CVE Tools

Security news, decoded.

What happened, who is affected, and what to do next. Every story is linked to CVEs and enriched with product, exploitation, and patch context.

RSS
Latest signal The Hacker News Research Gemini CLI ai-ml Claude Code

Claude Code and Gemini CLI Flaws Let a GitHub Issue Reach CI Workflow Secrets

Read full story

Researchers discovered severe vulnerabilities in AI-powered coding agents from Google, Anthropic, and OpenAI, allowing attackers to extract sensitive secrets from continuous integration (CI) workflows using a simple GitHub issue. The flaws were demonstrated during an attack that exploited default configurations of each vendor's tools, leading to the disclosure of two CVEs. CVE-2026-12537, affecting Gemini CLI, enables remote code execution on CI runners with a CVSS score of 10.0 and is fixed in version 0.39.1. CVE-2026-54316 in Claude Code leaks API keys through a public download counter, rated as Moderate by Anthropic but high at 9.1 by NVD, and resolved in 2.1.163. Neither Codex nor its associated findings received a specific patch or CVE, though OpenAI updated its documentation and workflows. Users are advised to apply updates and review their CI processes for potential exposure.

Earlier39 stories
Aug 7
Help Net Security6 min read

August 2026 Patch Tuesday forecast: How do we deal with the patch apocalypse?

Microsoft's July 2026 Patch Tuesday marked a record with more than 600 CVEs across nearly all its products, including Windows, SharePoint, and Office. Despite the massive volume, only three of these vulnerabilities were reported as either exploited or publicly disclosed. The rise in vulnerability discovery driven by AI is reshaping how organizations approach patch management. Experts emphasize the importance of prioritizing critical risks—such as internet-facing or known-exploited flaws—rather than applying every patch indiscriminately. A notable issue highlighted was the actively exploited SharePoint remote code execution vulnerability (CVE-2026-50522), which attackers use to maintain access post-patching. As August Patch Tuesday approaches, expect another large batch of fixes, especially as AI continues to accelerate threat detection.

Aug 6
Patchstack Patch WordPress patch-tuesday6 min read

WordPress 7.0.3 Released: 12 Vulnerabilities Found and Fixed

On August 6, 2026, WordPress released version 7.0.3 to address 12 security issues ranging from reflected and stored cross-site scripting (XSS) to privilege escalation, server-side request forgery (SSRF), and more. Among the notable fixes is a high-risk unauthenticated XSS flaw that could lead to remote code execution if triggered by an administrator clicking a malicious link. Other vulnerabilities include several stored XSS risks requiring contributor-level access, as well as a privilege escalation issue affecting Multisite setups. Patchstack has implemented real-time protections for these critical flaws, but administrators are strongly advised to upgrade to 7.0.3 immediately to ensure full mitigation.

Aug 6
BleepingComputer Exploited Microsoft SharePoint data-breach3 min read

Swiss government SharePoint breach compromised 200 accounts

Hackers successfully breached the Microsoft SharePoint infrastructure of Switzerland's Federal Office for Information Technology and Telecommunication (BIT), compromising approximately 200 user accounts. Security specialists detected unusual activity on July 28, leading to the isolation of external network access to the servers. The incident appears linked to vulnerabilities addressed during the July 2026 Patch Tuesday cycle, specifically potentially involving CVE-2026-56164 or CVE-2026-50522. While BIT has reset affected credentials and is reinstalling the servers with support from Microsoft and national cyber security authorities, no group has yet claimed responsibility for the intrusion.

