██████╗██╗   ██╗██████╗ ██████╗     ██████╗██╗  ██╗
 ██╔════╝╚██╗ ██╔╝██╔══██╗██╔══██╗   ██╔════╝╚██╗██╔╝
 ██║      ╚████╔╝ ██████╔╝██████╔╝ ● ██║      ╚███╔╝ 
 ██║       ╚██╔╝  ██╔══██╗██╔══██╗   ██║      ██╔██╗ 
 ╚██████╗   ██║   ██████╔╝██║  ██║   ╚██████╗██╔╝ ██╗
  ╚═════╝   ╚═╝   ╚═════╝ ╚═╝  ╚═╝    ╚═════╝╚═╝  ╚═╝
────────────────────────────────── STAY SHARP ───

N-able N-central Hit Twice: Auth Bypass Exploits Chain

Today's cybersecurity digest — CVEs, headline news, quantum computing, and something weird. August 05, 2026

Share

cybr.cx Daily Digest — August 05, 2026


Critical Vulnerabilities

⚠️ Actively exploited — CVE-2026-18577 | N-able N-central | CVSS: TBD
An authentication bypass in N-able N-central — itself an incomplete patch for CVE-2026-18556, which is also actively exploited — allows attackers to take over accounts via an alternate authentication path. Two KEV entries for the same product within 48 hours is a five-alarm signal: if you run N-central for RMM, assume you're a target. CISA's remediation deadline for -18577 was yesterday (August 6); for -18556, it's today. Patch immediately or isolate.

⚠️ Actively exploited — CVE-2026-18556 | N-able N-central | CVSS: TBD
The original N-central authentication bypass that spawned the incomplete patch above. Both CVEs are in active exploitation together, suggesting threat actors are chaining them or pivoting between variants. MSPs and enterprises relying on N-central for endpoint management face full platform compromise if either flaw is left unpatched.

⚠️ Actively exploited — CVE-2026-9198 | IBM Langflow | CVSS: TBD
An unauthenticated code injection vulnerability in Langflow permits full remote code execution on default deployments — no credentials required. Langflow is widely used for building LLM-based pipelines, and default configurations are commonly internet-exposed. If you're running Langflow in any environment, treat it as actively compromised until patched and audited.

⚠️ Actively exploited — CVE-2026-34486 | Apache Tomcat | CVSS: TBD
A missing encryption vulnerability in Apache Tomcat allows attackers to bypass the EncryptInterceptor, potentially exposing sensitive session and cluster communication data. Tomcat's ubiquity makes this a high-priority patch across virtually every enterprise environment. CISA's due date was August 7 — verify your Tomcat versions now.

⚠️ Actively exploited — CVE-2026-20316 | Cisco Secure Firewall Management Center (FMC) | CVSS: TBD
A hard-coded password in Cisco FMC (formerly Firepower Management Center) allows unauthenticated remote attackers to log in with a low-privileged account and access sensitive data. Hard-coded credentials in perimeter security tooling is about as bad as it gets — CISA's remediation deadline has already passed (August 1). If you haven't acted on this, escalate now.

CVE-2026-16793 | Lenovo XClarity Orchestrator (LXCO) 2.2.0 | CVSS: 8.8 — HIGH
An OS command injection flaw in LXCO allows an authenticated attacker to execute arbitrary commands as a privileged user under specific circumstances. The authenticated requirement limits opportunistic exploitation, but in data centre environments where LXCO credentials may be shared or compromised, the blast radius is significant. Patch or restrict access to the management interface.

CVE-2026-67200 | Perspective 5.0.0 | CVSS: 7.5 — HIGH
A path traversal vulnerability allows unauthenticated remote attackers to read arbitrary files by injecting literal ../ segments in HTTP request URLs, bypassing the query-string sanitisation. Credential files and system secrets are explicitly flagged as retrievable. No authentication required makes this trivially weaponisable — update or restrict external access to Perspective instances.

CVE-2026-18788 | Trippo ResponsiveFilemanager ≤ 9.14.0 | CVSS: 7.3 — HIGH
Unrestricted file upload via filemanager/dialog.php — and a public exploit is already circulating. The vendor has not responded to disclosure. Treat this as unpatched indefinitely and remove or firewall any public-facing ResponsiveFilemanager instances immediately.

