Tech Blog

everyWAN Blog

Technology, cybersecurity and IT trends that matter

Deep Analysis
Cybersecurity
IT Trends
Filter by:
CVE-2026-9198 en Langflow entra en el catálogo KEV de CISA el 4 de agosto de 2026: la capa de IA y automatización autoalojada (Langflow, n8n, Open WebUI) tratada como producción
8 min read

The AI pilot nobody switched off is already production

On 4 August, CISA added a 9.8 in Langflow to its exploited-vulnerabilities catalogue: one endpoint that hands superuser tokens to anyone who reaches the port, chained with another that runs whatever code you send it. The patch had been out for six weeks. It is not an isolated case: in Open WebUI the ENABLE_CODE_EXECUTION=false switch turned nothing off, and in n8n anyone who could edit a workflow could run commands on the host. Three products, the same starting assumption. What we do with the AI and automation layer, and when we recommend not self-hosting it at all.

CVE-2026-18577 en N-able N-central: un salto de autenticación en la consola desde la que los proveedores de IT gestionan los equipos de sus clientes, explotado con el control remoto del propio producto
10 min read

The agent we install on your machines is also a door

On 3 August, CISA added CVE-2026-18577 to its exploited-vulnerabilities catalogue with a deadline of the 6th. It is a flaw in the console many IT providers use to manage their customers' machines, and it arrived as the incomplete patch for another flaw published two days earlier. The vendor found out through a rise in licensing issues, not a security alert. Access was not granted by malware: the attackers used the product's own remote-control feature and left a tunnel behind so they would still be inside after the console was cut off. We are a managed services provider, and this post is about what that means for the people who hire us.

CVE-2026-66066, un fallo de CVSS 9,5 en Active Storage de Ruby on Rails, permite leer ficheros del servidor subiendo una imagen cuando la aplicación procesa variantes con libvips
10 min read

A 9.5 in Rails: the flaw is not in your application, it is in the library nobody chose

On 29 July 2026 Rails published CVE-2026-66066: a 9.5 in Active Storage letting an unauthenticated attacker read files from the server — including the process environment with secret_key_base and the database credentials — by uploading an image. The flaw is not in the code you commissioned, nor exactly in Rails: it is in which formats libvips considers safe to read, a C library nobody at your company chose. And libvips has published since 2022 which of its operations it has not verified, with a switch to block them. The label was there; what was missing was flipping it.

CVE-2026-63077, un fallo de CVSS 9,8 sin autenticación en todas las versiones de JetBrains TeamCity On-Premises, pone el foco en el servidor de CI/CD como sistema crítico
11 min read

Your CI/CD holds the keys to production. And you treat it as a developer tool

On 27 July 2026 JetBrains published CVE-2026-63077: an unauthenticated 9.8 affecting EVERY version of TeamCity On-Premises and allowing operating system commands to be run on the build server. There is no known exploitation. The two previous times TeamCity had a flaw like this ended with Russia's SVR inside technology companies and with BianLian operators creating users on build servers. The underlying problem is not TeamCity: it is that the machine which deploys to production is in almost nobody's critical systems inventory.

Más de 700 organizaciones afectadas por el robo de tokens OAuth de una aplicación conectada, sin ninguna contraseña robada
8 min read

The token that never asks for MFA: connected apps in your Microsoft 365

More than 700 organisations were potentially exposed in August 2025 without a single password being stolen: the attacker took the OAuth tokens of an application they had connected themselves. On 13 July 2026 Microsoft published the map of a full year of that technique: two attack chains and not one suspicious sign-in. The part that fails is not the login, it is consent: how to inventory the applications connected to your tenant with two Graph queries, what each button actually switches off, and why changing the consent setting revokes nothing already granted.

Nueve entradas del catálogo KEV de CISA en 2026 apuntan al plano de gestión de una red SD-WAN
8 min read

Your SD-WAN doesn't go down: it gets reconfigured

Of the 172 vulnerabilities CISA has flagged as exploited so far in 2026, nine point at the same place: the management plane of an SD-WAN. And the attacker Mandiant documented inside a Catalyst SD-WAN Manager took nothing down: they registered as a peer, copied the fabric's configuration templates through the product's own API and wiped their tracks. The numbers are our own count over the KEV catalogue, including the only two entries all year with a 48-hour deadline. What to look at when the attack looks like a legitimate configuration change and your monitoring stays green.

VMSA-2026-0006: dos vulnerabilidades CVSS 9,8 en VMware vCenter y un escape de máquina virtual en ESX
8 min read

VMSA-2026-0006: two 9.8s in vCenter, a VM escape and the flaw nobody will look at

On 29 July 2026 Broadcom published VMSA-2026-0006: five flaws in VMware ESX, vCenter, Workstation and Fusion, two of them CVSS 9.8 in vCenter and one 9.3 that allows escaping from a virtual machine to the host. There are no workarounds. What to patch first according to the advisory itself (the order is no longer the one you knew), why updating vCenter does not stop your workloads, where the patches are if you hold a perpetual licence with no support, and why the lowest-scoring flaw — ESX may not record what an administrator does — is the one that hurts afterwards.

Controladores de gestión BMC expuestos en internet: 36.872 servicios IPMI accesibles por UDP 623
8 min read

There is another computer inside your server, and 36,872 of them are on the internet

A scan published on 29 July 2026 found 36,872 management controllers (BMCs) listening on the internet over UDP/623, and 24,650 of them hand out material derived from the account password before anyone logs in. This is not a new CVE: it is CVE-2013-4786, a flaw in the IPMI 2.0 specification itself, dating from 2004, which Dell acknowledges has no patch. The numbers, why a factory password falls in between 32 seconds and one hour, why your EDR will not see it and the six steps to close the management plane of your hardware.

