Skip to content
feed: live
>_ 0dayNews
Briefing · 2026-08-10

Aug 3–10: Four KEV Additions, Metabase CVSS 10

Four CISA KEV additions this week. Metabase CVSS 10 patched under active exploitation. WordPress triple chain, 10 MCP CVEs, breaches at Levi Strauss and Valve.

tldr.txt
  • Metabase patched its CVSS 10.0 unauthenticated SQL injection zero-day today — active exploitation confirmed since August 8. No CVE assigned yet. Update immediately.
  • Four KEV additions this week: CVE-2026-18577 (N-able N-central, Aug 3), CVE-2026-34486 (Apache Tomcat, Aug 4), CVE-2026-9198 (Langflow, CVSS 9.8 unauth RCE), CVE-2026-8037 (Kemp LoadMaster, 792 attempts).
  • WordPress triple chain CVE-2026-18468/18469/18470 enables unauthenticated admin takeover in Login & Register Forms plugin before 4.0.2. Update now.
  • Ten MCP server CVEs hit NVD on August 9 — all SSRF or path traversal, ten distinct open-source implementations, most maintainers silent.
  • Microsoft warns a China-linked threat actor is exploiting a critical N-able vulnerability as a ransomware deployment platform.
  • Iranian-linked hackers targeted ICS at water facilities in at least a dozen US states including New Jersey and Alabama.
  • Levi Strauss confirmed data exfil via social engineering against employees. Valve notifying EU Steam hardware customers after shipping partner breach.

Twelve items from Aug 3–10. Four require immediate action.

Metabase — CVSS 10 zero-day, patch released today

Patch now. Metabase released a fix today for the maximum-severity unauthenticated SQL injection zero-day that entered active exploitation on August 8. Vendor-stated CVSS: 10.0. No CVE identifier assigned as of this writing.

Attack vector: unauthenticated SQL injection enabling full administrative access — every data source the Metabase instance is authorized to reach. Exploitation confirmed since August 8. Patch confirmed. Confidence: Metabase vendor statement via SecurityWeek.

If your Metabase instance is reachable from untrusted networks, this is today’s first action. Full coverage: Metabase Patches CVSS 10 Zero-Day Under Active Exploit.

KEV additions: four CVEs in eight days

CISA added four CVEs to the Known Exploited Vulnerabilities catalog this week.

CVE-2026-18577 — N-able N-central (added Aug 3, FCEB deadline Aug 6 — now past). Authentication bypass. Active exploitation confirmed by CISA. This is an incomplete fix for an earlier flaw in the same product — the bypass survives the prior patch. MSPs running N-central carry the broadest blast radius: N-central holds management access to client endpoints. Confidence: CISA KEV confirmed. Full coverage: CISA Flags N-able N-central Auth Bypass.

CVE-2026-34486 — Apache Tomcat EncryptInterceptor (added Aug 4, FCEB deadline Aug 7 — now past). Attackers bypass the EncryptInterceptor entirely, exposing clustered Tomcat node traffic to interception and injection. Active exploitation confirmed. Fixed builds available. Confidence: CISA KEV and Apache advisory confirmed. Full coverage: Apache Tomcat EncryptInterceptor Bypass Added to KEV.

CVE-2026-9198 — Langflow (KEV, exploitation confirmed). CVSS 9.8. Unauthenticated remote code execution on default deployments — no credentials, no user interaction, direct code execution on the service process. A public proof-of-concept is circulating. Patch to 1.10.1. Confidence: CISA KEV and Langflow advisory confirmed; PoC publication confirmed. Full coverage: Public PoC Lands for Langflow’s 9.8 Unauth RCE.

CVE-2026-8037 — Kemp LoadMaster (added Aug 8). CVSS 9.6 unauthenticated OS command injection in the HTTP management interface. 792 reported exploitation attempts preceded the KEV listing. Patch available since June 4. FCEB deadline August 29. If your LoadMaster management interface is internet-accessible and unpatched, that window is past overdue. Confidence: CISA KEV and Progress vendor bulletin confirmed. Full coverage: Kemp LoadMaster CVE-2026-8037 Lands on CISA KEV.

WordPress — unauthenticated admin takeover, three-CVE chain

CVE-2026-18468 / CVE-2026-18469 / CVE-2026-18470 in the Login & Register Forms plugin before 4.0.2. Three flaws in sequence: email confirmation bypass, insecure password reset, account takeover via predictable token. The chain requires no credentials. Outcome: full admin access to the WordPress installation. Update to 4.0.2 immediately. Confidence: chain and affected version confirmed via vulnerability disclosure. Full coverage: Three CVEs Chain to Admin Takeover in WordPress Login Plugin.

Ten MCP server CVEs — same day, same two vulnerability classes

On August 9, NVD received ten CVEs against ten distinct open-source MCP server implementations. All ten: server-side request forgery (SSRF) or path traversal. One vulnerability class targets URL-handling code in tool-facing handlers; the other targets file path resolution. Ten different projects, two patterns — the signature of a developer community shipping fast without security review. Coordinated disclosure batch. Most maintainers had not made public statements at time of publication.

