← All briefings

JetBrains TeamCity · Cisco Catalyst SD-WAN Manager & Controller · Progress MarkLogic Server

Date: 2026-08-06 Prepared for: SOC Analysts | Incident Responders | Vulnerability Management | Security Leadership


Executive Summary

CISA added CVE-2026-63077 (JetBrains TeamCity unauthenticated RCE via deserialization) to the KEV catalog with a three-day remediation deadline. Cisco disclosed a sweeping set of critical and high-severity vulnerabilities across Catalyst SD-WAN Manager/Controller and IOS XE Software, including two CVSS 9.9 privilege escalation flaws. Progress MarkLogic Server received a cluster of critical patches covering authentication bypass, SAML forgery, and privilege escalation. IBM Langflow OSS accumulated additional RCE and code-injection CVEs beyond yesterday’s KEV entry. BSI published new advisories for Veeam ONE, Aruba EdgeConnect SD-WAN Orchestrator, Lenovo XClarity Orchestrator, and Django.


Critical Vulnerabilities

CVE-2026-63077 — JetBrains TeamCity (Unauthenticated RCE via Deserialization)

  • Severity: Not formally scored (CISA KEV)
  • EPSS: Not yet scored
  • Technical detail: A deserialization of untrusted data vulnerability (CWE-502) in JetBrains TeamCity allows unauthenticated remote code execution via the agent polling protocol. The agent communication channel is typically network-accessible in CI/CD environments; no authentication is required to trigger deserialization. TeamCity is widely deployed in enterprise DevOps pipelines, making this a high-value target for supply-chain compromise.
  • Exploitation status: Actively exploited in the wild. Added to CISA KEV 2026-08-05; federal remediation deadline 2026-08-08.
  • Remediation: Apply the latest JetBrains TeamCity patch immediately. Restrict agent polling port access to known build agents via firewall rules. Audit recent build logs and agent connections for anomalous activity.

CVE-2026-20304 / CVE-2026-20303 — Cisco Catalyst SD-WAN Manager & Controller (Privilege Escalation)

  • Severity: CVSS 9.9 (both)
  • EPSS: 0 (newly published)
  • Technical detail: Two improper privilege management vulnerabilities discovered through Cisco’s internal security review affect the SQL/SPARQL/Optic REST query interfaces and REST API document patch operation of Cisco Catalyst SD-WAN Manager (all major branches from 17.x through 26.x) and SD-WAN Controller. An authenticated low-privileged user can escalate to full administrative control. The breadth of affected versions — spanning nearly a decade of releases — means most unpatched SD-WAN deployments are vulnerable. Compromise of the SD-WAN Manager provides full visibility and control over enterprise WAN routing policy.
  • Exploitation status: No confirmed exploitation; internally discovered.
  • Remediation: Apply Cisco SD-WAN Manager and Controller patches per the Cisco Security Advisory. Audit low-privileged REST API accounts for unauthorized privilege use; restrict REST API access to management networks.

CVE-2026-9192 — Progress MarkLogic Server (Authentication Bypass, Unauthenticated RCE)

  • Severity: CVSS 9.8
  • EPSS: 0 (newly published)
  • Technical detail: An authentication bypass in the ODBC App Server of MarkLogic Server (versions 11.0.0–11.3.5 and 12.0.0–12.0.2) allows an unauthenticated remote attacker to bypass password verification and execute arbitrary operations. MarkLogic is deployed as an enterprise NoSQL database in financial services, government, and healthcare sectors. This flaw is one of at least six critical/high vulnerabilities patched in the same release cycle, including SAML signature bypass (CVE-2026-7557, CVSS 9.1), HTTP request smuggling (CVE-2026-9190, CVSS 9.1), privilege escalation via SQL/SPARQL/Hadoop interfaces (CVE-2026-7329, CVE-2026-8709, CVE-2026-9193, all CVSS 9.9), and stored XSS in the Query Console (CVE-2026-9195, CVSS 9.3).
  • Exploitation status: No confirmed exploitation reported.
  • Remediation: Upgrade MarkLogic Server to 11.3.6 or 12.0.3. Restrict ODBC App Server and REST API exposure to trusted networks; disable SAML authentication if not required pending patch deployment.

