LoadMaster Zero-Day Exploited: Patch Deadline Already Missed
Today's cybersecurity digest — CVEs, headline news, quantum computing, and something weird. August 11, 2026
cybr.cx Daily Digest — August 11, 2026
Critical Vulnerabilities
⚠️ Actively exploited — CVE-2026-8037 | Progress LoadMaster | No CVSS in NVD feed
An unauthenticated command injection flaw in Progress LoadMaster allows attackers to execute arbitrary OS commands directly on the appliance. With no authentication required and CISA's remediation deadline already passed (August 10), any exposed LoadMaster should be treated as potentially compromised. Patch or isolate immediately.
⚠️ Actively exploited — CVE-2026-63077 | JetBrains TeamCity | No CVSS in NVD feed
A deserialization vulnerability in TeamCity's agent polling protocol enables unauthenticated remote code execution. TeamCity's position in CI/CD pipelines makes this especially dangerous — a foothold here means access to source code, secrets, and build artifacts across an entire organisation. CISA's due date has passed; patch now.
⚠️ Actively exploited — CVE-2026-9198 | IBM Langflow | No CVSS in NVD feed
A code injection vulnerability in Langflow allows fully unauthenticated attackers to achieve remote code execution on default deployments. AI/ML workflow tooling is increasingly internet-exposed with minimal hardening — if you're running Langflow anywhere accessible, assume it's a target.
⚠️ Actively exploited — CVE-2026-18556 & CVE-2026-18577 | N-able N-central | No CVSS in NVD feed
Two authentication bypass vulnerabilities — the second an incomplete fix for the first — allow attackers to bypass authentication and take over accounts in N-able N-central. RMM platform compromise is a high-value pivot for ransomware groups; both CVEs are in active exploitation and both patch deadlines have passed.
⚠️ Actively exploited — CVE-2026-34486 | Apache Tomcat | No CVSS in NVD feed
A missing encryption vulnerability in Apache Tomcat bypasses the EncryptInterceptor and is chainable with CVE-2025-24813, a previously known deserialization flaw. The chaining potential significantly raises the effective severity — review your Tomcat deployments and apply available patches.
CVE-2026-66738 | SPIP (before 4.4.18) | CVSS 8.8
A code injection vulnerability in SPIP's SQLite-backed installations allows an authenticated editor-level user to break out of a quoted PHP string context via the navigation menu endpoint. A single crafted GET request is sufficient for exploitation. Update to 4.4.18 immediately — editor privileges are widely held in SPIP installations.
CVE-2026-71965 & CVE-2026-71966 | CyberPanel 2.4.3 | CVSS 8.8 each
Two separate authenticated RCE vulnerabilities in CyberPanel's remote backup feature. The first allows an attacker to write their own SSH public key directly to /root/.ssh/authorized_keys, granting root SSH access. The second injects arbitrary OS commands via a crafted directory name returned in a remote server's API response. Both are fixed in commit eca0c3c — patch or restrict backup feature access.
CVE-2026-69118 | Cachet (through 2.4.1) | CVSS 8.8
Server-side template injection in Cachet's incident template rendering allows authenticated users to execute arbitrary PHP via Blade directives or Twig filters. Status page platforms often have broad internal access — treat this as a pivot risk and review who holds Cachet credentials.
CVE-2026-71576 | Red Hat Multicluster Global Hub | CVSS 8.5
The manager component fails to validate the source identity of CloudEvents on Kafka status topics. An attacker who has already compromised a managed hub and obtained its Kafka client certificate can falsify or delete compliance and inventory data across the cluster. A critical integrity risk in multi-cluster Kubernetes environments.
CVE-2026-71962 | Flowise 2.2.4–3.1.4 | CVSS 7.5
A missing authorization check on the file download endpoint allows completely unauthenticated access to private files. The endpoint is whitelisted globally, bypassing all session and API key checks. AI workflow platforms continue to be rich targets — audit your Flowise deployments and upgrade past 3.1.4.
CVE-2026-59087 | GIMP | CVSS 7.8
A heap overflow in GIMP's Seattle Filmworks file loader can be triggered by a maliciously crafted image file. Successful exploitation could lead to arbitrary code execution in the context of the user running GIMP. A classic user-targeted delivery vector — update GIMP and be cautious with image files from untrusted sources.
Headline News
The Quiet Decline of HackerOne
A detailed post-mortem examining what went wrong with HackerOne has been circulating widely among security practitioners, and the picture it paints is uncomfortable. The piece traces a trajectory from scrappy bug bounty pioneer to a platform increasingly criticised for delayed triage, opaque mediation decisions, and suppressed vulnerability disclosures — with researchers describing experiences of reports being closed without action and communication going dark for months. For practitioners, the operational concern is real: organisations that rely on HackerOne as their primary vulnerability intake mechanism may have a false sense of coverage if researcher confidence in the platform has eroded. The story touches a nerve because bug bounty platforms sit at a critical trust junction between researchers and defenders — when that trust degrades, vulnerabilities don't disappear, they just go elsewhere.
Ransomware Targeting the IT Manager, Not the C-Suite
New research into ransomware gang tactics reveals a deliberate pivot in social engineering targeting: rather than going after executives, threat actors are increasingly focusing on IT managers — specifically those in the 35–45 age bracket with broad system access and administrative credentials. The logic is straightforward: IT managers often hold the keys to backup systems, domain controllers, and remote access tooling without the additional security controls or executive monitoring that protect C-suite accounts. Ransomware operators are reportedly using LinkedIn-style OSINT to profile targets before launching credential phishing or vishing campaigns tailored to IT operations contexts. The implication for defenders is that privileged access management and phishing simulation programmes need to weight mid-level IT staff as high-value targets, not just leadership.
SMM Exploitation via Interrupt Abuse
A proof-of-concept technique for exploiting System Management Mode (SMM) using abnormally long interrupt sequences has surfaced, attracting significant attention from low-level security researchers. SMM is a highly privileged CPU execution mode invisible to the OS and hypervisor — code running there can bypass virtually all software-layer security controls, including EDR and secure boot protections. The technique demonstrates that timing and interrupt handling edge cases in SMM firmware implementations can be abused to gain execution in this protected ring, raising serious questions about the defensive assumptions baked into modern secure boot architectures. For practitioners working in firmware security, supply chain assurance, or high-assurance environments, this class of vulnerability warrants close attention — and underscores why SMM attack surface reduction remains an underinvested area.
Schrödinger's Feed
Utah has joined the growing list of US states launching formal quantum computing initiatives, signalling continued momentum in public-sector investment in quantum infrastructure. While the programme itself is broad, the underlying hardware context is notable: photonic quantum computing on silicon chips is maturing fast, with multi-qubit entangled states now achievable on manufacturable silicon platforms. For cryptographers, the trajectory matters more than any single announcement — photonic approaches are increasingly seen as a credible path to fault-tolerant, scalable quantum systems. Practitioners who haven't yet audited their cryptographic dependencies against NIST's finalised post-quantum standards should treat this drumbeat of progress as a deadline, not background noise.
/dev/random
Phrack Issue 72 has landed, and the hacker community is in a mild state of collective nostalgia and genuine excitement. The standout piece — "The Hacker's Renaissance" — makes the case that the current era of AI-assisted tooling, open hardware, and democratised exploit research represents a genuine cultural and technical revival, not just marketing language. It's Phrack, so the writing is dense, the code is real, and there's exactly zero vendor sponsorship to be found. The fact that a 2025-dated Phrack article is still generating significant practitioner attention in 2026 says something either about the quality of the writing or the state of the industry — possibly both.