JetBrains TeamCity RCE Flaw Exploited — Patch Now or Else
Today's cybersecurity digest — CVEs, headline news, quantum computing, and something weird. August 08, 2026
cybr.cx Daily Digest — August 08, 2026
Critical Vulnerabilities
⚠️ Actively exploited — CVE-2026-63077 | JetBrains TeamCity | CVSS: Not scored (KEV)
A deserialization of untrusted data vulnerability in JetBrains TeamCity allows unauthenticated remote code execution via the agent polling protocol. CISA's remediation deadline was today — if you haven't patched, you are almost certainly already a target. TeamCity's history as a soft spot for nation-state actors (notably in the 2023–2024 SVR campaigns) makes this one to treat as a four-alarm fire.
⚠️ Actively exploited — CVE-2026-8037 | Progress LoadMaster | CVSS: Not scored (KEV)
An unauthenticated command injection vulnerability in Progress LoadMaster allows attackers to execute arbitrary OS commands via unsanitised input across multiple command endpoints. No credentials required, network-accessible, and already weaponised in the wild — CISA added this yesterday with a three-day remediation window ending Monday. Load balancers at the perimeter are high-value pivot points; treat this as critical regardless of the unscored CVSS.
⚠️ Actively exploited — CVE-2026-18556 & CVE-2026-18577 | N-able N-central | CVSS: Not scored (KEV)
Two authentication bypass vulnerabilities in N-able N-central — the second (CVE-2026-18577) is an incomplete patch for the first — allow attackers to bypass authentication entirely and take over accounts. N-central is an RMM platform with broad access to managed endpoints, making a compromise here catastrophic in scope. Both are actively exploited; CISA's deadline for the first has already passed.
⚠️ Actively exploited — CVE-2026-34486 | Apache Tomcat | CVSS: Not scored (KEV)
Apache Tomcat's EncryptInterceptor can be bypassed due to a missing encryption of sensitive data flaw, and this vulnerability is confirmed to chain with CVE-2025-24813. The combination produces a particularly dangerous exploit path; if your Tomcat deployments haven't been patched for the earlier CVE, this one reopens that wound at scale.
⚠️ Actively exploited — CVE-2026-9198 | IBM Langflow | CVSS: Not scored (KEV)
A code injection vulnerability in Langflow — the popular AI workflow orchestration tool — permits unauthenticated attackers to achieve full remote code execution on default deployments. With Langflow instances frequently exposed to facilitate collaborative AI development, the attack surface is broad. If you're running Langflow anywhere internet-facing, assume it's a target right now.
CVE-2026-5857 | Contiki-NG MQTT Client | CVSS: 8.1 (High)
A state persistence bug in Contiki-NG's parse_publish_vhdr() function leaves topic_len_received set after an over-length topic triggers an early return. On the next TCP segment, the parser skips its own length-reading guard, leading to a heap corruption condition. This affects IoT and embedded devices running Contiki-NG — a class of targets where patching is slow and exploitation payoff for attackers is growing.
CVE-2026-68772 | ZenML 0.94.6 | CVSS: 8.0 (High)
Any attacker with write access to a shared ZenML artifact store can plant a malicious cloudpickle payload as artifact.pkl, which executes arbitrary system commands when the artifact is loaded. This is a supply-chain-style lateral movement risk in collaborative ML environments — if multiple teams share an artifact store, a compromised or malicious insider can pivot to any consumer of that store.
CVE-2026-20339 / 20345 / 20347 / 20348 | ClamAV Multiple Parsers | CVSS: 7.5 (High)
Four separate memory corruption vulnerabilities affect ClamAV's parsers for PESpin, GPT, Mach-O, and XAR file formats. All are remotely exploitable by submitting a crafted file for scanning — a particularly ironic attack vector for an antivirus engine. Risk ranges from DoS to potential code execution. Organisations running ClamAV at mail or web gateways should prioritise patching.
CVE-2026-7867 | udisks2 | CVSS: 7.8 (High)
A local privilege escalation in udisks2 allows any user with an active console session to spoof the as-user parameter in the org.freedesktop.UDisks2.Filesystem.Mount() D-Bus method, mounting filesystems as privileged users. Useful as a post-exploitation step on Linux desktops and servers — pair with any initial access and you have a clean LPE.
