Bharat Threat FeedGlobal threats, decoded for Indian defenders
Weekly Brief · 7 August 2026

Weekly Brief — 7 August 2026

Two separate CISA Known Exploited Vulnerabilities batches landed within a single week, pulling an RMM platform used to manage entire MSP client fleets and an open-source AI workflow builder into active-exploitation territory alongside each other, with federal remediation deadlines falling on the same day. A French national CERT advisory flagged fresh weaknesses in an SD-WAN orchestrator already familiar to Indian branch-network operators, while in the United States a warning about industrial-control-system intrusions with suspected Iranian links turned, within days, into confirmed operational incidents at water utilities across seven states; the Iranian attribution itself remains unconfirmed. Closer to the balance sheet, IBM's latest India breach-cost data puts a number on what slow detection actually costs Indian enterprises this year.
1HighCVSS 7.4

N-able N-central RMM Authentication Bypass Chain Actively Exploited — CVE-2026-18556, CVE-2026-18577

CVSS 7.4 / 8.1 | CISA KEV, 3-4 August — remediation due 7 August* N-able's original fix for CVE-2026-18556 in its N-central remote monitoring and management platform proved incomplete, leaving a residual flaw, now tracked as CVE-2026-18577, that still let an unauthenticated attacker reach administrative access on an N-central server through an alternate authentication path. N-able detected exploitation of the second flaw on 1 August 2026, shipped a hotfix on 2 August, and issued a public warning on 3 August. Attackers observed using the access abused the platform's own "Take Control" function to reach managed endpoints, then deployed Cloudflare Tunnel for covert, persistent outbound access without opening any inbound firewall port. CISA added CVE-2026-18577 to its KEV catalogue on 3 August and CVE-2026-18556 on 4 August, grouped with the Langflow and Tomcat additions below, with a federal deadline of 7 August for that batch.

India exposureRMM platforms of this kind are precisely what Indian MSPs and IT-services firms rely on to administer client endpoint fleets at scale. A single compromised N-central instance can cascade into every downstream client environment it touches, turning one intrusion into many.
ActionApply N-central 2026.3 Hotfix 1 (build 2026.3.1.7) immediately; hosted instances update automatically, on-premises deployments require manual action. Hunt for unexpected cloudflared processes and Take Control sessions initiated outside known administrative windows, and rotate admin credentials.
SourceN-able security advisory, 3 August 2026; BleepingComputer, 3 August 2026; TheHackerNews, 4-5 August 2026; Rapid7, Horizon3.ai and Arctic Wolf research notes; CISA KEV additions, 3 and 4 August 2026.
2CriticalCVSS 9.8

IBM Langflow Unauthenticated Remote Code Execution Added to KEV — CVE-2026-9198

CVSS 9.8 | CISA KEV, 4 August — remediation due 7 August* Langflow, IBM's open-source visual builder for AI and LLM agent workflows, carries a chainable flaw across versions 1.0.0 through 1.10.0: its /api/v1/auto_login endpoint mints SUPERUSER tokens for any unauthenticated network caller, and the /api/v1/validate/code endpoint then executes attacker-supplied Python through exec(). Combined, the two give unauthenticated remote code execution on default deployments. IBM patched the issue in Langflow 1.10.1, released 17 July 2026, but CISA added CVE-2026-9198 to its KEV catalogue on 4 August citing evidence of active exploitation, with the same 7 August federal deadline.

India exposureLangflow is a widely adopted tool for building AI and agent workflows, and Indian enterprises and GenAI startups building on it are exposed wherever instances are internet-reachable and unpatched. No named Indian victim has surfaced, but the installed-base overlap is real given how quickly Indian firms have been adopting agentic-AI tooling.
ActionUpgrade to Langflow 1.10.1 without delay, and take any internet-facing instance offline until patched. Audit for SUPERUSER tokens issued through the auto_login endpoint outside expected administrative activity.
SourceIBM security bulletin; SentinelOne vulnerability database; TheHackerNews, 4-5 August 2026; SecurityWeek; CISA KEV addition, 4 August 2026.
3

HPE Aruba EdgeConnect SD-WAN Orchestrator Vulnerabilities Disclosed — CVE-2026-63455, CVE-2026-63456

CERT-FR advisory CERTFR-2026-AVI-0969, 5 August — no exploitation observed* HPE published Security Bulletin HPESBNW05100 on 4 August 2026 covering EdgeConnect SD-WAN Orchestrator releases 9.6.2.x before 9.6.2.40210, 9.6.3.x before 9.6.3.40140, and 9.7.0.x before 9.7.0.43264. The following day, France's national CERT issued advisory CERTFR-2026-AVI-0969 describing multiple vulnerabilities that could let an attacker breach data confidentiality, compromise data integrity, and bypass security policy on affected orchestrators. Neither advisory specifies the exact technical mechanism, and none should be assumed. No evidence of active exploitation has surfaced as of this writing.

