If you just remember one thing from this briefing…
Four perimeter and remote-management platforms were added to the exploited-vulnerability catalogue in thirteen days.
FortiOS, Cisco's firewall manager, N-able's remote-monitoring platform and clustered Apache Tomcat all sit at
the edge or in the remote-access layer that airports, airlines and their IT suppliers depend on. Ask your
team this week: can we confirm patch status and internet exposure for all four, across our own estate and
every supplier that touches it, today rather than by next change window?
Priority1–5 Aug
N-able N-central remote-monitoring platform exploited to hijack MSP-managed endpoints
N-able confirmed active exploitation of an authentication bypass in its N-central RMM tool from 1 August,
bypassing an earlier fix. Attackers used the platform's remote-control function and deployed Cloudflare
Tunnel for persistence. CISA added both flaws to its exploited-vulnerability catalogue on 3 and 5 August.
So what: any supplier or station using N-central may already be compromised. Confirm
build 2026.3.1.7 or later and hunt for unexpected Cloudflare Tunnel activity.
Priority27 Jul
FortiOS patch-bypass added to the catalogue — old SSL-VPN compromises can regain persistence
CISA catalogued CVE-2025-68686, a FortiOS flaw letting an attacker who previously breached a device via
one of three earlier SSL-VPN CVEs bypass the symlink-removal patch and retain filesystem access. Affects
FortiOS 6.4 through 7.6.1.
So what: a device patched against the original flaw may still be compromised. Audit
any unit with a history of the earlier CVEs for lingering symlinks, not just current patch level.
Priority29 Jul
Hardcoded credential in Cisco Secure Firewall Management Center exploited
CISA catalogued CVE-2026-20316, a hardcoded low-privileged account in Cisco Secure FMC's web interface
(CVSS 8.9), giving remote unauthenticated access to firewall policy, event logs and configuration data, and
chainable to escalate privileges.
So what: FMC manages firewall policy across airport and airline networks. Install the
fixed release and rotate every exposed credential now.
Watch4–5 Aug
Apache Tomcat encryption-bypass exploited by China-nexus actor, added to the catalogue
CISA catalogued CVE-2026-34486 on 4 August after observing exploitation of clustered Tomcat deployments,
including use by a China-nexus group deploying the SNOWLIGHT loader against targets in over 100 countries.
Fixes are in 11.0.21, 10.1.54 and 9.0.117.
So what: check booking, reporting or back-office applications for clustered Tomcat
and patch to the fixed builds this week.