Weekly Threat Brief: A KEV Tied to an AI Hacking Agent

Published: August 10, 2026

Week Ending: August 9, 2026 | Overall Risk Posture: High

CISA added five vulnerabilities to its Known Exploited Vulnerabilities catalog during the week ending August 9, spread across three alerts and four products: N-able N-central (two CVEs), IBM Langflow, Apache Tomcat, and Progress LoadMaster. That’s a routine week by 2026 standards.

What isn’t routine is the paper trail sitting next to one of these entries. Four days before CISA added the Tomcat vulnerability, Palo Alto Networks’ Unit 42 published a rare, ground-truth account of a threat actor wiring an AI model into an open-source agent framework and letting it hunt, select, and fire exploits with no human in the loop. Several outlets connected that report directly to this week’s KEV list. The connection is real — it’s the same operator — but the framing skips a detail that matters for how you prioritize: the autonomous part of that campaign didn’t work. The part that did was ordinary manual exploitation, the kind CISA has been cataloging for years.

Threat at a Glance

Product Exploited Weakness Defender Priority
Progress LoadMaster Unauthenticated command injection in the API used by LoadMaster’s management endpoints allows arbitrary command execution on the appliance. Confirm you’re on GA 7.2.63.2 / LTSF 7.2.54.18 or later. Federal due date is today, August 10.
N-able N-central Authentication bypass allowing full admin takeover of the RMM console — the second CVE exists because the first patch didn’t fully close the hole. Apply N-able’s current hotfix (guidance has moved more than once this week — verify against N-able’s advisory directly) and audit Take Control activity logs.
Apache Tomcat A fix for an earlier CVE still allowed attackers to bypass EncryptInterceptor, exposing the unauthenticated inter-node clustering channel. Upgrade to the current release — 11.0.24 / 10.1.57 / 9.0.120 as of this writing, not just 11.0.21 / 10.1.54 / 9.0.117, which only fixed this specific CVE. If clustering is enabled and internet-reachable, treat it as compromised until proven otherwise.
IBM Langflow Unauthenticated code injection giving full remote code execution on default Langflow deployments. Upgrade to 1.10.1 or later. Assume any internet-facing instance has already been scanned — mass exploitation began in early July.

Active Exploitation

  • Progress LoadMaster: two months of exposure, three-day clock
    CVE-2026-8037 affects Progress LoadMaster, an application delivery controller with more than 100,000 deployments worldwide. Unsanitized input in multiple API command endpoints lets an unauthenticated attacker execute arbitrary commands on the appliance.

    Progress rated it 9.6 and shipped a fix back in June — GA 7.2.63.2 and LTSF 7.2.54.18. Exploitation attempts began the day after watchTowr Labs published technical research on the flaw, and by the time CISA added it to KEV on August 7, telemetry showed nearly 800 attempts from dozens of IP addresses over roughly six weeks.

    Because LoadMaster sits at the network edge in front of critical internal services, CISA’s three-day remediation clock puts the federal deadline today, August 10. Shadowserver counts close to 300 instances still exposed to the internet.
  • N-able N-central: a patch that needed a patch
    CVE-2026-18556 and CVE-2026-18577 affect N-able N-central, the remote monitoring and management platform MSPs and enterprise IT teams use to administer servers, workstations, and network devices from one console. The first CVE was patched in version 2026.2. On August 2, N-able found the patch was incomplete — a second path still let unauthenticated attackers bypass authentication and take over the admin account.

    From there, attackers abused N-central’s built-in Take Control feature to reach managed endpoints and deployed Cloudflare tunnels for persistence. N-able has confirmed a “limited number” of customers were compromised without giving a count; Sophos independently confirmed at least one organization was breached, with the attacker pivoting from the N-central server to high-value endpoints including a backup server.

    N-able’s remediation guidance moved more than once over the following days as the scope became clearer. Verify the current fixed build against N-able’s own advisory rather than a version number from earlier in the week.
  • Apache Tomcat: manually exploited, then linked to an AI campaign
    CVE-2026-34486 affects Apache Tomcat’s clustering component. The fix for an earlier CVE (2026-29146) still let attackers bypass EncryptInterceptor, the mechanism that’s supposed to encrypt and authenticate traffic on Tomcat’s inter-node clustering channel — exposing it to a malicious serialized Java object.

