← All briefings

N-able N-central · Ruby on Rails Active Storage · Adobe Campaign Classic

Date: 2026-08-04 Prepared for: SOC Analysts | Incident Responders | Vulnerability Management | Security Leadership


Executive Summary

The most critical new development is active exploitation of CVE-2026-18577 (N-able N-central authentication bypass), now confirmed by N-able and added to the CISA KEV catalog with a 3-day remediation deadline. Rapid7 has published a detailed technical analysis and working Metasploit module for CVE-2026-66066 (Rails Active Storage RCE), significantly raising exploitation risk for that vulnerability. INC Ransomware is actively exploiting SonicWall SMA 1000 flaws. Midnight Blizzard (APT29) has been attributed to a global hotel Wi-Fi campaign targeting Microsoft 365 accounts.


Critical Vulnerabilities

CVE-2026-18577 — N-able N-central (Authentication Bypass, Actively Exploited)

  • Severity: CVSS 8.2
  • EPSS: Not yet scored
  • Technical detail: An incomplete patch for CVE-2026-18556 leaves N-central vulnerable to authentication bypass via an alternate path or channel (CWE-288), enabling full account takeover. N-able confirmed attackers have exploited this to gain remote administrative access to N-central servers and pivot to all managed customer endpoints. Affected builds are all versions prior to 2026.3.1.7, which shipped 2026-08-02. Both hosted and on-premises deployments are affected.
  • Exploitation status: Actively exploited in the wild. Added to CISA KEV 2026-08-03; federal deadline 2026-08-06.
  • Remediation: Upgrade immediately to N-central build 2026.3.1.7 or later. Enforce MFA on all N-central accounts; restrict management interfaces to dedicated management networks; audit for unauthorized access or configuration changes since the original advisory. Previously applied patches for CVE-2026-18556 are insufficient.

CVE-2026-66066 — Ruby on Rails Active Storage (Arbitrary File Read → RCE)

  • Severity: Not yet formally scored
  • EPSS: Not yet scored
  • Technical detail: STATUS CHANGE — Rapid7 published a full technical analysis and confirmed a working Metasploit module (exploit/multi/http/rails_activestorage_vips_rce). The attack chain exploits a trust failure between Rails’s content-type database value and libvips’s file-byte sniffing: a crafted MAT/HDF5 file stored as image/png via direct upload reaches libvips matload, which is marked VIPS_OPERATION_UNTRUSTED. HDF5 external storage then reads attacker-chosen file paths, enabling arbitrary file read. Recovery of SECRET_KEY_BASE from /proc/self/environ allows signing a malicious ImageProcessing variation using send/spawn or send/eval, achieving RCE. Affected: Rails Active Storage < 7.2.3.2, 8.0.x < 8.0.5.1, 8.1.x < 8.1.3.1 using the Vips processor.
  • Exploitation status: Public Metasploit module confirmed; exploitation in the wild not yet confirmed but must be assumed imminent.
  • Remediation: Upgrade to Rails 7.2.3.2, 8.0.5.1, or 8.1.3.1. Requires libvips ≥ 8.13 and ruby-vips ≥ 2.2.1. Rotate SECRET_KEY_BASE and all Rails signing secrets on affected instances. Restrict direct-upload endpoints where possible.

CVE-2026-48323 / CVE-2026-48331 / CVE-2026-48330 / CVE-2026-48326 / CVE-2026-48317 / CVE-2026-48333 — Adobe Campaign Classic

  • Severity: CVSS 10.0 (CVE-2026-48323, -48331, -48330); 9.9 (CVE-2026-48326); 9.8 (CVE-2026-48333); 9.6 (CVE-2026-48317)
  • EPSS: 0 (newly published)
  • Technical detail: Adobe published a new batch of critical vulnerabilities in Adobe Campaign Classic (ACC) v7 prior to build 9399. The batch includes: template injection enabling arbitrary code execution (CVE-2026-48323), SSRF leading to privilege escalation (CVE-2026-48331), SQL injection enabling arbitrary code execution (CVE-2026-48330, CVE-2026-48326), eval injection enabling RCE (CVE-2026-48317), and incorrect authorization enabling privilege escalation (CVE-2026-48333). These are distinct from the previously reported CVE-2026-48449 (CVSS 10.0 unauthenticated RCE). ACC is widely deployed in European enterprise marketing and communications environments.
  • Exploitation status: No confirmed exploitation; zero EPSS reflects recency. The CVSS 10.0 ratings and unauthenticated attack vectors make these high-priority targets.
  • Remediation: Upgrade ACC v7 to build 9399 immediately. Restrict ACC management interfaces to internal networks; review for signs of unauthorized access.

