This month: 5 KEVs detected

CISA stopped reliably sending KEV alerts.
We didn't.

CyberComply monitors the CISA Known Exploited Vulnerabilities catalog 24/7 and alerts you the moment a new KEV drops — before the deadline clock starts ticking without you knowing.

CVE-2026-63077
JetBrains · TeamCity
JetBrains TeamCity Deserialization of Untrusted Data Vulnerability
Detected Aug 5 · 3-day patch deadline
CVE-2026-18556
N-able · N-central
N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability
Detected Aug 4 · 3-day patch deadline
CVE-2026-34486
Apache · Tomcat
Apache Tomcat Missing Encryption of Sensitive Data Vulnerability
Detected Aug 4 · 3-day patch deadline

KEV Intelligence Brief — August 4, 2026

TLP: WHITE | Audience: Federal Contractors, DevOps, Security Operations Issued: Tuesday, August 4, 2026

Eight vulnerabilities added to CISA's KEV catalog over the past two weeks span network management platforms, AI developer tooling, web infrastructure, and perimeter security devices. Three themes emerge: a cascading patch failure in a widely deployed RMM platform, a cluster of authentication and credential failures across security-critical network infrastructure, and the continued targeting of developer and AI toolchains as lateral movement vectors into production environments.

The N-able Patch Collapse: When Fixes Become New Vulnerabilities

The most operationally urgent story this cycle involves N-able N-central, which has generated two KEV entries in 48 hours — a rare and damning signal. CVE-2026-18556 (deadline: August 7) is an authentication bypass via alternate path or channel in N-central, already confirmed as actively exploited. What makes this situation worse is that CVE-2026-18577 — added just one day earlier with a deadline of August 6, now overdue — is explicitly described as the result of an incomplete patch for CVE-2026-18556. Threat actors almost certainly analyzed the initial fix, identified the residual bypass, and weaponized it before many organizations had finished deploying the first remediation.

For managed service providers and federal contractors relying on N-central for endpoint visibility, this is a full-stop priority. Authentication bypass in an RMM platform is not a perimeter issue — it is a keys-to-the-kingdom event. MSPs with multi-tenant deployments should assume that any organization managed through an unpatched N-central instance is potentially compromised. Immediate actions: isolate internet-facing N-central nodes, force credential rotation on all managed agent accounts, audit API tokens issued in the last 30 days, and apply forensic triage per BOD 26-04 requirements before assuming the patched state is clean.

Authentication Dead Zones: Hard-Coded Credentials, Token Theft, and Perimeter Device Compromise

Three entries this cycle share a particularly dangerous characteristic: they allow unauthenticated remote attackers to gain privileged access to security infrastructure that defenders typically trust implicitly.

CVE-2026-20316 in Cisco Secure Firewall Management Center (formerly Firepower Management Center) involves a hard-coded password enabling remote login via a low-privileged account. The patch deadline of August 1 has passed, meaning federal agencies are already in violation of BOD 26-04 if unpatched. Hard-coded credentials are not a nuanced flaw — they are deterministic. Any attacker with knowledge of the credential string owns a foothold inside your firewall management plane. Network segmentation for FMC consoles and immediate patch application are non-negotiable.

CVE-2026-16232 in Check Point SmartConsole represents an analogous failure at the policy management layer. An improper authentication flaw allows an unauthenticated remote attacker to harvest an application login token and authenticate with full administrative privileges. The deadline of July 25 is two weeks overdue. If your Check Point environment has not been patched, treat it as compromised: rotate all SmartConsole credentials, review administrative session logs from the past 30 days, and verify no unauthorized policy modifications or new administrator accounts were introduced.

CVE-2026-16812 in Arista VeloCloud Orchestrator (On-Prem) adds OS command injection to the list, with a deadline of July 30 — also overdue. Successful exploitation gives attackers privileged internal access and the ability to compromise both the orchestrator and all SD-WAN data it manages. For organizations running distributed WAN infrastructure, a compromised VeloCloud Orchestrator is equivalent to a network-wide configuration injection point. Isolate the management plane immediately if patching has not been completed.

Rounding out this cluster, CVE-2025-68686 in Fortinet FortiOS (deadline: August 10, the furthest out in this batch) addresses a bypass of the symbolic link persistence mechanism patched in earlier FortiOS remediations. Critically, this is a post-exploitation persistence technique — meaning attackers who previously gained filesystem-level access to FortiOS devices can maintain that access even after organizations believed they had remediated. Defenders should cross-reference this against prior FortiOS incident investigations and conduct fresh filesystem integrity checks, not just version validation.

Developer and AI Infrastructure as Lateral Movement Vectors

The remaining two entries target the software development and AI toolchain — an attack surface that frequently receives less scrutiny than perimeter devices despite sitting adjacent to source code, secrets, and production deployment pipelines.

CVE-2026-9198 in IBM Langflow is the most severe entry in this cycle. A code injection vulnerability allows unauthenticated attackers to achieve full remote code execution on default Langflow deployments. Langflow is an AI workflow orchestration platform increasingly deployed in enterprise AI pipelines. Default deployments are explicitly named as vulnerable, meaning organizations that stood up Langflow rapidly to support AI initiatives — without hardening — are exposed. RCE on an AI orchestration platform may provide access to model APIs, internal data connectors, and cloud credentials embedded in workflow configurations. Internet-facing Langflow instances should be taken offline or placed behind authenticated reverse proxies immediately. Patch deadline is August 7.

