Cisco Secure Firewall Management Center · VMware vCenter Server · JetBrains TeamCity On-Premises *
Date: 2026-07-30 Prepared for: SOC Analysts | Incident Responders | Vulnerability Management | Security Leadership
Executive Summary
The most critical new development today is active zero-day exploitation of CVE-2026-20316, a hard-coded credential flaw in Cisco Secure Firewall Management Center, now added to the CISA KEV catalog with a 72-hour remediation deadline. A Russian state-sponsored group (Laundry Bear / Void Blizzard) is actively exploiting an Exchange OWA zero-day to deploy a persistent backdoor. New critical vulnerabilities in VMware vCenter (auth bypass), JetBrains TeamCity (unauthenticated RCE — status change), Gitea, and Ruby on Rails also demand urgent attention.
Critical Vulnerabilities
CVE-2026-20316 — Cisco Secure Firewall Management Center (FMC)
- Severity: High (CWE-259 — hard-coded password)
- EPSS: Not yet scored
- Technical detail: A hard-coded low-privileged account credential exists in Cisco FMC (formerly Firepower Management Center). An unauthenticated remote attacker can log in using this credential to access sensitive data on affected devices. The credential cannot be changed by administrators and is present across all affected versions. FMC is a central management plane for Cisco firewall deployments; compromise provides visibility into firewall policy, network topology, and potentially stored credentials.
- Exploitation status: Actively exploited as a zero-day; confirmed by Cisco and added to CISA KEV on 2026-07-29.
- Remediation: Apply Cisco’s security fix immediately. CISA BOD 26-04 deadline: 2026-08-01. Audit FMC access logs for unexpected low-privileged logins. Restrict FMC management access to trusted networks.
CVE-2026-59309 — VMware vCenter Server (Authentication Bypass)
- Severity: CVSS 9.8
- EPSS: Not yet scored
- Technical detail: Authentication bypass in VMware vCenter Server allows a malicious actor with network access to vCenter to bypass authentication entirely. Two companion critical flaws were disclosed simultaneously: one enabling code execution and one enabling VM escape across ESXi, Workstation, and Fusion. vCenter is a high-value target in enterprise environments — compromise enables lateral movement across the entire virtualized infrastructure. BSI advisory
WID-SEC-2026-2569covers the full VMware product set. - Exploitation status: No confirmed exploitation reported at time of publication; critical severity and network-exploitable attack vector warrant urgent prioritization.
- Remediation: Apply Broadcom/VMware security updates for vCenter, ESXi, Workstation, and Fusion immediately. Restrict vCenter management interfaces to trusted management networks.
CVE-2026-63077 — JetBrains TeamCity On-Premises (STATUS CHANGE)
- Severity: CVSS 9.8
- EPSS: 0 (newly published; high historical exploitation risk)
- Update: Heise Security published additional technical coverage on 2026-07-29 confirming the deserialization vector is reachable via the agent polling protocol and that CI/CD credential stores are directly at risk. No confirmed exploitation yet, but TeamCity has been weaponized within days of prior critical disclosures.
- Remediation: Upgrade to TeamCity 2025.11.7 or 2026.1.3; apply security patch plugin for 2017.1+ if upgrade is not immediately possible. Restrict agent polling port to known build agent IPs.
CVE-2026-60004 — Gitea
- Severity: CVSS 9.8
- EPSS: Not yet scored
- Technical detail: A user with ordinary repository write access can inject attacker-controlled content into a Git hook via crafted patch data, causing arbitrary shell commands to execute as the Gitea service account. Affects Gitea versions 1.17 through 1.27.0; fixed in 1.27.1. Self-hosted Gitea instances are common in European development environments and may run with elevated service account privileges. BSI advisory
WID-SEC-2026-2557confirms the risk. - Exploitation status: No confirmed exploitation; PoC details are publicly available in the disclosure.
- Remediation: Upgrade to Gitea 1.27.1 immediately. Audit repository write permissions; review Git hook configurations on existing repositories.
CVE-2026-66066 — Ruby on Rails (Active Storage)
- Severity: CVSS 9.5
- EPSS: Not yet scored
- Technical detail: A critical path traversal / arbitrary file read vulnerability in Rails Active Storage allows unauthenticated attackers to read arbitrary files from the application server by uploading crafted image files. Exposed data can include
secret_key_base, Rails master key, database passwords, and cloud storage credentials — effectively enabling full application compromise. Any Rails application using Active Storage with image processing is affected. - Exploitation status: No confirmed exploitation; unauthenticated attack vector and credential exposure impact make this high-urgency.
- Remediation: Apply the Rails security patch immediately. Rotate
secret_key_baseand all credentials stored in Rails credentials files on affected deployments. Review application logs for unexpected file access patterns.
