CISA stopped reliably sending KEV alerts.
We didn't.
CyberComply monitors the CISA Known Exploited Vulnerabilities catalog 24/7 and alerts you the moment a new KEV drops — before the deadline clock starts ticking without you knowing.
KEV Intelligence Brief — August 28, 2026
Issued by: Security Operations Intelligence | Classification: TLP:WHITE Reporting Period: August 26–27, 2026 | Entries Covered: 8 CVEs
Eight vulnerabilities added to CISA's KEV catalog over the past 48 hours reflect three converging threat patterns: unauthenticated file system exposure in enterprise collaboration infrastructure, privilege escalation via Linux kernel weaknesses embedded across heterogeneous environments, and a cluster of aging-but-newly-exploited vulnerabilities in development toolchains and database services that organizations have allowed to persist far too long. Federal agencies and contractors operating under BOD 26-04 must treat the deadlines below as operational ceilings, not targets.
Emergency Window: Unauthenticated File Access and Active Infrastructure Targets
Two entries carry patch deadlines this weekend, making them the immediate operational priority for any team reading this brief.
CVE-2019-1068 (Microsoft SQL Server) carries a deadline of August 29 — tomorrow. This remote code execution vulnerability allows an attacker to execute arbitrary code in the context of the SQL Server Database Engine service account, a foothold that can rapidly translate into lateral movement, credential harvesting, and data exfiltration across any environment where SQL Server runs with elevated privileges. SQL Server instances should never be directly internet-exposed, but the reality of legacy architecture and misconfigured perimeter controls means many are. If patching cannot be completed before tomorrow's deadline, network-level isolation of SQL Server instances and audit of service account privileges are non-negotiable interim steps. Verify that the Database Engine service account is not running with domain admin or local system privileges.
CVE-2023-49105 (ownCloud) carries a deadline of August 30 and presents an arguably more acute risk: an improper authentication vulnerability that permits unauthenticated file access, modification, and deletion — provided the attacker knows the victim's username and the account lacks a configured signing key. In environments where ownCloud is used for document sharing, that username condition is trivially satisfied through directory harvesting, phishing artifacts, or prior breach data. Organizations should immediately audit signing-key configuration across all user accounts, force-enable signing keys as a mandatory baseline, and treat any ownCloud instance exposed to the public internet as compromised pending forensic review. CISA's Forensics Triage Requirements apply here explicitly.
Linux Kernel Privilege Escalation: A Multi-Distribution Crisis
CISA added two Linux Kernel entries that together represent a systemic risk across virtually every Linux-dependent workload in federal and commercial environments.
CVE-2026-53362 — a newly cataloged vulnerability in the Linux Kernel's IPv6 networking subsystem — enables privilege escalation and explicitly impacts distributions including SUSE and Red Hat, with the advisory noting additional products may be affected. The deadline is August 30, giving teams this weekend to act. Because IPv6 is enabled by default on most modern Linux deployments and is often left unmonitored relative to IPv4 traffic, this attack surface is broader than many teams currently model. Organizations that cannot patch immediately should assess whether disabling IPv6 is operationally feasible as a temporary mitigation and should prioritize patching on any internet-facing or multi-tenant systems first.
CVE-2022-0995 — a Linux Kernel out-of-bounds memory write vulnerability cataloged earlier — carries a deadline of September 9. Local users can leverage this to gain privileged access or trigger denial of service. While local access is required, this class of vulnerability is routinely chained with initial access techniques in post-exploitation sequences. Treat this as a privilege escalation enabler in your threat models, not a standalone low-severity finding. Distribution-specific patches from Red Hat, SUSE, Ubuntu, and Debian are available; confirm your kernel version and apply the appropriate update.
Developer Toolchain and Legacy Software: Long-Deferred Debt Comes Due
Three entries in this cycle target the software supply chain and development infrastructure, and two of them involve software that may already be end-of-life in your environment.
CVE-2026-66384 (JFrog Artifactory) is a path traversal vulnerability allowing authenticated users to write data outside the intended Docker cache path under specific remote-repository conditions. With a deadline of September 10, this is the furthest out in this cycle, but it demands immediate attention in any environment where Artifactory serves as a central artifact registry. A compromised artifact path in a CI/CD pipeline can propagate malicious content downstream to build systems and production deployments. Upgrade Artifactory and audit remote repository configurations for anomalous write activity.
CVE-2021-23758 (Ajax.NET Professional) exposes a critical deserialization of untrusted data vulnerability enabling remote code execution via arbitrary .NET class instantiation. AjaxPro is explicitly flagged as potentially end-of-life. The path forward here is not patching — it is removal or replacement. Any application surface still running AjaxPro should be inventoried immediately, and development teams should plan accelerated migration to supported .NET frameworks. Deadline: September 9.
The two Red Hat entries — CVE-2015-3246 (Libuser, race condition enabling /etc/passwd corruption and privilege escalation) and CVE-2015-5287 (ABRT, symlink attack enabling privilege escalation) — are over a decade old. Their addition to KEV in 2026 signals confirmed, active exploitation. ABRT is flagged as potentially end-of-life; discontinuation is the recommended path. For Libuser, apply available patches from Red Hat and assess whether the affected system configurations align with current hardening baselines. Deadline for both: September 9.
