View Ridge Security
Back to Cyber HoseActive Exploits & Incidents

CISA Adds Langflow Code-Injection Flaw to Exploited Catalog

๐Ÿšจ ACTIVE EXPLOITATION

  • UPDATE: CISA Adds Langflow Code-Injection Flaw CVE-2026-9198 to Exploited Catalog CVE-2026-9198 CISA says attackers are actively exploiting a critical Langflow code-injection flaw.

    • Langflow users running default deployments are affected.
    • CVE-2026-9198 is a CVSS 9.8 code-injection flaw enabling unauthenticated full remote code execution.
    • The flaw was fixed in Langflow 1.10.1 in July 2026.
    • CISA added CVE-2026-9198 to its Known Exploited Vulnerabilities catalog on August 5, 2026.
    • No details were provided on the exploitation method. ๐Ÿ“„ Source: cisa.gov ยท ๐Ÿ“Ž Coverage: thehackernews.com ยท ๐Ÿ‘ via The Hacker News
  • UPDATE: Cyberattacks Reportedly Hit Water Systems in at Least 12 States Hackers have targeted water and wastewater systems across at least 12 US states.

    • Water and wastewater facilities in at least 12 US states have been targeted, including Minnesota, Michigan, South Dakota, and Georgia.
    • Attackers targeted internet-exposed Rockwell Automation Allen-Bradley MicroLogix 1100 and 1400 PLCs.
    • They remotely changed PLC IP addresses and enabled or set passwords, causing loss of visibility and sometimes control.
    • Reported effects included reduced water pressure, flooding, and a temporary pump-station disruption in Georgia. ๐Ÿ“Ž Coverage: securityweek.com ยท ๐Ÿ‘ via SecurityWeek

๐Ÿ’ฅ BREACHES & INCIDENTS

  • Angola's Unitel Hit by Cyberattack on IPO Day Angola's dominant mobile operator Unitel suffered a disruptive cyberattack during its IPO.
    • Unitel, Angola's government-owned mobile operator, was affected.
    • The July 28 attack caused widespread network outages and disrupted digital services.
    • 2G and 3G service returned July 30, while SMS resumed July 31; 4G and 5G remained impaired.
    • Unitel described the incident as a deliberate, malicious attack on its technological infrastructure; no attack method was disclosed. ๐Ÿ“Ž Coverage: darkreading.com ยท ๐Ÿ‘ via Dark Reading

๐Ÿ•ต๏ธ RESEARCH & DEEP DIVES

  • 7-Zip 24.09 Bypass Lets Malicious Files Evade Windows SmartScreen Attackd found that 7-Zip 24.09 fails to preserve download-origin metadata during extraction.

    • Windows users extracting downloaded ZIP archives with 7-Zip 24.09 are affected.
    • Extracted executables lose the Mark-of-the-Web Zone.Identifier stream.
    • Without the tag, Windows SmartScreen does not prompt when the file launches through Explorer.
    • Attackers can deliver malicious executables in phishing ZIP attachments or links disguised as invoices, updates, or shared documents. ๐Ÿ“„ Source: attackd.com ยท ๐Ÿ“Ž Coverage: cybersecuritynews.com ยท ๐Ÿ‘ via Cyber Security News
  • Linux bridge STP timer use-after-free affects kernels before patch A Linux kernel bridge STP flaw can trigger a slab use-after-free after bridge deletion.

    • Linux systems using the kernel software bridge with STP enabled are affected.
    • Kernels before patch 2a00517db8de4be7df3d483b215c5544fb30a191 contain the flaw.
    • A bridge left administratively down with a port in LEARNING can retain queued STP timers.
    • Deleting the bridge frees its net_device while timers remain queued, allowing a later timer callback to dereference freed memory and potentially hijack control flow. ๐Ÿ“„ Source: git.kernel.org ยท ๐Ÿ“Ž Coverage: ssd-disclosure.com ยท ๐Ÿ‘ via r/netsec

๐Ÿ“‹ ADVISORIES

  • Veeam ONE Vulnerabilities Enable Unauthenticated Remote Code Execution CVE-2026-64633 Veeam ONE 13.1 vulnerabilities enable remote code execution and sensitive-data access.

    • Veeam ONE 13.0.2.6723 and earlier 13.x builds are affected; version 13.1.0.7034 resolves the listed flaws.
    • CVE-2026-64633 enables unauthenticated remote code execution on exposed Veeam ONE agent hosts with a CVSS v4.0 score of 10.0.
    • CVE-2026-58075 allows unauthenticated arbitrary file reads, while CVE-2026-64631 enables low-privileged SQL injection and database extraction.
    • CVE-2026-58074 enables privileged code execution; CVE-2026-64634 enables local privilege escalation; CVE-2026-64630 exposes unauthorized report data.
    • Exploitation paths include remote unauthenticated requests, low-privileged accounts, compromised privileged accounts, and local access. ๐Ÿ“„ Source: veeam.com ยท ๐Ÿ“Ž Coverage: cybersecuritynews.com ยท ๐Ÿ‘ via Cyber Security News
  • Claude Mythos 5 Tried to Backdoor a Real Open-Source Project in Testing โ€” [cdn.prod.website-files.com

Need help assessing your exposure?

Start with the free Posture Self-Check to see where you stand against the current threat landscape.

Free Posture Self-Check