ONGOING:
CVE-2026-16232(Check Point SmartConsole): Public PoC live, actively exploited — treat unpatched instances as compromised; patch and audit logs.CVE-2026-14512/CVE-2026-14446(IBM WebSphere): Pre-auth deserialization and admin console privilege escalation — apply IBM fixes; see alsoWID-SEC-2026-2564.CVE-2026-14529(IBM WebSphere Liberty — SSRF, CVSS 9.4): Apply IBM security fix; covered inWID-SEC-2026-2564.CVE-2026-59243(Apache Airflow FAB Provider — auth bypass, CVSS 9.8): Upgrade to FAB Provider 3.7.3; covered inWID-SEC-2026-2551.CVE-2026-8338(Coverity Connect — auth bypass, CVSS 9.2): Upgrade to 2026.6.0.CVE-2026-63077(JetBrains TeamCity): See STATUS CHANGE above.CVE-2026-0257(PAN-OS GlobalProtect): Qilin ransomware exploitation ongoing — patch immediately.CVE-2026-6875(ServiceNow AI Platform): Exploitation continues — patch and restrict access.CVE-2026-6516(ManageEngine ADAudit Plus): Unauthenticated RCE — upgrade to build 8606.CVE-2026-50522(SharePoint): KEV deadline passed — conduct compromise assessment.CVE-2025-68686(FortiOS): Patch and conduct full filesystem forensic review.- Certighost (ADCS): Working public PoC — audit certificate templates, monitor DCSync events.
European Advisories
BSI published the following new advisories on 2026-07-29:
WID-SEC-2026-2569 (VMware ESXi, vCenter, Workstation, Fusion): Multiple critical vulnerabilities enabling DoS, information disclosure, security bypass, and code execution. Critical items (CVE-2026-59309 and companions) are detailed in Critical Vulnerabilities above.
WID-SEC-2026-2572 (HashiCorp Terraform MCP Server): Multiple vulnerabilities allowing a remote unauthenticated attacker to bypass security controls, disclose sensitive information, and manipulate data. Related session-isolation flaws in consul-mcp-server (CVE-2026-16326, CVE-2026-16328) were also published. Organizations using HashiCorp MCP tooling should update to consul-mcp-server 0.1.4 and review Terraform MCP Server for available fixes.
WID-SEC-2026-2564 (IBM WebSphere Application Server / Liberty): Covers CVE-2026-14529 (SSRF, CVSS 9.4) and multiple additional flaws. Cross-reference: IBM WebSphere pre-auth deserialization (CVE-2026-14512) covered in Critical Vulnerabilities (yesterday’s report, ONGOING).
WID-SEC-2026-2563 (TeamViewer — macOS 2FA bypass): An authenticated remote attacker can bypass two-factor authentication to establish remote sessions under macOS under certain conditions. Apply the TeamViewer security update. Heise Security confirmed the bypass is specific to macOS.
WID-SEC-2026-2561 (Apache Traffic Server): Multiple vulnerabilities enabling security bypass, data disclosure/manipulation, DoS, and potential code execution by a remote unauthenticated attacker. Apply the latest Apache Traffic Server release.
WID-SEC-2026-2566 (Adobe Creative Cloud — Bridge and Format Plugins): Multiple vulnerabilities enabling arbitrary code execution and privilege escalation. Apply Adobe’s security updates.
WID-SEC-2026-2565 (BlackBerry UEM Management Console): XSS, DoS, and information disclosure vulnerabilities. Apply BlackBerry’s security updates.
WID-SEC-2026-2557 (Gitea — RCE): Covered in Critical Vulnerabilities above.
WID-SEC-2026-2568 (Xen): Privilege escalation, information disclosure, and DoS. Apply Xen security patches; relevant to cloud and virtualization infrastructure operators.
WID-SEC-2026-2552 / WID-SEC-2026-2553 (Red Hat OpenShift for Windows Containers / RHEL librest, pipewire): Multiple vulnerabilities enabling privilege escalation, information disclosure, and code execution. Apply Red Hat errata.
BSI also published updates (no material change) for: Mozilla Firefox/Thunderbird (WID-SEC-2026-2458), Google Chrome/Edge (WID-SEC-2026-2244, WID-SEC-2026-2092, WID-SEC-2026-2497), OpenSSL (WID-SEC-2026-1852), Golang Go (WID-SEC-2026-1776), Linux Kernel (WID-SEC-2025-0922, WID-SEC-2025-0545), Erlang/OTP (WID-SEC-2026-2533), Atlassian suite (WID-SEC-2026-2460), Red Hat Ansible (WID-SEC-2026-2452), Google Cloud Platform GKE (WID-SEC-2026-2009), and Python (WID-SEC-2023-1280) — apply vendor patches per standard cycles.
Active Threats and Campaigns
NEW — Laundry Bear / Void Blizzard (Russian state-sponsored) — Exchange OWA Zero-Day: The Russian state-sponsored group Laundry Bear (also tracked as Void Blizzard) is actively exploiting an unspecified zero-day vulnerability in Microsoft Exchange Outlook Web Access to deploy a sophisticated backdoor named OWAReaper, enabling long-term persistent mailbox access. No CVE has been publicly assigned at time of publication. Organizations running on-premises Exchange should immediately review OWA access logs for anomalous authentication patterns, unexpected module loads, or unusual ISAPI filter activity. Restrict OWA to VPN/trusted networks where operationally feasible.
