What to patch now — 10 August 2026
Source: CISA Known Exploited Vulnerabilities (KEV) catalog — the most recently added entries as of today. Every vulnerability below has been confirmed by CISA as actively exploited in the wild, meaning attackers are already using it, not just researching it. If you (or a supplier) run any of this software, treat it as urgent.
1. Progress LoadMaster — no login needed to run commands on your load balancer (CVE-2026-8037)
🛠️ Progress LoadMaster · added 7 Aug 2026 · CISA fix-by date 10 Aug 2026 (due today)
What it is: "Command injection" means an attacker can smuggle their own operating-system commands into a request the device processes, and it runs them as if they were legitimate. LoadMaster (formerly Kemp) is a load balancer — the appliance that sits in front of a business's website or application and spreads incoming traffic across multiple servers. Here, an outsider with no login at all can reach that command layer.
Who's affected: Businesses, or the hosting/IT provider running their infrastructure, using a Progress LoadMaster appliance or virtual instance to manage traffic to a website or application with more than one server behind it.
What to do: Apply Progress's fix today — CISA's deadline is today, and no login is required to exploit it. If a hosting or infrastructure provider runs your load balancing, ask directly whether LoadMaster is in their stack and whether it's patched.
2. JetBrains TeamCity — a flaw in the tool that builds and ships your team's code (CVE-2026-63077)
🛠️ JetBrains TeamCity · added 5 Aug 2026 · CISA fix-by date 8 Aug 2026 (already passed)
What it is: "Deserialization of untrusted data" means the software unpacks incoming data as if it were safe, structured content, but a crafted package can make it run as code instead. TeamCity is a continuous-integration server — the system a development team points at their code repository to automatically build, test and package software before it goes live. This flaw lets an attacker trigger that unpacking flaw with no login, through the channel TeamCity uses to talk to its build agents.
Who's affected: Businesses with an in-house or contracted development team that runs its own TeamCity server to build and deploy software — common wherever a company ships its own app, website backend, or internal tooling rather than buying it off the shelf.
What to do: Update TeamCity to the version in JetBrains' advisory now — the CISA deadline has already passed. If a development team or agency builds software for you, ask whether they self-host TeamCity and, if so, whether it's patched; a compromised build server can let an attacker slip malicious code into everything it ships afterward.
3–4. N-able N-central — two related bugs let an outsider bypass login on the tool your IT provider uses to manage you (CVE-2026-18577, CVE-2026-18556)
🛠️ N-able N-central · added 3–4 Aug 2026 · CISA fix-by dates 6 / 7 Aug 2026 (already passed)
What it is: "Authentication bypass using an alternate path or channel" means there's a side door into the system that skips the normal login check entirely. N-central is an RMM ("remote monitoring and management") platform — the console an outsourced IT provider or managed service provider (MSP) uses to remotely watch over and administer their clients' computers and servers. CISA added two of these bypass flaws within a day of each other; the second is described as leaving the door open even after the first fix, so one patch alone isn't enough.
Who's affected: You may never have heard of N-central, but if an external IT company manages your computers, servers or network, there's a real chance they use it. Because one N-central instance typically controls every client an MSP looks after, a breach here isn't limited to one business — it's a way in to all of them at once.
What to do: Ask your IT provider, in plain terms, whether they use N-able N-central and whether both of these fixes are applied — not just the first. This is exactly the kind of software that's invisible to the business being protected by it, which is precisely why it's worth asking about directly rather than assuming it's covered.
5. Apache Tomcat — a fix from last year gets a way around it (CVE-2026-34486)
🛠️ Apache Tomcat · added 4 Aug 2026 · CISA fix-by date 7 Aug 2026 (already passed)
What it is: "Missing encryption of sensitive data" here means a protection Tomcat added called EncryptInterceptor — designed to keep server-to-server traffic encrypted — can be sidestepped, undoing that protection. CISA notes this flaw can be chained with an older, previously fixed Tomcat bug (CVE-2025-24813) to achieve a fuller compromise, meaning last year's patch alone no longer closes the door.
Who's affected: Businesses running their own Apache Tomcat server to host a Java-based website or application — usually set up by a developer or hosting provider rather than something you'd install yourself.
What to do: Update Tomcat to the fixed version. If a developer or host manages your Tomcat server, confirm this specific update has been applied on top of last year's fix — the two are designed to work together, and one without the other isn't a complete fix.
