Continue reading the full briefing.
CVE-2026-48330: Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special…
Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary SQL commands, potentially gaining elevated access or control over the application. Exploitation of this…
Why it matters: CVE-2026-48330 may let attacker-controlled input cross into an interpreter or executable path, which can turn a reachable application feature into data access or code execution.
What to verify: Confirm the vulnerable route and authentication state, deploy the fixed release, review suspicious parameters and child processes, and test authorization boundaries after patching.
Operational focus: Map the affected product to asset owners and set a validation deadline before closing remediation.
Open the original NIST National Vulnerability Database record
CVE-2026-57092: Windows VMSwitch use-after-free privilege escalation
Microsoft describes a network-reachable VMSwitch use-after-free that lets an authorized attacker elevate privileges. The Microsoft CNA rates it 9.9 Critical.
Why it matters: Microsoft Windows VMSwitch is likely connected to identity, collaboration, or privileged Windows workloads, where one exposed role can widen impact beyond a single endpoint.
What to verify: Map supported builds and server roles, prioritize public and identity systems, confirm the installed update plus restart state, and review authentication and EDR telemetry for abnormal activity.
Operational focus: Look for exploitation indicators while patching, especially where the service was publicly reachable.
CVE-2026-10090: A flaw was found in the Application Subscription controller (multicluster-operators-subscription) of Red…
A flaw was found in the Application Subscription controller (multicluster-operators-subscription) of Red Hat Advanced Cluster Management for Kubernetes (ACM). A user with namespace-scoped "edit" privileges in an ACM hub namespace can create a Channel resource pointing to a Helm repository they control and a Subscription resource referencing it. The app-subscription controller fetches and applies the Helm chart contents…
Why it matters: CVE-2026-10090 may be embedded across servers, containers, appliances, and administration hosts. Package installation alone does not prove that the corrected code is running.
What to verify: Compare distribution package versions, identify the loaded kernel or library, plan required service restarts or reboots, and validate workload health after the change.
Operational focus: Check internet-facing and administrative instances first, then confirm the fixed version from the vendor.
Open the original NIST National Vulnerability Database record
CVE-2026-66747: Zbtlink router firmware ships an embedded remote-control implant, ENDLESSDOORS, present in every…
Zbtlink router firmware ships an embedded remote-control implant, ENDLESSDOORS, present in every published build across the product line. It is the open-source ycsunjane/rctl tool built in as an OpenWrt package (librctl.so), started at boot and run as root under the process name kworker to blend in with the kernel's [kworker/*] threads. It opens no listening port; it phones…
Why it matters: CVE-2026-66747 may be embedded across servers, containers, appliances, and administration hosts. Package installation alone does not prove that the corrected code is running.
What to verify: Compare distribution package versions, identify the loaded kernel or library, plan required service restarts or reboots, and validate workload health after the change.
Operational focus: Map the affected product to asset owners and set a validation deadline before closing remediation.
Open the original NIST National Vulnerability Database record
CVE-2026-70554: MaxSite CMS contains a PHP object injection vulnerability that allows unauthenticated attackers…
MaxSite CMS contains a PHP object injection vulnerability that allows unauthenticated attackers to execute arbitrary code by passing attacker-controlled serialized data in the maxsite_comuser cookie directly to unserialize() without validation or class allowlisting. Attackers can craft a malicious serialized PHP object payload delivered in a single HTTP request to trigger magic methods during object graph reconstruction, enabling property-oriented…
Why it matters: CVE-2026-70554 may let attacker-controlled input cross into an interpreter or executable path, which can turn a reachable application feature into data access or code execution.
What to verify: Confirm the vulnerable route and authentication state, deploy the fixed release, review suspicious parameters and child processes, and test authorization boundaries after patching.
Operational focus: Look for exploitation indicators while patching, especially where the service was publicly reachable.
Open the original NIST National Vulnerability Database record
CVE-2026-18577: N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability
N-able N-central contains an authentication bypass using an alternate path or channel allows for authentication bypass and account takeover in N-central. This vulnerability is the result of an incomplete patch for CVE-2026-18556.
Why it matters: N-able N-central concerns a trust decision rather than a cosmetic defect. If the affected path is reachable, an attacker may cross a role, tenant, or login boundary.
What to verify: Reproduce the expected access checks safely, identify exposed roles and tenants, invalidate risky sessions or tokens, patch the decision point, and retest denied cases.
CISA remediation date: 2026-08-06. Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance…
Operational focus: Check internet-facing and administrative instances first, then confirm the fixed version from the vendor.
Open the original CISA Known Exploited Vulnerabilities record
Triage and remediation plan
Move from exploit evidence to asset matching, containment, patching, and proof of remediation. A scanner finding is the start of the workflow, not the completion record.
- Compare every CISA KEV item with the external asset inventory and emergency patch queue.
- Confirm affected versions from vendor guidance instead of relying on scanner titles alone.
- Assign same-day owners to public, privileged, or business-critical matches.
- Preserve logs and review detection coverage while remediation is in progress.
- Document compensating controls and expiry dates for systems that cannot be patched immediately.
Evidence to confirm
Use these checks to decide whether an advisory is urgent in your environment and whether remediation is complete.
- Check internet-facing and administrative instances first, then confirm the fixed version from the vendor.
- Map the affected product to asset owners and set a validation deadline before closing remediation.
- Look for exploitation indicators while patching, especially where the service was publicly reachable.
Patch queue decision
The best patch order is the one that starts with exploited, reachable, and privileged systems, then records why every remaining item was deferred or found not applicable.
References used in this briefing
- NIST NVD and CISA KEV: CVE-2026-55255: Langflow cross-user flow authorization bypass
- CISA Known Exploited Vulnerabilities: CVE-2026-18556: N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability
- CISA Known Exploited Vulnerabilities: CVE-2026-34486: Apache Tomcat Missing Encryption of Sensitive Data Vulnerability
- CISA Known Exploited Vulnerabilities: CVE-2026-9198: IBM Langflow Code Injection Vulnerability
- NIST National Vulnerability Database: CVE-2026-48330: Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special…
- NIST NVD and Microsoft: CVE-2026-57092: Windows VMSwitch use-after-free privilege escalation
- NIST National Vulnerability Database: CVE-2026-10090: A flaw was found in the Application Subscription controller (multicluster-operators-subscription) of Red…
- NIST National Vulnerability Database: CVE-2026-66747: Zbtlink router firmware ships an embedded remote-control implant, ENDLESSDOORS, present in every…
- NIST National Vulnerability Database: CVE-2026-70554: MaxSite CMS contains a PHP object injection vulnerability that allows unauthenticated attackers…
- CISA Known Exploited Vulnerabilities: CVE-2026-18577: N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability
Need to add context to this briefing?
Send corrections, security tips, source updates, or collaboration notes through the contact page so the editorial team can review them properly.