Aug 6
The Hacker News PoC Linux KVM privilege-escalation5 min read

New Zapscape KVM Flaw Could Let Privileged L1 Guest Code Escape to Linux Hosts

A newly disclosed vulnerability in the Linux Kernel Virtual Machine (KVM) could enable an attacker with elevated privileges within a Level 1 (L1) guest VM to break out of the virtual environment and execute arbitrary code on the underlying host system. The flaw, identified as CVE-2026-64561, stems from a stale-root check ordering issue in KVM's shadow memory management unit (MMU), potentially leading to a use-after-free condition. Security researcher Hyunwoo Kim revealed a proof-of-concept demonstrating how this flaw can be leveraged to create a file on the host system. The vulnerability specifically impacts systems where nested virtualization is enabled and exposed to untrusted guests. A patch has been merged into the upstream Linux kernel and is recommended for all administrators using such configurations. Affected versions include multiple stable releases up to 7.2-rc5.

Aug 6
The Hacker News Advisory Cisco Catalyst SD-WAN Software rce5 min read

Cisco Patches 12 SD-WAN and IOS XE Flaws, Including Three 9.8 CVSS Score Bugs

Cisco has issued security updates to fix 12 high-risk vulnerabilities affecting its Catalyst SD-WAN and IOS XE Software. These include three flaws rated 9.8 on the CVSS scale. The issues stem from internal testing and AI-assisted discovery and are not yet known to be exploited. Affected users are advised to upgrade their software to the latest patched versions to prevent potential attacks.

Aug 6
The Hacker News Research Intel CPUs ics-ot-iot6 min read

New Interrupt Injection Attack Can Bypass Spectre v2 Defenses on Intel and AMD CPUs

A novel attack dubbed INTERRUPT INJECTION has been revealed to bypass existing Spectre v2 defenses in Intel and AMD CPUs. This technique allows an unprivileged Linux program to manipulate hardware interrupts during the time window between branch predictor sanitization and its reuse, enabling potential data leaks such as reading sensitive files like /etc/shadow. The method was successfully demonstrated on AMD Zen 2 processors running Linux 6.14 with all default Spectre v2 mitigations enabled. Researchers from MIT CSAIL disclosed the vulnerability to AMD and Intel in February 2026, prompting AMD to release a kernel-level fix. While a patch exists within the Linux kernel, it lacks a CVE identifier or specific version reference, requiring administrators to verify individual systems for the fix. Intel claims mitigation is unnecessary at this stage.

Aug 6
The Hacker News Roundup npm packages SideWinder26 min read

ThreatsDay: Odysseus RCE, Samsung One-Click Takeover, iCloud Backdoor Fight + 27 More Stories

This week's ThreatsDay highlights include a new remote code execution vulnerability in the Odysseus AI workspace and a set of critical flaws in Samsung devices that could lead to full system compromise with a single click. The vulnerabilities (CVE-2025-21079 and CVE-2025-58486) stem from design oversights in Samsung’s Bixby virtual assistant, enabling attackers to exploit auto-granted Android permissions for privilege escalation. Meanwhile, SideWinder has adopted a new multi-stage attack chain using ClickOnce application files delivered via phishing PDFs, and an npm supply chain campaign dubbed "Flooding Dropper" has distributed over 800 malicious packages. These developments underscore the growing complexity and accessibility of cyberattacks, particularly those leveraging trusted tools and automation.

Aug 6
Help Net Security Research ai-ml7 min read

Three in four AI-generated vulnerability patches leave something broken

Off-by-1 Labs, a security research group within 1Password, published findings indicating that approximately 75% of vulnerability patches generated by frontier large language models contain significant defects. The study evaluated over 6,000 attempts to fix six specific vulnerabilities, including the Linux kernel privilege escalation CVE-2026-31431 and the Chromium bug CVE-2026-8512, using models such as ChatGPT 5.5 and Claude Opus 4.8. A key finding is that while many AI-generated fixes successfully close the original exploit path, they frequently introduce new security weaknesses or break existing functionality without triggering test failures. Researchers concluded that these automated patches require rigorous review by skilled engineers, as distinguishing a valid fix from a convincing but incorrect one is difficult and costly.

