Security Roundup: IBM Langflow's Actively Exploited RCE Chain, a Qilin-Linked Check Point VPN Zero-Day, and a 31,000-Entity Government Breach (Week of August 3, 2026)

Weekly threat intelligence briefing: IBM Langflow CVSS 9.8 RCE, Check Point Qilin zero-day, Splunk Enterprise file write, and Liechtenstein breach.

Security Roundup: IBM Langflow's Actively Exploited RCE Chain, a Qilin-Linked Check Point VPN Zero-Day, and a 31,000-Entity Government Breach (Week of August 3, 2026)

From an unauthenticated remote code execution chain in IBM Langflow to a Qilin ransomware zero-day targeting Check Point VPNs and a 31,000-entity government register breach, here is your executive threat intelligence briefing for the week of August 3, 2026.

Key Stories This Week: IBM Langflow RCE: CVSS 9.8 code injection actively exploited against AI agent deployments. Check Point VPN Zero-Day: Qilin ransomware operators bypassing authentication on gateway appliances. Splunk Enterprise File Write: Unauth PostgreSQL sidecar flaw added to CISA KEV catalog. Liechtenstein Breach: 31,000 beneficial-ownership register records compromised.

1. IBM Langflow Unauthenticated RCE (CVE-2026-9198)

An unauthenticated CVSS 9.8 vulnerability in IBM Langflow allows remote attackers to execute arbitrary Python code directly on host systems through custom component evaluations.


2. Check Point VPN Zero-Day Exploited by Qilin (CVE-2026-50751)

Ransomware affiliates leveraged a zero-day authentication bypass flaw in Check Point Remote Access VPN gateways to breach enterprise perimeters and deploy file-encrypting payloads.


3. Splunk Enterprise Arbitrary File Write (CVE-2026-20253)

CISA issued an emergency directive after active exploitation was observed targeting an unauthenticated file write flaw in Splunk Enterprise's PostgreSQL sidecar daemon.


4. Liechtenstein Beneficial-Ownership Register Breach

Over 31,000 entity records detailing the true beneficial owners of private companies and trusts registered in Liechtenstein were accessed by unauthorized threat actors.