CISA stopped reliably sending KEV alerts.
We didn't.
CyberComply monitors the CISA Known Exploited Vulnerabilities catalog 24/7 and alerts you the moment a new KEV drops — before the deadline clock starts ticking without you knowing.
KEV Intelligence Brief — August 21, 2026
Prepared for: Federal Contractors · DevOps & Platform Engineering · Security Operations Leadership Distribution: TLP:WHITE Reporting Period: August 18–21, 2026
Eight vulnerabilities added to CISA's Known Exploited Vulnerabilities catalog over the past four days span infrastructure virtualization, enterprise collaboration, AI/ML developer tooling, and core Windows network services. The pattern is notable: threat actors are actively pivoting across the full stack, from developer workstations to hypervisor control planes. Federal civilian agencies operating under BOD 26-04 face legally binding remediation deadlines — several of which expire today. All other organizations should treat these with equivalent urgency.
Deadline Watch: Today's Expiry Cluster Demands Immediate Action
Four CVEs carry a patch deadline of August 21, 2026 — meaning remediation windows close as of this brief's publication.
CVE-2026-33824 (Microsoft IKE Service Extensions) is arguably the most structurally dangerous of the group. A double-free memory corruption vulnerability in the Internet Key Exchange service creates a remote code execution pathway in Windows environments with IPsec/VPN exposed to the network. IKE is rarely considered an attack surface by perimeter teams, yet it sits at the heart of encrypted tunnel negotiation in hybrid-cloud and zero-trust architectures. Organizations should verify that IKE endpoints are not directly reachable from untrusted networks and apply the relevant Windows security update immediately.
CVE-2026-55040 (Microsoft SharePoint) describes a weak authentication vulnerability that allows unauthenticated network attackers to bypass security controls. SharePoint is pervasive in government and federal contractor environments, frequently handling sensitive unclassified documents and serving as an identity-integrated collaboration hub. Authentication bypass on SharePoint can chain directly into credential harvesting, lateral movement, or data exfiltration — particularly dangerous in hybrid Microsoft 365 deployments where on-premise SharePoint federates with cloud identity. Teams running on-premise SharePoint servers should treat any unpatched instance as externally compromised until patched and forensically triaged per BOD 26-04 requirements.
CVE-2026-59310 (Broadcom VMware vCenter) adds a path traversal vulnerability enabling arbitrary code execution for any attacker with network-level access to vCenter. vCenter exploits consistently represent some of the highest-impact incidents in enterprise environments because successful exploitation gives adversaries hypervisor-level control over entire virtual infrastructure estates. The blast radius here is enormous. Organizations should immediately audit vCenter network exposure, enforce management-plane network segmentation if not already in place, rotate vCenter service account credentials, and apply Broadcom's patch without delay. Cloud environments managed through vCenter-compatible APIs should be evaluated per BOD 26-04 cloud service guidance.
CVE-2025-62593 (Ray-Project Ray) rounds out today's expired deadlines with a code injection vulnerability affecting the Ray distributed computing framework, exploitable through Firefox and Safari. Ray is widely used in AI/ML research and production inference pipelines. The browser-exploitable nature of this flaw is atypical and significant: developers running Ray dashboards locally or on shared development infrastructure are exposed through routine web browsing. This is a supply-chain and developer-endpoint risk, not just a server risk.
The AI/ML Attack Surface Expands: Developer Tooling in the Crosshairs
The simultaneous KEV listing of two AI/ML platform vulnerabilities — Ray (CVE-2025-62593) and MLflow (CVE-2026-64849) — signals that adversaries are actively targeting the machine learning development lifecycle, not just production deployments.