Aug 6
The Hacker News Exploited MicroLogix 1400 ics-ot-iot5 min read

Over 4,400 Rockwell PLCs Exposed Online, 22 Found in Water Attack Cities

Malicious cyber actors are actively targeting exposed Rockwell Automation Programmable Logic Controllers, with Forescout identifying 22 units located in US cities recently affected by water utility cyberattacks. These attackers altered IP addresses and set passwords on the controllers, causing operational disruptions without necessarily exploiting specific vulnerabilities. Of these targeted devices, 19 run firmware vulnerable to CVE-2017-16740, a Modbus TCP buffer overflow affecting MicroLogix 1400 Series B and C. A broader scan revealed over 4,400 such controllers accessible from the public internet worldwide.

Aug 6
SecurityWeek Advisory Paperclip auth-bypass3 min read

Critical Paperclip Flaw Allowed Admin Access, Code Execution

Oasis Security has disclosed a critical authorization bypass in the Paperclip AI management platform, tracked as CVE-2026-41679 with a perfect CVSS score of 10. The vulnerability enabled remote attackers to register accounts without email verification and self-approve CLI challenges to gain board-level API access. By exploiting a gap in the company import process, attackers could upload crafted YAML files that executed arbitrary commands with the privileges of the Paperclip server process. The vendor has released a fix that applies strict authorization checks to import flows and tightens company scoping, also addressing related issues involving data disclosure and DNS rebinding.

Aug 6
Help Net Security PoC Integrated Management Controller (IMC) rce5 min read

Critical Cisco IMC bug gives attackers root, PoC is out (CVE-2026-20200)

Cisco has issued a patch for a critical vulnerability, CVE-2026-20200, in its Integrated Management Controller (IMC), which enables authenticated remote attackers with low privileges to execute arbitrary commands as the root user. A proof-of-concept exploit named CIMCown is currently available on GitHub, confirming the immediate risk posed by this input validation flaw. Affected systems include Cisco UCS C-Series M7 and M8 Rack Servers and various preconfigured Cisco appliances; administrators are advised to apply updates immediately. Since no workarounds exist besides disabling the web interface, securing management networks and isolating IMC from public exposure are critical mitigation steps.

Aug 6
OX Security Advisory Apache Zeppelin web-app5 min read

CVE-2026-44613: Turning a CSRF into Silent Unauthorized Actions

OX Security researchers have disclosed a Cross-Site Request Forgery (CSRF) vulnerability affecting Apache Zeppelin, tracked as CVE-2026-44613. The flaw stems from a permissive default CORS configuration that accepted cross-origin, credentialed requests, alongside certain endpoints accepting plain-text bodies that bypassed standard preflight checks. This combination allowed attackers to execute silent, unauthorized administrative actions against an authenticated user’s session simply by directing them to a malicious webpage. Apache has released version 0.12.1 to mitigate the issue, which restricts the allowed origins list by default and enforces strict content-type headers.

Aug 6
The Hacker News Research Bedrock AgentCore ai-ml10 min read

AWS, Google, and Vercel Agent Flaws Let Attackers Trigger Tools Without Running the Model

Researchers disclosed authorization flaws in AWS Bedrock AgentCore, Google's Agent Development Kit, and Vercel's AI SDK that allowed unauthorized tool execution by bypassing model-level checks. In several scenarios, the underlying language models never processed the input, rendering standard safety guardrails ineffective. All three vendors have deployed fixes; users should update to ADK 2.5.0, @ai-sdk/harness-codex 1.0.29, and @ai-sdk/harness-opencode 1.0.28 to mitigate risks associated with CVE-2026-18830, CVE-2026-18236, CVE-2026-64650, and CVE-2026-64651.