    This is the CVE that ties to Unit 42’s report on an AI-driven hacking campaign, published four days before CISA’s addition. The overlap is real, but the exploitation of this specific flaw was manual, not autonomous — more on that below.

    CVE-2026-34486 itself was fixed in 11.0.21, 10.1.54, and 9.0.117 back in April — but Apache has since shipped further security releases addressing separate issues, putting the current baseline at 11.0.24, 10.1.57, and 9.0.120 as of this writing. Patch to the current release rather than stopping at the minimum version that closes this one CVE. If clustering is enabled and internet-reachable, treat it as a live investigation rather than a patch-and-close.
  • IBM Langflow: the mass-scan entry
    CVE-2026-9198 is an unauthenticated code-injection flaw in Langflow, the open-source platform for building AI agent workflows, giving full remote code execution on default deployments. It’s fixed in version 1.10.1.

    Telemetry cited by researchers puts exploitation attempts at roughly 650, originating from 244 unique IP addresses across 41 countries, running since early July. This is Langflow’s second actively exploited CVE inside a few months — the platform is now a standing target for opportunistic scanning regardless of which specific flaw is in play.

The scorecard behind the headline: two CVEs went through the AI actor’s autonomous track this summer — zero confirmed compromises. Five CVEs went through the same actor’s manual track — at least two confirmed compromises, plus the KEV entry sitting in this week’s list. If you’re prioritizing patches based on which flaw sounds more like an AI story, you’re optimizing for the wrong variable.

The AI Headline vs. the Manual Reality

Unit 42’s report, published July 30, documents a Chinese-speaking threat actor operating under the aliases knaithe and KnYuan, assessed to be based in Zhuhai and self-described as a “binary security researcher.” The actor wired DeepSeek into an open-source agent framework called Hermes Agent, using it as an autonomous offensive operator — independently enumerating internet-facing targets through the FOFA search engine, sourcing public exploit code, and launching attacks without further human input. A single Telegram command was enough to start a session; researchers found no evidence of further operator intervention. Unit 42 got this level of detail because the agent made a mistake — it started a file server from its own working directory instead of an isolated one, exposing its API keys, exploit scripts, target lists, and session logs to researchers.

The recovered session shows DeepSeek pivoting from a Langflow vulnerability — CVE-2026-33017, a different and unrelated CVE from the one in this week’s KEV list — to an n8n workflow-automation exploit chain after the first target proved unworkable. Both attempts failed: the Langflow flaw needed a configuration the target didn’t have, and the n8n exploit needed an unauthenticated form endpoint that none of the sampled targets exposed. DeepSeek reasoned through both dead ends and moved on entirely on its own. Unit 42’s point isn’t that the failures don’t matter — it’s that the reasoning loop worked exactly as an operator would.

Separately, the same actor ran conventional manual operations — FOFA enumeration, custom Python scanners, direct exploitation — against five other CVEs. This is where the confirmed damage happened: data exfiltration from three Citrix NetScaler targets, including a sustained session-hijacking attempt against a Malaysian government entity, and confirmed command execution on 11 exposed Marimo Notebook instances. The actor also attempted reverse-shell exploitation against nine Apache Tomcat servers using CVE-2026-34486 — the flaw that landed in this week’s KEV catalog. Unit 42’s report doesn’t confirm that attempt succeeded the way the NetScaler and Marimo activity did; it documents active exploitation attempts, not a confirmed compromise.

One clarification worth being precise about, since it’s the detail most coverage blurred: CISA does not attribute KEV additions to specific threat actors. The agency’s basis for adding CVE-2026-34486 is its own evidence of active exploitation in the wild — it isn’t a confirmation that the exploitation CISA observed is this specific campaign. The technique, target, and timing line up with what Unit 42 documented, and the overlap is genuinely notable. But “this actor’s manual attempt lines up with what CISA later catalogued” is a weaker and different claim than “the KEV entry confirms this actor’s success,” and the difference matters if you’re trying to scope an investigation.

