(TLP CLEAR) Weekly Vulnerabilities to Prioritize – August 6, 2026
Created: Thursday, August 6, 2026 - 14:58
Categories: Cybersecurity, Security Preparedness
The below vulnerabilities have been identified by WaterISAC analysts as important for water and wastewater utilities to prioritize in their vulnerability management efforts. WaterISAC shares critical vulnerabilities that affect widely used products and may be under active exploitation. WaterISAC draws additional awareness in alerts and advisories when vulnerabilities are confirmed to be impacting, or have a high likelihood of impacting, water and wastewater utilities. Members are encouraged to regularly review these vulnerabilities, many of which are often included in CISA’s Known Exploited Vulnerabilities (KEV) Catalog.
IBM Langflow Code Injection Vulnerability
CVSS v3.1: 9.8
CVEs: CVE-2026-9198
Description: IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to chain /api/v1/auto_login (mints SUPERUSER tokens to any network caller) with /api/v1/validate/code (executes user code via exec()) to achieve full RCE on default Langflow deployments. CISA added this vulnerabilities to its Known Exploited Vulnerability Catalog.
Source: https://www.ibm.com/support/pages/node/7278927
JetBrains TeamCity Deserialization of Untrusted Data Vulnerability
CVSS v3.1: 9.8
CVE: CVE-2026-63077
Description: In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent polling protocol. CISA added this vulnerabilities to its Known Exploited Vulnerability Catalog.
Source: https://www.jetbrains.com/privacy-security/issues-fixed/
N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability
See WaterISAC’s recent advisory regarding this vulnerability
Apache Tomcat Missing Encryption of Sensitive Data Vulnerability
CVSS v3.1: N/A
CVEs: CVE-2026-34486
Description: Missing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the fix for CVE-2026-29146 allowing the bypass of the EncryptInterceptor. This issue affects Apache Tomcat: 11.0.20, 10.1.53, 9.0.116. Users are recommended to upgrade to version 11.0.21, 10.1.54 or 9.0.117, which fix the issue. CISA added this vulnerabilities to its Known Exploited Vulnerability Catalog.
Source: https://lists.apache.org/thread/9510k5p5zdvt9pkkgtyp85mvwxo2qrly