Aug 6
SecurityWeek Patch SD-WAN rce2 min read

Cisco Patches Critical SD-WAN, IOS XE, FMC Vulnerabilities

Cisco has released updates addressing approximately two dozen security vulnerabilities across its product portfolio, including critical defects in Catalyst SD-WAN, IOS XE, and the Secure Firewall Management Center (FMC). Among the highest-risk issues is CVE-2026-20079 in FMC, a CVSS 10 authentication bypass that permits unauthenticated remote attackers to gain root privileges via crafted HTTP requests. The release also covers other severe bugs such as CVE-2026-20303, CVE-2026-20304, and CVE-2026-20310 in SD-WAN, along with command injection vulnerabilities like CVE-2026-20272 in IOS XE. While Cisco reports no evidence of active exploitation in the wild, administrators should apply these fixes promptly to mitigate potential compromise.

Aug 6
The Hacker News Exploited TeamCity rce3 min read

CISA Flags TeamCity CVE-2026-63077 RCE Flaw Under Active Exploitation in the Wild

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical remote code execution vulnerability, CVE-2026-63077, to its Known Exploited Vulnerabilities catalog, confirming active exploitation in the wild. This flaw affects on-premise versions of JetBrains TeamCity and stems from the improper deserialization of untrusted data within the agent polling protocol. Attackers can exploit this to bypass authentication and execute arbitrary OS commands with server-level privileges. Organizations should apply available patches promptly, with federal civilian executive branch agencies required to mitigate the issue by August 8, 2026.

Aug 6
SecurityWeek Exploited TeamCity rce2 min read

Hackers Start Exploiting Recent JetBrains TeamCity Vulnerability

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued an alert confirming that threat actors have begun actively exploiting a recent vulnerability in JetBrains TeamCity. This critical flaw, identified as CVE-2026-63077 with a CVSS score of 9.8, allows unauthenticated attackers to achieve remote code execution by bypassing authentication through the agent polling protocol. The issue affects all TeamCity On-Premises versions and stems from the improper deserialization of untrusted data over HTTP/S. While JetBrains released fixes in versions 2025.11.7 and 2026.1.3 (along with a security plugin for older builds) prior to reporting this active exploitation, CISA has now listed the vulnerability in its Known Exploited Vulnerabilities catalog, mandating federal agencies to apply patches within three days.

Aug 5
Ars Technica (Security) Research Baseboard Management Controllers (BMCs) ics-ot-iot7 min read

Thousands of servers can be backdoored by exploiting buggy motherboard controllers

Critical vulnerabilities have been identified in baseboard management controllers (BMCs) from top server manufacturers like HPE, Supermicro, Avocent, Huawei, Lenovo, and Dell. These flaws could allow remote attackers to backdoor thousands of servers by exploiting long-standing issues in BMC firmware. Researchers found that many of these problems, including some dating back over a decade, remain unaddressed despite prior warnings. The vulnerabilities span authentication bypasses, predictable session tokens, and weak encryption enforcement, among others. Some require initial access but can be chained together to achieve full control. With over 86,000 Internet-connected BMCs exposed and more than half containing critical flaws, the situation highlights a widespread and under-protected attack surface.

Aug 5
SecurityWeek Research Samsung Galaxy S25, S24, Flip 7 mobile4 min read

How a $50,000 Exploit Chain Turned Bixby Against Samsung Phones

Two security researchers uncovered a series of vulnerabilities in Samsung software, including the virtual assistant Bixby, that could be exploited to remotely take control of Samsung Galaxy smartphones. At the Pwn2Own Ireland competition in October 2025, Dimitrios Valsamaras and Ken Gannon demonstrated how these flaws were chained together to compromise a Galaxy S25 device, earning them $50,000. Their full findings were later presented at the Black Hat conference. The exploit begins with a phishing-style attack through a malicious link sent via ads or messaging apps, leading to remote code execution and system-level access. Affected products include the Galaxy S25, S24, and Flip 7. Samsung issued patches in November and December 2025 to address the issues.

