On-Premises servers on August 7. CVE-2026-63077 is an unauthenticated remote-code-execution flaw in the agent polling protocol; CISA records CVSS 9.8 and known exploitation. All On-Premises versions are affected when reachable over HTTP(S). Fixed releases are 2025.11.7 and 2026.1.3, with a patch plugin for 2017.1 and later; TeamCity Cloud is remediated. A compromised server can expose credentials, build configuration, artifacts, and downstream pipelines. Evidence: confirmed. Attribution: not public. Confidence: high. Uncertainty: victim set and post-exploitation activity remain undisclosed. Sources: JetBrains — “CVE-2026-63077: Additional Guidance Following Reports of Active Exploitation,” August 7, 2026; CISA — “Vulnerability Summary for the Week of July 27, 2026,” August 3, 2026.
RED — MSP and RMM | North America / Global — N-central requires a second hotfix
The Canadian Cyber Centre places N-able N-central versions before 2026.3.1.10 in scope for CVE-2026-18577 and CVE-2026-18556, both in CISA’s Known Exploited Vulnerabilities catalog. CVE-2026-18577 is an incomplete patch that enables authentication bypass and account takeover; its CNA CVSS score is 8.2. N-able Hotfix 2, build 2026.3.1.10, released August 6 and supersedes Hotfix 1 with additional hardening. The MSP control plane can reach customer servers and end points, so installing an update does not close downstream exposure. Evidence: confirmed. Attribution: not public. Confidence: high. Uncertainty: victim scope and a CVSS score for CVE-2026-18556 are unpublished. Sources: Canadian Centre for Cyber Security — “N-able security advisory (AV26-769) - Update 2,” August 7, 2026; N-able — “Release Notes,” August 6, 2026.
RED — SD-WAN control plane | Global — VeloCloud Orchestrator remains actively exploited
Arista’s CVE-2026-16812 is an unauthenticated VeloCloud Orchestrator command-injection flaw, rated CVSS 10.0 under v3.1 and v4.0. Affected releases are 5.2.x before 5.2.3.14, 6.1.x before 6.1.3.4, 6.4.x before 6.4.2.4, and 7.0.x before 7.0.0.1; on-premises and hosted VCO are in scope. Arista reports active exploitation, and compromise may reach managed Edge devices and configuration. Evidence: confirmed vendor disclosure and CISA bulletin. Attribution: not public. Confidence: high. Uncertainty: victim population and persistence are unknown. Sources: Arista Networks — “Security Advisory 0144,” August 3, 2026; CISA — “Vulnerability Summary for the Week of July 27, 2026,” August 3, 2026.
RED — Firewall management | Global — Secure FMC exploitation turns a low CVSS into a high operational concern
Cisco reports that CVE-2026-20316 in Secure Firewall Management Center Software was exploited in July. The static-credential flaw is CVSS 5.3, but Cisco rates impact High because it can chain with other FMC weaknesses for privilege escalation. Secure FMC is affected; Cloud-Delivered FMC, FDM, ASA, FTD, and SCC are not. Fixed hotfixes are 7.0.9.1-3, 7.2.11.1-4, 7.4.7.1-3, 7.6.5.1-2, 7.7.12.1-2, and 10.0.1.1-2. Evidence: confirmed vendor statement. Attribution: not public. Confidence: high. Uncertainty: victim count and objectives are undisclosed. Sources: Cisco — “Cisco Secure Firewall Management Center Software Static Credential Vulnerability,” July 31, 2026; SecurityWeek — “Cisco Secure FMC Zero-Day Exploited in the Wild,” July 30, 2026.
RED — Remote access and ransomware exposure | Global — SonicWall SMA1000 exploitation remains a recovery issue
SonicWall confirms active exploitation of CVE-2026-15409 and CVE-2026-15410 in SMA1000. The SSRF flaw is CVSS 10.0 Critical; the RCE flaw is 7.2 High. Models include SMA 6210, 7210, 8200v, and CMS on listed 12.4.3 and 12.5.0 builds; fixes are 12.4.3-03453 and 12.5.0-02835 or later. SonicWall requires forensics, re-imaging or redeployment, password and TOTP resets after compromise. Secondary reporting links exploitation to ransomware, but actor and victim count are unknown. Evidence: vendor-confirmed exploitation. Attribution: unconfirmed. Confidence: high for exploitation, moderate for ransomware linkage. Uncertainty: customer scope unknown. Sources: SonicWall — “Product Notice: SMA 1000 Series affected by Multiple Vulnerabilities,” July 13, 2026; SecurityWeek — “Recent SonicWall Vulnerabilities Exploited in Ransomware Attacks,” August 3, 2026.
