Executive Summary
FURULIE LLC reviewed authoritative defensive sources published or updated between Tuesday, August 5, 2026 and Friday, August 7, 2026, and found three items worth immediate attention for enterprise defenders. First, Cisco published two August 5 hardening releases covering grouped critical vulnerability classes in Cisco Catalyst SD-WAN Software and Cisco IOS XE Software. Second, JetBrains published an August 7 follow-up confirming reports of active exploitation and attempted exploitation against unpatched TeamCity On-Premises servers affected by CVE-2026-63077. Third, CERT/CC published vulnerability note VU#987105 on August 7 for a heap buffer overflow in the widely embedded stb_truetype font parsing library.
The operational pattern matters more than any single CVE count. Two of these developments sit on high-trust control planes that can influence routing, credentials, software delivery, and downstream service integrity. The third is a software supply chain signal: an embeddable library issue that may not appear cleanly in enterprise asset inventories even when it is present in internally built or third-party applications.