ThreatScope by DIAMATIX
N-central, TeamCity, LoadMaster and AI Infrastructure Risks (August 4–11, 2026)
Reporting period: August 4–11, 2026
Threat level: Critical
🎧 Listen to this week’s ThreatScope (audio brief)
Executive Snapshot
| Executive Snapshot | |
|---|---|
| Highest Risk | N-able N-central |
| Internet-facing Priority | N-central, JetBrains TeamCity, Progress LoadMaster, IBM Langflow |
| CI/CD Infrastructure Risk | JetBrains TeamCity, Jenkins |
| Active Exploitation | N-central, TeamCity, LoadMaster, Langflow, Apache Tomcat |
| Additional Threat Activity | Gunra ransomware, OT/ICS and transportation advisories |
This week’s ThreatScope covers five newly exploited vulnerabilities added to the CISA Known Exploited Vulnerabilities (KEV) Catalog, together with a significant Jenkins security release, ransomware activity and new operational technology advisories.
The highest priority is N-able N-central, where attackers obtained unauthenticated administrative access and subsequently used legitimate remote-management functionality to access managed endpoints. Observed activity also included deployment of Cloudflare tunnels for persistence.
JetBrains TeamCity, Progress LoadMaster and IBM Langflow are also under confirmed active exploitation. Their position within CI/CD, application delivery and AI environments creates the potential for compromise to extend beyond the initially affected platform.
This reporting period reinforces an important operational distinction. Installing a security update closes a vulnerability, but it does not establish whether exploitation occurred before remediation. For exposed management and CI/CD platforms, patching should be combined with compromise assessment, credential review and validation of downstream systems.
Is This Report Relevant to Your Organization?
This report is particularly relevant if your organization operates any of the following technologies or environments.
| Technology or Environment | Commonly Found In | Why It Matters |
|---|---|---|
| N-able N-central | MSPs, MSSPs, IT service providers, internal IT operations | Provides centralized administrative and remote-control access to managed endpoints |
| JetBrains TeamCity | Software vendors, SaaS, DevOps teams, enterprise development | May contain source code, deployment credentials, signing material and access to downstream environments |
| Progress LoadMaster | Enterprise, data centres, cloud and application infrastructure | Operates at the application edge and may expose traffic, credentials and internal networks if compromised |
| IBM Langflow | AI development, SaaS, cloud-native environments | May connect AI workflows to cloud services, databases, APIs and sensitive credentials |
| Apache Tomcat clusters | Enterprise applications, SaaS, Java environments | Affected encryption controls may expose trusted cluster communications |
| Jenkins | Software development, DevOps, CI/CD environments | Compromise of the controller may affect credentials, source code and production artifacts |
| Fortinet VPN and firewall infrastructure | Enterprise, government, healthcare, finance, critical infrastructure | Observed as an initial-access vector in Gunra ransomware activity |
| OT/ICS environments | Manufacturing, energy, transportation, critical infrastructure | Operational constraints may delay patching and require compensating controls |
If none of these technologies are present in your environment, immediate emergency remediation may not be required. However, the broader pattern remains relevant to organizations operating centralized management platforms, CI/CD systems, AI applications or internet-facing administrative infrastructure.
Executive Summary
CISA confirmed five newly exploited vulnerabilities between 4 and 7 August affecting N-able N-central, JetBrains TeamCity, Progress LoadMaster, IBM Langflow and Apache Tomcat.
The highest immediate risks come from:
- unauthenticated administrative access affecting N-able N-central;
- unauthenticated remote code execution affecting JetBrains TeamCity;
- unauthenticated command injection affecting Progress LoadMaster;
- superuser-token creation and Python code execution in IBM Langflow;
- encryption bypass affecting clustered Apache Tomcat environments.
N-central requires particular attention because observed exploitation progressed beyond initial server access. Attackers used the platform’s Take Control functionality to reach managed endpoints and deployed Cloudflare tunnels to establish persistence. N-able has warned that installing the update closes the entry point but does not remove an attacker who has already established access.