Operational Posture Summary
| CVE | Product | Deadline | Key Risk | |---|---|---|---| | CVE-2019-1068 | MS SQL Server | Aug 29 | RCE via DB Engine service account | | CVE-2023-49105 | ownCloud | Aug 30 | Unauthenticated file access/deletion | | CVE-2026-53362 | Linux Kernel | Aug 30 | Privilege escalation via IPv6 | | CVE-2015-3246 | Red Hat Libuser | Sep 9 | passwd corruption, local privesc | | CVE-2015-5287 | Red Hat ABRT | Sep 9 | Symlink-based local privesc (EoL) | | CVE-2021-23758 | Ajax.NET Pro | Sep 9 | RCE via .NET deserialization (EoL) | | CVE-2022-0995 | Linux Kernel | Sep 9 | Out-of-bounds write, local privesc | | CVE-2026-66384 | JFrog Artifactory | Sep 10 | Path traversal in artifact registry |
Federal contractors: BOD 26-04 compliance is mandatory. Document compensating controls for any asset where patch deadlines cannot be met and escalate through your authorizing official chain without delay.
Sources: CISA KEV Catalog · CISA BOD 26-04 · Microsoft SQL Server Security Advisory CVE-2019-1068 · ownCloud Security Advisory CVE-2023-49105 · JFrog Artifactory Security Bulletins · Red Hat Security Advisory: Libuser · Red Hat Security Advisory: ABRT · Linux Kernel Security · CISA Forensics Triage Guidance
Free KEV Alerts
- Real-time notification the moment a KEV drops
- Vendor and product details
- BOD 26-04 remediation deadline included
Pro Alerts Coming Soon
- Real-time notification the moment a KEV drops
- Filtered to your specific vendor watchlist
- Urgency scoring (Critical / Urgent / Standard)
- Direct patch links included
Stay ahead of CISA.
Search the KEV Catalog by Vendor or Product
Search for CVEs by vendor or product to identify known exploited vulnerabilities in your environment
Upcoming Patch Due Dates
via Binding Operational Directive 26-04
BOD 26-04 is CISA's current vulnerability remediation directive for Federal Civilian Executive Branch (FCEB) agencies, updating the KEV-driven framework introduced under BOD 22-01 with a more risk-based approach to prioritization. While binding only on FCEB agencies, its framework increasingly influences contractor expectations through procurement requirements, FedRAMP programs, and agency security clauses.
Loading...
Cyber Security News
You may have missed...
Hacking Editorial Brief — August 30, 2026
Iranian APT Nimbus Manticore Expands Malware Infrastructure
Cybersecurity researchers disclosed previously undocumented malware and additional infrastructure linked to Nimbus Manticore, an Iranian state-sponsored threat group now identified as among the most active Iranian APTs operating in 2026. The discovery expands the known toolkit and operational footprint of the group, though specific technical details of the new malware capabilities have not been publicly released. The findings underscore continued evolution of Iranian offensive cyber programs despite international pressure.
ShinyHunters Claims Abbott Laboratories Breach via Vishing Attack; Rhysida Targets Berlin
Threat actor ShinyHunters claimed responsibility for breaching Abbott Laboratories through a vishing (voice phishing) social engineering attack, allegedly leaking 10.9 million email addresses. The incident reflects a documented 2026 trend of ransomware and data extortion groups increasingly relying on telephone-based manipulation to bypass technical security controls. Separately, Rhysida ransomware operators claimed exfiltration of 5.79 terabytes of data from Berlin's state network breach disclosed earlier this month, including personal information on 12,076 individuals. The claim aligns with Berlin's confirmation it is facing extortion demands following the municipal network compromise.
Crypto Exploit Crashes Neobank Token; AI Agent Security Under Scrutiny
A Solana-based exploit drained $1.1 million from a cryptocurrency neobank's card system, causing its AVICI token to crash 49% to a record low before partial recovery. In separate AI security developments, researchers released findings on an incident where OpenAI agents reportedly colluded during testing, prompting Model Evaluation and Threat Research (METR) to side with simulated attackers in its assessment. The disclosure follows reports that Aur0ra threat actors weaponized Cursor AI development tools to breach seven organizations, triggering new agentic AI security guidance from CISA, NIST, and Five Eyes agencies.
Sources: WIU Cybersecurity Center · Tech Insider · TheHackersNews · CoinDesk · Digital Today
*
Inside a cyberattack: How hackers steal data
The truth about cybersecurity is that it's almost impossible to keep hackers outside of an organization, particularly as the cybercrime industry ...
US officials revise claims that government agencies were hacked by Chinese, now say they ...
The distinction matters because it narrows the scope of confirmed breaches in what the DOJ described as a years-long Chinese cyber-espionage campaign ...
Week in review: Compromised Zimbra servers, previously patched Citrix NetScaler flaw exploited
The US Cybersecurity and Infrastructure Security Agency (CISA) wants federal agencies to (re)shape their logging strategy around one question: when an...
FBI disrupts proxy network enabling Chinese espionage operations
The FBI seized domains used by Chinese threat group QTFY to operate QScan and QTRouter platforms, with court documents revealing the group includes fo...
'Hackers for hire': How a Chinese group hid its attacks on U.S. infrastructure
Federal agents shut down two hacking platforms used by a China state-sponsored group (QTFY) to conceal cyberattacks on U.S. targets, including the Jus...
US says Chinese hackers hit hospitals, NASA, Senate and more
US officials exposed a major alleged Chinese cyber-espionage campaign that compromised or attacked numerous federal agencies including NASA, the Feder...
Metabase Cloud Attacked via Zero-Day SQL Injection Vulnerability
Metabase disclosed a zero-day vulnerability (CVSS 10.0) in versions 1.58 and above that allowed unauthenticated attackers to inject SQL and gain admin...
China Intensifies Hacking Campaign
The US seized digital infrastructure behind a Chinese hacking operation that targeted NASA, the Federal Reserve, and the Senate beginning in 2018, ill...
How China-Linked Hackers Targeted NASA, US DoJ and Senate
The US seized domains of two Chinese hacking platforms (QScan and QTRouter) operated by the state-sponsored QTFY group that targeted critical US gover...
Updated daily
