CVE Intelligence
Actively exploited vulnerabilities from CISA's Known Exploited Vulnerabilities catalog — with IT Intelligence's analysis of real-world impact and specific remediation steps.
Actively exploited vulnerabilities from CISA's Known Exploited Vulnerabilities catalog — with IT Intelligence's analysis of real-world impact and specific remediation steps.
Updated August 6, 2026
Patch TeamCity to prevent code execution
JetBrains TeamCity contains a deserialization of untrusted data vulnerability, allowing remote code execution via the agent polling protocol. This vulnerability poses a significant risk to organizations using TeamCity, as it can be exploited by unauthenticated attackers. Immediate attention is required to prevent potential attacks.
Update N-central to fix authentication bypass
N-able N-central contains an authentication bypass vulnerability using an alternate path or channel, allowing attackers to bypass authentication mechanisms. This vulnerability can be exploited by attackers to gain unauthorized access to the system, potentially leading to data breaches and system compromise. Immediate attention is required to prevent potential attacks.
Patch Apache Tomcat to encrypt sensitive data
Apache Tomcat contains a missing encryption of sensitive data vulnerability, allowing attackers to bypass the EncryptInterceptor. This vulnerability poses a moderate risk to organizations using Tomcat, as it can be exploited by attackers to access sensitive data. Immediate attention is recommended to prevent potential attacks.
Update Langflow to prevent code injection
IBM Langflow contains a code injection vulnerability, allowing unauthenticated attackers to achieve full remote code execution on default deployments. This vulnerability poses a significant risk to organizations using Langflow, as it can be exploited by attackers to gain complete control over the system. Immediate attention is required to prevent potential attacks.
Update N-central to fix incomplete patch
N-able N-central contains an authentication bypass vulnerability using an alternate path or channel, allowing attackers to bypass authentication mechanisms. This vulnerability is the result of an incomplete patch for CVE-2026-18556 and poses a significant risk to organizations using N-central. Immediate attention is required to prevent potential attacks.
Update Cisco FMC to fix hard-coded password
Cisco Secure Firewall Management Center contains a use of hard-coded password vulnerability, allowing unauthenticated attackers to log in to an affected device using a low-privileged account. This vulnerability poses a significant risk to organizations using Cisco FMC, as it can be exploited by attackers to gain access to sensitive data. Immediate attention is required to prevent potential attacks.
Update FortiOS to fix information exposure
Fortinet FortiOS contains an exposure of sensitive information to an unauthorized actor vulnerability, allowing remote unauthenticated attackers to bypass the patch developed for the symbolic link persistency mechanism. This vulnerability poses a moderate risk to organizations using FortiOS, as it can be exploited by attackers to gain access to sensitive information. Immediate attention is recommended to prevent potential attacks.
Patch VeloCloud Orchestrator to prevent command injection
Arista VeloCloud Orchestrator contains an OS command injection vulnerability, allowing remote attackers to access privileged internal functionality and impact the VCO host. This vulnerability poses a significant risk to organizations using VeloCloud Orchestrator, as it can be exploited by attackers to gain control over the system. Immediate attention is required to prevent potential attacks.