This week's roundup highlights the exploitation of Apache Tomcat and SonicWall SMA vulnerabilities, a nearly two-decade-old Linux kernel flaw, critical bugs in N-able N-Central, Veeam ONE, Jenkins, and Cisco IOS XE, along with AI-security incidents affecting Claude, Kimi K3, and code editors like Cursor and VS Code. CISA Warns of Apache Tomcat Encryption Flaw CISA added a high-severity missing-encryption flaw in Apache Tomcat's EncryptInterceptor to its Known Exploited Vulnerabilities catalog, requiring federal agencies to remediate by August 7, 2026. A 18-Year-Old Linux Kernel SCTP Vulnerability Named SCTPhantom This use-after-free bug in the Linux kernel's SCTP Dynamic Address Reconfiguration feature dates back to code from 2007, enabling unprivileged local users to escalate privileges and even escape containers.
TencentOS Security Team utilized an AI-assisted research tool called Corvus AI to construct a full privilege-escalation chain that bypasses Kernel Address Space Layout Randomization (KASLR) and triggers commit_creds without the need for shellcode or ROP chains, achieving root access across various Linux distributions. Mitigations include enforcing Extended Protection for Authentication, segmenting database network access, and auditing stored-procedure calls involving suspicious file extensions. The most severe vulnerability is CVE-2026-20272 (CVSS 9.8), involving command/OS injection risks; while CVE-2026-20267 (CVSS 9.0) covers improper access control, with five additional flaws scoring up to 8.6 for memory buffer, resource lifetime, calculation, control-flow, and input-validation weaknesses.












