top of page

Cybersecurity Weekly Update: 27 July - 3 August 2026

  • Writer: SOC Team
    SOC Team
  • 4 hours ago
  • 3 min read

1. N-able N-central Infrastructure Account Takeover Campaign

Threat actors actively exploited a zero-day authentication bypass vulnerability in N-able N-central servers to execute unauthenticated administrative account takeovers across enterprise IT environments.


CVE ID: CVE-2026-18577 (CVSS Score: 9.8)


Why It Matters: N-central is an enterprise remote monitoring and management (RMM) platform widely deployed across managed service providers, financial institutions, and educational networks. Attackers who gained administrative access deployed persistent Cloudflare outbound tunnels onto managed endpoints, allowing continued remote access even after management portal routes were revoked.


Actions:

  1. Upgrade all self-hosted N-able N-central instances to build 2026.3.1.7 or later immediately.

  2. Audit endpoint service registries for unauthorized Cloudflare tunnel (cloudflared) services.


2. Check Point SmartConsole Critical Authentication Bypass


An improper authentication handling flaw in Check Point Security Management Server (SMS) and Multi-Domain Security Management (MDS) allows unauthenticated remote attackers to forge application tokens and gain full administrator privileges.


CVE ID: CVE-2026-16232 (CVSS Score: 9.1)


Why It Matters: Check Point management servers govern central firewall policies and access controls across defense, healthcare, and financial subnets in Europe and South Africa. Compromising the management plane enables adversaries to silently modify security rules and create persistent entry points.


Actions:

  1. Apply Check Point Jumbo Hotfixes immediately across all Gaia OS SMS and MDS deployments.

  2. Restrict SmartConsole login ports (TCP 19009) to trusted out-of-band management IP addresses.


3. JetBrains TeamCity Critical Authentication Bypass and Remote Code Execution


A critical vulnerability in JetBrains TeamCity On-Premises allows unauthenticated attackers to bypass authentication checks and execute arbitrary operating system commands on vulnerable servers. The vulnerability affects the TeamCity agent polling protocol and can potentially expose sensitive build configurations, credentials, and software development infrastructure.


CVE ID: CVE-2026-63077 (CVSS Score: 9.8)


Why It Matters: TeamCity is a widely used CI/CD platform that can hold source-code credentials, deployment secrets, build configurations, and access tokens. Successful exploitation of an internet-accessible TeamCity server could therefore give attackers a foothold into software development and deployment environments and potentially expose credentials that can be used for further compromise. JetBrains released fixes for the affected On-Premises versions on July 27, 2026.


Actions:

  1. Upgrade all affected TeamCity On-Premises servers to a fixed version immediately.

  2. Restrict internet exposure of TeamCity servers and place management interfaces behind VPN or other trusted access controls.

  3. Review TeamCity authentication, build, and administrative logs for suspicious activity.

  4. Rotate credentials and access tokens stored on potentially exposed TeamCity servers if compromise is suspected.


4. Arista VeloCloud Orchestrator Critical Zero-Day Exploited in the Wild

A critical command-injection vulnerability in Arista VeloCloud Orchestrator (VCO) On-Prem allows unauthenticated remote attackers to access privileged internal functionality and potentially compromise the VCO host. The vulnerability was disclosed on July 27, 2026, and was added to CISA's Known Exploited Vulnerabilities catalog after evidence of active exploitation.


CVE ID: CVE-2026-16812 (CVSS Score: 10.0)


Why It Matters: VeloCloud Orchestrator is used to centrally manage SD-WAN infrastructure. Successful exploitation could compromise the confidentiality, integrity, and availability of the orchestration platform and the data it manages. Because the flaw requires no authentication or user interaction, exposed VCO systems present a significant risk to enterprise network infrastructure.


Actions:

  1. Apply Arista's security update for CVE-2026-16812 immediately.

  2. Restrict access to VeloCloud Orchestrator management interfaces to trusted administrative networks.

  3. Review VCO logs for unexpected access, command execution, or other suspicious administrative activity.

  4. Investigate potentially exposed VCO systems for signs of unauthorized access or compromise.

  5. Ensure hosted and dedicated VCO environments have received the vendor's security updates.

Key Recommendations


  • Isolate Central Management & RMM Platforms

    Ensure remote management consoles (such as N-able N-central and Check Point SmartConsole) are strictly isolated behind dedicated management subnets.

    Protect management platforms with multi-factor authentication.

  • Harden Edge Remote Access Appliances

    Audit perimeter VPN gateways (such as Palo Alto GlobalProtect) to prevent cookie manipulation and unauthorized VPN session generation.

  • Enforce Out-of-Band Patching Cycles

    Prioritize zero-day vulnerabilities with confirmed active exploitation for emergency remediation within 24–48 hours.

    Ensure critical internet-facing systems are patched as soon as vendor fixes become available.

 
 
bottom of page