CISA stopped reliably sending KEV alerts.
We didn't.
CyberComply monitors the CISA Known Exploited Vulnerabilities catalog 24/7 and alerts you the moment a new KEV drops — before the deadline clock starts ticking without you knowing.
KEV Intelligence Brief — August 28, 2026
Issued by: Security Operations Intelligence | Classification: TLP:WHITE Reporting Period: August 26–27, 2026 | Entries Covered: 8 CVEs
Eight vulnerabilities added to CISA's KEV catalog over the past 48 hours reflect three converging threat patterns: unauthenticated file system exposure in enterprise collaboration infrastructure, privilege escalation via Linux kernel weaknesses embedded across heterogeneous environments, and a cluster of aging-but-newly-exploited vulnerabilities in development toolchains and database services that organizations have allowed to persist far too long. Federal agencies and contractors operating under BOD 26-04 must treat the deadlines below as operational ceilings, not targets.
Emergency Window: Unauthenticated File Access and Active Infrastructure Targets
Two entries carry patch deadlines this weekend, making them the immediate operational priority for any team reading this brief.
CVE-2019-1068 (Microsoft SQL Server) carries a deadline of August 29 — tomorrow. This remote code execution vulnerability allows an attacker to execute arbitrary code in the context of the SQL Server Database Engine service account, a foothold that can rapidly translate into lateral movement, credential harvesting, and data exfiltration across any environment where SQL Server runs with elevated privileges. SQL Server instances should never be directly internet-exposed, but the reality of legacy architecture and misconfigured perimeter controls means many are. If patching cannot be completed before tomorrow's deadline, network-level isolation of SQL Server instances and audit of service account privileges are non-negotiable interim steps. Verify that the Database Engine service account is not running with domain admin or local system privileges.
CVE-2023-49105 (ownCloud) carries a deadline of August 30 and presents an arguably more acute risk: an improper authentication vulnerability that permits unauthenticated file access, modification, and deletion — provided the attacker knows the victim's username and the account lacks a configured signing key. In environments where ownCloud is used for document sharing, that username condition is trivially satisfied through directory harvesting, phishing artifacts, or prior breach data. Organizations should immediately audit signing-key configuration across all user accounts, force-enable signing keys as a mandatory baseline, and treat any ownCloud instance exposed to the public internet as compromised pending forensic review. CISA's Forensics Triage Requirements apply here explicitly.
Linux Kernel Privilege Escalation: A Multi-Distribution Crisis
CISA added two Linux Kernel entries that together represent a systemic risk across virtually every Linux-dependent workload in federal and commercial environments.
CVE-2026-53362 — a newly cataloged vulnerability in the Linux Kernel's IPv6 networking subsystem — enables privilege escalation and explicitly impacts distributions including SUSE and Red Hat, with the advisory noting additional products may be affected. The deadline is August 30, giving teams this weekend to act. Because IPv6 is enabled by default on most modern Linux deployments and is often left unmonitored relative to IPv4 traffic, this attack surface is broader than many teams currently model. Organizations that cannot patch immediately should assess whether disabling IPv6 is operationally feasible as a temporary mitigation and should prioritize patching on any internet-facing or multi-tenant systems first.
CVE-2022-0995 — a Linux Kernel out-of-bounds memory write vulnerability cataloged earlier — carries a deadline of September 9. Local users can leverage this to gain privileged access or trigger denial of service. While local access is required, this class of vulnerability is routinely chained with initial access techniques in post-exploitation sequences. Treat this as a privilege escalation enabler in your threat models, not a standalone low-severity finding. Distribution-specific patches from Red Hat, SUSE, Ubuntu, and Debian are available; confirm your kernel version and apply the appropriate update.
Developer Toolchain and Legacy Software: Long-Deferred Debt Comes Due
Three entries in this cycle target the software supply chain and development infrastructure, and two of them involve software that may already be end-of-life in your environment.
CVE-2026-66384 (JFrog Artifactory) is a path traversal vulnerability allowing authenticated users to write data outside the intended Docker cache path under specific remote-repository conditions. With a deadline of September 10, this is the furthest out in this cycle, but it demands immediate attention in any environment where Artifactory serves as a central artifact registry. A compromised artifact path in a CI/CD pipeline can propagate malicious content downstream to build systems and production deployments. Upgrade Artifactory and audit remote repository configurations for anomalous write activity.
CVE-2021-23758 (Ajax.NET Professional) exposes a critical deserialization of untrusted data vulnerability enabling remote code execution via arbitrary .NET class instantiation. AjaxPro is explicitly flagged as potentially end-of-life. The path forward here is not patching — it is removal or replacement. Any application surface still running AjaxPro should be inventoried immediately, and development teams should plan accelerated migration to supported .NET frameworks. Deadline: September 9.
The two Red Hat entries — CVE-2015-3246 (Libuser, race condition enabling /etc/passwd corruption and privilege escalation) and CVE-2015-5287 (ABRT, symlink attack enabling privilege escalation) — are over a decade old. Their addition to KEV in 2026 signals confirmed, active exploitation. ABRT is flagged as potentially end-of-life; discontinuation is the recommended path. For Libuser, apply available patches from Red Hat and assess whether the affected system configurations align with current hardening baselines. Deadline for both: September 9.
