Threat Intelligence Report — August 5, 2026 | 5 New KEVs · 276 Victims

Report Date: 2026-08-05

New KEVs: 5  ▲ +2 vs last weekRansomware Victims: 276  ▲ +19 vs last week

5 vulnerabilities were added to the CISA Known Exploited Vulnerabilities catalog this period. N-Able products show the strongest concentration of risk signals this week. Threat intelligence sources this period reference Salt Typhoon (China). Ransomware activity is moderate with 276 new victims posted to leak sites over the last 7 days, with Thegentlemen posting the most victims.

Patch This Week

The top 3 KEVs to remediate right now, ranked by CISA deadline proximity, ransomware exploitation, and severity. These are confirmed exploited — if you do nothing else today, patch these.

  1. CVE-2026-18577 – N-able N-central | CVSS 8.2 | EPSS 4.1% / 90th pct
    CISA deadline: 2026-08-06 (1d remaining) — Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
  2. CVE-2026-34486 – Apache Tomcat | CVSS 9.8 | EPSS 81.2% / 100th pct
    CISA deadline: 2026-08-07 (2d remaining) — Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
  3. CVE-2026-9198 – IBM Langflow | CVSS 9.8 | EPSS 17.1% / 97th pct
    CISA deadline: 2026-08-07 (2d remaining) — Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Top KEVs

Vulnerabilities confirmed actively exploited in the wild by CISA — ranked by ransomware use, then severity. Patch these before anything else.

New Today

  • CVE-2026-63077 – JetBrains TeamCity | CVSS 9.8 (CRITICAL) | AV: Network | EPSS 0.6% / 48th pct | Ransomware Use: No

Still Outstanding

  • CVE-2026-34486 – Apache Tomcat | CVSS 9.8 (CRITICAL) | AV: Network | EPSS 81.2% / 100th pct | Ransomware Use: No
  • CVE-2026-9198 – IBM Langflow | CVSS 9.8 (CRITICAL) | AV: Network | EPSS 17.1% / 97th pct | Ransomware Use: No
  • CVE-2026-18556 – N-able N-central | CVSS 8.2 (HIGH) | AV: Network | EPSS 0.5% / 40th pct | Ransomware Use: No
  • CVE-2026-18577 – N-able N-central | CVSS 8.2 (HIGH) | AV: Network | EPSS 4.1% / 90th pct | Ransomware Use: No

Security News

Advisories, threat research, and incident reports from 12 sources across government, commercial research, and security journalism — prioritized by source credibility.

Threat Actors Mentioned

Salt Typhoon (China)

Ransomware Activity

Victim counts posted to ransomware group leak sites — use this to gauge which groups are most active and which sectors and regions are being targeted.

90 new victims posted today
7-day total: 276 via Ransomware.live

Infostealer Exposure: 3,269 employee credentials and 83,996 user credentials compromised via infostealer malware across victim organisations — indicating credential theft likely preceded these ransomware deployments.

Most Active Groups

Thegentlemen 44 Clop 41 Qilin 33 Everest 18 Orova 14

Group Intelligence

  • ThegentlemenThe Gentlemen is a RaaS group that emerged in July–August 2025, rapidly claiming over 320 victims across 17+ countries by offering affiliates a 90% revenue share, deploying a Go-based locker against Windows, Linux, NAS, and BSD systems; a compromised C2 server in 2026 revealed more than 1,570 linked victims.
  • ClopThe ransomware group known as Cl0p is a variant of a previously known strain dubbed CryptoMix. It is worth noting that this variant was delivered as the final payload in a phishing campaign in 2019 and was exclusively financially motivated, with attacks carried out by the threat actors TA505.<br> <br> At that time, malicious actors sent phishing emails that led to a macro-enabled document that would drop a loader called 'Get2.' After gaining an initial foothold in the system or infrastructure, the actors began using reconnaissance, lateral movement, and exfiltration techniques to prepare for the deployment of the ransomware.<br> <br> After the execution of the ransomware, Cl0p appends the extension '.clop' to the end of files, or other types of extensions such as '.CIIp, .Cllp, and .C_L_O_P,' as well as different versions of the ransom note that were also observed after encryption. Depending on the variant, any of the ransom text files were created with names like 'ClopReadMe.txt, README_README.txt, Cl0pReadMe.txt, and READ_ME_!!!.TXT.'<br> <br> The Clop operation has shifted from delivering its final payload via phishing and has begun initiating attacks using vulnerabilities that resulted in the exploitation and infection of victims' infrastructures.<BR>Source: https://github.com/crocodyli/ThreatActors-TTPs
  • QilinQilin ransomware was first observed in July of 2022. Qilin Ransomware is written in Golang and supports multiple encryption modes; all of which are controlled by the operator. Qilin actors practice double extortion – demanding payment for a decryptor, as well as for the non-release of stolen data.
  • EverestEverest ransom group collects and analyzes information about their victims. They specialize in customer privacy data, financial information, databases, credit card information, and more. The Everest ransom group leaks the victim's data to the darknet and they announced that any victim that will not contact them will suffer from a data leak and they will not delete hist files for future usage.
  • OrovaFirst seen 2026-07-07

Most Targeted Sectors

Manufacturing 57 Technology 33 Other 24 Professional Services 24 Financial Services 18

Top Countries

US (95), GB (11), TR (9), IN (9), DE (8)

Notable Incidents

  • Oleoductos del Valle (Energy & Utilities · AR) — claimed by Incransom. During the analysis of data obtained from Oldelval, we have compiled information covering key aspects of the company's operations. The materials include:

    1.HR documentation: full payroll data, bank account details (CB… Press coverage →

  • Universitatea De Vest Vasile Goldi Din Arad (Education · RO) — claimed by Qilin. N/A Press coverage →
  • Loyalist College (Education · CA) — claimed by Incransom. The management of this institution was repeatedly warned about the disclosure of hundreds of personal data. Each of you who is faced with the consequences of the leak can be absolutely sure that the management of Loyalis… Press coverage →
  • Mairie de Drancy (Government & Defense · FR) — claimed by Qilin. N/A Press coverage →
  • Stadler Rail (Transportation · CH) — claimed by Everest. [AI generated] Stadler Rail is a Swiss manufacturer of railway vehicles headquartered in Bussnang, Switzerland. Founded in 1942, the company designs and produces a wide range of trains including regional and intercity tr… Press coverage →

Vendor-Specific Risks

Vendors with confirmed KEV exploitation this week — the stacked bar shows how that exposure breaks down across exploited CVEs (red), critical CVEs to watch (orange), and news mentions (yellow). Prioritize patching vendors with the largest red segment.

N-Able 2 Jetbrains 1 Apache 1 Ibm 1 KEVs CVEs Mentions

Stay Ahead

Found this useful? Get the daily report in your reader.

Free. No account. No email. Follow in Feedly, Inoreader, or any RSS reader.