6. IBM Langflow — full remote takeover with no login, on an AI workflow tool (CVE-2026-9198)
🛠️ IBM Langflow · added 4 Aug 2026 · CISA fix-by date 7 Aug 2026 (already passed)
What it is: "Code injection" means an attacker can insert their own instructions into data the application processes, and have those instructions run as if they were part of the program. Here it gives an unauthenticated outsider full remote code execution on a default Langflow install — no login, no trickery needed beyond sending the request. CISA lists this as a separate advisory from the unrelated Langflow flaw in entry 14 below, under a different vendor tag (IBM) — patch each on its own, since one fix does not cover the other.
Who's affected: Businesses that have stood up Langflow (via IBM's distribution) to build internal AI chatbots or automation workflows — increasingly common as small businesses experiment with in-house AI tooling, usually self-hosted by a developer or technical staff member.
What to do: Apply IBM's fix now — the deadline has already passed and no login is required to exploit it. If someone on your team or a contractor set up an AI workflow tool, check specifically which Langflow distribution it is and whether it's patched.
7. Cisco Secure Firewall Management Center — a built-in password lets anyone log in (CVE-2026-20316)
🛠️ Cisco Secure Firewall Management Center (FMC) · added 29 Jul 2026 · CISA fix-by date 1 Aug 2026 (over a week overdue)
What it is: "Use of a hard-coded password" means the software ships with a built-in login that's the same on every installation and can't be changed by the customer. That fixed credential lets anyone on the internet log in to FMC — the console businesses and IT providers use to manage their Cisco firewalls — using a low-privileged account, and from there reach sensitive configuration data on the box.
Who's affected: Any business, or the IT/security provider that manages their network, running Cisco Secure FMC to administer their firewalls.
What to do: If this hasn't been applied yet, it's now well past CISA's original 3-day window — treat it as an active gap, not a routine backlog item. Ask whoever manages your Cisco firewalls to confirm the management console itself, not just the firewalls it controls, has been patched.
8. Fortinet FortiOS — a way back in even after you've been patched (CVE-2025-68686)
🛠️ Fortinet FortiOS · added 27 Jul 2026 · CISA fix-by date 10 Aug 2026 (due today)
What it is: This one only matters if an attacker already got a foothold on your FortiGate device through a separate, earlier flaw. Fortinet had shipped a fix removing a "symbolic link" trick attackers used to quietly keep read access to the file system even after being cleaned up. This flaw is a way to sidestep that fix using ordinary-looking web requests, and re-establish that same persistence.
Who's affected: Businesses running Fortinet FortiGate firewalls (FortiOS), particularly anyone whose device was ever flagged in the earlier "symlink" incident reported through 2024–2025.
What to do: Apply Fortinet's update today — the deadline is today. If your FortiGate was ever named in that earlier incident or you're not sure, have your IT provider check the device for lingering access rather than assuming the original clean-up was final.
9. Arista VeloCloud Orchestrator — one flaw takes over the box managing your whole SD-WAN (CVE-2026-16812)
🛠️ Arista VeloCloud Orchestrator (on-prem) · added 27 Jul 2026 · CISA fix-by date 30 Jul 2026 (over a week overdue)
What it is: "OS command injection" means an attacker can smuggle their own operating-system-level commands into a request the software processes, so the server runs commands it was never meant to accept from an outsider. Here it hits the Orchestrator — the central control point for a VeloCloud SD-WAN — giving an attacker privileged access to the box that manages the network links between a business's sites.
Who's affected: Businesses (typically multi-site or franchise operations) running their own on-prem VeloCloud Orchestrator to connect offices or shops together, rather than a version fully hosted by Arista.
What to do: If unpatched, this is now significantly overdue. Ask a network provider who set up your SD-WAN to confirm directly whether the on-prem orchestrator, not just the individual site devices, has been patched.
10. Check Point SmartConsole — attackers get full admin login tokens with no password (CVE-2026-16232)
🛠️ Check Point SmartConsole · added 22 Jul 2026 · CISA fix-by date 25 Jul 2026 (over two weeks overdue)
What it is: "Improper authentication" means the system doesn't correctly verify who's asking before handing something sensitive over. SmartConsole — the console admins use to configure Check Point security devices — can be tricked into handing out valid login tokens to an attacker who never logged in, and those tokens carry full administrator rights.