RED — AI workflow infrastructure | Global — CISA’s Langflow deadline has passed
CVE-2026-9198 affects Langflow OSS 1.0.0 through 1.10.0. An unauthenticated caller can mint a superuser token and execute Python through auto-login and code validation. CVSS 9.8; fixed 1.10.1. CISA added it to KEV August 4, due August 7. Internet-facing instances reaching stores, model credentials, or internal services are high concern. IBM bulletins on August 5 recommend 1.11.0+ for other weaknesses. Evidence: vendor/CISA-confirmed. Attribution: not public. Confidence: high. Uncertainty: deployment and campaign detail unknown. Sources: IBM — “Security Bulletin: Unauthenticated Remote Code Execution via Auto-Login Bypass and Code Validation,” July 2, 2026; CISA — “Known Exploited Vulnerabilities Catalog,” August 4, 2026; IBM — “Security Bulletin: Langflow is affected by weaknesses in secret handling and sensitive configuration access,” August 5, 2026.
RED — Application servers | Global — Tomcat encryption-boundary bypass is in KEV
CVE-2026-34486 affects Apache Tomcat 9.0.116, 10.1.53, and 11.0.20. An error in the fix for CVE-2026-29146 allows EncryptInterceptor bypass. Apache rates it Important and fixes it in 9.0.117, 10.1.54, and 11.0.21. CISA lists it as known exploited with an August 7 due date, but no confirmed remote code execution or victims are public. Apache publishes no CVSS; a secondary 7.5 score is not an Apache rating. Evidence: advisory and KEV confirmed. Attribution: not public. Confidence: high for scope and exploitation. Uncertainty: mechanics and impact remain limited. Sources: Apache Software Foundation — “CVE-2026-34486 Apache Tomcat - Fix for CVE-2026-29146 allowed bypass of EncryptInterceptor,” April 9, 2026; CISA — “Known Exploited Vulnerabilities Catalog,” August 4, 2026.
RED — OT and water dependencies | North America / Middle East — PLC access can become process manipulation
CISA and partners report Iranian-affiliated actors targeting internet-connected Rockwell CompactLogix and Micro850, Schneider Modicon M340, and Siemens S7-1200 PLCs. Activity includes project-file downloads, logic and code changes, and altered alarm, shutdown, HMI, or SCADA behavior. This campaign has no CVE, CVSS, or fixed release. The July 22 update warns any exposed PLC may be at risk and emphasizes isolation, project-file validation, offline backups, and safe controller mode. Evidence: government-confirmed. Attribution: publicly assessed as Iranian-affiliated. Confidence: high for techniques. Uncertainty: victim count and spread are unknown. Sources: CISA — “Iranian-Affiliated Cyber Actors Exploit Programmable Logic Controllers Across US Critical Infrastructure,” July 22, 2026; CISA — “CISA, FBI, EPA and U.S. Government Partners Update Warning,” July 22, 2026.
AMBER — Network infrastructure | Global — Cisco IOS XE hardening release spans seven vulnerability classes
Cisco’s August 5 IOS XE hardening release groups CVE-2026-20267 through CVE-2026-20273. The highest score is CVSS 9.8 for command or argument injection; other scores reach 9.0 and 8.6. Scope includes IOS XE in autonomous or controller mode across 17.9, 17.12, 17.15, 17.18, and 26.1. First fixed releases are 17.9.10, 17.12.8, 17.15.6, 17.18.4 or 17.18.4a, and 26.1.2. Cisco says internal testing found the issues, no exploitation is known, and no workarounds exist. Evidence: confirmed vendor advisory. Attribution: not applicable. Confidence: high. Uncertainty: exposure depends on release and operating mode. Sources: Cisco — “Cisco IOS XE Software Security Hardening Release: August 2026,” August 5, 2026.