There’s also a detail worth stating plainly because it cuts against the scarier version of this story. Unit 42 found that Claude Code’s entire session history on the actor’s exposed infrastructure — ten entries across three sessions — consisted of model checks, connectivity tests, and one package install, with no evidence it was used offensively. Attempted misuse of OpenAI’s Codex for exploit development was flagged and the associated account disabled by OpenAI’s own provider-side safety systems before Unit 42 shared its findings with them. The actor’s own stated reasoning, per Unit 42, was that DeepSeek — accessed through a framework with no client-side safety controls — was simply the path of least resistance compared to tools with provider-side guardrails.

Why “Patched” Isn’t Always Patched

Two of this week’s five entries are bypasses of earlier fixes, not first-time disclosures. N-central’s CVE-2026-18577 exists because the fix for CVE-2026-18556 was incomplete. Tomcat’s CVE-2026-34486 exists because the fix for an earlier CVE, 2026-29146, still left EncryptInterceptor bypassable. Neither vendor shipped a bad patch out of negligence — both closed the reported path and missed an adjacent one.

That’s the quieter pattern sitting underneath the AI headline this week: whether the attacker is a human running a Python scanner or a model reasoning over FOFA output, the flaws that keep getting exploited are disproportionately the ones where “patched” turned out to be incomplete. A version number that matches the vendor’s advisory from last month is not the same thing as confirmation that the specific bypass path is closed. Where possible, confirm remediation against the vendor’s current advisory, not a cached one.

Defender Priorities

  • Patch LoadMaster today if you haven’t
    The federal deadline lands on August 10 and nearly 300 instances are still exposed. Confirm the appliance version after patching rather than assuming the update succeeded.
  • Don’t trust N-central’s earlier fix number
    Pull N-able’s current advisory directly, apply the latest hotfix, and audit Take Control session logs for activity you can’t attribute to a known technician.
  • Treat exposed Tomcat clustering as a live investigation
    If clustering is enabled and internet-reachable, review for reverse-shell artifacts before and after upgrading to the current release — 11.0.24 / 10.1.57 / 9.0.120 as of this writing — not just the version that originally fixed CVE-2026-34486.
  • Assume internet-facing Langflow has already been probed
    Upgrade to 1.10.1 or later and review logs back to early July for the exploitation window already documented.
  • Separate confirmed attribution from plausible overlap
    If you’re investigating any of this week’s CVEs, don’t assume a named threat-actor campaign is responsible just because the technique and timing match a recent report — verify against your own indicators first.

Weekly Pulse

CISA added five vulnerabilities across four products this week, spread over three separate alerts — a heavier week than the one before it, and one with a rare piece of ground-truth attacker telemetry attached.

Langflow’s CVE-2026-9198 carries the highest severity score at 9.8, but the more instructive entry is Tomcat’s, where the timing overlap with Unit 42’s AI-agent report drew outsized attention to a flaw that was, in the end, exploited the ordinary way. LoadMaster is this week’s most time-pressured item, with a federal deadline landing today after roughly six weeks of climbing exploitation attempts against a patch that shipped in June.

The broader trend: incomplete remediation is doing as much work for attackers this week as new disclosures are. Two of five entries exist because an earlier fix didn’t fully close the door.

Bottom Line

CISA added five actively exploited vulnerabilities this week affecting Progress LoadMaster, N-able N-central, Apache Tomcat, and IBM Langflow.

One of them, the Tomcat flaw, was manually exploited by a threat actor who also ran a well-documented autonomous AI campaign against unrelated targets — a campaign that, on its own terms, failed twice. The capability is real, and Unit 42’s own read is that the failure margin was thin. But this week’s actual damage — the compromised N-central customers, the Tomcat reverse-shell attempts, the mass Langflow scanning — came from patches that were late, incomplete, or both.

The AI agent didn’t need to win. The unpatched box was already open.

Support independent security analysis

If you find ByteVanguard useful, you can support the site and help keep the analysis independent.

Support the analysis
Intelligence over headlines. Signal over noise.

Stay Connected

Report Intelligence
© 2026 ByteVanguard. Built for security professionals.