TeamCity creates a different form of downstream risk. Successful exploitation may expose source code, repository and registry credentials, deployment tokens, signing material, build artifacts and connected CI/CD environments. A public proof of concept is available, further increasing the likelihood of exploitation.
IBM Langflow demonstrates that AI application infrastructure is becoming part of mainstream vulnerability management. The affected endpoints can provide an unauthenticated attacker with a superuser token and subsequently allow execution of attacker-controlled Python code.
A separate Jenkins advisory addresses several vulnerabilities affecting controllers and plugins, while a joint international advisory on Gunra ransomware identifies previously vulnerable Fortinet appliances as an observed initial-access vector.
Key Vulnerabilities
| CVE | Product and Scope | CVSS / Status | Most Relevant For | Business Impact | Required Response |
|---|---|---|---|---|---|
| CVE-2026-18556 / CVE-2026-18577 | N-able N-central | 7.4 / 8.2, KEV | MSP, MSSP, IT service providers | Unauthenticated administrative access and compromise of managed endpoints | Upgrade immediately, hunt for persistence and investigate downstream endpoints |
| CVE-2026-63077 | JetBrains TeamCity | 9.8 Critical / KEV | Software, SaaS, DevOps, enterprise development | Unauthenticated RCE and potential CI/CD supply-chain compromise | Patch immediately, investigate activity and rotate exposed credentials |
| CVE-2026-8037 | Progress LoadMaster | 9.8 Critical / KEV | Enterprise, cloud, application infrastructure | Unauthenticated command injection, credential theft and internal access | Update firmware, restrict management access and assess compromise |
| CVE-2026-9198 | IBM Langflow | 9.8 Critical / KEV | AI development, SaaS, cloud environments | Superuser access, Python code execution and exposure of connected secrets | Upgrade to 1.10.1+, remove public exposure and rotate potentially exposed secrets |
| CVE-2026-34486 | Apache Tomcat | 7.5 / KEV | Enterprise applications, SaaS, clustered Java environments | Encryption bypass affecting cluster communications | Upgrade and validate cluster security configuration |
| CVE-2026-70426 | Jenkins Core | Critical | Software, DevOps, CI/CD | Agent-to-controller code execution | Upgrade Jenkins and investigate untrusted or compromised agents |
| CVE-2026-70427 / 70428 | Jenkins Core | High | Software, DevOps, CI/CD | Arbitrary file write and potential controller RCE | Upgrade and review affected workflows |
| CVE-2026-70431 / 70432 | Jenkins Multijob Plugin | High | Jenkins environments | Controller-side arbitrary code execution | Update or remove affected plugin |
Vulnerability Analysis
N-able N-central. CVE-2026-18556 / CVE-2026-18577
The N-able N-central vulnerabilities represent the highest operational priority during this reporting period.
Attackers have exploited vulnerable N-central environments to obtain remote administrative access without authentication. Observed post-exploitation activity includes use of the legitimate Take Control functionality to connect to managed systems and deployment of Cloudflare tunnel services for persistence.
N-able released Hotfix 1 as version 2026.3.1.7 and subsequently Hotfix 2 as version 2026.3.1.10, which supersedes the earlier correction. The vendor has also observed account creation and password resets in affected environments.
Applying the update closes the vulnerability but does not remove persistence already established by an attacker.
Most Relevant For
- managed service providers;
- managed security service providers;
- IT service providers;
- organizations operating N-central on-premises.
How to Verify Exposure
Confirm the following:
- Is an on-premises N-central instance deployed?
- Was it accessible while running a vulnerable version?
- Has version 2026.3.1.10 been installed?
- Are there unexpected Take Control sessions?
- Have new accounts, privilege changes or password resets occurred?
- Is a service named Cloudflared present on managed endpoints?
- Is svchost.exe present unexpectedly in user Documents directories?
Required Response
Upgrade every on-premises N-central instance to version 2026.3.1.10 immediately.
Treat systems that remained exposed while vulnerable as potentially compromised. Review managed endpoints even where the N-central IOC scan is clean, rotate N-central, service-account and remote-access credentials, enforce multi-factor authentication and disable unused vendor-support accounts.