CVE-2026-20272 — Cisco IOS XE Software (Unauthenticated RCE)

  • Severity: CVSS 9.8
  • EPSS: 0 (newly published)
  • Technical detail: Discovered through Cisco’s internal security review, this vulnerability in Cisco IOS XE Software affects a very broad range of versions (16.x through 26.x). The flaw allows an unauthenticated remote attacker to execute arbitrary code. Cisco IOS XE underpins a large proportion of enterprise routing and switching infrastructure globally. Five additional IOS XE vulnerabilities were published simultaneously (CVE-2026-20267, CVE-2026-20268, CVE-2026-20269, CVE-2026-20270, CVE-2026-20271, CVE-2026-20273, CVE-2026-20301), ranging from CVSS 8.6–9.0, covering DoS, privilege escalation, and further RCE vectors.
  • Exploitation status: No confirmed exploitation; internally discovered.
  • Remediation: Apply Cisco IOS XE Software updates per the Cisco Security Advisory. Prioritize internet-facing and perimeter devices; restrict management plane access to dedicated OOB networks.

CVE-2026-70426 — Jenkins Remoting (JEP-200 Filter Bypass, RCE)

  • Severity: CVSS 9.0
  • EPSS: 0 (newly published)
  • Technical detail: In Jenkins Remoting 3384.v60d89463d9e0 and earlier (Jenkins ≤2.575 / LTS ≤2.568.1), the JEP-200 class filter is not applied to classes resolved during deserialization of certain objects, allowing an attacker with agent-level access to bypass the security filter and achieve RCE on the Jenkins controller JVM. Jenkins is a critical component of enterprise CI/CD pipelines; controller compromise enables supply-chain attacks across all managed build jobs.
  • Exploitation status: No confirmed exploitation reported.
  • Remediation: Upgrade Jenkins to 2.576 (weekly) or 2.568.2 (LTS); update Remoting to 3385.vf1123fb_515da_ or 3355.3357.v931d3c992987. Restrict agent-to-controller trust boundaries; audit agent permissions.

ONGOING:

  • CVE-2026-9198 (IBM Langflow): Actively exploited; CISA KEV deadline 2026-08-07 — patch immediately, restrict to internal networks.
  • CVE-2026-34486 (Apache Tomcat): Actively exploited; CISA KEV deadline 2026-08-07 — apply latest Tomcat release.
  • CVE-2026-18556 / CVE-2026-18577 (N-able N-central): KEV deadlines 2026-08-06/07 — hotfix 2026.3.1.7 required; review N-able IOCs.
  • CVE-2026-58073/72/75 (Veeam VSPC): Upgrade to 9.3; restrict management interface.
  • CVE-2026-63455/56 (HPE EdgeConnect SD-WAN): Apply HPE patches; restrict REST API.
  • CVE-2026-16232 (Check Point SmartConsole): Actively exploited — treat unpatched instances as compromised.
  • CVE-2026-0257 (PAN-OS GlobalProtect): Qilin ransomware exploitation ongoing — patch immediately.

European Advisories

BSI published several new advisories on 2026-08-05:

[NEU] WID-SEC-2026-2661 — Aruba EdgeConnect SD-WAN Orchestrator: Multiple vulnerabilities allow unauthenticated remote attackers to bypass security controls, exposing confidential data and enabling data manipulation. Apply HPE/Aruba patches; restrict Orchestrator management access to trusted networks. Note: this advisory covers the same product family as CVE-2026-63455/56 reported yesterday — cross-reference Critical Vulnerabilities from 2026-08-05.

[NEU] WID-SEC-2026-2656 — Veeam ONE: Multiple vulnerabilities allow RCE, information disclosure, SQL injection, and privilege escalation. Apply Veeam ONE patches immediately; restrict management interface exposure.

[NEU] WID-SEC-2026-2660 — Lenovo XClarity Orchestrator: Vulnerabilities allow information disclosure and arbitrary OS command execution as a privileged user from an adjacent network. Apply Lenovo patches; segment XClarity management traffic.

[NEU] WID-SEC-2026-2649 — Django: Multiple vulnerabilities enable RCE, data manipulation, XSS, and DoS. Apply Django security updates; critical items are detailed in Critical Vulnerabilities if applicable.

[NEU] WID-SEC-2026-2648 — Langflow (RCE): Covered in Critical Vulnerabilities (CVE-2026-9198, yesterday’s report).

[UPDATE] WID-SEC-2026-2316 — Microsoft Windows: Updated advisory; apply current Patch Tuesday updates.

[UPDATE] WID-SEC-2026-2410 — IBM Langflow Desktop OSS: Updated to reflect additional CVEs published 2026-08-05 (see IBM Langflow cluster below); apply latest IBM Langflow OSS release.

BSI also updated advisories for GNU libc, Linux Kernel (multiple batches), Ruby, HCL BigFix, Red Hat Enterprise Linux (freeipmi), rsyslog, CPython, Rancher, and Apache Tomcat — apply vendor patches per standard patch cycles.