Who's affected: Businesses (or their IT/security provider) that manage Check Point firewalls or other security appliances through SmartConsole.
What to do: This is now well past due. Ask whoever manages your Check Point kit to confirm today — a compromised management console can mean a compromised firewall.
11. Microsoft SharePoint — a third confirmed flaw, still open (CVE-2026-50522)
🛠️ Microsoft SharePoint · added 22 Jul 2026 · CISA fix-by date 25 Jul 2026 (over two weeks overdue)
What it is: "Deserialization of untrusted data" means the software unpacks incoming data as if it were safe, structured content, but a crafted package can make it run as code instead, handing an attacker the ability to execute their own commands on the server. This is a distinct bug from the older SharePoint flaw further down this list; fixing one does not cover the other.
Who's affected: Businesses running an on-premises SharePoint Server. Cloud "SharePoint Online" inside Microsoft 365 is patched centrally by Microsoft and isn't affected.
What to do: If your organisation runs SharePoint on its own server, confirm with whoever manages it that every SharePoint security update released this year has actually been applied — this fix is now two weeks overdue.
12–13. WordPress Core — two flaws that chain into a takeover with no login needed (CVE-2026-60137, CVE-2026-63030)
🛠️ WordPress Core · added 21 Jul 2026 · CISA fix-by dates 4 Aug / 24 Jul 2026 (both passed)
What it is: "SQL injection" means an attacker sneaks database commands into a form field or web-address parameter the site wasn't expecting, tricking the database into running them. The second flaw, an "interpretation conflict," is a separate quirk that lets that injected command be read differently by WordPress than intended, and CISA confirms the two can be chained together into full remote code execution without ever logging in.
Who's affected: Any business running a self-hosted WordPress website — a huge share of small-business sites, whether it's the main site, a blog, or a customer-facing shop.
What to do: Update to WordPress 7.0.2 or later if this hasn't happened yet. If a web designer or agency manages your site, confirm the update is live; many hosts apply core updates automatically, but it's worth checking rather than assuming, especially given how overdue this now is.
14. Langflow — a flaw in a popular AI workflow-builder lets outsiders run their own code (CVE-2026-0770)
🛠️ Langflow · added 21 Jul 2026 · CISA fix-by date 24 Jul 2026 (over two weeks overdue)
What it is: "Inclusion of functionality from an untrusted control sphere" is the formal way of saying the software will load and run functionality handed to it from a source it shouldn't trust, letting an outsider supply code that then executes as if it were part of the trusted application. Note this is a separate CISA advisory from entry 6 above (IBM Langflow) — two different vendor listings for related tooling, each needing its own fix confirmed.
Who's affected: Businesses that have set up their own Langflow instance to build internal AI chatbots or automation workflows, usually self-hosted on a cloud server by a developer or technical staff member.
What to do: Update to Langflow 1.9.0 or later. If someone on your team, or a contractor, set up an AI tool using Langflow, check with them directly which distribution it is and whether it's patched — this fix is now well overdue.
15. DD-WRT router firmware — a 15-year-old bug, still unpatched on some routers (CVE-2021-27137)
🛠️ DD-WRT · added 21 Jul 2026 · CISA fix-by date 24 Jul 2026 (over two weeks overdue)
What it is: A "stack-based buffer overflow" happens when a program tries to cram more data into a fixed-size piece of memory than it was built to hold, spilling into space it doesn't own, which an attacker can exploit to make the device run their own code instead of its own. This one sits in UPnP, the feature that lets devices on a network automatically open ports for themselves.
Who's affected: Businesses or tech-savvy owners running DD-WRT, a free, open-source alternative firmware some people install on their own router in place of the manufacturer's software.
What to do: Update to a DD-WRT build that includes this fix. If you're not sure whether your router runs DD-WRT, check its admin page (often at an address like 192.168.1.1) for the firmware name. As an immediate mitigation either way, turning off UPnP in your router settings closes this specific door — most small businesses don't need it switched on.
This is an awareness summary of public CISA KEV data, not professional security advice. CISA "fix-by" dates are US federal deadlines; for everyone else they're a strong urgency signal, not a legal obligation. Always confirm the affected versions and the fix against the vendor's own advisory.