AMBER — Internet proxy and delivery layer | Global — Apache Traffic Server ships a 38-CVE security release
Apache Traffic Server’s July release fixes 38 CVEs covering request smuggling, policy bypass, HTTP/2 and HTTP/3 parsing, TLS, memory safety, SSRF, and plugins. CISA lists scores to 10.0, including CVE-2026-33267, CVE-2026-57834, CVE-2026-58150, and CVE-2026-58162. Affected ranges include ATS 8.0-8.1.9, 9.0-9.2.14, and 10.0-10.1.3; fixed releases are 9.2.15 and 10.1.4. Apache reports no exploitation, so it is not KEV in reviewed evidence. Evidence: project/CISA-confirmed. Attribution: not applicable. Confidence: high. Uncertainty: prevalence and exploitation unknown. Sources: Apache Traffic Server — “[SECURITY] Multiple vulnerabilities fixed in Apache Traffic Server 9.2.15 and 10.1.4,” July 28, 2026; CISA — “Vulnerability Summary for the Week of July 27, 2026,” August 3, 2026.
AMBER — Virtualization and telco cloud | Global — VMware fixes vCenter authentication and ESX host paths
Broadcom’s VMSA-2026-0006.1 covers VMware ESX, vCenter, Workstation, Fusion, Cloud Foundation, vSphere Foundation, and telco-cloud products. CVE-2026-59309 and CVE-2026-59310 are vCenter authentication-bypass and directory-traversal RCE issues rated CVSS 9.8; CVE-2026-47876 is an ESX VMXNET3 out-of-bounds write rated 9.3. Fixed vCenter releases include 9.1.0.0300, 9.0.2.0100, and 8.0 U3k or U2f; fixed ESX builds include ESXi80U3k-25595708 and ESXi80U2f-25626445. Broadcom reports private disclosure and no active exploitation. Evidence: confirmed vendor advisory. Attribution: not applicable. Confidence: high. Uncertainty: virtualization concentration makes correlated impact material even without exploitation evidence. Sources: Broadcom — “VMSA-2026-0006.1: VMware ESX, vCenter, Workstation, and Fusion Security Updates,” August 3, 2026.
AMBER — Network edge and supplier trust | Indo-Pacific / Global — Zbtlink firmware is a device-trust problem
VulnCheck reports CVE-2026-66747, an embedded ENDLESSDOORS remote-control implant in published Zbtlink firmware. The researcher rates it CVSS v4 9.3 and identifies roughly 21 images across 20 models sold under ZBT, ZBTWiFi, Wiflyer, and unbranded labels. The implant runs with root privileges, initiates outbound connections, and accepts commands without an authentication handshake; a fixed release was not available at cutoff. The Canadian Cyber Centre lists the affected firmware images, while no source reviewed establishes external exploitation or attribution. Evidence: confirmed technical disclosure and government advisory. Attribution: unconfirmed. Confidence: high for the firmware finding. Uncertainty: inventory, distribution, and vendor remediation remain incomplete. Sources: VulnCheck — “ENDLESSDOORS Is Phoning Home. Pick Up.,” August 5, 2026; Canadian Centre for Cyber Security — “Zbtlink security advisory (AV26-779),” August 5, 2026.
Defensive Posture Changes
Treat administrative planes as incident surfaces
TeamCity, N-central, VeloCloud Orchestrator, Secure FMC, SonicWall SMA1000, and Cisco IMC all place trusted administration near the attack path. The posture change is to preserve evidence and assess downstream identities, device state, credentials, build artifacts, and managed customers before declaring remediation complete.
Revalidate the second-order patch state
N-central Hotfix 2 supersedes Hotfix 1, and IBM’s Langflow updates show that a product can receive additional security notices while an earlier KEV deadline is still driving action. Track fixed build, hotfix lineage, and service-provider-managed status separately; do not infer closure from the first installed update.
Make OT isolation and recoverability testable
CISA’s PLC warning turns planned isolation, controller mode control, project-file integrity, offline backups, and manual or safe fallback into concrete resilience requirements. The relevant question is whether an operator can isolate and recover without freezing an unsafe process or restoring tampered logic.
Reclassify embedded equipment by provenance
Zbtlink demonstrates that a white-label or branch-network device can be a supplier-trust issue even when no exploit campaign is confirmed. Procurement, asset inventory, egress controls, and replacement decisions should account for firmware provenance and model identity, not only the brand visible in a management console.
Regional and Sector Pulse
North America
The immediate North American concentration is known exploitation across MSP, firewall, CI/CD, application-server, and AI workflow control planes, alongside CISA’s PLC warning. Water, manufacturing, public-sector, and managed-service operators should not collapse these into one patch queue because each has a different downstream trust boundary.