JetBrains TeamCity. CVE-2026-63077
CVE-2026-63077 is an unsafe-deserialization vulnerability affecting TeamCity On-Premises.
An unauthenticated attacker who can reach the TeamCity server over HTTP or HTTPS may execute operating-system commands with the privileges of the TeamCity service.
Because TeamCity may contain source code, build configurations, credentials, deployment tokens, signing material and production access, successful exploitation can extend into the wider software delivery chain. A public proof of concept is available.
Most Relevant For
- software vendors;
- SaaS providers;
- DevOps teams;
- enterprises operating internal CI/CD pipelines.
How to Verify Exposure
Confirm the following:
- Is TeamCity On-Premises deployed?
- Was the server accessible over HTTP or HTTPS from untrusted networks?
- Is the environment running TeamCity 2025.11.7, 2026.1.3 or the applicable security patch plugin?
- Have requests to
/app/agents/v1been reviewed? - Have unusual child processes been launched by the TeamCity Java process?
- Have unexpected agents or configuration changes appeared?
Required Response
Update TeamCity or install the available security patch plugin immediately.
Remove direct internet exposure. Where compromise cannot be excluded, rotate repository, registry, cloud and deployment credentials stored in TeamCity and validate recent build artifacts before production deployment.
Progress LoadMaster. CVE-2026-8037
CVE-2026-8037 allows an unauthenticated attacker to inject operating-system commands through improperly validated LoadMaster API parameters.
A compromised load balancer may enable traffic interception, credential theft, configuration manipulation and access to internal application networks.
Most Relevant For
- enterprise organizations;
- data centres;
- cloud environments;
- organizations using LoadMaster for application delivery.
How to Verify Exposure
Confirm the following:
- Is Progress LoadMaster deployed?
- Are administrative or API interfaces accessible from untrusted networks?
- Has the corrected firmware been installed?
- Do system or API logs contain unusual command activity?
- Are there unauthorized users, SSH keys, scheduled tasks or modified files?
- Does the running configuration match a trusted baseline?
Required Response
Apply the corrected LoadMaster firmware immediately.
Restrict administrative and API access to dedicated management networks and disable unnecessary API exposure. Where compromise cannot be excluded, rotate certificates, administrative credentials and API secrets.
IBM Langflow. CVE-2026-9198
CVE-2026-9198 affects Langflow versions 1.0.0 through 1.10.0 and combines two weaknesses that can provide full remote code execution in default-configured deployments.
The /api/v1/auto_login endpoint can issue a superuser token to an unauthenticated network caller. The /api/v1/validate/code endpoint can subsequently execute attacker-supplied Python code.
Most Relevant For
- AI development teams;
- software vendors;
- SaaS providers;
- organizations integrating LLM applications with cloud and business services.
How to Verify Exposure
Confirm the following:
- Is Langflow deployed?
- Is the installed version between 1.0.0 and 1.10.0?
- Are Langflow interfaces accessible from the internet?
- Have the affected API endpoints received suspicious requests?
- Are unexpected Python or shell child processes present?
- Have stored flows or agent definitions changed unexpectedly?
Required Response
Upgrade to Langflow 1.10.1 or later. There is no vendor-supported workaround.
Remove Langflow interfaces from public exposure. Review potentially affected API activity and rotate LLM-provider keys, database credentials, cloud tokens and integration secrets where exposure cannot be excluded.
Apache Tomcat. CVE-2026-34486
CVE-2026-34486 results from an incomplete correction for CVE-2026-29146 and allows Tomcat EncryptInterceptor protection to be bypassed.
The risk primarily affects clustered Tomcat environments using the vulnerable interceptor. Affected releases include Tomcat 9.0.116 and earlier affected 9.x releases, Tomcat 10.1.53 and earlier affected 10.x releases, and Tomcat 11.0.20 and earlier affected 11.x releases.
Most Relevant For
- enterprise Java environments;
- SaaS providers;
- organizations operating clustered Tomcat applications.
How to Verify Exposure
Confirm the following:
- Is Apache Tomcat deployed?
- Is clustering enabled?