Operational Posture Summary
| CVE | Product | Deadline | Key Risk | |---|---|---|---| | CVE-2019-1068 | MS SQL Server | Aug 29 | RCE via DB Engine service account | | CVE-2023-49105 | ownCloud | Aug 30 | Unauthenticated file access/deletion | | CVE-2026-53362 | Linux Kernel | Aug 30 | Privilege escalation via IPv6 | | CVE-2015-3246 | Red Hat Libuser | Sep 9 | passwd corruption, local privesc | | CVE-2015-5287 | Red Hat ABRT | Sep 9 | Symlink-based local privesc (EoL) | | CVE-2021-23758 | Ajax.NET Pro | Sep 9 | RCE via .NET deserialization (EoL) | | CVE-2022-0995 | Linux Kernel | Sep 9 | Out-of-bounds write, local privesc | | CVE-2026-66384 | JFrog Artifactory | Sep 10 | Path traversal in artifact registry |
Federal contractors: BOD 26-04 compliance is mandatory. Document compensating controls for any asset where patch deadlines cannot be met and escalate through your authorizing official chain without delay.
Sources: CISA KEV Catalog · CISA BOD 26-04 · Microsoft SQL Server Security Advisory CVE-2019-1068 · ownCloud Security Advisory CVE-2023-49105 · JFrog Artifactory Security Bulletins · Red Hat Security Advisory: Libuser · Red Hat Security Advisory: ABRT · Linux Kernel Security · CISA Forensics Triage Guidance
Free KEV Alerts
- Real-time notification the moment a KEV drops
- Vendor and product details
- BOD 26-04 remediation deadline included
Pro Alerts Coming Soon
- Real-time notification the moment a KEV drops
- Filtered to your specific vendor watchlist
- Urgency scoring (Critical / Urgent / Standard)
- Direct patch links included
Stay ahead of CISA.
Search the KEV Catalog by Vendor or Product
Search for CVEs by vendor or product to identify known exploited vulnerabilities in your environment
Upcoming Patch Due Dates
via Binding Operational Directive 26-04
BOD 26-04 is CISA's current vulnerability remediation directive for Federal Civilian Executive Branch (FCEB) agencies, updating the KEV-driven framework introduced under BOD 22-01 with a more risk-based approach to prioritization. While binding only on FCEB agencies, its framework increasingly influences contractor expectations through procurement requirements, FedRAMP programs, and agency security clauses.
Loading...
Cyber Security News
You may have missed...
Hacking Editorial Brief — August 29, 2026
U.S. Officials Walk Back Claims on Chinese Government Agency Hacks
The Department of Justice and FBI revised statements claiming multiple U.S. government agencies were successfully breached by Chinese state-sponsored hackers, now clarifying that HHS, the National Institutes of Health, and other federal entities were targeted but not confirmed as compromised. The correction follows Wednesday's seizure of infrastructure used by QTFY, a China-linked hacking group employed by Nanjing Xinjiuwei Network Technology Co. that sells offensive cyber services. The QScan and QTRouter platforms disrupted in the operation were used to target critical infrastructure sectors including financial services, though officials have not disclosed the success rate of intrusion attempts or confirmed data exfiltration from any agency systems.
Nevada Ransomware Attack Takes Down 60+ State Agencies; Berlin Faces Extortion After Data Theft
Nevada confirmed a ransomware attack on August 24 forced statewide systems offline, affecting more than 60 agencies including the DMV, Department of Health and Human Services, and Department of Public Safety. Systems remain down as incident response continues. Separately, Berlin's mayor disclosed the city is facing extortion demands after hackers compromised municipal networks and exfiltrated data earlier this month. The Berlin government has refused payment, though the scope of stolen information and operational impact have not been detailed publicly.
Over 8,300 Gitea Instances Remain Unpatched Against Actively Exploited RCE Flaw
More than 8,300 internet-exposed Gitea code repository instances remain vulnerable to a critical remote code execution flaw currently under active exploitation. The unpatched systems represent immediate compromise risk as attackers target the self-hosted Git service used by development teams for source code management.
Sources: Medical Daily · US News · BBC · Bleeping Computer
*
Inside a cyberattack: How hackers steal data
The truth about cybersecurity is that it's almost impossible to keep hackers outside of an organization, particularly as the cybercrime industry ...
China Intensifies Hacking Campaign
The US seized digital infrastructure behind a Chinese hacking operation that targeted NASA, the Federal Reserve, and the Senate beginning in 2018, ill...
How China-Linked Hackers Targeted NASA, US DoJ and Senate
The US seized domains of two Chinese hacking platforms (QScan and QTRouter) operated by the state-sponsored QTFY group that targeted critical US gover...
QTFY Campaign Targets NASA, Federal Reserve, and Other U.S. Agencies
The Department of Justice revealed that QTFY computer intrusion activity targeted NASA, the Federal Reserve, Department of Energy, Department of Justi...
Medical device maker Boston Scientific says a cyberattack is causing a 'global disruption' to ...
Zack Whittaker is the security editor at TechCrunch. He also authors the weekly cybersecurity newsletter, ...
ATF responds to cybersecurity incident
WASHINGTON - The Bureau of Alcohol, Tobacco, Firearms and Explosives is responding to a cybersecurity incident affecting a standalone system.
DOJ blames China for string of hacks targeting federal agencies and hospitals - POLITICO
Chinese hackers carried out a yearslong coordinated campaign to worm their way into federal networks — including those at the Departments of ...
UK's small power plants face continued cyber risk after Iran-linked hack - The Guardian
Government measures to improve resilience are not due until 2030 and July's hack has not altered this timeline.
US says Chinese-linked hackers attacked NASA, Senate, and gov't agencies
The U.S. disrupted a China-affiliated hacking operation that targeted the Department of Justice, NASA, the Federal Reserve, and the Senate using QScan...
Updated daily
