This week’s cybersecurity update highlights critical vulnerabilities and exploitation trends affecting various technologies. Key issues include Apache Tomcat’s encryption flaw, a long-standing Linux kernel vulnerability, and multiple security incidents involving AI models and software platforms.
CISA Alerts on Apache Tomcat Encryption Issue
The Cybersecurity and Infrastructure Security Agency (CISA) has identified a high-severity encryption flaw in Apache Tomcat, labeled CVE-2026-34486. This vulnerability, arising from an incomplete fix of a previous issue, permits attackers to bypass encryption on clustered Tomcat traffic. Affected versions include Tomcat 11.0.20, 10.1.53, and 9.0.116. To mitigate risks, CISA advises federal agencies to address this flaw by August 7, 2026.
Unit 42 has observed exploitation attempts by a Chinese-speaking threat group, deploying reverse shells through Java deserialization. Apache has issued updates to address these vulnerabilities, and organizations are encouraged to apply these patches promptly or take interim protective measures.
Linux Kernel Vulnerability: SCTPhantom
An 18-year-old vulnerability in the Linux kernel, known as SCTPhantom and tracked as CVE-2026-64564, has been disclosed. This use-after-free flaw in the SCTP Dynamic Address Reconfiguration feature allows local users to gain root access. It was discovered by TencentOS Security Team using AI-assisted tools, demonstrating a full privilege escalation chain.
The flaw has been rated 8.5 under CVSS v4.0 and patched in recent kernel updates. Administrators are urged to prioritize these updates, especially in environments utilizing SCTP-enabled kernels.
N-Able N-Central Under Threat
A critical vulnerability, CVE-2026-18577, affecting N-able’s N-Central platform, has surfaced. This authentication-bypass flaw allows attackers to gain complete administrative access. Exploitation of this vulnerability could lead to significant supply-chain incidents, especially in managed service provider environments.
N-able has issued a hotfix to resolve the issue, and organizations are advised to secure their systems by limiting public access, enforcing multi-factor authentication, and reviewing logs for suspicious activities.
Further Exploits and Vulnerabilities
Additional threats include a zero-click root compromise in SonicWall SMA appliances and multiple vulnerabilities in Veeam ONE, prompting urgent patching and security measures. The SonicWall issue, attributed to the INC Ransomware group, highlights the importance of keeping firmware up to date.
Moreover, researchers have identified a prompt injection vulnerability affecting AI models such as Claude in Chrome, emphasizing the need for robust security practices in AI implementations.
Conclusion and Recommendations
The landscape of cybersecurity threats continues to evolve, with attackers exploiting both new and longstanding vulnerabilities. Organizations must remain vigilant, applying patches and updates promptly, and implementing comprehensive security strategies to protect their systems and data.
Staying informed on these developments is crucial to maintaining robust defenses against potential exploits and ensuring the security of digital infrastructures.
