Forwarded Cybersecurity Alert from Taiwan Computer Emergency Response Team/Coordination Center TWCERTCC-200-202608-00000009
【CVE-2026-18556】N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability (CVSS v4.0: 8.2)
【Ransomware Use: Unknown】 An authentication bypass vulnerability exists in N-able N-central, allowing attackers to bypass authentication mechanisms using an alternate path or channel.
【CVE-2026-18577】N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability (CVSS v4.0: 8.2)
【Ransomware Use: Unknown】 An authentication bypass vulnerability exists in N-able N-central, allowing attackers to bypass authentication mechanisms via an alternate path or channel and subsequently take over accounts in N-central. This vulnerability stems from an incomplete patch issued for CVE-2026-18556.
【CVE-2026-34486】Apache Tomcat Missing Encryption of Sensitive Data Vulnerability (CVSS v3.1: 7.5)
【Ransomware Use: Unknown】 A missing encryption of sensitive data vulnerability exists in Apache Tomcat, allowing attackers to exploit it to bypass EncryptInterceptor. This vulnerability can be chained with CVE-2025-24813.
【CVE-2026-9198】IBM Langflow Code Injection Vulnerability (CVSS v3.1: 9.8)
【Ransomware Use: Unknown】 A code injection vulnerability exists in Langflow, allowing unauthenticated attackers to achieve full remote code execution in default Langflow deployment environments.
【CVE-2026-63077】JetBrains TeamCity Deserialization of Untrusted Data Vulnerability (CVSS v3.1: 9.8)
【Ransomware Use: Unknown】 A deserialization of untrusted data vulnerability exists in JetBrains TeamCity, allowing attackers to execute remote code unauthenticated via the agent polling protocol.
【CVE-2026-8037】Progress LoadMaster Command Injection Vulnerability (CVSS v3.1: 9.6)
【Ransomware Use: Unknown】 A command injection vulnerability exists in Progress LoadMaster, allowing unauthenticated attackers to execute arbitrary commands on LoadMaster devices by leveraging unsanitized inputs across multiple command endpoints.