- Is EncryptInterceptor in use?
- Is an affected Tomcat version installed?
- Have unexpected cluster membership changes or inter-node traffic been observed?
Required Response
Upgrade to the current supported Tomcat release.
Restrict cluster communication to trusted network segments and require network-layer encryption and mutual authentication. Do not assume that the earlier CVE-2026-29146 correction provides sufficient protection.
Jenkins CI/CD Security Cluster
Jenkins published a significant security advisory on 5 August covering multiple vulnerabilities in Jenkins Core and plugins.
The highest-risk issue, CVE-2026-70426, bypasses the JEP-200 deserialization filter. A malicious or compromised build agent, or an attacker with Agent/Connect permission, may execute code on the Jenkins controller.
Additional vulnerabilities include arbitrary file write, path traversal potentially leading to controller RCE, Unicode username handling that may enable impersonation and Multijob Plugin vulnerabilities capable of controller-side arbitrary code execution. Multiple plugins also expose credentials, stored XSS or workspace contents.
Fixed releases include Jenkins 2.576, Jenkins LTS 2.568.2 and Multijob Plugin 677.v7ffc23d6a_4c2. Some affected plugins had no correction at publication and should be disabled or removed where no safe update is available.
Most Relevant For
- software development teams;
- DevOps environments;
- SaaS providers;
- organizations operating Jenkins-based CI/CD pipelines.
How to Verify Exposure
Confirm the following:
- Is Jenkins Core fully updated?
- Are affected plugins installed?
- Can untrusted or externally controlled agents connect to the controller?
- Have unusual controller processes or file changes occurred?
- Were build artifacts generated while the environment was vulnerable?
Required Response
Upgrade Jenkins Core and all affected plugins.
Disable or remove plugins for which no correction is available. Review connected agents and validate artifacts produced during the potential exposure period before deployment.
Active Campaigns and Tactics
Gunra Ransomware
On 10 August, CISA, the FBI, NSA and international partners published a joint advisory regarding Gunra ransomware.
Gunra operates as ransomware-as-a-service and uses double extortion. Data is stolen before systems are encrypted. Affiliates have targeted government, healthcare, financial services and critical infrastructure.
Observed initial access includes exploitation of internet-facing Fortinet appliances through CVE-2024-55591 and CVE-2025-24472.
Organizations should patch and investigate exposed VPN and firewall appliances, disable administrative access from the internet, rotate credentials associated with previously vulnerable devices, review VPN sessions and configuration changes and validate offline or immutable backups.
Monitoring should also focus on data exfiltration activity that may occur before encryption.
N-central Post-Exploitation
The N-central activity demonstrates why remediation cannot stop at patch deployment.
Observed attackers used legitimate remote-control functionality after gaining access and deployed Cloudflare tunnels for persistence. This creates downstream risk for managed endpoints even after the original N-central vulnerability has been corrected.
Organizations should therefore investigate remote-control sessions, account changes and endpoint activity before considering remediation complete.
OT/ICS and Transportation Watch
CISA published new advisories affecting several operational and transportation technologies during the reporting period.
These include:
- ABB Ability Zenon, with vulnerabilities potentially enabling security bypass, system crashes, unauthorized actions and data compromise;
- CPDLC over ATN-B1, where protocol weaknesses were demonstrated under specific laboratory conditions;
- Acrisure KARR BT and DR-100, with potential unauthorized vehicle-control operations.
OT and transportation systems should be patched only through approved change procedures. Until updates can be deployed, organizations should restrict remote access, isolate affected components and increase monitoring.
What Deserves Attention This Week?
MSP and IT Management Infrastructure
Priority systems:
- N-able N-central.
Primary actions:
- upgrade to version 2026.3.1.10;
- investigate Take Control activity;
- hunt for Cloudflared persistence;
- review managed endpoints;
- rotate potentially exposed credentials.
CI/CD Infrastructure
Priority systems:
- JetBrains TeamCity;
- Jenkins.
Primary actions:
- patch controllers and plugins;
- remove unnecessary internet exposure;
- review build agents;
- rotate repository and deployment credentials where necessary;
- validate recently generated artifacts.
