Six independent disclosures this week ended with the same result: the vendor's fix was applied and the estate was still exposed — a bypassable hotfix, a fix that reintroduced the bug, a patch build that was itself the affected version, and an actor observed rolling a patch back
If you did nothing this week: nothing changed. If you patched this week, six separate products could still leave you exposed — because the fix was bypassable, was superseded, was itself the affected build, or was rolled back by someone already inside.
The clearest case is the one that is actively exploited. N-able confirmed in-the-wild exploitation of an authentication bypass giving unauthenticated administrative access to the N-central RMM console, and then confirmed that its own earlier remediation had failed, issuing a second identifier for an alternative path to the same flaw that the first fix did not mitigate (N-able, 2026-08-06). It then shipped Hotfix 2 with language that leaves no room for interpretation — "Hotfix 2 is required, even if you already applied the earlier hotfix. Hotfix 2 supersedes Hotfix 1" (N-able, 2026-08-06). This pipeline named build 2026.3.1.7 as the remedy on 3 August; that build is no longer sufficient. Between those two dates Sophos X-Ops published what the actor does with the console once it has it — reaching "high-value endpoints such as a backup server, domain controllers, and application servers" from the compromised N-central server (Sophos X-Ops, 2026-08-04) — which is why upgrading the server is the start of the work rather than the end of it.
Three more cases are failures of the fix itself rather than of its coverage. The Apache Tomcat security team's own description of CVE-2026-34486, which CISA added to its exploited-vulnerabilities catalogue on 4 August, is that "an error in the fix for CVE-2026-29146 allowed the EncryptInterceptor to be bypassed" — so the affected set is limited to the releases that carried that broken fix; on the 11.x line that is 11.0.20, fixed in 11.0.21 (Apache Tomcat, 2026-04-09). Adobe published APSB26-120 on 3 August for seven flaws in on-premise Campaign Classic v7, three of them unauthenticated CVSS 10.0 paths to code execution, with the affected range given as "7.4.3 build 9398 and earlier" (Adobe PSIRT, 2026-08-03) — and build 9398 is the release Adobe shipped five days earlier, in APSB26-114, to close the preceding critical wave (Adobe PSIRT, 2026-07-29). In Flowise, CVE-2026-70636 lets an unauthenticated caller reach the OAuth2 credential-refresh endpoint by appending a trailing identifier that defeats prefix-based whitelist matching in the auth middleware — which VulnCheck records as a bypass of the earlier fix for CVE-2026-41273 (VulnCheck, 2026-08-07). Apple's fifth case is adjacent rather than identical: macOS 26.6.1 and its siblings fix CVE-2026-65400, where "an attacker on the network may be able to authenticate to Screen Sharing without valid credentials" (Apple, 2026-08-06), one week after the reverse-engineer fG! publicly described a separate pre-authentication bug in the same screensharingd daemon which he says Apple had closed under a denial-of-service entry in the preceding bulletin (fG!, 2026-07-29) — a characterisation Apple has not endorsed.
The sixth case is the one that generalises the others, because it removes the assumption underneath all patch-state reporting. Rapid7's account of the SonicWall SMA 1000 chain is that the actor did not merely survive remediation but undid it: "We observed the threat actor maintaining persistence and rolling the newly applied patch back to a vulnerable state to maintain access. A comprehensive forensic review of the firewall is required to ensure complete eviction" (Dark Reading, 2026-07-17). Resecurity's parallel analysis makes the same point about artefacts rather than versions, noting that setuid binaries, Python injectors, modified init scripts and web-server configuration changes "can survive reboots and may persist after a superficial firmware upgrade if not remediated" (Resecurity, 2026-08-01).
Triage: the benign lookalike for all of this is ordinary patch and maintenance activity, and the discriminator is authorship and sequence. A version downgrade or a firmware rollback on an edge appliance is a rare, deliberate operation — correlate every observed version regression against your own change record, and treat an unexplained one as intrusion evidence rather than administrative error. On managed-endpoint platforms, the tell is a tunnelling or remote-access client registered as a service on hosts below the management server rather than on the server itself, since a legitimate administrator deploys tooling from the console rather than leaving per-endpoint services behind.
This is not a duplicate of our previous communication — Hotfix 2 is required, even if you already applied the earlier hotfix. Hotfix 2 supersedes Hotfix 1 with additional hardening measures to further protect you and your customers.
An error in the fix for CVE-2026-29146 allowed the EncryptInterceptor to be bypassed.
We observed the threat actor maintaining persistence and rolling the newly applied patch back to a vulnerable state to maintain access. A comprehensive forensic review of the firewall is required to ensure complete eviction.
ATT&CK mapping
6 techniques mapped from the cited reporting · MITRE ATT&CK v19.2
Initial Access TA0001
T1190Exploit Public-Facing Application
Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.
Execution TA0002
T1072Software Deployment Tools
Adversaries may gain access to and use centralized software suites installed within an enterprise to execute commands and move laterally through the network. Configuration management and software deployment applications may be used in an enterprise network or cloud environment for routine administration purposes. These systems may also be integrated into CI/CD pipelines. Examples of such solutions include: SCCM, HBSS, Altiris, AWS Systems Manager, Microsoft Intune, Azure Arc, and GCP Deployment Manager.
Defense Impairment TA0112
T1601.002Modify System Image: Downgrade System Image
Adversaries may install an older version of the operating system of a network device to weaken security. Older operating system versions on network devices often have weaker encryption ciphers and, in general, fewer/less updated defensive features.
Lateral Movement TA0008
T1072Software Deployment Tools
Adversaries may gain access to and use centralized software suites installed within an enterprise to execute commands and move laterally through the network. Configuration management and software deployment applications may be used in an enterprise network or cloud environment for routine administration purposes. These systems may also be integrated into CI/CD pipelines. Examples of such solutions include: SCCM, HBSS, Altiris, AWS Systems Manager, Microsoft Intune, Azure Arc, and GCP Deployment Manager.
T1210Exploitation of Remote Services
Adversaries may exploit remote services to gain unauthorized access to internal systems once inside of a network. Exploitation of a software vulnerability occurs when an adversary takes advantage of a programming error in a program, service, or within the operating system software or kernel itself to execute adversary-controlled code. A common goal for post-compromise exploitation of remote services is for lateral movement to enable access to a remote system.
Command and Control TA0011
T1219Remote Access Tools
An adversary may use legitimate remote access tools to establish an interactive command and control channel within a network. Remote access tools create a session between two trusted hosts through a graphical interface, a command line interaction, a protocol tunnel via development or management software, or hardware-level access such as KVM (Keyboard, Video, Mouse) over IP solutions. Desktop support software (usually graphical interface) and remote management software (typically command line interface) allow a user to control a computer remotely as if they are a local user inheriting the user or software permissions. This software is commonly used for troubleshooting, software installation, and system management. Adversaries may similarly abuse response features included in EDR and other defensive tools that enable remote access.
T1572Protocol Tunneling
Adversaries may tunnel network communications to and from a victim system within a separate protocol to avoid detection/network filtering and/or enable access to otherwise unreachable systems. Tunneling involves explicitly encapsulating a protocol within another. This behavior may conceal malicious traffic by blending in with existing traffic and/or provide an outer layer of encryption (similar to a VPN). Tunneling could also enable routing of network packets that would otherwise not reach their intended destination, such as SMB, RDP, or other traffic that would be filtered by network appliances or not routed over the Internet.
Sources
AI-generated · no human review · this permalink is the shareable record for the finding · verify operationally critical claims against the linked primary source.