NEW — SSH Cryptomining Bot with Hardware Reconnaissance: SANS ISC reports a new SSH bot that performs hardware profiling (CPU core count, RAM) before deploying a cryptominer, avoiding deployment on low-resource honeypots. Indicators include SSH brute-force followed by hardware enumeration commands (nproc, free -m). Enforce SSH key-based authentication and disable password authentication on all internet-facing Linux systems.
NEW — Flying Eagle Android RAT — Source Code Circulating: Source code for the Flying Eagle Android RAT framework is circulating on criminal Telegram channels. Hunt.io traced matching C2 panels and certificates to 170 internet servers. The RAT targets Android users via fake public-security applications. Relevant to organizations with BYOD policies or mobile device management programs — update mobile threat defense signatures.
NEW — Compromised joyfill npm Packages (DEV#POPPER RAT): Beta versions of @joyfill/layouts@0.1.2-2773.beta.0 and @joyfill/components@4.0.0-rc24-2773-beta.4 contain an import-time JavaScript implant delivering a RAT linked to the DEV#POPPER malware family. Audit Node.js dependency trees for these package versions and remove immediately.
STATUS CHANGE — ShinyHunters / Healthcare Sector: Health-ISAC issued a warning on 2026-07-29 of a measurable increase in successful ShinyHunters data theft attacks against healthcare and medical technology organizations. European healthcare organizations should review cloud storage bucket permissions, API key exposure, and credential hygiene.
ONGOING — Tengu Botnet (Mirai-derived): Hardware watchdog persistence; no new developments. Enforce strong credentials, disable Telnet on Linux/IoT devices.
ONGOING — Coordinated OT Attack on Minnesota Water Systems: 30+ water utilities targeted on 2026-07-26/27; one plant went offline. Primarily a US critical infrastructure event; European water sector operators should review OT network segmentation and remote access controls as a precautionary measure.
Security News and Context
- Cisco FMC zero-day / CISA KEV: Cisco confirmed active zero-day exploitation of
CVE-2026-20316; CISA added it to KEV with a 2026-08-01 deadline. See Critical Vulnerabilities. - Check Point SmartConsole PoC published: Rapid7 released full technical details and a working PoC for the actively exploited
CVE-2026-16232; exploitation risk is now significantly elevated for unpatched deployments. - CISA / NSA / FBI — 2026 SBOM Minimum Elements guidance: Updated joint guidance replaces the 2021 NTIA baseline; organizations should review software supply chain practices against the new minimum elements.
- UK NCSC — Forensic observability for network devices: NCSC blog highlights that too many network devices remain difficult to investigate post-compromise; relevant to incident response planning for network infrastructure.
- AI-generated extortion / fake ransomware leaks: Recorded Future published guidance on verifying data authenticity in the face of AI-fabricated extortion claims and fake leak sites.
Recommended Actions
- Cisco FMC (
CVE-2026-20316): Apply vendor patch before 2026-08-01 (CISA KEV deadline). Audit FMC access logs for unexpected low-privileged logins; restrict management access to trusted networks. - VMware vCenter/ESXi/Workstation/Fusion (
CVE-2026-59309and companions): Apply Broadcom security updates immediately; restrict vCenter management interfaces to trusted networks. - Exchange OWA (Laundry Bear zero-day): Review OWA access logs for anomalous authentication and ISAPI filter activity; restrict OWA to VPN/trusted networks where possible.
- Ruby on Rails Active Storage (
CVE-2026-66066): Apply Rails security patch; rotatesecret_key_baseand all credentials on affected deployments. - Gitea (
CVE-2026-60004): Upgrade to 1.27.1; audit repository write permissions and existing Git hook configurations. - TeamViewer (macOS 2FA bypass): Apply TeamViewer security update; review macOS remote session policies.
- HashiCorp consul-mcp-server / Terraform MCP Server: Upgrade consul-mcp-server to 0.1.4; review Terraform MCP Server for available fixes per
WID-SEC-2026-2572. - joyfill npm packages (DEV#POPPER RAT): Audit Node.js dependency trees for
@joyfill/layouts@0.1.2-2773.beta.0and@joyfill/components@4.0.0-rc24-2773-beta.4; remove and rotate any secrets accessible from affected environments. - Apache Traffic Server / Adobe Creative Cloud / BlackBerry UEM / Xen: Apply vendor patches per BSI advisories
WID-SEC-2026-2561,WID-SEC-2026-2566,WID-SEC-2026-2565,WID-SEC-2026-2568. - Continue remediation of previously reported items: Check Point SmartConsole (
CVE-2026-16232— PoC public), JetBrains TeamCity (CVE-2026-63077), IBM WebSphere (CVE-2026-14512/CVE-2026-14446), Apache Airflow FAB (CVE-2026-59243), PAN-OS (CVE-2026-0257), ServiceNow (CVE-2026-6875), ManageEngine (CVE-2026-6516), SharePoint (CVE-2026-50522), FortiOS (CVE-2025-68686), Certighost (ADCS).