NIS2 en España: la ley sin publicar y el cuestionario de proveedor que ya está en tu correo
8 min read

NIS2 in Spain: the law is not here yet, your customer's questionnaire is

As of 29 July 2026 the Spanish law transposing NIS2 still has not been published in the official gazette: the text was approved by the Council of Ministers in January 2025 at first reading and is still a draft bill, and on 8 July the European Commission decided to refer Spain to the Court of Justice of the EU asking for penalties. That does not mean NIS2 is not affecting you: it means it will not arrive via an inspector, but via your largest customer's procurement department. What already applies today with no transposition needed, what those supplier questionnaires really ask, and what we would do with ninety days ahead of us.

CVE-2025-68686: el parche de FortiOS que se saltaba con una barra de más
8 min read

Patching is not cleaning: FortiOS and the extra slash

On 27 July, CISA added a FortiOS flaw to its exploited-vulnerabilities catalogue with a deadline attached: 10 August. CVE-2025-68686 opens no new door: it reopens the one Fortinet believed it had closed in April 2025, and it does so with one extra slash in the path. The story of the symbolic link in the language-files folder, the patch that was a string comparison, the 7.2, 7.0 and 6.4 branches left with no fix at all, and why patching is an action while being clean is a conclusion you have to prove.

CVE-2026-16812 en el VeloCloud Orchestrator: el orquestador SD-WAN expuesto por diseño
7 min read

Your WAN orchestrator is on the internet by design: VeloCloud's 10.0

CVE-2026-16812 is an unauthenticated command injection in the on-premises VeloCloud Orchestrator: CVSS 10.0, exploited before a patch existed, and in CISA's KEV catalogue the same day with three days to fix it. Arista's advisory says the console is exposed by default and that no configuration prevents that exposure; a few lines further down it recommends restricting access to the web interface to trusted administrative networks. Both are true, and the bad day is decided in the distance between them.

Cl0p extorsiona sin cifrar: campaña contra PTC Windchill y FlexPLM
7 min read

Cl0p didn't encrypt a single file: extortion walks in through the app nobody watches

Cl0p is exploiting a critical vulnerability in PTC Windchill and FlexPLM (CVE-2026-12569, CVSS 9.3) to steal engineering data and extort without encrypting anything. The patch had existed since June 17; the wave of extortion emails arrived a month later. Why your backups can't undo a theft, what the Accellion→MOVEit→Oracle EBS pattern teaches (2,700+ organizations in a single campaign), and the five things we would do this week.

Secuestro de DNS en Wi-Fi de hoteles para robar cuentas de Microsoft 365
7 min read

The hotel Wi-Fi works for someone else: DNS hijacked to steal Microsoft 365 accounts

Since June 2026 an active campaign has been compromising captive portals at hotels and conference centers, changing their DNS and redirecting guests to fake Microsoft 365 pages. The refined part: by abusing the device code flow they take your account without stealing your password, with MFA "satisfied". What is happening, why the padlock won't save you, and what we would do: from full-tunnel VPN to blocking the device code flow.

Una IA autónoma automatiza la post-explotación en un ataque real; la respuesta es detección 24/7
8 min read

The tireless intern now works for the other side: an autonomous AI is already automating real attacks

In an intrusion at Thailand's Ministry of Finance, the attacker left an open-source AI agent running unattended to automate the boring part of the attack: enumerate, escalate privileges, find the next step. It broke nothing new —it got in through default credentials and unpatched 2021 CVEs— but it did the dirty work faster and without rest. What actually changes is speed, and the only answer to speed is 24/7 detection and response.

Certighost (CVE-2026-54121): impersonar un Domain Controller vía AD CS
8 min read

Certighost: any user could become your Domain Controller. The question isn't whether you patched, it's whether you've audited your AD CS

Certighost (CVE-2026-54121) let an unprivileged domain user impersonate a Domain Controller via Active Directory Certificate Services and take over the entire domain. Microsoft patched it on July 14; a working PoC has been public since July 24. The mechanism in one sentence, why AD CS is the escalation surface almost nobody audits, and the plan for today: patch, inventory your CAs, machine account quota to zero, and audit templates.

Check Point SmartConsole
Zero-day CVE-2026-16232 · exposed management
8 min read

The Check Point zero-day wasn't after your firewall: it was after its console

CVE-2026-16232: an authentication bypass in SmartConsole allowed logging into the server that governs all your Check Point gateways as an administrator, with no credentials. It was exploited before the patch existed and CISA gave three days to remediate. Why the management plane is a bigger prize than the firewall itself, and the checklist that applies even without Check Point.

FakeGit
7,600 fake repos; your AI is the target
8 min read

Malware no longer fools you: it fools your AI. FakeGit and its 7,600 fake GitHub repositories

The FakeGit campaign seeded GitHub with 7,600 fake repositories; roughly 200 of them alone account for over 14 million malware downloads. The news isn't the volume: more than 800 posed as MCP servers and AI skills, and the assistants recommended them on their own. It has a name now: agentbaiting.

Romania's land registry
Wiped; saved by the out-of-reach copy
8 min read

Romania's land registry was wiped, backups included. It was saved by the copy the attacker couldn't touch

On July 14 an attacker got into Romania's ANCPI with valid credentials, failed to extort the agency, and wiped the land registry database plus every backup within reach. A week with no property sales or mortgages nationwide. The difference between incident and catastrophe was one copy beyond his reach.

Subscribe to our newsletter

To receive IT stories, everyWAN news and exclusive subscriber offers, sign up to our mailing list

Minorisa de Sistemas Informaticos y Gestión S.L. © 2026
everyWAN
everyWAN