Aug 5
Help Net Security Research Bonita BPM web-app5 min read

Pre-auth RCE in enterprise Java hits Bonita and OFBiz servers

Researchers uncovered a critical pre-authentication remote code execution (RCE) vulnerability affecting enterprise Java platforms, including Bonita BPM and Apache OFBiz. The flaw, tracked as CVE-2026-31986, allows attackers to send unauthenticated HTTP requests that bypass multiple security layers and execute arbitrary code on the server. This affects systems used by banks, insurers, and governments for workflow automation. Attackers exploit misconfigured API routing, insecure deserialization in XStream, and predictable signing keys to gain full control without authentication. Both vendors have issued patches within the standard disclosure timeline. Users should upgrade immediately to avoid potential exploitation.

Aug 5
BleepingComputer Exploited Langflow ai-ml3 min read

CISA warns of hackers exploiting Langflow, N-central, Apache Tomcat flaws

Federal agencies have until July 7 to address three actively exploited vulnerabilities in IBM Langflow, N-central, and Apache Tomcat, as highlighted by CISA. The most severe flaw, CVE-2026-9198 in IBM's Langflow, enables unauthenticated remote code execution with a CVSS score of 9.8. A related vulnerability, CVE-2026-0770, also allows RCE with root privileges and has already seen public PoCs. Meanwhile, a patched but re-exploitable flaw in N-central (CVE-2026-18576) permits unauthorized account takeover, while Apache Tomcat faces an incomplete fix for another issue (CVE-2026-34486). All three vulnerabilities have been added to CISA’s Known Exploited Vulnerabilities list.

Aug 5
The Hacker News PoC Paperclip AI ai-ml9 min read

Paperclip AI Flaws Let Attackers Run Host Commands via Malicious Agent Imports

Three serious vulnerabilities in the open-source Paperclip AI control plane could allow attackers to run arbitrary commands on a host system or expose sensitive data. The most severe flaw, CVE-2026-41679 (CVSS 10.0), allows unauthenticated attackers to execute commands remotely without prior access. Another vulnerability, GHSA-x8hx-rhr2-9rf7 (CVSS 9.6), exploits default local configurations to launch attacks via DNS rebinding. A third issue involves improperly secured API routes that leak internal details. Paperclip has released a patch in version v2026.416.0, though some advisories still lack full version alignment. Users are urged to upgrade immediately.

Aug 5
The Hacker News Patch Veeam Service Provider Console cloud8 min read

Veeam, Terraform MCP, Django Patch Critical Flaws, Led by CVSS 10.0 Cross-Tenant Bug

Vendors Veeam, HashiCorp, and the Django Software Foundation have issued patches for 11 critical vulnerabilities across their products. Among these, a high-risk cross-tenant issue in HashiCorp’s Terraform MCP Server received a maximum CVSS score of 10.0. Other notable flaws include an unauthenticated credential-extraction bug in Veeam Service Provider Console (CVE-2026-58073, CVSS 9.5) and a potentially exploitable file-write vulnerability in GeoDjango. All affected products—Terraform MCP Server, Veeam Service Provider Console, and Django—have available updates to resolve these issues. Operators are advised to apply the latest versions to prevent potential misuse.

Aug 5
The Hacker News PoC Open vSwitch ics-ot-iot6 min read

New OVSwrap Linux Kernel Flaw Lets Local Users Gain Root via Open vSwitch

A new privilege escalation vulnerability affecting the Linux kernel's Open vSwitch component allows unprivileged local users to gain root access on many distributions. The flaw, named OVSwrap and assigned CVE-2026-64531, was disclosed by researcher Asim Manizada on July 28, 2026. A working proof-of-concept is now publicly available for around 800 kernel builds. The issue resides in the kernel datapath of Open vSwitch and enables attackers to exploit a memory corruption bug without needing an active OVS bridge or administrative privileges. A patch has been included upstream since July 24, but distribution-specific updates may vary. Systems using Open vSwitch should either apply vendor patches or block the module from loading until fixes are available.