CVE-2026-19192 | DeepCool DisplayService 1.2.12 | CVSS: 7.8 (High)
Improper access controls in the DeepCool DisplayService Windows executable allow a local attacker to elevate privileges. A public exploit is already available. Niche software, but widely installed on gaming and enthusiast hardware that increasingly appears in corporate environments.
Headline News
AI Agents Attacking AI Infrastructure: The OpenAI/Hugging Face Incident
New technical details have emerged from a significant attack targeting AI infrastructure spanning both OpenAI and Hugging Face. The intrusion revealed that adversaries are now specifically targeting the supply chain of AI development — model repositories, shared artifact stores, and the APIs that connect AI agents to one another. What's particularly striking is confirmation that AI agents within these platforms were communicating autonomously at scale, creating an expanded and poorly-monitored attack surface that traditional security tooling wasn't positioned to observe. The incident has sharpened an already heated debate in the security community about whether current access control and monitoring paradigms are adequate for agentic AI systems, where actions can propagate faster than human review cycles. For practitioners, the immediate takeaway is that AI platforms need to be treated with the same rigorous network segmentation and audit logging applied to any privileged infrastructure — they are not sandboxed research toys.
Zapscape: A Documented Guest-to-Host KVM Escape
A newly published exploit chain dubbed "Zapscape" (CVE-2026-64561) demonstrates a guest-to-host escape in the KVM/x86 hypervisor. The proof-of-concept code is publicly available on GitHub, which significantly lowers the bar for exploitation by less sophisticated actors. KVM underpins a significant proportion of cloud and on-premises virtualisation infrastructure across Linux environments, meaning the potential blast radius — tenant isolation failures, hypervisor-level compromise — is substantial. The vulnerability sits in the x86 emulation layer, and the researcher's write-up details the precise conditions under which guest code can break containment. Cloud providers and any organisation running KVM-based virtualisation should treat this as an urgent review item; hypervisor escapes are rare enough that a working public PoC is a significant event.
Financial Sector Targeted in Coordinated Intrusion Campaign
A coordinated hacking campaign has been confirmed to have targeted major US financial institutions over the past month, with private equity firms, exchanges, and financial infrastructure operators — including Blackstone and CME Group — among the named victims. While attribution details remain limited, the targeting pattern is consistent with either financially motivated threat actors conducting reconnaissance ahead of fraud operations, or nation-state actors seeking intelligence on capital flows, deal pipelines, and market infrastructure. Financial sector organisations should review access logs for their trading and back-office platforms, audit third-party vendor access, and cross-reference any anomalous authentication events from the past 30 days. The breadth of targeting across different financial verticals suggests a deliberate sector-wide campaign rather than opportunistic access.
Schrödinger's Feed
The most pressing quantum security story right now isn't a hardware breakthrough — it's the question of when. A detailed analysis of post-quantum cryptography migration timelines reveals that while every major class of organisation — governments, financial institutions, cloud providers, critical infrastructure operators — has published a migration roadmap, none of them agree on when a cryptographically relevant quantum computer will actually arrive. This divergence in threat modelling is creating a patchwork of migration urgency: some organisations are mid-deployment of NIST-standardised PQC algorithms, while others are still in the "monitoring" phase. For practitioners, the uncomfortable truth is that "harvest now, decrypt later" attacks are already underway — adversaries collecting encrypted traffic today don't need to wait for your migration timeline. If long-lived sensitive data is traversing your network unprotected by PQC-ready encryption, the threat is present-tense, not future-tense.
/dev/random
Oracle has formally banned AI-generated code from contributions to OpenJDK — the open-source foundation of Java itself — even as Oracle's own chairman Larry Ellison has publicly claimed the company has largely stopped writing code manually in favour of AI. The policy catches a specific irony: Oracle's own tooling and development culture is apparently going one direction while its open-source governance goes firmly the other, with contributors now required to affirm their submissions are human-authored. The concern driving the ban is likely a mixture of copyright ambiguity around AI-generated code and the practical security reality that LLM-produced code has a well-documented tendency to introduce subtle vulnerabilities, outdated API usage, and occasionally confident nonsense. Given that OpenJDK is the upstream for virtually every enterprise Java runtime on the planet, the stakes of a quietly-introduced bug are high enough that the overcaution is probably warranted.