Security Roundup: IBM Langflow's Actively Exploited RCE Chain, a Qilin-Linked Check Point VPN Zero-Day, and a 31,000-Entity Government Breach (Week of August 3, 2026)

Weekly threat intelligence briefing: IBM Langflow CVSS 9.8 RCE, Check Point Qilin zero-day, Splunk Enterprise file write, and Liechtenstein breach.

Security Roundup: IBM Langflow's Actively Exploited RCE Chain, a Qilin-Linked Check Point VPN Zero-Day, and a 31,000-Entity Government Breach (Week of August 3, 2026)
Photo by Roman Denisenko / Unsplash

From an unauthenticated remote code execution chain in IBM Langflow to a Qilin ransomware zero-day targeting Check Point VPNs and a 31,000-entity government register breach, here is your executive threat intelligence briefing for the week of August 3, 2026.

⚡
Key Stories This Week: IBM Langflow RCE: CVSS 9.8 code injection actively exploited against AI agent deployments. Check Point VPN Zero-Day: Qilin ransomware operators bypassing authentication on gateway appliances. Splunk Enterprise File Write: Unauth PostgreSQL sidecar flaw added to CISA KEV catalog. Liechtenstein Breach: 31,000 beneficial-ownership register records compromised.

1. IBM Langflow Unauthenticated RCE (CVE-2026-9198)

An unauthenticated CVSS 9.8 vulnerability in IBM Langflow allows remote attackers to execute arbitrary Python code directly on host systems through custom component evaluations.


2. Check Point VPN Zero-Day Exploited by Qilin (CVE-2026-50751)

Ransomware affiliates leveraged a zero-day authentication bypass flaw in Check Point Remote Access VPN gateways to breach enterprise perimeters and deploy file-encrypting payloads.


3. Splunk Enterprise Arbitrary File Write (CVE-2026-20253)

CISA issued an emergency directive after active exploitation was observed targeting an unauthenticated file write flaw in Splunk Enterprise's PostgreSQL sidecar daemon.


4. Liechtenstein Beneficial-Ownership Register Breach

Over 31,000 entity records detailing the true beneficial owners of private companies and trusts registered in Liechtenstein were accessed by unauthorized threat actors.

Read more

Brecha de Datos Médicos en Photon Health

Filtración en Photon Health: Zero-Day de Inyección SQL en Metabase Expone Recetas Médicas de Pacientes

📌Security Roundup Series: Semana del 9 de Octubre de 2026 • 4 min read deep dive🏛️Incident Overview: Target / Organization: Photon Health, Inc. (Plataforma de Prescripción Médica Digital) Threat Actor / Attribution: Actor Desconocido (Extorsión Financiera) Impact / Records Compromised: Nombres de pacientes, direcciones, números de teléfono, fechas de nacimiento, recetas médicas completas

By James Luther