MLflow's server-side request forgery vulnerability (CVE-2026-64849, deadline September 2) is particularly high-value in cloud-native ML environments. An SSRF in MLflow can be weaponized to reach AWS Instance Metadata Service (IMDS), Azure IMDS, or GCP metadata endpoints, harvesting cloud credentials and enabling lateral movement far beyond the ML platform itself. Organizations running MLflow on cloud infrastructure should immediately enforce IMDSv2 with hop-limit restrictions, block MLflow's egress to internal metadata IP ranges (169.254.169.254, fd00:ec2::254), and evaluate whether MLflow instances are inadvertently internet-exposed. Credential rotation for any cloud roles accessible from MLflow hosts is strongly advised regardless of confirmed exploitation.
For Ray (CVE-2025-62593), teams should audit all Ray cluster dashboard ports for external exposure, restrict dashboard binding to loopback or internal-only interfaces, and ensure developer machines are not running unpatched Ray versions while using affected browsers. Given Ray's prevalence in both research and production AI inference, security teams should treat any Ray deployment as potentially affected until patched.
Collaboration Infrastructure Under Pressure: TrueConf and Zimbra
Three CVEs target enterprise communication and collaboration platforms, and together they form an alarming chain for organizations running unified communications infrastructure.
The two TrueConf Server vulnerabilities — CVE-2026-72529 (missing authentication, deadline August 23) and CVE-2026-72530 (code injection, deadline September 3) — both operate through port 4307/TCP and require no authentication to reach. CVE-2026-72529 allows unauthenticated script execution; CVE-2026-72530 allows sandbox breakout and host-level code execution. Chained together, these two flaws constitute a complete unauthenticated RCE path to the underlying host. Any organization with TrueConf Server exposed — even on internal networks — should immediately firewall port 4307 from all but explicitly required sources, apply available patches, and conduct forensic triage for signs of prior exploitation consistent with BOD 26-04 requirements. Discontinue use if vendor patches are unavailable.
CVE-2026-73570 (Zimbra Collaboration Suite, deadline August 24) enables OS command injection via unauthenticated SMTP requests, with commands executing as the Zimbra service user. Zimbra has been a recurring KEV target due to its prevalence in government and international organizational deployments. Unauthenticated SMTP injection is particularly severe because SMTP is an operationally required open port; organizations cannot simply firewall it away. Apply the vendor patch on an emergency basis, review Zimbra process execution logs for anomalous child processes, and ensure outbound SMTP relay rules do not permit lateral pivot.
Summary Remediation Priorities
| CVE | Product | Deadline | Priority | |---|---|---|---| | CVE-2026-33824 | Microsoft IKE | Aug 21 — TODAY | Critical | | CVE-2026-55040 | Microsoft SharePoint | Aug 21 — TODAY | Critical | | CVE-2026-59310 | VMware vCenter | Aug 21 — TODAY | Critical | | CVE-2025-62593 | Ray | Aug 21 — TODAY | High | | CVE-2026-72529 | TrueConf Server | Aug 23 | Critical | | CVE-2026-73570 | Zimbra ZCS | Aug 24 | Critical | | CVE-2026-64849 | MLflow | Sep 2 | High | | CVE-2026-72530 | TrueConf Server | Sep 3 | High |
All deadlines are binding for federal civilian agencies under BOD 26-04. Non-federal organizations should apply equivalent urgency to any internet-facing or internally critical instances.
Sources: CISA KEV Catalog · CISA BOD 26-04 · Broadcom VMware Security Advisories · Microsoft Security Response Center · Synacor Zimbra Security Advisories · MLflow Security Disclosures · Ray-Project Security Advisories
Free KEV Alerts
- Real-time notification the moment a KEV drops
- Vendor and product details
- BOD 26-04 remediation deadline included
Pro Alerts Coming Soon
- Real-time notification the moment a KEV drops
- Filtered to your specific vendor watchlist
- Urgency scoring (Critical / Urgent / Standard)
- Direct patch links included
Stay ahead of CISA.