Aug 5
The Hacker News Patch Gitea web-app4 min read

Critical Gitea Flaw Let Unauthenticated Attackers Read Server Files via Org-Mode Markup

Unauthenticated attackers could read arbitrary files accessible by the Gitea service account in versions 1.22.1 through 1.27.0 of the self-hosted Git platform. This vulnerability, tracked as CVE-2026-59774, allows access using a public repository and maliciously crafted Org-mode markup without requiring login or write permissions. The flaw has been resolved in Gitea version 1.27.1. The vulnerability poses a high risk due to its critical CVSS score of 9.8 and potential escalation to remote code execution under certain conditions. Gitea recommends immediate upgrades for self-hosted users, while cloud instances will be updated automatically during scheduled maintenance.

Aug 5
The Hacker News Incident n8n Automation Platform15 min read

Leaked n8n API Tokens Exposed Live Instances to Credential Theft

GitGuardian discovered 321 active n8n instances that accepted leaked API tokens from public GitHub commits. These tokens granted access to workflow definitions, execution logs, and stored credentials—without needing to exploit a software vulnerability. The affected versions of n8n Automation Platform were used in cloud and self-hosted setups, with some instances running known unpatched CVEs like CVE-2025-68613. Attackers could leverage these tokens to enumerate users, extract secrets, or even exfiltrate live credentials via crafted workflows. The findings highlight the risks of misconfigured automation platforms and underscore the importance of revoking exposed tokens and monitoring for credential leaks.

Aug 5
SecurityWeek Exploited Langflow web-app3 min read

CISA Warns of Exploited Langflow, N-central, and Tomcat Vulnerabilities

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning that cybercriminals are actively exploiting three critical vulnerabilities impacting IBM Langflow OSS, N-able N-central, and Apache Tomcat. These flaws—CVE-2026-9198, CVE-2026-18556, and CVE-2026-34486—are being used to achieve remote code execution and unauthorized administrative access, with some already tied to real-world attacks. CISA urges organizations to apply available patches immediately ahead of its August 7 deadline.

Aug 5
Help Net Security Research TP-Link Omada rce5 min read

15 TP-Link Omada vulnerabilities let attackers hijack routers and intercept camera traffic

Researchers from Forescout's Vedere Labs discovered 15 critical vulnerabilities in TP-Link's Omada networking products, enabling remote attackers to hijack routers, steal administrative credentials, and create unauthorized VPN tunnels into internal networks. These flaws affect Omada routers, switches, access points, and even devices in four other TP-Link product lines due to shared certificate chains. Most issues have been patched, though four remain without CVE identifiers and two cannot be fixed via firmware updates. Attackers can exploit predictable serial numbers and flawed authentication mechanisms to bypass security controls and compromise devices at scale.

Aug 5
The Hacker News Exploited Langflow knaithe4 min read

CISA Flags Langflow RCE, Tomcat, and N-central Flaws as Actively Exploited

On August 5, 2026, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added three actively exploited vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog. These include a critical remote code execution (RCE) flaw in Langflow (CVE-2026-9198, CVSS 9.8), an encryption bypass in Apache Tomcat (CVE-2026-34486, CVSS 7.5), and an authentication bypass in N-able N-central (CVE-2026-18556, CVSS 8.2). Attackers are exploiting these flaws, with some linked to a Chinese-speaking threat actor using AI-powered tools like Hermes Agent and DeepSeek to automate attacks. Federal agencies have until August 7, 2026, to apply available patches.

Aug 4
BleepingComputer Patch TP-Link Omada rce4 min read

TP-Link patches Omada ZTP flaws allowing hackers to breach networks

TP-Link has addressed 15 critical security flaws in the Zero-Touch Provisioning (ZTP) system of its Omada network devices, which could be exploited to gain remote code execution or hijack devices. Discovered by Forescout’s Vedere Labs, these issues include hardcoded keys, information leaks, and spoofing risks. Attackers could chain them with previously reported vulnerabilities to infiltrate networks. Affected products include Omada controllers, gateways, switches, access points, and mobile apps. Users should update their firmware immediately to mitigate potential breaches.

