ctipilot.ch
← Back to Weekly 2026-W31
NOTABLEexploitedNATOB2synthesis

Both standard prioritisation feeds failed in the same week — an exploited flaw absent from KEV, and four critical flaws with no fix to apply

discovered 2026-08-02 23:52 UTCrun 2026-08-02T2311Z-weekly9 sourcesmulti-source

Most vulnerability processes reduce to two questions: is anyone exploiting it, and is there something to install. The KEV catalog answers the first for a great many flaws, and a vendor advisory answers the second. This week produced counterexamples to both, in the same seven days.

On the exploitation axis, VulnCheck reported that it has watched attackers use Langflow's pre-authentication eval injection and stated the gap directly: "with LangFlow, we've seen attackers gain initial access using exploits targeting both CVE-2026-0769 and CVE-2026-5027, harvest credentials, likely for services such as OpenAI and Claude, deploy cryptominers, and attempt lateral movement. Neither of these vulnerabilities have been added to CISA KEV." (VulnCheck, 2026-07-28). The underlying advisory compounds it: Zero Day Initiative published CVE-2026-0769 as a 0-day, records that "this vulnerability allows remote attackers to execute arbitrary code on affected installations of Langflow. Authentication is not required to exploit this vulnerability." (Zero Day Initiative, 2026-01-09), and offers restricting interaction with the product as its only mitigation. A KEV-driven patch queue surfaces neither the flaw nor the fact that there is nothing to queue.

On the remediation axis, four items arrived with no fix to apply. The fastjson flaw "is exploitable under fastjson's stock default configuration — no AutoType enablement required, no classpath gadget required" (Alibaba fastjson2 project, 2026-07-21), attacks are already under way against organisations across financial services, healthcare and retail (Imperva, 2026-07-24), and the line is finished: "FastJson 1.x is no longer actively maintained, and no patched 1.x version has been released for this vulnerability." (Imperva, 2026-07-24). Siemens' own machine-readable advisory splits Desigo CC three ways — V9 fixed in 9.0.1, V8 fixed by applying patch V8.0 QU2.0021, and the entire V7 family carrying remediation category none_available with network segmentation as the only offered control (Siemens ProductCERT, 2026-07-14) — which for a building-management platform means the unpatchable population is a set of buildings, not a set of servers. That advisory predates this week; what puts it in the window is CISA's republication of it as ICSA-26-209-01 on 2026-07-28 (CISA, 2026-07-28). IBM disclosed a missing-authentication flaw in the WebSphere Application Server traditional administrative console at CVSS 9.8, states no workaround exists, and names APAR DT496500 with the permanent Fix Packs 9.0.5.29 / 8.5.5.31 targeted for 3Q2026 (IBM PSIRT, 2026-07-28); a companion bulletin the same day covers the unsafe-deserialization flaw and its interim fix under APAR PH72166 (IBM PSIRT, 2026-07-28). And CERT@VDE published 20 CVEs in Phoenix Contact CHARX SEC-3xxx EV charging controllers — five of them CVSS 9.8 with an unauthenticated network vector, including command injection that executes as root — with the fix still in the future at publication: "the updated firmware will be made available as soon as possible, but no later than August 12, 2026." (CERT@VDE, 2026-07-30).

The operational consequence is that for five of this week's most severe items, the work is not a patch ticket. It is answering an architecture question — what can reach this, and can that be reduced — on a building-management platform, a Java dependency buried inside vendor-supplied fat-JARs, an application server, an EV-charging controller fleet, and a self-hosted AI-agent platform. Those are different teams and different change processes from the one that applies monthly updates, and none of them is triggered by a KEV addition or a patch-available flag.

With LangFlow, we've seen attackers gain initial access using exploits targeting both CVE-2026-0769 and CVE-2026-5027, harvest credentials, likely for services such as OpenAI and Claude, deploy cryptominers, and attempt lateral movement. Neither of these vulnerabilities have been added to CISA KEV.

VulnCheck 2026-07-28

FastJson 1.x is no longer actively maintained, and no patched 1.x version has been released for this vulnerability.

Imperva 2026-07-24

The updated firmware will be made available as soon as possible, but no later than August 12, 2026.

CERT@VDE 2026-07-30

ATT&CK mapping

3 techniques mapped from the cited reporting · MITRE ATT&CK v19.1

Initial Access TA0001
T1190Exploit Public-Facing Application

Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.

overlap matrix · ATT&CK page ↗

Persistence TA0003
T1542.001Pre-OS Boot: System Firmware

Adversaries may modify system firmware to persist on systems.The BIOS (Basic Input/Output System) and The Unified Extensible Firmware Interface (UEFI) or Extensible Firmware Interface (EFI) are examples of system firmware that operate as the software interface between the operating system and hardware of a computer.

overlap matrix · ATT&CK page ↗

Privilege Escalation TA0004
T1068Exploitation for Privilege Escalation

Adversaries may exploit software vulnerabilities in an attempt to elevate privileges. Exploitation of a software vulnerability occurs when an adversary takes advantage of a programming error in a program, service, or within the operating system software or kernel itself to execute adversary-controlled code. Security constructs such as permission levels will often hinder access to information and use of certain techniques, so adversaries will likely need to perform privilege escalation to include use of software exploitation to circumvent those restrictions.

overlap matrix · ATT&CK page ↗

Stealth TA0005
T1542.001Pre-OS Boot: System Firmware

Adversaries may modify system firmware to persist on systems.The BIOS (Basic Input/Output System) and The Unified Extensible Firmware Interface (UEFI) or Extensible Firmware Interface (EFI) are examples of system firmware that operate as the software interface between the operating system and hardware of a computer.

overlap matrix · ATT&CK page ↗

PROVENANCE

AI-generated · no human review · this permalink is the shareable record for the finding · verify operationally critical claims against the linked primary source.