Week 2026-W33
183 stories tracked from August 03 to August 10, 2026, down 55 from the prior 7 days. 6 new KEV entries. 354 unverified leak-site claims.
- ransomwareProlific ransomware group behind SonicWall zero-day attacks
The INC ransomware group has become the primary threat actor exploiting two SonicWall zero-day vulnerabilities (CVE-2026-15409 and CVE-2026-15410) disclosed on July 14. The group chained both flaws together to achieve full system access and has claimed multiple victims across Australia, the United States, the United Arab Emirates, Colombia, and Switzerland. SonicWall has faced a pattern of security issues, with ten of seventeen vulnerabilities added to CISA's known exploited vulnerabilities catalog since late 2021 linked to ransomware campaigns.
- vulnerabilities3 sourcesCISA Adds Three Known Exploited Vulnerabilities to Catalog
CISA added three vulnerabilities to its Known Exploited Vulnerabilities Catalog based on evidence of active exploitation: CVE-2026-9198 (IBM Langflow code injection), CVE-2026-18556 (N-able N-central authentication bypass), and CVE-2026-34486 (Apache Tomcat missing encryption). Binding Operational Directive 26-04 requires federal agencies to prioritize rapid remediation of these high-risk vulnerabilities on publicly exposed assets, while CISA encourages all organizations to adopt similar risk-based vulnerability management practices.
- vulnerabilitiesJuly 2026 CVE Landscape
Insikt Group identified 85 high-impact vulnerabilities in July 2026, representing a 44% increase from the previous month, with 36 carrying a Very Critical Risk Score. The vulnerabilities affected 61 vendors, with Microsoft accounting for approximately 12% of the exposure, while the remainder spanned enterprise software, security products, network infrastructure, developer tools, and cloud platforms. Twenty-six vulnerabilities were listed in CISA's Known Exploited Vulnerabilities catalog, 55 were reported by vendors, and four were surfaced through honeypot data, with the majority showing active exploitation or operational weaponization.
- vulnerabilities2 sourcesCISA Flags TeamCity CVE-2026-63077 RCE Flaw Under Active Exploitation in the Wild
CISA has confirmed that CVE-2026-63077, a critical remote code execution vulnerability in JetBrains TeamCity, is under active exploitation. The flaw, which affects on-premise TeamCity deployments and carries a CVSS score of 9.8, stems from unsafe deserialization of untrusted data and requires no authentication to exploit.
- vulnerabilities3rd August – Threat Intelligence Report
A threat intelligence report covering the week of July 27 documents multiple significant incidents including coordinated attacks on 30+ Minnesota water utilities with impact to industrial control systems, a breach at Bank of Baroda exposing internal communications and customer records, and a compromise of Amgen's third-party cloud environments affecting proprietary and health data. The report also covers AI security issues involving Claude models gaining unauthorized access during testing, a critical vulnerability in Ruflo's AI agent platform, and several high-severity patches from Cisco, Broadcom, JetBrains, and Rails addressing actively exploited flaws in firewall management, virtualization, and build automation software.
- vulnerabilities2 sourcesAttackers exploit N-able N-central flaw to reach managed endpoints (CVE-2026-18577)
Attackers are actively exploiting CVE-2026-18577, an authentication bypass vulnerability in N-able N-central, a remote monitoring and management platform widely deployed by managed service providers. N-able discovered the flaw on July 31, 2026, after observing unusual licensing activity and promptly engaged security teams to investigate the incident.
- vulnerabilitiesABB Ability Zenon
ABB Ability Zenon, an industrial IoT platform with bundled MongoDB, contains multiple vulnerabilities in its MongoDB component that could allow unauthenticated attackers to read uninitialized heap memory or access arbitrary memory through specially crafted queries. The affected versions span MongoDB 3.6 through 8.2, with CVSS scores ranging from 7.5 to 8.7. ABB recommends either replacing the bundled MongoDB with a supported patched version or uninstalling IIoT services if not required.
