Full briefing
Markdown renderedMSP Threat Radar Weekly Briefing — Week of 2026-08-03
This week’s briefing tracks 12 recent watch items across 6 vendors, with emphasis on active service incidents and high-priority operational issues.
Top items
Progress LoadMaster Command Injection Vulnerability
- Vendor: Progress
- Published: 2026-08-07
- Status: active
- Source: cisa-kev
- Official advisory: https://community.progress.com/s/article/LoadMaster-Critical-Security-Bulletin-June-2026-CVE-2026-8037-CVE-2026-33691
Progress LoadMaster contains a command injection vulnerability that allows an un-authenticated attacker to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in multiple command endpoints.
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines. Due date: 2026-08-10.
Apache Tomcat Missing Encryption of Sensitive Data Vulnerability
- Vendor: Apache
- Published: 2026-08-04
- Status: active
- Source: cisa-kev
- Official advisory: https://lists.apache.org/thread/9510k5p5zdvt9pkkgtyp85mvwxo2qrly
Apache Tomcat contains a missing encryption of sensitive data vulnerability that allows the bypass of the EncryptInterceptor. This vulnerability can be chained with CVE‑2025‑24813.
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines. Due date: 2026-08-07.
IBM Langflow Code Injection Vulnerability
- Vendor: IBM
- Published: 2026-08-04
- Status: active
- Source: cisa-kev
- Official advisory: https://www.ibm.com/support/pages/node/7278927
Langflow contains a code injection vulnerability that allows unauthenticated attackers to achieve full remote code execution on default Langflow deployments.
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines. Due date: 2026-08-07.
JetBrains TeamCity Deserialization of Untrusted Data Vulnerability
- Vendor: Jetbrains
- Published: 2026-08-05
- Status: active
- Source: cisa-kev
- Official advisory: https://blog.jetbrains.com/teamcity/2026/07/cve-2026-63077/
JetBrains TeamCity contains a deserialization of untrusted data vulnerability that could allow unauthenticated remote code execution via the agent polling protocol.
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines. Due date: 2026-08-08.
N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability
- Vendor: N Able
- Published: 2026-08-04
- Status: active
- Source: cisa-kev
- Official advisory: https://uptime.n-able.com/
N-able N-central contains an authentication bypass using an alternate path or channel that allows for authentication bypass.
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines. Due date: 2026-08-07.