Internet-facing Infrastructure
Priority systems:
- Progress LoadMaster;
- Apache Tomcat;
- Fortinet VPN and firewall appliances.
Primary actions:
- validate installed versions;
- restrict management access;
- review configuration changes;
- investigate indicators of compromise.
AI Infrastructure
Priority systems:
- IBM Langflow;
- connected LLM and cloud services.
Primary actions:
- upgrade Langflow;
- remove public exposure;
- review API activity;
- rotate potentially exposed keys and secrets;
- validate connected services.
Recommended Management Actions
Immediate Actions (0–7 Days)
- Identify whether N-able N-central, JetBrains TeamCity, Progress LoadMaster, IBM Langflow, affected Apache Tomcat versions or vulnerable Jenkins components are present in the environment.
- Patch N-central, TeamCity, LoadMaster and Langflow immediately and determine whether they were externally accessible while vulnerable.
- Conduct compromise assessment for exposed KEV-listed systems rather than relying on patch status alone.
- Hunt for N-central persistence and unauthorized remote-control activity across managed endpoints.
- Rotate credentials and secrets stored in potentially compromised management, CI/CD and AI platforms.
- Review Fortinet appliances for exposure associated with Gunra initial-access techniques.
Actions Within 30 Days
- Review administrative accounts, privileged authentication and configuration changes across management platforms.
- Validate network segmentation around management, CI/CD and AI infrastructure.
- Review build artifacts produced during known exposure periods.
- Perform authenticated vulnerability scanning and external attack-surface validation.
- Validate offline or immutable backups and test restoration of critical systems.
- Close or formally document outstanding remediation exceptions.
Strategic Actions (Within 90 Days)
- Reduce direct internet exposure of administrative and management interfaces.
- Integrate CI/CD and AI platforms fully into vulnerability management and security monitoring programmes.
- Strengthen privileged-access controls and multi-factor authentication across control-plane systems.
- Improve detection coverage for misuse of legitimate remote-management tools and tunnelling services.
- Review vulnerability prioritisation criteria to ensure that KEV status, external exposure and asset criticality influence remediation timelines.
- Incorporate lessons from management-platform compromise into incident response and recovery planning.
Enterprise Exposure Assessment
Security teams should prioritize systems based on four factors.
1. Active Exploitation
Five of this week’s primary vulnerabilities have confirmed real-world exploitation and are included in the CISA Known Exploited Vulnerabilities Catalog.
Confirmed exploitation should immediately increase remediation priority, regardless of whether the vulnerability has the highest CVSS score.
2. External Accessibility
Internet-facing management interfaces, CI/CD platforms, APIs and edge appliances require immediate attention.
An internally deployed vulnerable system and an externally accessible administrative platform do not represent the same operational risk.
3. Business Role
The role of the affected platform should influence response priority.
Compromise of N-central may provide access to managed endpoints.
Compromise of TeamCity or Jenkins may affect source code, credentials and production deployments.
Compromise of LoadMaster may affect application traffic and internal networks.
Compromise of Langflow may expose AI workflows, cloud credentials and connected business services.
4. Recovery Readiness
Organizations should determine whether affected platforms and downstream systems can be restored safely.
Recovery planning should include validated backups, tested restoration procedures and review of credentials, certificates, tokens and build artifacts that may have been exposed before remediation.
Ongoing Security Controls
Beyond the immediate remediation cycle, security teams should:
- maintain an accurate inventory of internet-facing management and business-critical systems;
- map centralized platforms to the endpoints, applications and services they control;
- validate remediation through version checks, vulnerability scanning and configuration review;
- monitor privileged authentication and administrative interfaces continuously;
- conduct threat hunting whenever confirmed exploitation and exposure overlap;
- monitor CI/CD environments for unexpected agents, builds and credential use;
- include AI application platforms and their connected secrets in security monitoring;
- test offline and immutable recovery capabilities regularly;
- report unresolved remediation exceptions and accepted risks to management.
Questions for Leadership
Boards and executive teams should ask:
- Do we operate any of the technologies covered in this report?
