Tuesday, August 11, 2026 | Jonathan Brown

Attackers continue to exploit N-central after a second authentication-bypass fix

N-able’s N-central remote-management platform remains under active exploitation through CVE-2026-18556 and CVE-2026-18577. Both vulnerabilities have been added to CISA’s Known Exploited Vulnerabilities catalog. N-able issued follow-on remediation after its earlier response proved incomplete, making the current vendor update essential for self-hosted operators.

The more important risk is downstream reach. Sophos reported post-compromise activity that included new administrative accounts, password changes, reconnaissance, and remote-management tooling. An RMM server can administer many managed customer environments, so operators should apply N-able’s latest guidance, investigate activity before remediation, and treat unexpected Take Control sessions, new administrator accounts, and tunnel software as potential incident evidence.

Watch for: A further vendor update or evidence of broader compromise across managed customer environments.

Sources: CISA, “Known Exploited Vulnerabilities Catalog,” August 2026; N-able, “N-central Release Notes,” August 2026; Sophos, “N-able N-central Exploitation Results in RMM Tool Deployment,” August 4, 2026.

Apache Tomcat cluster deployments face an actively exploited encryption-control bypass

CISA lists CVE-2026-34486, an Apache Tomcat issue involving the EncryptInterceptor component used in clustered Tribes deployments, as known exploited. Apache’s advisory identifies the affected releases as 11.0.20, 10.1.53, and 9.0.116. Ordinary standalone Tomcat installations do not automatically share the same exposure because the vulnerable condition depends on the clustering feature and configuration.

The flaw is significant because it weakens the protection expected around cluster communication and may expose cluster members to more serious consequences under vulnerable configurations. Operators should determine whether Tomcat clustering and EncryptInterceptor are enabled, patch according to Apache’s current advisory, restrict cluster-receiver exposure, and review cluster traffic and logs for unexpected peers or authentication failures. Public reporting has not established the scale of exploitation or a confirmed actor.

Watch for: A technical report connecting exploitation to a named intrusion set or identifying the configuration most commonly abused.

Sources: CISA, “Known Exploited Vulnerabilities Catalog,” August 2026; Apache Tomcat, “Security Advisories,” August 2026; Corgea, “CVE-2026-34486: Apache Tomcat EncryptInterceptor KEV,” August 2026.

Active exploitation turns TeamCity build servers into a software-supply-chain priority

JetBrains TeamCity On-Premises is affected by CVE-2026-63077, an unauthenticated remote-code-execution vulnerability in the agent-polling protocol. CISA added the issue to its Known Exploited Vulnerabilities catalog, and JetBrains has reported active and attempted exploitation. Public reporting has not established a victim count or named an actor.

A build server can hold deployment credentials, signing keys, build configurations, and artifacts trusted by customers. That makes it a higher-priority recovery problem than a typical application server. Organisations should apply JetBrains’ current update or supported security patch, examine the server for unexpected agents and administrative activity, rotate secrets stored in TeamCity, and review recent build outputs before relying on them.

Watch for: Confirmed tampering with build artifacts or a disclosure that links the flaw to a software-supply-chain compromise.

Sources: CISA, “Known Exploited Vulnerabilities Catalog,” August 2026; JetBrains, “CVE-2026-63077: Critical Security Issue in TeamCity,” July 27, 2026; Rapid7, “Unauthenticated RCE in JetBrains TeamCity: CVE-2026-63077,” August 2026.

LoadMaster command injection has become an urgent edge-appliance exposure

CISA added CVE-2026-8037 in Progress LoadMaster to the Known Exploited Vulnerabilities catalog after reports of active exploitation. The vulnerability is an unauthenticated command-injection issue in the appliance management API. Available reporting does not consistently state the final fixed-build matrix, but the product, CVE, active exploitation status, and need for immediate remediation are clear.

LoadMaster commonly terminates TLS and fronts business-critical applications, so a compromise could expose both the appliance and the services behind it. Organisations should apply current Progress remediation, remove management interfaces from public reach, and investigate the appliance for unusual outbound traffic and unexpected command execution. A completed patch should not be treated as evidence that a previously exposed appliance was not accessed.

Watch for: A Progress update clarifying exploitation scope, affected sectors, or the final fixed-release matrix.

Sources: CISA, “Known Exploited Vulnerabilities Catalog,” August 2026; Progress, “LoadMaster Critical Security Bulletin: CVE-2026-8037 and CVE-2026-33691,” June 2026; Canadian Centre for Cyber Security, “Progress Security Advisory AV26-552,” August 2026.

IBM Langflow’s code-injection flaw joins the exploited-vulnerability list

CISA added CVE-2026-9198 in IBM Langflow OSS to the Known Exploited Vulnerabilities catalog. Available reporting identifies Langflow OSS versions 1.0.0 through 1.10.0 as affected, and the KEV listing confirms exploitation. Public reporting describes an unauthenticated code-injection path that can lead to elevated application access and arbitrary code execution in vulnerable deployments.

Langflow is especially relevant to organisations connecting artificial-intelligence workflows to data stores, APIs, and internal tools. A compromised orchestration service can inherit the authority of every connector it holds. Operators should patch or isolate exposed deployments, review application logs for suspicious unauthenticated API activity and token creation, rotate secrets reachable from the service, and reduce connector permissions to the minimum required.

Watch for: IBM confirmation of the final fixed version, exploitation details, or evidence of access to connected enterprise systems.

Sources: CISA, “Known Exploited Vulnerabilities Catalog,” August 2026; IBM Security Bulletin for CVE-2026-9198, July 2, 2026; Security Affairs, “U.S. CISA Adds Langflow, Apache Tomcat and N-able N-central Flaws to Its Known Exploited Vulnerabilities Catalog,” August 4, 2026.


Jonathan Brown is a cybersecurity researcher and investigative journalist at bordercybergroup.com.

If you would like to support our work — useful, well-researched, ad-free cybersecurity intelligence — subscribe, comment, or buy us a coffee! Thanks.