Security Digest: August 10, 2026 - 28 Critical Vulnerabilities
Today’s digest is dominated by active exploitation and high-risk remote code execution flaws across edge appliances, CI/CD, developer tooling, and web platforms. The immediate priority is simple: patch internet-facing systems first, then lock down development environments and confirm no exposed services are still running vulnerable versions.
· 36 min read
Executive Summary
Today’s digest is dominated by active exploitation and high-risk remote code execution flaws across edge appliances, CI/CD, developer tooling, and web platforms. The immediate priority is simple: patch internet-facing systems first, then lock down development environments and confirm no exposed services are still running vulnerable versions.
Eight of today’s issues are already in CISA KEV, which means attackers are using them now. If you run Langflow, LoadMaster, TeamCity, N-able N-central, Tomcat, VeloCloud Orchestrator, FortiOS, or Cisco FMC, treat this as a same-day emergency.
🚨 ACTIVELY EXPLOITED
- CVE-2026-9198 — Langflow unauthenticated code injection leading to full RCE. Immediate action: isolate or disable exposed Langflow instances now; patch to the vendor-fixed release as soon as available.
- CVE-2026-8037 — Progress LoadMaster command injection on appliance endpoints. Immediate action: patch appliances immediately and restrict management access to trusted networks only.
- CVE-2026-63077 — JetBrains TeamCity deserialization leading to unauthenticated RCE. Immediate action: upgrade TeamCity now; if exposed, take it offline until patched.
- CVE-2026-18556 — N-able N-central authentication bypass. Immediate action: patch and review for unauthorized logins immediately.
- CVE-2026-34486 — Apache Tomcat EncryptInterceptor bypass, chainable with prior exploitation. Immediate action: patch Tomcat and inspect for suspicious post-exploit activity.
- CVE-2026-16812 — Arista VeloCloud Orchestrator On-Prem command injection. Immediate action: patch and restrict admin access now.
- CVE-2025-68686 — Fortinet FortiOS sensitive-information exposure tied to post-exploit persistence. Immediate action: patch FortiOS and assume prior compromise may have left artifacts.
- CVE-2026-20316 — Cisco Secure Firewall Management Center hard-coded password issue. Immediate action: patch immediately and rotate credentials / review access logs.
- CVE-2026-18577 — N-able N-central authentication bypass and account takeover. Immediate action: patch immediately; this is an incomplete-fix follow-on to CVE-2026-18556.
Critical Vulnerabilities
- CVE-2026-71319: Nuxt DevTools RPC abuse in development mode
- Impact: Remote code execution on developer machines when dev servers are reachable over the network or from a malicious website.
- Affected Systems:
@nuxt/devtools < 3.3.1in development environments. - Immediate Action: Update DevTools, disable DevTools on untrusted networks, and stop binding dev servers to non-loopback interfaces.
- Mitigation: Upgrade to
@nuxt/devtools@3.3.1; setdevtools: { enabled: false }if not required.
- CVE-2026-63221: CodeIgniter Query Builder SQL injection in deleteBatch()
- Impact: SQL injection when user input is passed through
where()beforedeleteBatch(). - Affected Systems:
composer codeigniter4/frameworkbeforev4.7.4. - Immediate Action: Upgrade framework versions and stop using user-controlled values in
deleteBatch()paths. - Mitigation: Upgrade to
v4.7.4+; use validated values or normaldelete()flows instead.
- Impact: SQL injection when user input is passed through
- CVE-2026-65600: Traefik ReplacePathRegex auth bypass
- Impact: Authentication bypass to protected routes via crafted path normalization.
- Affected Systems: Traefik
v2.11.52,v3.6.23,v3.7.7and earlier affected builds using the vulnerable middleware pattern. - Immediate Action: Upgrade Traefik and audit any
ReplacePathRegexrules that rewrite user-controlled paths. - Mitigation: Deploy patched releases and reject malformed rewritten paths at the edge.
- CVE-2026-71851: CryptoJS weak randomness
- Impact: Predictable secrets and wallet recovery phrases can be enumerated and stolen.
- Affected Systems: Applications using
crypto-js < 4.0.0andWordArray.random()for security-sensitive values. - Immediate Action: Upgrade CryptoJS, rotate any secrets generated by the vulnerable code, and treat old seed phrases as compromised.
- Mitigation: Move to
crypto-js@4.0.0+or native cryptographic RNG APIs; do not reuse affected recovery phrases.
- CVE-2026-59733: rclone private-repos path traversal
- Impact: Authenticated users can read, overwrite, or delete other users’ repositories on shared restic servers.
- Affected Systems:
github.com/rclone/rclonewithserve restic --private-repos. - Immediate Action: Patch rclone and disable exposed private-repo endpoints until updated.
- Mitigation: Upgrade to a fixed build; enforce canonicalized paths and review tenant isolation assumptions.
- CVE-2026-71327: Traefik Kubernetes Gateway route collision
- Impact: A tenant can hijack another namespace’s traffic by creating colliding route identities.
- Affected Systems: Traefik
v3.xKubernetes Gateway API provider. - Immediate Action: Upgrade Traefik and review shared Gateway deployments for namespace/name collisions.
- Mitigation: Move to
v3.6.25+orv3.7.10+and validate route ownership controls.
- CVE-2026-71320: Nuxt server-island template injection to RCE
- Impact: Server-side code execution in the Nitro process when runtime compiler and server islands are both enabled.
- Affected Systems: Nuxt
>=3.4.0 <3.21.10and>=4.0.0 <4.5.1withvue.runtimeCompiler: true. - Immediate Action: Disable runtime compiler or upgrade Nuxt immediately.
- Mitigation: Patch to
nuxt@4.5.1or3.21.10; blocktemplatekeys in island props.
- CVE-2026-64665: Statamic OAuth login bypass
- Impact: Unauthenticated attackers can sign in as existing users, including privileged accounts, when email verification is not guaranteed.
- Affected Systems:
statamic/cmsbefore5.74.1and6.24.0. - Immediate Action: Disable risky OAuth providers or upgrade immediately.
- Mitigation: Use providers with verified email guarantees only; patch to the fixed release.
- CVE-2026-71312: rclone PowerShell command injection via SFTP hashing
- Impact: Remote filenames can trigger command execution as the SSH account when hashing runs.
- Affected Systems:
github.com/rclone/rcloneSFTP backend on PowerShell shells. - Immediate Action: Patch rclone and disable server-side hashing on affected shells until fixed.
- Mitigation: Upgrade to a patched build; avoid PowerShell command construction from filenames.
- CVE-2026-15895: jsii-diff command injection
- Impact: Arbitrary shell command execution through crafted package specifiers.
- Affected Systems:
npm jsii-diffbefore1.131.0. - Immediate Action: Upgrade immediately and restrict who can pass arguments to the tool.
- Mitigation: Use
jsii-diff@1.131.0+; never pass untrusted package specifiers.
- CVE-2026-71314: Nuxt island v-for denial of service
- Impact: A single crafted request can exhaust CPU and memory in server rendering.
- Affected Systems: Nuxt
3.xand4.xbefore3.21.10/4.5.1when server islands usev-forover props. - Immediate Action: Patch Nuxt and clamp any server-side iteration over request data.
- Mitigation: Upgrade and add request-size / iteration limits at the edge.
- CVE-2026-71316: Nuxt payload cache data leak
- Impact: Cached payloads can leak one user’s SSR data to another user or to unauthenticated visitors.
- Affected Systems: Nuxt
4.xwith payload extraction and cache/SWR/ISR route rules before4.5.1. - Immediate Action: Disable payload extraction on protected pages and purge caches after patching.
- Mitigation: Upgrade to
nuxt@4.5.1; avoid caching authenticated pages.
- CVE-2026-71488: league/commonmark parser DoS
- Impact: Crafted Markdown can pin CPU and stall render workers.
- Affected Systems:
composer league/commonmark0.6.0through2.8.3. - Immediate Action: Upgrade and rate-limit untrusted Markdown inputs now.
- Mitigation: Patch to
2.9.0+; enforce per-line input limits.
- CVE-2026-67422: pymdown-extensions regex ReDoS
- Impact: Sub-50-byte Markdown lines can cause runaway CPU usage.
- Affected Systems:
pip pymdown-extensionsthrough11.0. - Immediate Action: Upgrade and cap untrusted Markdown line length immediately.
- Mitigation: Patch the extension set; disable unneeded processors where possible.
- CVE-2026-54572: rclone symlink traversal to arbitrary file write
- Impact: An attacker-controlled remote can write outside the destination directory, potentially leading to code execution.
- Affected Systems:
github.com/rclone/rclonewhen copying with-l/--links. - Immediate Action: Stop copying untrusted remotes with links preserved until patched.
- Mitigation: Upgrade rclone and reject absolute or escaping symlink targets.
- CVE-2026-71321: Nuxt island body parsing DoS
- Impact: Large unauthenticated island requests consume CPU and delay all traffic.
- Affected Systems: Nuxt
3.x/4.xbefore3.21.10/4.5.1. - Immediate Action: Add a request-body limit at the proxy and patch Nuxt.
- Mitigation: Upgrade and block oversized
/__nuxt_island/requests at the edge.
- CVE-2026-63222: CodeIgniter file upload path traversal
- Impact: Uploaded files can be written outside the intended directory when default filename handling is used.
- Affected Systems:
composer codeigniter4/frameworkbeforev4.7.4. - Immediate Action: Patch immediately and stop using client-provided names for moves.
- Mitigation: Upgrade to
v4.7.4+; use generated or sanitized filenames only.
- CVE-2026-71556: go-git symlink traversal in worktree operations
- Impact: Worktree writes can escape into repository metadata or other files outside the intended path.
- Affected Systems:
github.com/go-git/go-git/v5and/v6filesystem-backed worktrees. - Immediate Action: Upgrade patched versions and audit any symlink-bearing worktrees.
- Mitigation: Move to the fixed release and reject symlink-following write paths.
Previously Alerted
- CVE-2026-35290
- CVE-2026-60358
- CVE-2026-60360
- CVE-2026-60365
- CVE-2026-47056
- CVE-2026-60644
- CVE-2026-60389
- CVE-2026-60379
- CVE-2026-60217
- CVE-2026-60429
- CVE-2026-60627
- CVE-2026-60377
- CVE-2026-60461
- CVE-2026-60565
- CVE-2026-60402
- CVE-2026-60542
- CVE-2026-60458
- CVE-2026-60247
- CVE-2026-60275
- CVE-2026-60446
- CVE-2026-46982
- CVE-2026-60566
- CVE-2026-60216
- CVE-2026-60234
- CVE-2026-60256
- CVE-2026-60302
- CVE-2026-60460
- CVE-2026-46983
- CVE-2026-60204
- CVE-2026-60278
- CVE-2026-60290
- CVE-2026-60328
- CVE-2026-46876
- CVE-2026-60221
- CVE-2026-60230
- CVE-2026-60200
- CVE-2026-60232
- CVE-2026-60269
- CVE-2026-60287
- CVE-2026-60298
- CVE-2026-60362
- CVE-2026-60378
- CVE-2026-60463
- CVE-2026-63764
- CVE-2026-60631
- CVE-2026-60168
- CVE-2026-46989
- CVE-2026-60567
- CVE-2026-47037
- CVE-2026-60193
- CVE-2026-47688
- CVE-2026-60192
- CVE-2026-60586
- CVE-2026-60180
- CVE-2026-60179
- CVE-2026-16484
- CVE-2026-46954
- CVE-2026-60381
- CVE-2026-60333
- CVE-2026-60361
- CVE-2026-60524
- CVE-2026-60562
- CVE-2026-60456
- CVE-2026-60257
- CVE-2026-60294
- CVE-2026-60535
- CVE-2026-46994
- CVE-2026-46924
- CVE-2026-60225
- CVE-2026-60241
- CVE-2026-60258
- CVE-2026-60308
- CVE-2026-60541
- CVE-2026-47036
- CVE-2026-60210
- CVE-2026-60280
- CVE-2026-60292
- CVE-2026-60363
- CVE-2026-60198
- CVE-2026-60224
- CVE-2026-60240
- CVE-2026-60205
- CVE-2026-60244
- CVE-2026-60272
- CVE-2026-60289
- CVE-2026-60300
- CVE-2026-60364
- CVE-2026-60380
- CVE-2026-60540
- CVE-2026-60632
- CVE-2026-65057
- CVE-2026-60649
- CVE-2026-60326
- CVE-2026-60249
- CVE-2026-60559
- CVE-2026-60163
- CVE-2026-60560
- CVE-2026-60325
- CVE-2026-47018
- CVE-2026-47690
- CVE-2026-47058
- CVE-2026-47685
- CVE-2026-47697
- CVE-2026-60457
- CVE-2026-60537
- CVE-2026-60206
- CVE-2026-60531
- CVE-2026-60561
- CVE-2026-60447
- CVE-2026-60259
- CVE-2026-60435
- CVE-2026-60386
- CVE-2026-60532
- CVE-2026-60197
- CVE-2026-60227
- CVE-2026-60246
- CVE-2026-60274
- CVE-2026-60355
- CVE-2026-60551
- CVE-2026-60173
- CVE-2026-60236
- CVE-2026-60286
- CVE-2026-60297
- CVE-2026-60375
- CVE-2026-60212
- CVE-2026-60226
- CVE-2026-60242
- CVE-2026-60209
- CVE-2026-60254
- CVE-2026-60279
- CVE-2026-60291
- CVE-2026-60306
- CVE-2026-60374
- CVE-2026-60385
- CVE-2026-60564
- CVE-2026-60248
- CVE-2026-60438
- CVE-2026-60208
- CVE-2026-60606
- CVE-2026-60424
- CVE-2026-60327
- CVE-2026-65056
- CVE-2026-60416
- CVE-2026-46923
- CVE-2026-47057
- CVE-2026-60314
- CVE-2026-60317
- CVE-2026-47687
- CVE-2026-56147
- CVE-2026-60459
- CVE-2026-60547
- CVE-2026-60422
- CVE-2026-60552
- CVE-2026-60568
- CVE-2026-60445
- CVE-2026-60262
- CVE-2026-60441
- CVE-2026-60388
- CVE-2026-60538
- CVE-2026-60202
- CVE-2026-60229
- CVE-2026-60251
- CVE-2026-60276
- CVE-2026-60442
- CVE-2026-60555
- CVE-2026-60199
- CVE-2026-60253
- CVE-2026-60288
- CVE-2026-60299
- CVE-2026-60384
- CVE-2026-60215
- CVE-2026-60228
- CVE-2026-60250
- CVE-2026-60219
- CVE-2026-60264
- CVE-2026-60285
- CVE-2026-60296
- CVE-2026-60329
- CVE-2026-60376
- CVE-2026-60387
- CVE-2026-60239
- CVE-2026-60220
- CVE-2026-60267
- CVE-2026-47040
- CVE-2026-47731
- CVE-2026-60493
- CVE-2026-60356
- CVE-2026-60315
- CVE-2026-10678
- CVE-2026-47237
- CVE-2026-60498
- CVE-2026-47063
- CVE-2026-63358
- CVE-2026-60316
- CVE-2026-60623
- CVE-2026-52472
- CVE-2026-52469
- CVE-2026-52470
- CVE-2026-30631
- CVE-2026-52474
- CVE-2026-52476
- CVE-2026-60663
- CVE-2026-60719
- CVE-2026-60711
- CVE-2026-60668
- CVE-2026-60690
- CVE-2026-60689
- CVE-2026-60704
- CVE-2026-60667
- CVE-2026-60725
- CVE-2026-60705
- CVE-2026-60773
- CVE-2026-60763
- CVE-2026-55851
- CVE-2026-63223
What to Do Now
- Patch exposed systems first. Start with KEV-listed appliances, CI/CD, and internet-facing gateways. If you cannot patch within hours, isolate the service.
- Lock down developer tooling. Nuxt DevTools, server islands, and local dev servers should never be exposed on untrusted networks.
- Audit edge and routing rules. Review Traefik middleware, Kubernetes Gateway routes, and any rewrite logic that touches authentication boundaries.
- Assume old secrets may be compromised. For CryptoJS-based wallets or apps, rotate secrets and reissue recovery material.
- Review logs for exploitation. Look for unusual logins, new admin sessions, command execution traces, route collisions, and unexpected payload access.
Verification steps: confirm versions against vendor advisories, check whether affected features are enabled, and validate that patched releases are actually deployed in production—not just in source control. For Nuxt, verify both the package lockfile and the runtime config. For rclone, CodeIgniter, Traefik, and go-git, verify the vulnerable code paths are not reachable even if the package is present.
Monitoring recommendations: alert on authentication anomalies, unexpected outbound connections from appliances, new webshell-like files, large island or Markdown requests, and repeated 4xx/5xx spikes on edge routers. Watch for config drift in CI/CD and developer environments, especially any service bound to non-loopback interfaces.
Related Resources
- Internal blog: a follow-up post on today’s KEV exploitation wave is planned; do not publish until patch guidance is confirmed.
- Official vendor advisories: JetBrains, Progress, N-able, Cisco, Fortinet, Arista, Apache, Nuxt, Traefik, CodeIgniter, rclone, go-git, Statamic, jsii, league/commonmark, and pymdown-extensions advisories.