【Vulnerability Alert】CISA Added 6 Known Exploited Vulnerabilities to the KEV Catalog (2026/08/03-2026/08/09)

publish date : 2026-08-21 update date : 2026-08-21

Source: Ministry of education information & communication security contingency platform

"" "" ""

Publication Number TACERT-ANA-2026081310080404 Publication Time 2026-08-13 10:08:05
Incident Type ANA-Vulnerability Alert Discovery Time 2026-08-13 10:08:05
Impact Level Low  
[Subject]
【Vulnerability Alert】CISA Added 6 Known Exploited Vulnerabilities to the KEV Catalog (2026/08/03-2026/08/09)
[Content]

Forwarded from TWCERTCC Cybersecurity Alert TWCERTCC-200-202608-00000009

【CVE-2026-18556】N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability (CVSS v4.0: 8.2)
【Whether exploited by ransomware: Unknown】N-able N-central contains an authentication bypass vulnerability. An attacker may use an alternate path or channel to bypass the authentication mechanism.

【CVE-2026-18577】N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability (CVSS v4.0: 8.2)
【Whether exploited by ransomware: Unknown】N-able N-central contains an authentication bypass vulnerability. An attacker may bypass the authentication mechanism through an alternate path or channel, thereby taking over accounts in N-central. This vulnerability originates from an incomplete patch released for CVE-2026-18556.

【CVE-2026-34486】Apache Tomcat Missing Encryption of Sensitive Data Vulnerability (CVSS v3.1: 7.5)
【Whether exploited by ransomware: Unknown】Apache Tomcat contains a Missing Encryption of Sensitive Data vulnerability. An attacker may exploit this vulnerability to bypass EncryptInterceptor. This vulnerability may be chained with CVE-2025-24813.

【CVE-2026-9198】IBM Langflow Code Injection Vulnerability (CVSS v3.1: 9.8)
【Whether exploited by ransomware: Unknown】Langflow contains a code injection vulnerability. An unauthenticated attacker may exploit this vulnerability to achieve full remote code execution in a default Langflow deployment environment.

【CVE-2026-63077】JetBrains TeamCity Deserialization of Untrusted Data Vulnerability (CVSS v3.1: 9.8)
【Whether exploited by ransomware: Unknown】JetBrains TeamCity contains a deserialization of untrusted data vulnerability. An attacker may remotely execute code without authentication through the agent polling protocol.

【CVE-2026-8037】Progress LoadMaster Command Injection Vulnerability (CVSS v3.1: 9.6)
【Whether exploited by ransomware: Unknown】Progress LoadMaster contains a command injection vulnerability. An unauthenticated attacker may exploit unsanitized input in multiple command endpoints to execute arbitrary commands on a LoadMaster appliance.

Information Sharing Level: WHITE (the intelligence content is information that may be publicly disclosed)

[Affected Platform]

【CVE-2026-18556】Please refer to the affected versions listed by the official vendor https://uptime.n-able.com/event/201522/

【CVE-2026-18577】Please refer to the affected versions listed by the official vendor https://uptime.n-able.com/event/201522/

【CVE-2026-34486】Please refer to the affected versions listed by the official vendor https://lists.apache.org/thread/9510k5p5zdvt9pkkgtyp85mvwxo2qrly

【CVE-2026-9198】Please refer to the affected versions listed by the official vendor https://www.ibm.com/support/pages/node/7278927

【CVE-2026-63077】JetBrains TeamCity versions prior to 2026.1.3 and 2025.11.7

【CVE-2026-8037】Please refer to the affected versions listed by the official vendor https://community.progress.com/s/article/LoadMaster-Critical-Security-Bulletin-June-2026-CVE-2026-8037-CVE-2026-33691

[Recommended Actions]

【CVE-2026-18556】The official vendor has released a remediation update for the vulnerability. Please update to the relevant version https://uptime.n-able.com/event/201522/

【CVE-2026-18577】The official vendor has released a remediation update for the vulnerability. Please update to the relevant version https://uptime.n-able.com/event/201522/

【CVE-2026-34486】The official vendor has released a remediation update for the vulnerability. Please update to the relevant version https://lists.apache.org/thread/9510k5p5zdvt9pkkgtyp85mvwxo2qrly

【CVE-2026-9198】The official vendor has released a remediation update for the vulnerability. Please update to the relevant version https://www.ibm.com/support/pages/node/7278927

【CVE-2026-63077】The official vendor has released a remediation update for the vulnerability. Please update to the relevant version https://www.jetbrains.com/privacy-security/issues-fixed/

【CVE-2026-8037】The official vendor has released a remediation update for the vulnerability. Please update to the relevant version https://community.progress.com/s/article/LoadMaster-Critical-Security-Bulletin-June-2026-CVE-2026-8037-CVE-2026-33691

[Reference]

(This notification is for informational purposes only and does not constitute a cybersecurity incident).
If you have questions or suggestions regarding this notification, please feel free to contact us.
Ministry of education information & communication security contingency platform
Website: https://info.cert.tanet.edu.tw/
Phone: +886-7-5250211
Internet Phone: 98400000
E-Mail: service@cert.tanet.edu.tw
Organizer: Computer Center