Active Threats and Campaigns

NEW — ClickFix macOS Campaign (250+ Domains, Browser Fingerprinting): Microsoft Threat Intelligence has tracked a macOS ClickFix operation now spanning more than 250 front-end domains. The infrastructure uses server-side browser fingerprinting to hide malicious lures from crawlers and sandboxes, presenting only selected Mac users with fake software download pages. This represents a significant operational security upgrade for ClickFix operators. Block ClickFix-associated domains at proxy; update macOS endpoint detection signatures; alert on unexpected osascript or clipboard-paste execution patterns.

NEW — Kali365 Device-Code Phishing Against US Enterprises: A phishing kit named Kali365 is abusing Microsoft’s OAuth 2.0 Device Authorization Grant flow, directing victims to approve attacker-controlled device codes on Microsoft’s legitimate authentication page. Once tokens are issued, attackers retain persistent access to email, documents, and cloud resources. Block device-code OAuth flow in Entra ID Conditional Access policies; alert on device-code grant approvals from unfamiliar locations or devices.

NEW — QuickFox VPN Supply-Chain Attack (FDMTP Backdoor): Fortinet FortiGuard Labs disclosed a supply-chain attack ongoing since at least August 2025 targeting QuickFox, a VPN tool used by overseas Chinese users. Trojanized Windows installers deliver the FDMTP backdoor. Organizations with Chinese-diaspora user populations or QuickFox deployments should audit endpoints for FDMTP indicators.

NEW — COLDCARD Phishing Campaign (ScreenConnect RAT): A phishing campaign exploiting fears around the recently disclosed COLDCARD hardware wallet vulnerability and a suspected $88.6M Bitcoin theft is tricking users into installing ConnectWise ScreenConnect. Alert on unauthorized ScreenConnect deployments; block RMM tools outside approved change windows.

ONGOING — ChainDrop npm Supply-Chain Worm: 1,300+ packages compromised; audit npm dependencies for poisoned keyv/cacheable packages; enforce lockfile integrity. ONGOING — Greatness PhaaS / Device-Code Phishing (Microsoft 365): Block device-code flow in Entra ID; alert on anomalous OAuth token grants. ONGOING — Midnight Blizzard hotel Wi-Fi campaign: Enforce VPN-before-browsing for traveling staff.


Security News and Context

  • Ransom Cartel creator sentenced: Maksim Silnikau, creator of the Ransom Cartel ransomware operation, was sentenced to 16 years in prison for attacks against at least 18 companies worldwide. Bleeping Computer
  • Snowflake data-theft guilty plea: A Canadian national pleaded guilty to accessing Snowflake customer accounts and stealing data from at least 165 organizations in an extortion scheme. Bleeping Computer
  • Trojanized npm packages use NullReceiver blockchain C2: Two malicious npm packages (bianira-ui, fluid-type-ui) decode C2 server IPs from Ethereum null-value transfers, evading traditional C2 detection. The Hacker News
  • OpenAI disrupts Poipet scam network: OpenAI banned a coordinated ChatGPT account network linked to a Cambodia-based operation running investment, romance, and law enforcement impersonation fraud schemes. The Hacker News

  1. CVE-2026-63077 (JetBrains TeamCity): Patch immediately — CISA KEV deadline 2026-08-08; restrict agent polling port to known build agents.
  2. CVE-2026-20304/20303 (Cisco SD-WAN): Apply Cisco SD-WAN Manager/Controller patches; audit low-privileged REST API accounts for privilege abuse.
  3. CVE-2026-20272 et al. (Cisco IOS XE): Apply IOS XE updates; prioritize perimeter and internet-facing devices.
  4. CVE-2026-9192 et al. (Progress MarkLogic): Upgrade to 11.3.6 or 12.0.3; restrict ODBC and REST API exposure.
  5. CVE-2026-70426 (Jenkins): Upgrade to Jenkins 2.576 / LTS 2.568.2; audit agent-to-controller trust boundaries.
  6. Veeam ONE (BSI WID-SEC-2026-2656): Apply Veeam ONE patches; restrict management interface.
  7. Lenovo XClarity Orchestrator (BSI WID-SEC-2026-2660): Apply Lenovo patches; segment XClarity management traffic.
  8. ClickFix macOS / Kali365 device-code phishing: Update macOS endpoint detection; block OAuth device-code flow in Entra ID Conditional Access.
  9. QuickFox / FDMTP backdoor: Audit endpoints with QuickFox installations for FDMTP indicators of compromise.
  10. Continue remediation of previously reported items: CVE-2026-9198 (Langflow, deadline 2026-08-07), CVE-2026-34486 (Tomcat, deadline 2026-08-07), CVE-2026-18556/18577 (N-central, deadlines 2026-08-06/07), CVE-2026-58073/72/75 (Veeam VSPC), CVE-2026-16232 (Check Point), CVE-2026-0257 (PAN-OS), CVE-2026-59309/10 (VMware vCenter).