daily cyber × ai intelligence

index

tagged

[CVE-2026-18577]

3 editions · 3 items

August 6, 2026

  • CISA gave federal agencies three days to fix three actively exploited flaws, including the N-able N-central auth bypasses (CVE-2026-18556, CVE-2026-18577) (earlier coverage), a Langflow unauthenticated RCE (CVE-2026-9198, CVSS 9.8), and an Apache Tomcat flaw (BleepingComputer, The Hacker News). Horizon3 published attack-research validation for the N-central bypasses (Horizon3); the Langflow-based IBM agentic platform is separately reported under active attack (The Register). · Vulnerabilities & Exploits

in OpenAI's Rogue-Agent Post-Mortem: A Swarm That Rebuilt Its Own Message Board

August 4, 2026

  • N-able N-central auth bypass (CVE-2026-18577) is under active exploitation, and the first fix didn't hold. Over the weekend N-able discovered a second authentication-bypass vector that grants attackers administrator access to both hosted and on-prem N-central servers, letting them reach the customer systems those servers manage; build 2026.3.1.7 (shipped Aug 2) is the first unaffected version (The Hacker News, BleepingComputer). Huntress has published exploitation details and detection guidance (Huntress). Continues our earlier coverage. · Vulnerabilities & Exploits

in Attackers Seize N-central RMM Servers After N-able's Second Fix Falls Short