Critical CVE Live Watch for August 4, 2026: Exploited and High-Risk Vulnerabilities

Critical CVE Live Watch for August 4, 2026: Exploited and High-Risk Vulnerabilities

A live vulnerability watch focused on exploited flaws, critical and high-severity records, remediation deadlines, and practical patch priority.

Exploit-led priority

The fastest way to reduce vulnerability risk is to combine exploitation evidence with your own exposure. This briefing separates CISA KEV entries from newly published high-severity records so patch teams can see which signals carry the strongest urgency.

For August 4, 2026, the lead development is CVE-2026-55255: Langflow cross-user flow authorization bypass. Start by confirming where Langflow Langflow before 1.9.1 is deployed, who owns it, and whether the affected path is reachable. The remaining items below add the product-specific context needed to turn the headline into an owned security decision.

Vulnerabilities requiring action

CVE-2026-55255: Langflow cross-user flow authorization bypass

NIST NVD and CISA KEV | July 7, 2026 | Known Exploited | CVSS 8.4 | Langflow Langflow before 1.9.1

Before version 1.9.1, an authenticated attacker could specify another user's flow ID and execute that flow. The CNA rates the issue 8.4 High, and CISA lists active exploitation.

Why it matters: Langflow Langflow before 1.9.1 can combine untrusted text with connectors, stored credentials, and tool permissions. The meaningful risk is what the surrounding agent is allowed to read, change, or send.

What to verify: Test with hostile input in an isolated environment, inspect connector scopes and retained context, require approval for sensitive actions, and confirm that tool calls are logged and attributable.

CISA remediation date: 2026-07-10. Apply the current Langflow fix and follow CISA KEV remediation guidance.

Operational focus: Check internet-facing and administrative instances first, then confirm the fixed version from the vendor.

Open the original NIST NVD and CISA KEV record

CVE-2026-18577: N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability

CISA Known Exploited Vulnerabilities | August 3, 2026 | Known Exploited | N-able N-central

N-able N-central contains an authentication bypass using an alternate path or channel allows for authentication bypass and account takeover in N-central. This vulnerability is the result of an incomplete patch for CVE-2026-18556.

Why it matters: N-able N-central concerns a trust decision rather than a cosmetic defect. If the affected path is reachable, an attacker may cross a role, tenant, or login boundary.

What to verify: Reproduce the expected access checks safely, identify exposed roles and tenants, invalidate risky sessions or tokens, patch the decision point, and retest denied cases.

CISA remediation date: 2026-08-06. Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance…

Operational focus: Map the affected product to asset owners and set a validation deadline before closing remediation.

Open the original CISA Known Exploited Vulnerabilities record

CVE-2026-20316: Cisco Secure Firewall Management Center Use of Hard-coded Password Vulnerability

CISA Known Exploited Vulnerabilities | July 29, 2026 | Known Exploited | Cisco Secure Firewall Management Center (FMC)

Cisco Secure Firewall Management Center (FMC) formerly known as Firepower Management Center contains a use of hard-coded password vulnerability that could allow an unauthenticated, remote attacker to log in to an affected device using a low-privileged account to access sensitive data within the impacted systems.

Why it matters: Cisco Secure Firewall Management Center (FMC) belongs in an exploit-led queue only after the affected product is matched to a reachable asset and accountable owner.

What to verify: Separate confirmed applicability from broad advisory language, assign the remediation decision, and keep any exception visible with an expiry date.

CISA remediation date: 2026-08-01. Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance…

Operational focus: Look for exploitation indicators while patching, especially where the service was publicly reachable.

Open the original CISA Known Exploited Vulnerabilities record

CVE-2025-68686: Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability

CISA Known Exploited Vulnerabilities | July 27, 2026 | Known Exploited | Fortinet FortiOS

Fortinet FortiOS contains an exposure of sensitive information to an unauthorized actor vulnerability. This may allow a remote unauthenticated attacker to bypass the patch developed for the symbolic link persistency mechanism observed in some post-exploit cases, via crafted HTTP requests. An attacker would need first to have compromised the product via another vulnerability, at filesystem level.

Why it matters: Fortinet FortiOS commonly protects an internet edge or management boundary. Exposure there can affect remote access, traffic inspection, credentials, and the trust placed in downstream systems.

What to verify: Check the running firmware and model, restrict management access, compare configuration changes and new accounts, preserve independent logs, and rotate credentials if compromise cannot be excluded.

Continue reading the full briefing.

Corrections and tips

Need to add context to this briefing?

Send corrections, security tips, source updates, or collaboration notes through the contact page so the editorial team can review them properly.

Contact InfoSecNexus