CVE-2026-62870 — Microsoft Office Excel (Use-After-Free, RCE)

  • Severity: CVSS 8.8
  • EPSS: 0 (newly published)
  • Technical detail: A use-after-free vulnerability in Microsoft Excel allows an unauthenticated attacker to execute code over a network. Affected products include Excel 2016, Office 2019, Office LTSC 2021/2024, and Microsoft 365 Apps for Enterprise. Network-exploitable RCE in a universally deployed productivity suite represents significant enterprise risk, particularly in phishing and malicious document delivery scenarios.
  • Exploitation status: No confirmed exploitation reported.
  • Remediation: Apply the latest Office security releases via Microsoft Update or the Office Security Releases page (https://aka.ms/OfficeSecurityReleases). Excel 2016 fixed at build 16.0.5561.1001.

CVE-2026-18667 — Tenable Sensor Proxy (RCE via Attacker-Controlled Host)

  • Severity: CVSS 9.3
  • EPSS: 0 (newly published)
  • Technical detail: A vulnerability in Tenable Sensor Proxy (versions prior to 1.4.2) allows a remote attacker to execute code with elevated privileges by inducing an operator to connect the sensor to an attacker-controlled host. This is a supply-chain-adjacent risk: if an attacker can intercept or redirect sensor connectivity (e.g., via DNS poisoning or network interception), they can achieve RCE on the sensor host. Relevant for organizations using Tenable.sc or Tenable.io with distributed sensor deployments.
  • Exploitation status: No confirmed exploitation reported.
  • Remediation: Upgrade Tenable Sensor Proxy to 1.4.2 or later. Ensure sensor-to-manager connectivity is restricted to known, verified endpoints; use network controls to prevent sensor redirection.

ONGOING:

  • CVE-2026-58062 et al. (Bouncy Castle for Java): Upgrade BC-JAVA to 1.85, BC-LTS-JAVA to 2.73.12; audit Java applications for bundled JARs.
  • CVE-2026-48449 (Adobe Campaign Classic): CVSS 10.0 unauthenticated RCE — patch to build 9399 now covers both this and the new batch above.
  • CVE-2026-68582 / CVE-2026-68581 (Vikunja): Upgrade to 2.4.0; audit API tokens.
  • CVE-2026-68579 (FreeRDP): Upgrade to 3.30.0.
  • CVE-2026-16232 (Check Point SmartConsole): Actively exploited — treat unpatched instances as compromised.
  • CVE-2026-0257 (PAN-OS GlobalProtect): Qilin ransomware exploitation ongoing — patch immediately.
  • CVE-2026-20316 (Cisco FMC): CISA KEV deadline passed — verify patch completion.
  • CVE-2026-59309/10 (VMware vCenter): No workarounds; patch urgently.

European Advisories

BSI published a significant volume of new and updated advisories on 2026-08-03. New advisories cover: rclone (multiple flaws including RCE, DoS, information disclosure, and security bypass — WID-SEC-2026-2623); Bouncy Castle (multiple cryptographic flaws — WID-SEC-2026-2622, covered in Critical Vulnerabilities yesterday); Wazuh (RCE, file manipulation, information disclosure — WID-SEC-2026-2620); IBM Langflow Desktop and IBM App Connect Enterprise (multiple RCE and bypass flaws — WID-SEC-2026-2619, WID-SEC-2026-2618); Microsoft Azure Cosmos DB (remote code execution — WID-SEC-2026-2617); pgAdmin (RCE, SQL injection, security bypass — WID-SEC-2026-2613); Gitea (RCE and information disclosure — WID-SEC-2026-2612); and cPanel/WHM (privilege escalation and file manipulation — WID-SEC-2026-2611). Updated advisories cover rsyslog, MariaDB, Red Hat Ansible Automation Platform, X.Org/Xwayland, Red Hat Enterprise Linux, Mozilla Firefox/Thunderbird, and multiple Linux Kernel batches. Apply vendor patches for all affected products; critical items are detailed in Critical Vulnerabilities.

Heise Security reports a cyberattack on the Government of Liechtenstein exposing 31,000 records from a personnel directory — relevant for European public sector security teams monitoring regional incident trends.

CVE-2026-18577 (N-able N-central): covered in Critical Vulnerabilities.

CERT-EU published its Cyber Brief 26-08 (July 2026 monthly executive summary) — available at cert.europa.eu (TLP:CLEAR).