- Which affected management, CI/CD or AI platforms were accessible from the internet?
- Have all KEV-listed systems been patched or isolated?
- Have we investigated whether exploitation occurred before remediation?
- Have potentially exposed administrative, cloud and deployment credentials been rotated?
- Have managed endpoints and software artifacts downstream of compromised platforms been validated?
- Are administrative interfaces protected through segmentation and multi-factor authentication?
- Can critical systems be restored from validated offline or immutable backups?
- Which remediation exceptions remain open, and who has accepted the associated risk?
ISO 27001 Alignment
The actions described in this report support several areas of an Information Security Management System (ISMS) aligned with ISO/IEC 27001, including:
- asset inventory and ownership;
- vulnerability management;
- secure configuration;
- identity and access management;
- logging and monitoring;
- incident response;
- network security;
- supplier and software supply-chain security;
- backup and recovery;
- business continuity;
- risk treatment and management review.
Evidence should be retained for every remediation activity. Confirmation that an update has been installed is not sufficient on its own. Organizations should preserve version records, vulnerability scan results, threat-hunting outcomes, credential reviews, artifact validation and recovery evidence.
ISO 9001 Alignment
The response activities described in this report also support quality management principles under ISO 9001 by promoting:
- clearly defined ownership;
- controlled change management;
- documented evidence;
- corrective actions;
- validation of remediation outcomes;
- management review;
- continual improvement.
The objective is not simply to deploy updates but to demonstrate that remediation has successfully reduced operational risk.
Need Help Assessing Your Exposure?
If your organization operates any of the technologies covered in this report, identifying them is only the first step.
The next step is understanding:
- whether vulnerable systems were exposed before remediation;
- whether indicators of attempted or successful compromise exist;
- whether credentials, tokens or other secrets require rotation;
- whether downstream endpoints or software artifacts may also have been affected;
- which systems should be prioritized according to operational impact.
DIAMATIX helps organizations assess exposure, validate remediation and strengthen continuous monitoring through expert-led Security Operations Center as a Service (SOCaaS), Managed Detection and Response as a Service (MDRaaS) and Incident Response services.
Contact our team to discuss your environment.
Conclusion
This week’s findings demonstrate concentrated targeting of systems that occupy highly trusted positions within enterprise infrastructure.
N-able N-central can provide remote access to managed endpoints. TeamCity and Jenkins sit inside the software delivery chain. LoadMaster operates at the application edge. Langflow may connect AI workflows to cloud platforms, APIs and business data. Compromise of any of these platforms can therefore create downstream exposure beyond the initially affected server.
The highest immediate priority is N-central because observed exploitation includes use of legitimate remote-management functionality and persistence on managed systems. TeamCity, LoadMaster and Langflow also require immediate attention because unauthenticated exploitation has been confirmed.
For these platforms, organizations should combine patching with compromise assessment. Where exposure occurred, credentials and secrets should be reviewed or rotated, persistence should be investigated and downstream systems or artifacts should be validated.
The objective is to establish, with evidence, that the vulnerability has been corrected, attacker access has not persisted and the systems that depend on the affected platform remain trustworthy.
Sources
- ThreatScope Weekly Research
- CISA. Known Exploited Vulnerabilities additions, August 4–7, 2026
- N-able security update and indicators
- JetBrains security advisory
- Rapid7 technical analysis
- Progress LoadMaster security bulletin
- IBM Langflow security bulletin
- Apache Tomcat security advisories
- Jenkins Security Advisory 2026-08-05
- Joint CISA/FBI/NSA #StopRansomware Gunra advisory
- CISA ABB Ability Zenon advisory
- CISA CPDLC advisory
- CISA Acrisure advisory
Methodology
This report is based on open-source threat intelligence and vulnerability intelligence, prioritizing confirmed exploitation, CISA KEV status, vendor advisories, external exposure and business criticality.
Applicability should always be validated against the organization’s actual asset inventory, deployed software versions and configuration.
The report does not, by itself, confirm the presence or absence of compromise.
Trusted · Innovative · Vigilant