Europe and the UK
European operators inherit the same TeamCity, Tomcat, Traffic Server, VeloCloud, and VMware exposure. The UK’s downstream energy cyber-regulation response continues to move toward measurable segmentation, remote-access governance, supplier visibility, and IT/OT integration controls; final enforcement language remains unsettled. Status: WATCH. Sources: UK Department for Energy Security and Net Zero and Ofgem — “Reshaping Cyber Regulation in Downstream Gas and Electricity: Government Response,” August 5, 2026.
Indo-Pacific
The Zbtlink disclosure is relevant to cellular CPE, branch connectivity, remote sites, and unbranded network equipment used in the region, but no verified Indo-Pacific exploitation campaign was established through cutoff. VMware telco-cloud scope and VeloCloud hosted remediation remain relevant to telecom and managed-network operators. Status: AMBER for supplier exposure, CONTEXT for regional campaign claims.
Middle East and Africa
CISA’s Iranian-affiliated PLC assessment remains the clearest operational-technology signal. Separately, Angola’s Unitel reported a cyberattack that disrupted voice, mobile-data, and internet services nationwide; no CVE, technical entry path, attribution, or recovery detail has been published. These are distinct assessments: one is a government-documented technique set, the other an operator-reported telecom disruption. Status: RED for PLC exposure, WATCH for Unitel’s unresolved cause. Sources: Reuters — “Angola’s Unitel hit by cyberattack ahead of stock market debut,” July 28, 2026.
Latin America and the Caribbean
No new, independently verified regional escalation affecting essential services was identified through the cutoff. The practical regional watch remains concentrated supplier and network-management exposure, including VeloCloud, N-central, Secure FMC, SonicWall, and Cisco IOS XE, where service-provider or public-sector deployments can create correlated impact. Status: WATCH.
Vulnerability and Supplier Watchlist
JetBrains TeamCity On-Premises
Issue: CVE-2026-63077 unauthenticated remote code execution through the agent polling protocol.
Affected scope: All TeamCity On-Premises versions reachable over HTTP(S).
Fixed release: 2025.11.7 or 2026.1.3; security patch plugin for 2017.1 and later.
Severity: CVSS 9.8, Critical.
Status: RED; active exploitation and attempted exploitation reported. Cloud remediated.
N-able N-central
Issue: CVE-2026-18556 authentication bypass and CVE-2026-18577 incomplete-patch bypass with account-takeover risk.
Affected scope: N-central versions before 2026.3.1.10.
Fixed release: Hotfix 2, build 2026.3.1.10.
Severity: CVE-2026-18577 CNA CVSS 8.2, High; CVE-2026-18556 score not stated in reviewed sources.
Status: RED; both CVEs are in CISA KEV. Hotfix 2 supersedes Hotfix 1.
Arista VeloCloud Orchestrator
Issue: CVE-2026-16812 unauthenticated operating-system command injection.
Affected scope: On-premises and hosted VCO 5.2.x before 5.2.3.14, 6.1.x before 6.1.3.4, 6.4.x before 6.4.2.4, and 7.0.x before 7.0.0.1.
Fixed release: 5.2.3.14, 6.1.3.4, 6.4.2.4, and 7.0.0.1.
Severity: CVSS 10.0 under v3.1 and v4.0.
Status: RED; actively exploited; downstream Edge integrity must be assessed.
Cisco Secure Firewall Management Center
Issue: CVE-2026-20316 static credential vulnerability with chaining risk.
Affected scope: Secure FMC Software; Cloud-Delivered FMC, FDM, ASA, FTD, and SCC are not affected.
Fixed release: Hotfixes for 7.0.9.1-3, 7.2.11.1-4, 7.4.7.1-3, 7.6.5.1-2, 7.7.12.1-2, and 10.0.1.1-2.
Severity: CVSS 5.3; Cisco Security Impact Rating High.
Status: RED; Cisco observed exploitation in July.
SonicWall SMA1000
Issue: CVE-2026-15409 SSRF and CVE-2026-15410 RCE.
Affected scope: SMA 6210, 7210, 8200v, and CMS on listed 12.4.3 and 12.5.0 firmware builds.
Fixed release: 12.4.3-03453 and 12.5.0-02835 or later.
Severity: CVSS 10.0 Critical and 7.2 High.
Status: RED; active exploitation; forensic analysis and recovery validation required.
IBM Langflow Open Source
Issue: CVE-2026-9198 unauthenticated token issuance and arbitrary Python execution.
