Threat Intelligence Report — August 4, 2026 | 5 New KEVs · 196 Victims

Report Date: 2026-08-04

New KEVs: 5  ▲ +1 vs last weekRansomware Victims: 196  ▼ -72 vs last week

5 vulnerabilities were added to the CISA Known Exploited Vulnerabilities catalog this period. N-Able products show the strongest concentration of risk signals this week. Ransomware activity is moderate with 196 new victims posted to leak sites over the last 7 days, with Thegentlemen posting the most victims.

Patch This Week

The top 3 KEVs to remediate right now, ranked by CISA deadline proximity, ransomware exploitation, and severity. These are confirmed exploited — if you do nothing else today, patch these.

  1. CVE-2026-20316 – Cisco Secure Firewall Management Center (FMC) | CVSS 5.3 | EPSS 0.8% / 53th pct
    CISA deadline: 2026-08-01 (overdue by 3d) — Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
  2. CVE-2026-18577 – N-able N-central | CVSS 8.2 | EPSS 2.5% / 83th pct
    CISA deadline: 2026-08-06 (2d remaining) — Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
  3. CVE-2026-9198 – IBM Langflow | CVSS 9.8 | EPSS 1.9% / 78th pct
    CISA deadline: 2026-08-07 (3d remaining) — Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Top KEVs

Vulnerabilities confirmed actively exploited in the wild by CISA — ranked by ransomware use, then severity. Patch these before anything else.

New Today

  • CVE-2026-9198 – IBM Langflow | CVSS 9.8 (CRITICAL) | AV: Network | EPSS 1.9% / 78th pct | Ransomware Use: No
  • CVE-2026-18556 – N-able N-central | CVSS 8.2 (HIGH) | AV: Network | EPSS 0.3% / 19th pct | Ransomware Use: No
  • CVE-2026-34486 – Apache Tomcat | CVSS 7.5 (HIGH) | AV: Network | EPSS 42.6% / 99th pct | Ransomware Use: No

Still Outstanding

  • CVE-2026-18577 – N-able N-central | CVSS 8.2 (HIGH) | AV: Network | EPSS 2.5% / 83th pct | Ransomware Use: No
  • CVE-2026-20316 – Cisco Secure Firewall Management Center (FMC) | CVSS 5.3 (MEDIUM) | AV: Network | EPSS 0.8% / 53th pct | Ransomware Use: No

Security News

Advisories, threat research, and incident reports from 12 sources across government, commercial research, and security journalism — prioritized by source credibility.

  • CISA ICS AdvisoryAdvisory · todayAcrisure KARR BT and DR-100
    View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to perform unauthorized vehicle control operations. The following versions of Acrisure KARR BT and DR-100 are affected: KARR BT firm…
  • CISA ICS AdvisoryAdvisory · 5 days agoSchneider Electric IGSS
    View CSAF Summary Schneider Electric is aware of a vulnerability in its IGSS Definition module for the IGSS (Interactive Graphical SCADA System) product. The [IGSS](https://igss.schneider-electric.com/) product is a stat…
  • CISA ICS AdvisoryAdvisory · 5 days agoToptech Systems RCU II+ and Multiload II+
    View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to gain full system control and misuse it to access or manipulate connected networks and resources. The following versions of Toptec…
  • SANS ISCResearch · todayBotnet Hunting for Vulnerabilities in Diagnostic Tools, (Tue, Aug 4th)
    This morning, I noticed specific sources "hunting" for vulnerabilities in URLs that I haven&&#x23&#x3b;x26&#x3b;&#x23&#x3b;39&#x3b;t noticed before. All of these URLs appear to be associated with diagnostic tools:
  • SANS ISCIncident · 3 days agoPhishing Campaigns Targeting AI Solutions Providers, (Sat, Aug 1st)
    Most phishing campaigns rely on the fact that the victim is afraid to loose "something": money, access to information, … Many brands have been impersonated by campaigns but I spotted some phishing emails that focus on …
  • Unit 42Research · todayThe Frontier AI Vulnerability Burst: Industrializing Autonomous Zero-Day Discovery in Open-Source Software
    Frontier AI is reshaping vulnerability discovery. Learn how our NOVA system found 14,000+ unknown vulnerabilities across the open-source software supply chain. The post The Frontier AI Vulnerability Burst: Industrializin…
  • Unit 42Research · todayAlmost Half of Malware Samples Communicate Direct to IP
    Nearly half of C2 malware bypasses DNS by connecting directly to IP addresses. Zero trust IP enforcement secures networks against these threats. The post Almost Half of Malware Samples Communicate Direct to IP appeared f…
  • Sophos X-OpsResearch · 7 days agoChaos in Teams vishing
    Attackers used Microsoft Teams vishing, custom malware, and remote access tools to facilitate ransomware deployment Categories: Threat Research Tags: Microsoft Teams, vishing, Ransomware, Chaos
  • Sophos X-OpsResearch · 8 days ago2607-secai
    <p>What that means for Customer Protections </p> Categories: Threat Research, AI Research
  • The RecordIncident · todayPolish convenience store chain Å»abka hacked through third-party account
    Reports said intruders appeared to gain access to the Jira environment and other sensitive data of the Żabka retail chain. The company confirmed an intrusion occurred in late July.
  • Security Affairs (APT)Incident · 2 days agoCISA Urges Utilities to Remove Internet-Exposed PLCs After Minnesota Attacks
    After attacks hit 30+ Minnesota water systems, CISA urged utilities to remove internet-exposed PLCs and strengthen OT security. Between Sunday and Monday, July 26 and 27, a coordinated cyberattack hit operational technol…
  • Security Affairs (APT)News · 3 days agoRussian Hackers Hijack Hotel Wi-Fi to Steal Microsoft 365 Tokens
    Microsoft says Russian hackers hijacked hotel Wi-Fi portals to spread malware and steal Microsoft 365 tokens from travelers. Microsoft Threat Intelligence disclosed CaptiveCrunch, a campaign it attributes to Storm-2945, …
  • Security Affairs (Cybercrime)Incident · todayINC Ransomware is Calling Victims – Pressure Tactics Post SonicWall Zero-Day Exploit
    INC Ransomware exploits SonicWall SMA 1000 flaws, using calls and emails to pressure victims during extortion campaigns targeting global organizations. Resecurity disclosed that INC Ransomware has emerged as the dominant…
  • Security Affairs (Cybercrime)Incident · today31,000 Records Compromised in Breach of Liechtenstein Companies and Foundations Register
    Cyberattack exposed data of 31,000 people in Liechtenstein’s beneficial ownership register for companies and foundations. A cyberattack compromised data belonging to about 31,000 people in Liechtenstein’s reg…
  • Bleeping ComputerIncident · todayPhishing service spoofs RingCentral to steal Microsoft 365 accounts
    The Greatness phishing-as-a-service (PhaaS) platform has expanded from credential phishing to adversary-in-the-middle attacks and device-code phishing targeting Microsoft 365 accounts. […]