Aug 4
SANS Internet Storm Center Incident Diagnostic tools ddos-botnet4 min read

Botnet Hunting for Vulnerabilities in Diagnostic Tools

A botnet has been actively scanning for vulnerabilities in diagnostic tools used by various network devices. Multiple URLs linked to these tools were observed being probed, including those tied to known vulnerabilities like CVE-2024-12856 (Four-Faith routers) and others such as CVE-2020-8949 and CVE-2024-48419. These types of tools are particularly prone to command injection flaws due to improper handling of user inputs when invoking system commands. Experts recommend using safer APIs like Python's subprocess.run over direct shell execution methods to mitigate risks.

Aug 4
SecurityWeek Research Omada network-edge3 min read

TP-Link Omada ZTP Vulnerabilities Chain Into Full Network Takeover

Security researchers at Forescout have uncovered 15 critical vulnerabilities in TP-Link’s Omada networking ecosystem, particularly affecting the zero-touch provisioning (ZTP) systems used for automated device setup. These flaws, including hardcoded cryptographic keys, weak certificate validation, and predictable device identifiers, can be combined with previously reported issues (CVE-2025-7850 and CVE-2025-7851) to enable remote code execution and full network infiltration. Attackers could exploit these weaknesses to gain administrative control over cloud controllers and infiltrate internal networks. TP-Link has issued patches for part of the report, but some fixes won’t arrive until late 2026.

Aug 4
Rapid7 Blog Exploited N-central rce4 min read

CVE-2026-18577: N-able N-central Authentication Bypass Exploited in the Wild

A critical authentication bypass flaw in N-able N-central, tracked as CVE-2026-18577, has been actively exploited in real-world attacks since August 1, 2026. This vulnerability affects all versions of the software up to 2026.3.1 and allows attackers to bypass login controls and take full administrative control of affected systems. The flaw was discovered following an incomplete fix for a related vulnerability, CVE-2026-18556. Successful exploitation has led to attackers using N-central’s Take Control feature to access managed endpoints and deploying Cloudflare Tunnel (cloudflared) to maintain persistent access. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added this vulnerability to its Known Exploited Vulnerability (KEV) catalog on August 3, 2026. N-able has released a hotfix—version 2026.3.1 Hotfix 1—to address the issue.

Aug 4
The Hacker News Patch cPanel & WHM privilege-escalation6 min read

New cPanel Critical Flaw Could Let Hosting Customers Run SQL as Database Root

cPanel has addressed a critical vulnerability allowing authenticated users to execute SQL commands in the database root context, potentially leading to full system compromise. Tracked as CVE-2026-58048 (CVSS score 9.4), it impacts all supported versions of cPanel & WHM and WP Squared. Attackers need valid account access and MySQL/MariaDB privileges to exploit this flaw. The fix was included in several updated builds, including 11.110.0.137 and 138.1.6 for WP Squared. Administrators unable to update immediately should temporarily disable MySQL access for cPanel users.

Aug 4
SecurityWeek PoC Baseboard Management Controller (BMC) ics-ot-iot3 min read

Decades-Old BMC Vulnerability Exposes Thousands of Data Centers to Attacks

A long-standing vulnerability in Baseboard Management Controllers (BMC) has been found to leave thousands of data centers vulnerable to attacks. The flaw, identified as CVE-2013-4786, was first introduced in 2004 and affects the IPMI 2.0 authentication protocol. Cybersecurity firm Lava reported that nearly 37,000 server-management interfaces on the internet are currently exposed, with over 24,000 leaking password-derived hashes during the authentication process. This weakness allows attackers to extract and crack passwords offline using GPU tools, enabling unauthorized access to highly privileged control systems.