India exposureEdgeConnect is one of the SD-WAN platforms Indian enterprises and telecom or ISP providers run for branch and multi-site connectivity, in the same category as the Arista VeloCloud orchestrator flaw covered in last week's edition. An orchestrator compromise gives an attacker visibility and control across every branch site it manages. No named Indian victim.
ActionApply HPE's fixed builds across all three affected release trains per HPESBNW05100. Pending confirmed patching, restrict orchestrator management access to trusted administrative networks and monitor CERT-FR and HPE channels for further technical detail.
SourceCERT-FR CERTFR-2026-AVI-0969, 5 August 2026; HPE Security Bulletin HPESBNW05100, 4 August 2026; GlobalSecurityMag, 5 August 2026.
4

Suspected Iranian-Linked Intrusions Reach US Water-Utility PLCs Across Seven States — AA26-097A Escalation

No CVE | Intrusions identified 26-27 July; joint CISA/FBI/EPA warning, 30 July; attribution unconfirmed* Investigators identified malicious activity targeting programmable logic controllers at municipal water utilities across at least seven US states in late July 2026, including more than thirty community water systems in Minnesota, systems in Michigan, and Clayton County, Georgia. Affected utilities switched to manual operation, and water quality and delivery were reportedly not interrupted. Whether Iranian-linked actors, whose activity bears hallmarks of past CyberAv3ngers and IRGC-affiliated campaigns, are responsible remains under investigation rather than confirmed, and officials have cautioned the assessment could change as more technical evidence comes in. CISA, the FBI and the EPA issued a joint warning on 30 July urging water utilities to remove internet-exposed PLCs and OT from the internet immediately. This marks a concrete escalation of the exposure pattern flagged in the CISA/FBI/NSA advisory AA26-097A that we covered in our 31 July edition: guidance about exposed PLC engineering access became live intrusions into real utilities within days.

India exposureNo Indian utility has been named. The common thread for Indian defenders is internet-exposed PLC engineering interfaces, not a specific vendor or geography; Indian power distribution, water utilities and manufacturing plants running internet-reachable engineering access face the same exposure class regardless of who is ultimately behind this particular campaign.
ActionConfirm no PLC engineering interfaces are reachable from the internet or general IT networks, segment OT decisively from IT, enforce authentication on programming ports where supported, and check AA26-097A's indicators of compromise against historical logs.
SourceCISA/FBI/EPA joint statement, 30 July 2026; CBS News, 1-2 August 2026; Time, 2 August 2026.
5

India's Average Data-Breach Cost Hits Record ₹25.5 Crore as AI Widens the Detection Gap

No CVE | IBM Cost of a Data Breach Report 2026 (India), published 3 August* IBM's 2026 India breach-cost report puts the average cost of a data breach at ₹25.5 crore, up 15.9 percent from ₹22 crore in 2025 and a record high. The gap between organisations runs wide: those with no AI or automation in their security operations averaged ₹31.6 crore per breach, 236 days to identify it and 75 days to contain it, while organisations with extensive AI and automation averaged ₹21.3 crore, identified breaches in 175 days but took slightly longer to contain them at 81 days, meaning this year's AI advantage shows up in detection speed rather than containment. Twenty-six percent of malicious breaches in India involved AI-generated attack techniques, and the average scale of a breach rose to 39,500 compromised records, up from 38,200 in 2025. IBM's own recommendation is to embed AI across the full security lifecycle, detection, analysis, prioritisation and remediation, and Indian organisations surveyed already rank incident response plans (67 percent), threat detection technology (51 percent), identity management (49 percent) and AI security governance tools (39 percent) as priority investment areas.

ActionWith no patch or CVE attached to this item, the practical response is closing the detection-speed gap directly: invest in AI-assisted detection and SOC tooling, and fund incident-response plan development and testing ahead of the next budget cycle rather than after an incident forces the question.
SourceIBM Newsroom India press release, 3 August 2026; Business Standard, 4 August 2026; VARINDIA, 4 August 2026.

Takeaway

This week's KEV sweep put two clusters on the board within a day of each other: an RMM platform and an AI workflow builder, both reachable by unauthenticated attackers, both added to CISA's catalogue with the same 7 August remediation deadline. The 4 August batch also picked up CVE-2026-34486, a missing-encryption flaw in Apache Tomcat's EncryptInterceptor cluster-messaging component, fixed since April 2026 in Tomcat 11.0.21, 10.1.54 and 9.0.117, worth checking even on a patch issued months ago. The throughline across N-central, Langflow and the EdgeConnect orchestrator is management-plane software becoming the attacker's entry point once reachable from outside its intended network, a pattern this brief has tracked for weeks running. The water-utility intrusions turn last week's advisory update into a live operational lesson for any Indian OT operator with internet-facing engineering access, and IBM's India breach-cost figures put a rupee value on that lesson: slower detection costs roughly ten crore more per incident than faster detection does. This week's vendor sweep also checked Fortinet, Cisco, Palo Alto Networks, Check Point, Juniper, SonicWall, Sophos, Barracuda, WatchGuard, Zscaler, Citrix NetScaler, Ivanti, F5 BIG-IP and Versa by name; none showed a fresh, India-relevant escalation strong enough to displace the five items above.

Nirad Threat Research