Security teams tracked 1,877 new vulnerabilities between August 3 and August 9, 2026. This weekly CVE report, drawn from the CVE WATCHTOWER service, breaks down what actually matters. Six of those flaws are already under active attack.
Why This Week’s Vulnerabilities Matter
Volume alone does not tell the story. Most of the 1,877 disclosures will never see exploitation. However, the six additions to CISA’s Known Exploited Vulnerabilities catalog demand urgent attention.
These six span remote monitoring tools, developer platforms, and web servers. Attackers reach several of them without any credentials. As a result, a single unpatched system can hand over full control.
Actively Exploited Vulnerabilities
The following flaws all carry active exploitation status. Each now sits in the CISA KEV catalog, so federal agencies must patch them on a deadline.
| CVE | Product | Type | Severity |
|---|---|---|---|
| CVE-2026-18556 | N-able N-central | Authentication bypass | High |
| CVE-2026-18577 | N-able N-central | Auth bypass (incomplete patch) | High |
| CVE-2026-63077 | JetBrains TeamCity | Unauthenticated RCE | Critical (9.8) |
| CVE-2026-9198 | IBM Langflow OSS | Auth bypass to RCE chain | Critical (9.8) |
| CVE-2026-8037 | Progress LoadMaster (ADC) | OS command injection RCE | Critical (9.6) |
| CVE-2026-34486 | Apache Tomcat | Encryption bypass | High (7.5) |
N-able N-central Under Attack
Two authentication bypass bugs top the list. CVE-2026-18577 stems from an incomplete fix for CVE-2026-18556. Attackers gain admin access to N-central servers, then pivot into managed endpoints. Reports describe rogue accounts and Cloudflare tunnels used for persistence.
Critical Remote Code Execution Bugs
Three critical flaws allow remote code execution. TeamCity exposes unauthenticated RCE through its agent polling protocol. IBM Langflow lets attackers mint superuser tokens and then run code. Progress LoadMaster accepts injected OS commands through its API.
New CVE Volume at a Glance
Beyond the exploited set, this weekly CVE report logged a heavy disclosure load. High and medium ratings dominated the week.
| Severity | Count |
|---|---|
| Critical | 254 |
| High | 634 |
| Medium | 633 |
| Low | 65 |
| Unrated | 291 |
What to Do Now
Start with the six exploited flaws above. Patch N-able N-central, TeamCity, Langflow, LoadMaster, and Tomcat first. Next, triage the 254 critical CVEs against your own stack.
Prioritize by exposure, not just score. Internet-facing and unauthenticated bugs deserve the fastest response. This weekly CVE report gives you the shortlist; your asset inventory decides the order.
Support Our Threat Intelligence
If you find our CVE report and cybersecurity news helpful, consider supporting our work.