This month: 6 KEVs detected

CISA stopped reliably sending KEV alerts.
We didn't.

CyberComply monitors the CISA Known Exploited Vulnerabilities catalog 24/7 and alerts you the moment a new KEV drops — before the deadline clock starts ticking without you knowing.

CVE-2026-8037
Progress · LoadMaster
Progress LoadMaster Command Injection Vulnerability
Detected Aug 7 · 3-day patch deadline
CVE-2026-63077
JetBrains · TeamCity
JetBrains TeamCity Deserialization of Untrusted Data Vulnerability
Detected Aug 5 · 3-day patch deadline
CVE-2026-18556
N-able · N-central
N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability
Detected Aug 4 · 3-day patch deadline

KEV Intelligence Brief — August 7, 2026

Prepared by: Cybersecurity Intelligence | Distribution: Federal Contractors, DevOps, SecOps Leadership

This week's KEV additions paint a consistent picture: attackers are targeting the infrastructure layer beneath applications — load balancers, build systems, RMM platforms, AI tooling, and firewall management consoles. Several deadlines have already passed or expire this weekend. Teams should treat this brief as an active operational checklist, not background reading.

Network and Security Management Infrastructure: Multiple Paths to Full Compromise

The most operationally urgent cluster this week involves products that sit at the trust boundary of enterprise networks — where a single bypass can hand an adversary the keys to everything downstream.

N-able N-central is carrying two related CVEs added within 24 hours of each other. CVE-2026-18577 (added August 3, deadline August 6 — now overdue) is an authentication bypass enabling account takeover. CVE-2026-18556 (added August 4, deadline August 7 — today) is explicitly described as an incomplete patch for that first vulnerability. This is a textbook patch-bypass scenario. If your team applied the initial N-central fix and considered the matter closed, you should assume the remediation is insufficient. N-central's privileged position as a remote monitoring and management platform means compromise here translates directly to lateral movement across every managed endpoint in your environment. Isolate internet-facing N-central instances immediately, verify the latest vendor patch is applied, and audit administrative account activity for anomalous access patterns dating back at least 30 days.

Cisco Secure Firewall Management Center (FMC) (CVE-2026-20316, deadline August 1 — overdue by six days) exposes a hard-coded password that allows unauthenticated remote attackers to authenticate with a low-privileged account. On a firewall management plane, "low-privileged" is rarely the end of the story — it is reconnaissance real estate. If you have not patched, assume the credential is known to threat actors. Rotate all local FMC accounts, review policy change logs, and verify no unauthorized firewall rules were introduced. BOD 26-04 obligations for this CVE are past due; federal contractors operating unpatched FMC instances are out of compliance today.

Fortinet FortiOS (CVE-2025-68686, deadline August 10) requires a slightly different analytical frame. Exploitation requires prior filesystem-level access, making this a post-exploitation persistence mechanism rather than an initial access vector. Specifically, it bypasses the symbolic link cleanup patch Fortinet has pushed in response to earlier campaigns. If your FortiOS devices have been involved in any incident in the past 12 months, this vulnerability means previously believed-remediated persistence may still be active. Apply the patch, but also conduct forensic triage per CISA's requirements — particularly examining SSL-VPN virtual filesystem mounts and unexpected symbolic links.

Developer and Build Infrastructure: Unauthenticated RCE in the Pipeline

Attackers who can compromise the systems that build and deploy software gain access far beyond any single application. Two entries this week target exactly that surface.

JetBrains TeamCity (CVE-2026-63077, deadline August 8 — tomorrow) introduces deserialization of untrusted data exploitable through the agent polling protocol — meaning the attack surface is not just the web UI but any port TeamCity build agents use to check in. Unauthenticated RCE on a CI/CD server is a supply chain event waiting to happen. Treat an unpatched TeamCity server as a compromised build environment: review recent build artifacts, pipeline configurations, and deployment keys for signs of tampering. If TeamCity is internet-facing, take it offline until patched. This is not an acceptable tradeoff to preserve build uptime.

IBM Langflow (CVE-2026-9198, deadline August 7 — today) allows unauthenticated code injection on default deployments — a detail worth underlining. Many Langflow instances in AI development environments were stood up rapidly, often without hardened configurations, as teams moved fast on generative AI initiatives. The default attack surface is broad. Any organization running Langflow for AI workflow orchestration should audit for internet exposure immediately, apply vendor mitigations, and validate that no unauthorized flows or API keys were injected into the environment.

Deadline Watch: Application Infrastructure Under Active Exploitation

Two additional entries round out the week and require immediate attention from application and platform teams.

Progress LoadMaster (CVE-2026-8037, deadline August 10) enables command injection through unsanitized input across multiple command endpoints — with no authentication required. LoadMaster appliances are often deployed as ADCs for critical application delivery; compromise can enable traffic interception and session hijacking at scale. Notably, Progress had a difficult 2024–2025 with MOVEit and related tooling; their products have been attractive targets. Apply vendor mitigations now, restrict management interface access to trusted IP ranges, and treat this with the same urgency as prior Progress vulnerabilities that led to mass exploitation.

Apache Tomcat (CVE-2026-34486, deadline August 7 — today) allows bypass of the EncryptInterceptor, effectively stripping the encryption layer from cluster session replication traffic. In multi-node Tomcat deployments — common in Java enterprise and government application stacks — this exposure can allow a network-adjacent attacker to intercept or tamper with sensitive session data. Patch immediately and verify EncryptInterceptor configuration is functioning as intended post-update.