Affected scope: Langflow OSS 1.0.0 through 1.10.0; additional August 5 bulletins extend other weaknesses through 1.10.3.
Fixed release: 1.10.1 for CVE-2026-9198; IBM recommends 1.11.0 or newer for additional August bulletins.
Severity: CVSS 9.8, Critical.
Status: RED; CISA KEV with an August 7 due date.
Apache Tomcat
Issue: CVE-2026-34486 bypass of EncryptInterceptor protections.
Affected scope: Tomcat 9.0.116, 10.1.53, and 11.0.20.
Fixed release: 9.0.117, 10.1.54, or 11.0.21.
Severity: Apache Important; CVSS not published by Apache, with 7.5 reported in secondary coverage.
Status: RED; CISA KEV; exploit mechanics and victim scope remain unknown.
Cisco IOS XE
Issue: CVE-2026-20267 through CVE-2026-20273, covering access control, memory safety, command injection, and input validation.
Affected scope: IOS XE 17.9, 17.12, 17.15, 17.18, and 26.1 in autonomous or controller mode.
Fixed release: 17.9.10, 17.12.8, 17.15.6, 17.18.4 or 17.18.4a, and 26.1.2.
Severity: Highest CVSS 9.8; other grouped scores include 9.0 and 8.6.
Status: AMBER; no known active exploitation or workaround.
Apache Traffic Server
Issue: 38 CVEs spanning request smuggling, policy bypass, HTTP/2 and HTTP/3 parsing, SSRF, TLS, and memory safety.
Affected scope: Depending on CVE, ATS 8.0 through 8.1.9, 9.0 through 9.2.14, and 10.0 through 10.1.3.
Fixed release: ATS 9.2.15 or 10.1.4.
Severity: CISA bulletin scores up to CVSS 10.0; Apache’s release notice uses Important or Moderate ratings.
Status: AMBER; no exploitation reported in reviewed advisories.
Broadcom VMware
Issue: CVE-2026-59309 and CVE-2026-59310 vCenter flaws; CVE-2026-47876 ESX VMXNET3 out-of-bounds write.
Affected scope: Listed vCenter, ESX, Cloud Foundation, vSphere Foundation, and telco-cloud release trains.
Fixed release: vCenter 9.1.0.0300, 9.0.2.0100, 8.0 U3k or U2f; ESXi80U3k-25595708 and ESXi80U2f-25626445 for the ESX issue.
Severity: CVSS 9.8, 9.8, and 9.3 respectively.
Status: AMBER; private disclosure and no active exploitation reported by Broadcom.
Zbtlink routers
Issue: CVE-2026-66747 embedded ENDLESSDOORS root-level remote-control implant.
Affected scope: Approximately 21 firmware images across 20 models sold under ZBT, ZBTWiFi, Wiflyer, and unbranded labels.
Fixed release: None published by cutoff.
Severity: CVSS v4 9.3, Critical.
Status: AMBER; device-trust compromise demonstrated, external exploitation and attribution unconfirmed.
Outlook and Uncertainty
Next 24 hours
Expect additional exploitation reporting, vendor hotfix clarifications, and emergency remediation activity around TeamCity, N-central, VeloCloud Orchestrator, and the two August 7 KEV deadlines. Monitor whether Cisco IMC proof-of-concept material becomes operational exploitation, whether Zbtlink publishes a trustworthy replacement path, and whether N-able releases further detection or victim-scope details.
What is not known
Public reporting does not establish victim counts, persistence, or attribution for most management-plane vulnerabilities. N-central’s downstream customer impact, TeamCity’s compromised build artifacts, Tomcat exploitation mechanics, Apache Traffic Server exploitation, and Zbtlink distribution remain incompletely documented. Absence of published indicators is not evidence of absence of compromise.
Trigger for escalation
Move AMBER items to RED when a trusted source confirms active exploitation, internet-facing compromise, or downstream service impact. Escalate any TeamCity, N-central, VCO, FMC, SonicWall, or Langflow finding when privileged credentials, build artifacts, managed-device state, customer end points, or OT logic may have been accessed or changed. Treat PLC project-file integrity failure as an operational incident even without a named actor.
Jonathan Brown is a cybersecurity researcher and investigative journalist at bordercybergroup.com.
If you would like to support our work — useful, well-researched, ad-free cybersecurity intelligence — subscribe, comment, or buy us a coffee! Thanks.
Member discussion: