Security Digest: August 10, 2026 - 28 Critical Vulnerabilities

Today’s digest is dominated by active exploitation and high-risk remote code execution flaws across edge appliances, CI/CD, developer tooling, and web platforms. The immediate priority is simple: patch internet-facing systems first, then lock down development environments and confirm no exposed services are still running vulnerable versions.

· 36 min read

Executive Summary

Today’s digest is dominated by active exploitation and high-risk remote code execution flaws across edge appliances, CI/CD, developer tooling, and web platforms. The immediate priority is simple: patch internet-facing systems first, then lock down development environments and confirm no exposed services are still running vulnerable versions.

Eight of today’s issues are already in CISA KEV, which means attackers are using them now. If you run Langflow, LoadMaster, TeamCity, N-able N-central, Tomcat, VeloCloud Orchestrator, FortiOS, or Cisco FMC, treat this as a same-day emergency.

🚨 ACTIVELY EXPLOITED

  • CVE-2026-9198 — Langflow unauthenticated code injection leading to full RCE. Immediate action: isolate or disable exposed Langflow instances now; patch to the vendor-fixed release as soon as available.
  • CVE-2026-8037 — Progress LoadMaster command injection on appliance endpoints. Immediate action: patch appliances immediately and restrict management access to trusted networks only.
  • CVE-2026-63077 — JetBrains TeamCity deserialization leading to unauthenticated RCE. Immediate action: upgrade TeamCity now; if exposed, take it offline until patched.
  • CVE-2026-18556 — N-able N-central authentication bypass. Immediate action: patch and review for unauthorized logins immediately.
  • CVE-2026-34486 — Apache Tomcat EncryptInterceptor bypass, chainable with prior exploitation. Immediate action: patch Tomcat and inspect for suspicious post-exploit activity.
  • CVE-2026-16812 — Arista VeloCloud Orchestrator On-Prem command injection. Immediate action: patch and restrict admin access now.
  • CVE-2025-68686 — Fortinet FortiOS sensitive-information exposure tied to post-exploit persistence. Immediate action: patch FortiOS and assume prior compromise may have left artifacts.
  • CVE-2026-20316 — Cisco Secure Firewall Management Center hard-coded password issue. Immediate action: patch immediately and rotate credentials / review access logs.
  • CVE-2026-18577 — N-able N-central authentication bypass and account takeover. Immediate action: patch immediately; this is an incomplete-fix follow-on to CVE-2026-18556.

Critical Vulnerabilities

  • CVE-2026-71319: Nuxt DevTools RPC abuse in development mode
    • Impact: Remote code execution on developer machines when dev servers are reachable over the network or from a malicious website.
    • Affected Systems: @nuxt/devtools < 3.3.1 in development environments.
    • Immediate Action: Update DevTools, disable DevTools on untrusted networks, and stop binding dev servers to non-loopback interfaces.
    • Mitigation: Upgrade to @nuxt/devtools@3.3.1; set devtools: { enabled: false } if not required.
  • CVE-2026-63221: CodeIgniter Query Builder SQL injection in deleteBatch()
    • Impact: SQL injection when user input is passed through where() before deleteBatch().
    • Affected Systems: composer codeigniter4/framework before v4.7.4.
    • Immediate Action: Upgrade framework versions and stop using user-controlled values in deleteBatch() paths.
    • Mitigation: Upgrade to v4.7.4+; use validated values or normal delete() flows instead.
  • CVE-2026-65600: Traefik ReplacePathRegex auth bypass
    • Impact: Authentication bypass to protected routes via crafted path normalization.
    • Affected Systems: Traefik v2.11.52, v3.6.23, v3.7.7 and earlier affected builds using the vulnerable middleware pattern.
    • Immediate Action: Upgrade Traefik and audit any ReplacePathRegex rules that rewrite user-controlled paths.
    • Mitigation: Deploy patched releases and reject malformed rewritten paths at the edge.
  • CVE-2026-71851: CryptoJS weak randomness
    • Impact: Predictable secrets and wallet recovery phrases can be enumerated and stolen.
    • Affected Systems: Applications using crypto-js < 4.0.0 and WordArray.random() for security-sensitive values.
    • Immediate Action: Upgrade CryptoJS, rotate any secrets generated by the vulnerable code, and treat old seed phrases as compromised.
    • Mitigation: Move to crypto-js@4.0.0+ or native cryptographic RNG APIs; do not reuse affected recovery phrases.
  • CVE-2026-59733: rclone private-repos path traversal
    • Impact: Authenticated users can read, overwrite, or delete other users’ repositories on shared restic servers.
    • Affected Systems: github.com/rclone/rclone with serve restic --private-repos.
    • Immediate Action: Patch rclone and disable exposed private-repo endpoints until updated.
    • Mitigation: Upgrade to a fixed build; enforce canonicalized paths and review tenant isolation assumptions.
  • CVE-2026-71327: Traefik Kubernetes Gateway route collision
    • Impact: A tenant can hijack another namespace’s traffic by creating colliding route identities.
    • Affected Systems: Traefik v3.x Kubernetes Gateway API provider.
    • Immediate Action: Upgrade Traefik and review shared Gateway deployments for namespace/name collisions.
    • Mitigation: Move to v3.6.25+ or v3.7.10+ and validate route ownership controls.
  • CVE-2026-71320: Nuxt server-island template injection to RCE
    • Impact: Server-side code execution in the Nitro process when runtime compiler and server islands are both enabled.
    • Affected Systems: Nuxt >=3.4.0 <3.21.10 and >=4.0.0 <4.5.1 with vue.runtimeCompiler: true.
    • Immediate Action: Disable runtime compiler or upgrade Nuxt immediately.
    • Mitigation: Patch to nuxt@4.5.1 or 3.21.10; block template keys in island props.
  • CVE-2026-64665: Statamic OAuth login bypass
    • Impact: Unauthenticated attackers can sign in as existing users, including privileged accounts, when email verification is not guaranteed.
    • Affected Systems: statamic/cms before 5.74.1 and 6.24.0.
    • Immediate Action: Disable risky OAuth providers or upgrade immediately.
    • Mitigation: Use providers with verified email guarantees only; patch to the fixed release.
  • CVE-2026-71312: rclone PowerShell command injection via SFTP hashing
    • Impact: Remote filenames can trigger command execution as the SSH account when hashing runs.
    • Affected Systems: github.com/rclone/rclone SFTP backend on PowerShell shells.
    • Immediate Action: Patch rclone and disable server-side hashing on affected shells until fixed.
    • Mitigation: Upgrade to a patched build; avoid PowerShell command construction from filenames.
  • CVE-2026-15895: jsii-diff command injection
    • Impact: Arbitrary shell command execution through crafted package specifiers.
    • Affected Systems: npm jsii-diff before 1.131.0.
    • Immediate Action: Upgrade immediately and restrict who can pass arguments to the tool.
    • Mitigation: Use jsii-diff@1.131.0+; never pass untrusted package specifiers.
  • CVE-2026-71314: Nuxt island v-for denial of service
    • Impact: A single crafted request can exhaust CPU and memory in server rendering.
    • Affected Systems: Nuxt 3.x and 4.x before 3.21.10/4.5.1 when server islands use v-for over props.
    • Immediate Action: Patch Nuxt and clamp any server-side iteration over request data.
    • Mitigation: Upgrade and add request-size / iteration limits at the edge.
  • CVE-2026-71316: Nuxt payload cache data leak
    • Impact: Cached payloads can leak one user’s SSR data to another user or to unauthenticated visitors.
    • Affected Systems: Nuxt 4.x with payload extraction and cache/SWR/ISR route rules before 4.5.1.
    • Immediate Action: Disable payload extraction on protected pages and purge caches after patching.
    • Mitigation: Upgrade to nuxt@4.5.1; avoid caching authenticated pages.
  • CVE-2026-71488: league/commonmark parser DoS
    • Impact: Crafted Markdown can pin CPU and stall render workers.
    • Affected Systems: composer league/commonmark 0.6.0 through 2.8.3.
    • Immediate Action: Upgrade and rate-limit untrusted Markdown inputs now.
    • Mitigation: Patch to 2.9.0+; enforce per-line input limits.
  • CVE-2026-67422: pymdown-extensions regex ReDoS
    • Impact: Sub-50-byte Markdown lines can cause runaway CPU usage.
    • Affected Systems: pip pymdown-extensions through 11.0.
    • Immediate Action: Upgrade and cap untrusted Markdown line length immediately.
    • Mitigation: Patch the extension set; disable unneeded processors where possible.
  • CVE-2026-54572: rclone symlink traversal to arbitrary file write
    • Impact: An attacker-controlled remote can write outside the destination directory, potentially leading to code execution.
    • Affected Systems: github.com/rclone/rclone when copying with -l/--links.
    • Immediate Action: Stop copying untrusted remotes with links preserved until patched.
    • Mitigation: Upgrade rclone and reject absolute or escaping symlink targets.
  • CVE-2026-71321: Nuxt island body parsing DoS
    • Impact: Large unauthenticated island requests consume CPU and delay all traffic.
    • Affected Systems: Nuxt 3.x/4.x before 3.21.10/4.5.1.
    • Immediate Action: Add a request-body limit at the proxy and patch Nuxt.
    • Mitigation: Upgrade and block oversized /__nuxt_island/ requests at the edge.
  • CVE-2026-63222: CodeIgniter file upload path traversal
    • Impact: Uploaded files can be written outside the intended directory when default filename handling is used.
    • Affected Systems: composer codeigniter4/framework before v4.7.4.
    • Immediate Action: Patch immediately and stop using client-provided names for moves.
    • Mitigation: Upgrade to v4.7.4+; use generated or sanitized filenames only.
  • CVE-2026-71556: go-git symlink traversal in worktree operations
    • Impact: Worktree writes can escape into repository metadata or other files outside the intended path.
    • Affected Systems: github.com/go-git/go-git/v5 and /v6 filesystem-backed worktrees.
    • Immediate Action: Upgrade patched versions and audit any symlink-bearing worktrees.
    • Mitigation: Move to the fixed release and reject symlink-following write paths.

Previously Alerted

What to Do Now

  1. Patch exposed systems first. Start with KEV-listed appliances, CI/CD, and internet-facing gateways. If you cannot patch within hours, isolate the service.
  2. Lock down developer tooling. Nuxt DevTools, server islands, and local dev servers should never be exposed on untrusted networks.
  3. Audit edge and routing rules. Review Traefik middleware, Kubernetes Gateway routes, and any rewrite logic that touches authentication boundaries.
  4. Assume old secrets may be compromised. For CryptoJS-based wallets or apps, rotate secrets and reissue recovery material.
  5. Review logs for exploitation. Look for unusual logins, new admin sessions, command execution traces, route collisions, and unexpected payload access.

Verification steps: confirm versions against vendor advisories, check whether affected features are enabled, and validate that patched releases are actually deployed in production—not just in source control. For Nuxt, verify both the package lockfile and the runtime config. For rclone, CodeIgniter, Traefik, and go-git, verify the vulnerable code paths are not reachable even if the package is present.

Monitoring recommendations: alert on authentication anomalies, unexpected outbound connections from appliances, new webshell-like files, large island or Markdown requests, and repeated 4xx/5xx spikes on edge routers. Watch for config drift in CI/CD and developer environments, especially any service bound to non-loopback interfaces.

Related Resources

  • Internal blog: a follow-up post on today’s KEV exploitation wave is planned; do not publish until patch guidance is confirmed.
  • Official vendor advisories: JetBrains, Progress, N-able, Cisco, Fortinet, Arista, Apache, Nuxt, Traefik, CodeIgniter, rclone, go-git, Statamic, jsii, league/commonmark, and pymdown-extensions advisories.

Keep reading