Security Roundup: IBM Langflow's Actively Exploited RCE Chain, a Qilin-Linked Check Point VPN Zero-Day, and a 31,000-Entity Government Breach (Week of August 3, 2026)
Weekly threat intelligence briefing: IBM Langflow CVSS 9.8 RCE, Check Point Qilin zero-day, Splunk Enterprise file write, and Liechtenstein breach.
From an unauthenticated remote code execution chain in IBM Langflow to a Qilin ransomware zero-day targeting Check Point VPNs and a 31,000-entity government register breach, here is your executive threat intelligence briefing for the week of August 3, 2026.
1. IBM Langflow Unauthenticated RCE (CVE-2026-9198)
An unauthenticated CVSS 9.8 vulnerability in IBM Langflow allows remote attackers to execute arbitrary Python code directly on host systems through custom component evaluations.
2. Check Point VPN Zero-Day Exploited by Qilin (CVE-2026-50751)
Ransomware affiliates leveraged a zero-day authentication bypass flaw in Check Point Remote Access VPN gateways to breach enterprise perimeters and deploy file-encrypting payloads.
3. Splunk Enterprise Arbitrary File Write (CVE-2026-20253)
CISA issued an emergency directive after active exploitation was observed targeting an unauthenticated file write flaw in Splunk Enterprise's PostgreSQL sidecar daemon.
4. Liechtenstein Beneficial-Ownership Register Breach
Over 31,000 entity records detailing the true beneficial owners of private companies and trusts registered in Liechtenstein were accessed by unauthorized threat actors.