If you operate AI pipelines built on open-source MCP server implementations, audit your stack against the August 9 NVD batch. Confidence: NVD batch publication confirmed. Full coverage: Ten MCP Server CVEs Drop in a Single Day.

China-linked actors weaponize N-able for ransomware delivery

Microsoft warned today that a China-linked threat actor is exploiting a critical N-able vulnerability to deploy ransomware — turning managed security tooling into a ransomware delivery mechanism against client networks. Attribution: Microsoft Threat Intelligence, reported via The Record. Confidence: Microsoft advisory confirmed high; full attack chain details medium-high pending further disclosure.

This pattern — compromising RMM infrastructure to pivot to managed endpoints — has appeared across multiple campaigns since 2023. If N-able is in your environment and CVE-2026-18577 is unpatched, this is the second compelling reason today. The first was CISA’s KEV listing two weeks ago.

Water utilities — ICS attacks, Iranian nexus, multiple states

Iranian-linked hackers targeted industrial control systems at water facilities in at least a dozen US states, SecurityWeek confirmed today. New Jersey and Alabama reported effects. ICS and SCADA systems at water treatment and distribution facilities were directly targeted. Attribution: Iranian nexus, confidence medium-high per SecurityWeek sourcing.

No CVE confirmed in connection with these attacks as of this writing. CISA’s joint advisory guidance for water and wastewater utilities remains the active defensive reference. If you operate OT in the water sector and are not running network segmentation between IT and OT environments, that is the structural exposure.

Also this week

  • Levi Strauss breach (Aug 10): Social engineering against three Levi Strauss employees, corporate data exfiltrated from their machines. No CVE — the access path bypassed technical controls through direct employee targeting. Attribution and full scope unconfirmed. Confidence: SecurityWeek report confirmed. Full coverage: Levi Strauss Breach: Social Engineering, Data Exfil.
  • Valve/Steam (Aug 10): Valve is notifying Steam hardware customers in Europe that their data was stolen after a threat actor breached CEVA Logistics, Valve’s shipping partner. Third-party supply chain compromise — not a flaw in Valve’s own infrastructure. Confidence: BleepingComputer report confirmed.
  • LexisNexis services offline (Aug 10): LexisNexis pulled Diligence, Metabase API, and Newsdesk offline after detecting unusual activity on servers managed by an unnamed third-party vendor. Root cause and scope unconfirmed. Confidence: BleepingComputer report confirmed; full scope low-confidence pending investigation.
  • GStreamer CVE-2026-19387 / CVE-2026-19389 (HIGH): Heap corruption in the ADPCM decoder (CVSS 7.6, crafted WAV, realistic path to code execution) and integer overflows in the ASF demuxer (CVSS 7.1, crafted WMV/WMA, crash to info disclosure range). Both triggered by attacker-controlled media files. GStreamer underlies most Linux desktop stacks. No reported exploitation; no KEV listing. Update gst-plugins-bad and gst-plugins-ugly. Confidence: Red Hat advisories confirmed. Full coverage: GStreamer Bugs Allow RCE Via Crafted Media Files.
  • Perl CVE-2026-15534 (CVSS pending): Signed 32-bit integer overflow in Perl’s superlinear regex cache enables heap out-of-bounds write on attacker-controlled regex input. Affects Perl through 5.45.1. Patch exists. Not a standalone remote issue — requires attacker-supplied strings to reach Perl regex evaluation. Applications that pass external input into complex regexes are in scope. Confidence: CVE assigned and patch confirmed; CVSS score pending at time of writing. Full coverage: Perl Heap OOB in Regex Engine Through 5.45.1.
  • Ash Framework CVE-2026-69659 / CVE-2026-70395: Two vulnerabilities in the Elixir Ash Framework. Coverage: Ash Framework Vulnerabilities: CVE-2026-69659 and CVE-2026-70395.

What to watch

  1. Metabase CVE assignment. No CVE ID yet. When NVD assigns one, remediation timelines formalize for organizations tracking via KEV and patch management tooling. Watch NVD and Metabase’s official channels.
  2. N-able + China-linked actor scope. Microsoft’s warning today does not fully disclose the campaign scale or targeting pattern. Further disclosure expected. Patch status for CVE-2026-18577 and N-central network segmentation are the immediate questions.
  3. Water sector ICS — federal advisory. Multi-state targeting with Iranian attribution is the profile that generates a CISA coordinated advisory. Watch US-CERT and CISA for additional guidance.
  4. LexisNexis scope. Unknown third-party vendor, unknown root cause, services involving due-diligence and newsdesk data. If you use LexisNexis Diligence or Newsdesk, confirm service status and data exposure posture directly with LexisNexis.
  5. MCP ecosystem disclosure. Ten CVEs from one apparent audit suggests the researcher may not be done. Additional MCP server CVEs likely. Audit your dependencies before the next batch.

— airgap

Sources