CVE-2026-18810 | H3C NX15 V100R017 | CVSS: 7.3 — HIGH
A missing authentication vulnerability in the /api/wizard/networkSetup endpoint on H3C NX15 routers allows unauthenticated remote attackers to manipulate network configuration. Network devices with unauthenticated setup APIs are a persistent and frustrating class of vulnerability — check your H3C inventory and ensure management interfaces are not exposed to untrusted networks.


Headline News

Supply Chain Under Siege: Shai-Hulud Campaign Hits npm Ecosystem

A coordinated supply chain attack dubbed Shai-Hulud has compromised keyv and several related npm packages, injecting malicious code into libraries with significant downstream adoption. The attack follows a pattern now well-established in the ecosystem: maintainer credential theft or account takeover, followed by a poisoned release that propagates silently through dependency trees before detection. Security researchers identified the compromise through behavioural anomaly detection in published package diffs rather than any registry-level control — a reminder that npm's publish pipeline remains largely trust-based. Any project pulling affected keyv versions should audit dependency locks, rotate secrets accessible to the affected packages, and verify integrity against known-good hashes. The incident is being actively investigated, and the full scope of downstream impact is still being assessed. Practitioners should treat this as an opportunity to audit their npm audit policies and consider registry mirroring with integrity enforcement.

Coldcard Air-Gap Exploit Drains 1,367 BTC — Offline Isn't Invulnerable

A demonstrated exploit against Coldcard hardware wallets — widely regarded as the gold standard for air-gapped Bitcoin self-custody — has resulted in the confirmed theft of over 1,367 BTC, worth tens of millions of dollars at current prices. Air-gapped devices, by design, never connect to a network; the attack vector therefore relied on the data exchange mechanisms that even offline devices must use — PSBTs (partially signed Bitcoin transactions) passed via SD card or QR code — to introduce malicious transaction data that the device processed without adequate validation. The exploit undermines a foundational assumption in the self-custody security model: that physical isolation is sufficient. For security practitioners advising clients on crypto asset custody or building custody tooling, this is a significant architectural signal — supply chain integrity of the device firmware and the data passed to air-gapped devices matters as much as the air gap itself. The incident is likely to accelerate institutional custody adoption among high-value holders.

Adform Breach Puts Malvertising Risk Back in the Spotlight

Online advertising platform Adform confirmed it was compromised in a breach that raises immediate concerns about malvertising at scale. Ad platforms occupy a privileged position in the web ecosystem — they serve code into millions of third-party sites, and a compromised ad network is a force-multiplier for drive-by attacks against end users who have no direct relationship with the breached vendor. Technical details of the intrusion method are still emerging, but the incident reinforces why ad network compromise is a persistent vector for malware delivery, particularly against enterprise users who may have weaker browser hardening policies than personal devices. Security teams should review endpoint telemetry for unusual browser-initiated connections during the breach window and consider whether outbound ad network traffic warrants additional scrutiny in their environments.


Schrödinger's Feed

A joint project between Quantum Corridor, Ciena, and Toshiba has successfully tested quantum-safe network encryption at 1.6 Tb/s — a throughput figure that starts to make post-quantum cryptography look operationally viable at backbone scale rather than a niche lab curiosity. The test validates that PQC-hardened encryption can be deployed without crippling performance on high-capacity optical links, which has been one of the quieter objections to real-world PQC rollout. This matters because the "harvest now, decrypt later" threat model is already in play — state actors are almost certainly archiving encrypted traffic today against future quantum capability. Practitioners planning long-lifecycle infrastructure — anything with a 10+ year operational horizon — should be watching PQC network layer deployments like this one as the template for what migration actually looks like in production.


/dev/random

Researchers have published a systematic study finding that AI benchmarks — the standardised tests used to declare one model smarter than another — are saturating: models are hitting near-ceiling scores on tests that were considered hard only 18 months ago, making it increasingly difficult to distinguish genuine capability improvements from benchmark overfitting. The underlying problem is straightforward: once benchmark datasets are public, they inevitably bleed into training data, and a model "acing" a test it was inadvertently trained on tells you approximately nothing. The security parallel is uncomfortably apt — it's Goodhart's Law in neural network form, where the measure becomes the target and stops being a useful measure. The field is now in the slightly embarrassing position of needing benchmarks to evaluate its benchmarks.