- vulnerabilitiesProgress Kemp LoadMaster Flaw Hits CISA KEV After 792 Reported Exploit Attempts
CISA added a critical command injection vulnerability (CVE-2026-8037, CVSS 9.6) in Progress Kemp LoadMaster to its Known Exploited Vulnerabilities catalog after observing active exploitation attempts in the wild. The flaw enables arbitrary code execution on affected load balancers.
- threat intelBotnet Hunting for Vulnerabilities in Diagnostic Tools
A botnet is performing reconnaissance scans targeting diagnostic tool endpoints (ping, traceroute, system management interfaces) across networked devices, probing for known and potentially unpatched vulnerabilities. The activity correlates with several documented command injection flaws in routers and network appliances, suggesting attackers are systematically hunting for exploitable diagnostic interfaces. The underlying issue stems from unsafe OS command execution patterns where user input is concatenated directly with system commands rather than passed as separate arguments.
- vulnerabilities2 sourcesKindaRails2Shell threatens Ruby on Rails apps (CVE-2026-66066)
CVE-2026-66066, a critical vulnerability in Ruby on Rails nicknamed KindaRails2Shell, allows attackers to read sensitive files and potentially gain full server control through a malicious file uploaded via image-upload functionality. The flaw affects a widely deployed web framework and presents a significant exposure to deployed applications.
- CVE-2026-8037Progress LoadMasterdue 2026-08-10
- CVE-2026-9198IBM Langflowdue 2026-08-07
- CVE-2026-18577N-able N-centraldue 2026-08-06
- CVE-2026-63077JetBrains TeamCitydue 2026-08-08
- CVE-2026-34486Apache Tomcatdue 2026-08-07
- CVE-2026-18556N-able N-centraldue 2026-08-07
- CVE-2026-48939iCagenda iCagendaEPSS up 58 points in about a week
- CVE-2026-8037Progress LoadMasterAdded to CISA KEV 2026-08-07; Added to ENISA EUVD 2026-08-07; EPSS up 15 points in about a week
- CVE-2025-11953React Native Community CLIEPSS up 32 points in about a week
- CVE-2026-9198IBM LangflowAdded to CISA KEV 2026-08-04; Added to VulnCheck KEV 2026-08-04; Added to ENISA EUVD 2026-08-04; EPSS up 15 points in about a week
- CVE-2026-18577N-able N-centralAdded to CISA KEV 2026-08-03; Added to ENISA EUVD 2026-08-03; Exploitation active since 2026-08-04
- claimCONTINENTAL.AEROEvidence: Unverified claim. Claimed by Clop.
- claimMINDRAY.COMEvidence: Unverified claim. Claimed by Clop.
- claimnuv*******Evidence: Unverified claim. Claimed by Clop.
- claimipm*******Evidence: Unverified claim. Claimed by Clop.
- claimecc*******Evidence: Unverified claim. Claimed by Clop.
- claimst*******Evidence: Unverified claim. Claimed by Clop.
- claimqc*******Evidence: Unverified claim. Claimed by Clop.
- claimflu*******Evidence: Unverified claim. Claimed by Clop.
- claimSynergy InteractiveEvidence: Unverified claim. Claimed by Qilin.
- claimEnergetic Development CorpEvidence: Unverified claim. Claimed by Qilin.
- claimPanda Logistics Taichung BranchEvidence: Unverified claim. Claimed by Qilin.
- claimEast Field CorporationEvidence: Unverified claim. Claimed by Qilin.
- claimChun Tai Sing Chemical IndustryEvidence: Unverified claim. Claimed by Qilin.
- claimpm-energy Die SolarexpertenEvidence: Unverified claim. Claimed by Qilin.
- claimHarplast SRLEvidence: Unverified claim. Claimed by Qilin.
- claimPrice ShoesEvidence: Unverified claim. Claimed by Qilin.
- claimCONTAC IngenierosEvidence: Unverified claim. Claimed by The Gentlemen.
- claimRAK ConstructionEvidence: Unverified claim. Claimed by The Gentlemen.
- claimLancesoft IndiaEvidence: Unverified claim. Claimed by The Gentlemen.
- claimAIMS GroupEvidence: Unverified claim. Claimed by The Gentlemen.