Operational Reminder: Six of these eight deadlines fall between July 27 and August 10. Three are already overdue. For federal agencies and contractors subject to BOD 26-04, compliance is not optional — document your remediation status, exceptions, and compensating controls now.

Sources: CISA KEV Catalog · CISA BOD 26-04 · Cisco Security Advisory – FMC · Fortinet PSIRT Advisory – FortiOS · Progress LoadMaster Security Advisories · JetBrains TeamCity Security Bulletin · N-able Security Advisories · Apache Tomcat Security Reports

Free KEV Alerts

  • Real-time notification the moment a KEV drops
  • Vendor and product details
  • BOD 26-04 remediation deadline included

Pro Alerts Coming Soon

  • Real-time notification the moment a KEV drops
  • Filtered to your specific vendor watchlist
  • Urgency scoring (Critical / Urgent / Standard)
  • Direct patch links included

Stay ahead of CISA.

No spam. Unsubscribe anytime. We don't sell your data.


Upcoming Patch Due Dates

via Binding Operational Directive 26-04

BOD 26-04 is CISA's current vulnerability remediation directive for Federal Civilian Executive Branch (FCEB) agencies, updating the KEV-driven framework introduced under BOD 22-01 with a more risk-based approach to prioritization. While binding only on FCEB agencies, its framework increasingly influences contractor expectations through procurement requirements, FedRAMP programs, and agency security clauses.

Loading...

News Logo

Cyber Security News

You may have missed...


Hacking Editorial Brief — August 8, 2026

Snowflake Breach Attacker Pleads Guilty

Connor Riley Moucka, a Canadian national, pleaded guilty to charges stemming from the mass Snowflake data breach that compromised 165 companies. The attacker faces between 2 and 30 years in prison for the campaign, which represents one of the largest cloud data theft incidents on record. Separately, a Coldcard Bitcoin hardware wallet firmware vulnerability has resulted in over $111 million in cryptocurrency theft, with victims reporting a median loss of 1 BTC. The exploit, which began last Thursday with an initial $35 million in stolen Bitcoin, targets a bug in Coldcard's firmware that manufacturer Coinkite is now addressing.

Zero-Click Exploits and Critical Infrastructure Targeting

Security researchers at Black Hat demonstrated a zero-click exploit chain capable of remotely compromising mobile devices without user interaction, highlighting persistent weaknesses in mobile platforms. The disclosure follows Apple's decision to limit bug bounty submissions due to an influx of AI-generated reports degrading program quality. Meanwhile, Iran-linked threat actors are conducting an active campaign targeting U.S. water utilities, though operators report no successful compromises to date. North Carolina ports have also faced recent cyberattacks, and Wall Street hedge funds were targeted in separate intrusion attempts, according to incident reports this week.

Sources: CSO Online · Bitcoin Magazine · PC Mag · SecurityWeek · Keys Weekly

📌 Pinned

*

https:betanews.comMar 5

Inside a cyberattack: How hackers steal data

The truth about cybersecurity is that it's almost impossible to keep hackers outside of an organization, particularly as the cybercrime industry ...

https://thehackernews.comFeb 12

China-Linked UNC3886 Targets Singapore Telecom Sector in Cyber Espionage Campaign

A China-linked group designated UNC3886 breached all four of Singapore's major telecommunications providers using zero-day exploits and rootkits to ga...

https://therecord.mediaAug 5

Chinese telcos maintain deep US presence despite Salt Typhoon links, House committee says

Congress's bipartisan Select Committee on China published a 49-page investigation finding that China Mobile, China Unicom, and China Telecom continue ...

https://x.comAug 7

Metabase Zero-Day RCE Exploit (CVSS 10.0)

An exploited Metabase zero-day with a CVSS 10.0 SQL injection vulnerability allows unauthenticated attackers to reach administrator access, steal conn...

https://www.fbi.govAug 2

Malicious Cyber Actors Targeting Water and Wastewater Sector Internet-Facing Programmable Logic Controllers

The FBI and EPA issued a joint alert warning of cyberattacks since July 27 targeting water utilities using Rockwell Automation PLCs, causing operation...

https://www.cisa.govAug 27

CISA and Partners Release Joint Advisory on Countering Chinese State-Sponsored Actors

CISA, NSA, FBI, and international partners released a joint cybersecurity advisory detailing ongoing malicious activity by Chinese state-sponsored APT...

https://www.bloomberg.comAug 4

House Report Finds US Telecom Data Centers Exposed in Chinese Hack

A House Select Committee on China report reveals that US telecommunications companies connected their systems to data centers in ways that exposed the...

https://www.youtube.comAug 7

FBI says hackers altered operating instructions for water systems in some states - YouTube

At least 12 states are reporting cyberattacks on water systems that may be linked to Iran-backed hackers. CBS News homeland security correspondent ...

https://thehackernews.comAug 6

CISA Flags TeamCity CVE-2026-63077 RCE Flaw Under Active Exploitation in the Wild

CISA warns that attackers are actively exploiting TeamCity CVE-2026-63077, an unauthenticated RCE flaw that can expose credentials and compromise buil...


Updated daily