Active Threats and Campaigns

NEW — Midnight Blizzard (APT29) Hotel Wi-Fi Campaign: Microsoft has attributed a global campaign targeting hospitality Wi-Fi networks to Midnight Blizzard (APT29). Custom malware is deployed via compromised hotel networks to breach Microsoft 365 accounts of guests. This is a direct evolution of the previously reported Storm-2945/CaptiveCrunch activity. Enforce VPN-before-browsing policy for all traveling staff; review M365 sign-in logs for anomalous geographic or network-based access.

NEW — INC Ransomware / SonicWall SMA 1000: INC Ransomware has emerged as the dominant threat actor exploiting recently disclosed SonicWall SMA 1000 series VPN vulnerabilities, with accelerating victim listings on its data leak site since early August 2026. Organizations running SonicWall SMA 1000 appliances should treat unpatched instances as potentially compromised and apply vendor patches immediately.

NEW — DOUBLECUP ClickFix Loader-as-a-Service: A new Russian loader-as-a-service named DOUBLECUP uses ClickFix social engineering to hide malicious code in PNG images cached by victims’ browsers, delivering CountLoader (Windows/macOS) and a new RAT named DeviceManager (Windows). Update endpoint detection signatures; block ClickFix-style browser-cache abuse patterns at the proxy layer.

NEW — Malicious npm Packages Targeting Alibaba Tool Users: 18 malicious npm packages targeting users of Alibaba developer tools were discovered, delivering a cross-platform RAT. The campaign targets Chinese-speaking development environments via supply-chain poisoning. Audit npm dependencies in development pipelines; enforce package integrity verification.

ONGOING — AMOS Stealer (macOS): Active; update macOS EDR signatures. ONGOING — XCSSET v40 (macOS/Xcode): Scan Xcode project repos; enforce code-signing. ONGOING — DeepSeek-assisted autonomous attacks: Ensure internet-facing systems are patched and monitored.


Security News and Context

  • Pass-ta-key attacks on Google Password Manager: Unit 42 and Bleeping Computer detail three attack paths (Pass-ta-key, Silver Pass-ta-key, Golden Pass-ta-key) allowing malware on a compromised Windows host to hijack Google-synced passkeys without user interaction — undermining passkey security assumptions. Bleeping Computer
  • UK Police National Legal Database breach: ExfilSquad leaked contact data of over 100,000 UK police officers and criminal justice professionals; incident identified 2026-07-26. Bleeping Computer
  • Arch Linux AUR updates suspended: Arch Linux blocked all AUR package adoption following a new malware wave via compromised AUR packages — audit AUR-sourced packages in build pipelines. Heise Security

  1. CVE-2026-18577 (N-able N-central): Upgrade to build 2026.3.1.7 immediately — CISA KEV deadline 2026-08-06; enforce MFA and audit for unauthorized access.
  2. CVE-2026-66066 (Rails Active Storage): Upgrade to patched Rails versions; rotate all signing secrets; treat as actively exploitable given public Metasploit module.
  3. Adobe Campaign Classic (CVE-2026-48323 et al.): Upgrade ACC v7 to build 9399; covers all new and previously reported ACC vulnerabilities.
  4. CVE-2026-62870 (Microsoft Excel): Apply current Office security releases across all affected Office versions and M365 Apps.
  5. CVE-2026-18667 (Tenable Sensor Proxy): Upgrade to 1.4.2; restrict sensor connectivity to verified endpoints.
  6. INC Ransomware / SonicWall SMA 1000: Apply SonicWall patches immediately; treat unpatched appliances as potentially compromised.
  7. Midnight Blizzard hotel Wi-Fi campaign: Enforce VPN-before-browsing for traveling staff; review M365 conditional access and sign-in anomalies.
  8. DOUBLECUP / malicious npm packages: Update endpoint detection signatures; audit npm dependencies and enforce package integrity controls.
  9. BSI advisories (Wazuh, pgAdmin, Gitea, cPanel, rclone, Azure Cosmos DB): Apply vendor patches; prioritize internet-facing and privileged management tools.
  10. Continue remediation of previously reported items: Bouncy Castle (CVE-2026-58062 et al.), FreeRDP (CVE-2026-68579), Vikunja (CVE-2026-68582/81), Check Point SmartConsole (CVE-2026-16232), PAN-OS (CVE-2026-0257), Cisco FMC (CVE-2026-20316), VMware vCenter (CVE-2026-59309/10).