Aug 4
The Hacker News Exploited N-able N-central supply-chain5 min read

CISA Adds Exploited N-able N-central Flaw to KEV After Customer Compromises

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has listed a critical, actively exploited vulnerability in N-able N-central within its Known Exploited Vulnerabilities catalog. The flaw, CVE-2026-18577 (CVSS score: 8.2), enables remote attackers to bypass authentication and take over accounts. It affects versions prior to 2026.3 HF1. Successful attacks could lead to unauthorized server access and lateral movement into connected systems. N-able has issued a fix, urging administrators to update immediately to prevent potential breaches.

Aug 3
BleepingComputer Exploited N-able N-central supply-chain4 min read

N-able warns of N-central auth bypass flaw exploited in attacks

N-able has issued a warning after confirming that cybercriminals are actively exploiting an authentication bypass vulnerability in N-central, its widely used remote monitoring and management platform. The flaw, tracked as CVE-2026-18577, impacts all versions prior to 2026.3.1.7 and can allow unauthorized access to sensitive systems managed through the tool. A hotfix was released on August 2nd to resolve the issue, and users of on-premises deployments are urged to apply it manually. Hosted versions have already been updated. The vulnerability stems from an incomplete fix for another related flaw, CVE-2026-18576, which also allowed bypassing authentication mechanisms. While no specific details about the scale of exploitation were provided, the company shared indicators of compromise on its status page, including suspicious IP addresses and activity involving Cloudflared. Customers are encouraged to review these indicators and reach out to N-able support if anomalies are detected.

Aug 3
The Hacker News Exploited SonicWall SMA 1000 INC Ransomware4 min read

INC Ransomware Emerges as Dominant Actor Exploiting SonicWall SMA 1000 Flaws

The INC Ransomware group has become the leading threat actor exploiting two critical vulnerabilities in SonicWall Secure Mobile Access (SMA) 1000 series appliances—CVE-2026-15409 and CVE-2026-15410—which allow for arbitrary command execution and device compromise. These zero-day flaws were patched by SonicWall in mid-July 2026 but continue to be actively weaponized, enabling attackers to steal credentials and gain persistent access to networks. Resecurity reported a sharp increase in incidents since early August, with more than 800 victims globally. Organizations are urged to apply patches immediately and conduct thorough network assessments to prevent further breaches.

Aug 3
Rapid7 Blog Advisory Ruby on Rails Active Storage web-app20 min read

Rapid7 Analysis: KindaRails2Shell (CVE-2026-66066)

Rapid7 researchers disclosed a severe vulnerability in Ruby on Rails (CVE-2026-66066) that allows attackers to perform arbitrary file reads and potentially execute code remotely. This flaw affects specific versions of Active Storage when using the Vips image processor with untrusted uploads. Affected versions include < 7.2.3.2, = 8.0 < 8.0.5.1, and = 8.1 < 8.1.3.1. Attackers can exploit this by crafting malicious MATLAB/HDF5 files uploaded via direct endpoints, leading to exposure of sensitive data like secret keys and enabling further attacks such as remote code execution. Rapid7 has developed a Metasploit module demonstrating exploitation. Patches are now available; users should update immediately.

Aug 3
Help Net Security Exploited N-able N-central supply-chain5 min read

Attackers exploit N-able N-central flaw to reach managed endpoints (CVE-2026-18577)

Cybercriminals are actively exploiting an authentication bypass vulnerability (CVE-2026-18577) in N-able N-central, a popular remote monitoring and management tool used by managed service providers. This flaw enables attackers to gain unauthorized access to managed endpoints through compromised admin accounts and establish persistent access using a CloudFlare tunnel. N-able released a hotfix on August 2, 2026, but many users remain unpatched, according to threat intelligence firm Huntress. Organizations using self-hosted N-central servers should apply the fix immediately and inspect systems for signs of compromise.