Search the KEV Catalog by Vendor or Product
Search for CVEs by vendor or product to identify known exploited vulnerabilities in your environment
Upcoming Patch Due Dates
via Binding Operational Directive 26-04
BOD 26-04 is CISA's current vulnerability remediation directive for Federal Civilian Executive Branch (FCEB) agencies, updating the KEV-driven framework introduced under BOD 22-01 with a more risk-based approach to prioritization. While binding only on FCEB agencies, its framework increasingly influences contractor expectations through procurement requirements, FedRAMP programs, and agency security clauses.
Loading...
Cyber Security News
You may have missed...
Hacking Editorial Brief — August 24, 2026
Federal Agencies Issue Alert on AI-Assisted Attacks Targeting Industrial Control Systems
Five federal agencies released a joint cybersecurity advisory warning that unspecified threat actors are conducting AI-assisted attacks against Siemens S7 Series programmable logic controllers at critical infrastructure facilities across the United States. The advisory represents the first confirmed government acknowledgment of artificial intelligence being weaponized to target industrial control systems in active campaigns. The attacks focus on PLCs widely deployed in energy, manufacturing, and water treatment facilities, suggesting sophisticated threat actors are leveraging AI capabilities to automate reconnaissance, vulnerability discovery, or exploitation of operational technology environments. The warning comes as the UAE separately reports defending against approximately 800,000 daily hacking attempts—four times pre-conflict levels—using its own AI-powered defensive systems.
Novel FTP Banner Technique Delivers Malware in Ongoing Campaign
Threat actors are exploiting File Transfer Protocol server banners to hide malware commands and infect Windows systems in a campaign active since early July. The technique abuses FTP banner messages—typically used to display server information—to inject and execute malicious payloads, representing a creative evasion method that bypasses traditional detection focused on file transfers or standard command-and-control channels. The campaign continues to target Windows environments with no identified attribution. Separately, a hacker group identifying itself as "Madarx" claims to be selling six million Bangladeshi job seeker CVs on dark web marketplaces, while Apollo Global reportedly suffered a data breach exposing names, addresses, and Social Security numbers after attackers accessed the firm's cloud infrastructure.
Sources: SC World · Rest of World · Techzine Global · New Age · IDN Financials
*
Inside a cyberattack: How hackers steal data
The truth about cybersecurity is that it's almost impossible to keep hackers outside of an organization, particularly as the cybercrime industry ...
Canvas is back in the classroom despite security concerns following hack - Cardinal News
In April, hackers breached Instructure, the company behind Canvas, which schools use to manage assignments, track grades and deliver course content, ....
Iran-linked hackers blamed for power pant shut down - Energy Live News
Iran-linked hackers have been blamed for a cyber-attack that temporarily shut down a small UK power plant, reports the Guardian.
After raising $51 million, Minimus shuts down as Twistlock founders return remaining | Ctech
The cybersecurity startup failed to gain enough commercial momentum to continue operating. Customers will have 60 days to migrate before the ...
Lazarus Group Exploits Windows Zero-Day to Target Defense and Aerospace
The North Korean Lazarus Group exploited a newly patched Windows zero-day to deliver a never-before-seen backdoor targeting defense and aerospace comp...
Microsoft Patches Critical Entra ID Remote Code Execution Vulnerability CVE-2026-69836
Microsoft patched a critical remote code execution vulnerability in Entra ID (CVSS 10.0) that allows unauthorized attackers to execute code over a net...
UAT-10147 Uses AI to Scale Server Attacks, Deploys SPECTRE With EDR Bypass and Linux Rootkit
Cybersecurity researchers have disclosed details of a Chinese-speaking cybercrime group dubbed UAT-10147 that's targeting Windows and Linux web ...
Iranian hackers carry out unprecedented attack on UK's power network - The Independent
Iranian hackers carry out unprecedented attack on UK's power network · The generator was forced to shut down for four days following the cyber ...
Iranian hackers forced UK energy facility to shut for four days - The Times
Iranian hackers shut down a British energy facility for four days last month in what is believed to be the first attack of its kind in this ...
Updated daily