Ransomware Activity

Victim counts posted to ransomware group leak sites — use this to gauge which groups are most active and which sectors and regions are being targeted.

32 new victims posted today
7-day total: 196 via Ransomware.live

Infostealer Exposure: 2,016 employee credentials and 66,037 user credentials compromised via infostealer malware across victim organisations — indicating credential theft likely preceded these ransomware deployments.

Most Active Groups

Thegentlemen 44 Qilin 30 Orova 13 Incransom 11 Crpxo 11

Group Intelligence

  • ThegentlemenThe Gentlemen is a RaaS group that emerged in July–August 2025, rapidly claiming over 320 victims across 17+ countries by offering affiliates a 90% revenue share, deploying a Go-based locker against Windows, Linux, NAS, and BSD systems; a compromised C2 server in 2026 revealed more than 1,570 linked victims.
  • QilinQilin ransomware was first observed in July of 2022. Qilin Ransomware is written in Golang and supports multiple encryption modes; all of which are controlled by the operator. Qilin actors practice double extortion – demanding payment for a decryptor, as well as for the non-release of stolen data.
  • OrovaFirst seen 2026-07-07
  • IncransomINC Ransom is a prolific ransomware-as-a-service operation active since July 2023 that systematically targets healthcare, government, education, and manufacturing sectors in North America and Europe, having posted over 200 victims in 2025 alone with no sector off-limits.
  • CrpxoCRPxO is actively recruiting affiliates, offering:
    🔹 70% revenue share
    🔹 XMR/BTC payouts
    🔹 Claimed payouts within 24 hours
    🔹 $333 one-time affiliate access

Most Targeted Sectors

Manufacturing 47 Technology 22 Other 20 Professional Services 19 Healthcare 17

Top Countries

US (77), TR (10), DE (7), GB (6), HK (5)

Notable Incidents

  • Oleoductos del Valle (Energy & Utilities · AR) — claimed by Incransom. During the analysis of data obtained from Oldelval, we have compiled information covering key aspects of the company's operations. The materials include:

    1.HR documentation: full payroll data, bank account details (CB… Press coverage →

  • Universitatea De Vest Vasile Goldi Din Arad (Education · RO) — claimed by Qilin. N/A Press coverage →
  • Mairie de Drancy (Government & Defense · FR) — claimed by Qilin. N/A Press coverage →

Vendor-Specific Risks

Vendors with confirmed KEV exploitation this week — the stacked bar shows how that exposure breaks down across exploited CVEs (red), critical CVEs to watch (orange), and news mentions (yellow). Prioritize patching vendors with the largest red segment.

N-Able 2 Ibm 2 Cisco 1 Apache 1 KEVs CVEs Mentions

Stay Ahead

Found this useful? Get the daily report in your reader.

Free. No account. No email. Follow in Feedly, Inoreader, or any RSS reader.