Security NEXTAugust 5, 2026🇯🇵Translated from Japanese

Prepare for Summer Vacation: Patch Tuesday Overlaps with Obon Holiday Week Raises Risks

As August begins, increasing numbers of individuals and organizations prepare for summer vacation. In 2026, many organizations will see Patch Tuesday coincide with the Obon holiday week, creating elevated risk that requires attention.

During long holidays, system administrators and security personnel are frequently absent, making contact difficult. This extends the time from incident discovery and reporting to the implementation of countermeasures, increasing overall risk compared with normal operations. Although vacation periods show some dispersion trends, certain organizations still concentrate absences in specific windows.

Security agencies continue to issue calls for holiday preparedness. Ransomware and other attack campaigns often exploit periods when patching and response are delayed, such as evenings, weekends, and consecutive holidays.

Before vacation, organizations should update server, network, and endpoint software as appropriate to remediate known vulnerabilities. Security product definition files must be brought to the latest versions, and basic controls should be re-verified. Systems and devices not required during the break should be powered off after confirming the impact, thereby reducing exposure.

Related vulnerabilities reported

  • Tenable Sensor Proxy RCE vulnerability – fixed version released
  • Serious flaw in Terraform MCP Server – corrected release published
  • Critical vulnerability in backup management product Veeam ONE
  • Exploitation warnings for three vulnerabilities affecting Langflow, Tomcat and others – U.S. authorities
  • Synology NAS detection tool Windows version vulnerability – patch available
  • Adobe Campaign Classic vulnerability – affects prior fixed version, requires further update

Related articles

HabrVulnerabilities & Exploits

2.2 Million Line Vulnerability Report: What Happens After Discovery and How to Turn Findings Into Action

A massive vulnerability scan produced an 1,819-page report and a 2.2-million-row Excel file that exceeded spreadsheet limits, highlighting the gap between detection and remediation. The article explains that finding vulnerabilities accounts for only 10 percent of the work, while the remaining 90 percent involves prioritization, remediation, verification, and ensuring issues do not reappear. Research from BI.ZONE, Sber, Qualys, Cyentia Institute, Kenna Security, and Hadrian shows that organizations can typically remediate only one in ten open vulnerabilities per month and that Time-to-Exploit has dropped dramatically, with many edge-device flaws exploited on the day of disclosure. The piece stresses that continuous scanning, full infrastructure coverage including shadow IT, and separate high-frequency perimeter scans are essential because 85 percent of KEV-vulnerable assets remain unpatched at disclosure time. It recommends replacing bulky reports with concise, role-specific registries that answer four questions: what to do, where to do it, by when, and the consequences of inaction. Three legitimate outcomes for every vulnerability are outlined: patching, compensating controls, or formal risk acceptance with defined review dates, while false positives such as orphaned OpenSSL libraries must be cleaned rather than ignored.

Security NEXTVulnerabilities & Exploits

Critical Remote Code Execution Flaw Patched in Veeam ONE Backup Management Product

Veeam Software disclosed six vulnerabilities in its backup environment operations management product Veeam ONE on July 29, 2026. The most severe issue, tracked as CVE-2026-64633, permits unauthenticated remote code execution on the agent host and received a maximum CVSS v4.0 base score of 10.0, rated Critical. A second flaw, CVE-2026-58075, allows unauthenticated arbitrary file reads that can lead to local privilege escalation and carries a CVSS score of 8.7. The vendor released updated versions addressing all six issues in Veeam ONE 13.1. Security researchers and administrators are urged to apply the patches immediately given the high severity and lack of authentication requirements for the critical vulnerability.

Security NEXTVulnerabilities & Exploits

CISA Adds Three Actively Exploited Vulnerabilities to KEV Catalog Affecting Langflow, Apache Tomcat and N-central

The U.S. Cybersecurity and Infrastructure Security Agency has added three known exploited vulnerabilities to its KEV catalog, urging federal agencies to apply patches by August 7, 2026. CVE-2026-9198 affects the AI application development platform Langflow and allows unauthenticated attackers to chain API calls, obtain tokens, and execute arbitrary code. CVE-2026-34486 impacts Apache Tomcat and enables bypass of the EncryptInterceptor, leaving cluster node communications unencrypted. CVE-2026-18556 in N-able N-central permits authentication bypass through alternate channels, while an incomplete fix introduced CVE-2026-18577, which was added to the catalog one day earlier. All three issues have confirmed exploitation in the wild.

BoletimSecVulnerabilities & Exploits

Web Application Vulnerabilities Surge as Rapid Development Outpaces Security Reviews

The number of vulnerabilities in web applications continues to rise each quarter with no signs of slowing. Frequent releases, lean teams, and pressure for speed are pushing systems into production with flaws that should have been caught earlier. Vibe Coding is accelerating the problem by enabling anyone to launch applications in days and push dozens of updates daily without integrating cybersecurity into the process. Most new software reaches production without any security review, and attackers are already exploiting the common weaknesses these applications share. Companies face data leaks, service disruptions, and customer exposure from issues that a single test could have identified. The recommended response is AI-driven pentesting that simulates real attacker behavior instead of relying on known patterns. Launching web applications without security testing is becoming an increasingly expensive decision as incident costs far exceed preventive measures.