CVE-2026-34486 in Apache Tomcat involves missing encryption of sensitive data that allows bypass of the EncryptInterceptor — a control specifically designed to protect cluster communication traffic. The deadline is August 7. Organizations running Tomcat in clustered configurations, common in Java-based enterprise applications and CI/CD environments, should treat inter-node traffic as potentially observable by adversaries until patching is confirmed. Verify TLS enforcement on all cluster communication channels as a compensating control.

Summary Deadline Tracker

| CVE | Product | Deadline | Status | |---|---|---|---| | CVE-2026-16232 | Check Point SmartConsole | July 25 | Overdue | | CVE-2026-16812 | Arista VeloCloud Orchestrator | July 30 | Overdue | | CVE-2026-20316 | Cisco Secure FMC | August 1 | Overdue | | CVE-2026-18577 | N-able N-central | August 6 | Overdue | | CVE-2026-18556 | N-able N-central | August 7 | Imminent | | CVE-2026-34486 | Apache Tomcat | August 7 | Imminent | | CVE-2026-9198 | IBM Langflow | August 7 | Imminent | | CVE-2025-68686 | Fortinet FortiOS | August 10 | Active window |

Sources: CISA KEV Catalog · CISA BOD 26-04 · N-able Security Advisories · Cisco Security Advisories · Fortinet PSIRT · Check Point Security Advisories · Arista Security Advisories · Apache Tomcat Security · IBM Security Bulletins

Free KEV Alerts

  • Real-time notification the moment a KEV drops
  • Vendor and product details
  • BOD 26-04 remediation deadline included

Pro Alerts Coming Soon

  • Real-time notification the moment a KEV drops
  • Filtered to your specific vendor watchlist
  • Urgency scoring (Critical / Urgent / Standard)
  • Direct patch links included

Stay ahead of CISA.

No spam. Unsubscribe anytime. We don't sell your data.


Upcoming Patch Due Dates

via Binding Operational Directive 26-04

BOD 26-04 is CISA's current vulnerability remediation directive for Federal Civilian Executive Branch (FCEB) agencies, updating the KEV-driven framework introduced under BOD 22-01 with a more risk-based approach to prioritization. While binding only on FCEB agencies, its framework increasingly influences contractor expectations through procurement requirements, FedRAMP programs, and agency security clauses.

Loading...

News Logo

Cyber Security News

You may have missed...


Hacking Editorial Brief — August 6, 2026

Supply Chain Worm Compromises Hundreds of npm Packages

A threat actor successfully compromised hundreds of npm packages, including the widely-used 'keyv' library with over 150 million weekly downloads, deploying a self-propagating backdoor worm across the JavaScript ecosystem. According to Datadog Security Labs analysis, the attack represents a significant supply chain compromise affecting numerous downstream dependencies. The worm's self-spreading mechanism allows it to automatically infect additional packages, amplifying the campaign's reach beyond the initial compromise vector. The incident underscores persistent vulnerabilities in package repository security and dependency chain integrity, with the scale of affected installations potentially reaching millions of applications relying on compromised packages.

Iranian Threat Actors Target U.S. Water Infrastructure

Multiple U.S. municipal water systems came under cyberattack over the past week in a coordinated campaign officials attribute to Iranian threat actors. The FBI and Environmental Protection Agency issued joint warnings to critical infrastructure operators following confirmed intrusions affecting facilities in New Jersey and other states. The attacks targeted operational technology systems used to manage water treatment and distribution, raising concerns about potential disruption to public utilities. The campaign follows established patterns of Iranian-linked threat activity against U.S. critical infrastructure, though authorities have not disclosed specific technical details of the intrusion methods or whether any systems experienced operational impacts. Separately, Canadian authorities disclosed that a Kitchener resident pleaded guilty to charges related to a 2021 breach of a U.S. cloud services provider that compromised data on over 165 million customers, facing up to 30 years in federal prison for participation in the international hacking conspiracy.

Sources: Datadog Security Labs · 6ABC · Philadelphia Inquirer · CityNews Kitchener

📌 Pinned

*

https:betanews.comMar 5

Inside a cyberattack: How hackers steal data

The truth about cybersecurity is that it's almost impossible to keep hackers outside of an organization, particularly as the cybercrime industry ...

https://www.wired.comAug 5

A Security Pro Hacked North Korean Hackers. He Found They'd Breached Hundreds of ...

For nearly two years, researcher Vangelis Stykas has maintained access to North Korean hackers' servers. His work shows they pulled off intrusions ...

https://www.wired.comAug 6

OpenAI Didn't Notice Its AI Agents Using a Message Board to Plan Their Hacking Spree

At the Black Hat security conference, the AI giant revealed new details about how its agents went rogue, hacked several other companies—and did it ...

https://www.cbsnews.comAug 5

At least 12 states report cyberattacks on water systems possibly linked to Iran-backed ...

Cyberattacks on U.S. water systems that officials suspect may be linked to Iran-backed hackers have been reported in at least a dozen states, ...

https://statescoop.comAug 5

New York boosts funding for water cybersecurity grants - StateScoop

New York Gov. Kathy Hochul announced the state will distribute $9 million to fund more than 150 cybersecurity projects tied to the state's water ...

https://premierchristian.newsAug 6

Christian organisations caught up in cybersecurity breach

A number of Christian organisations have been affected by a cybersecurity incident, which may have led to supporters' information being obtained.

https://www.bbc.comAug 6

Meta says AI model accessed the internet and hacked another firm - BBC

Meta is the latest company to disclose an AI agent breach, raising cyber-security concerns.

https://securitylabs.datadoghq.comAug 6

Worm compromises hundreds of popular npm packages

A threat actor compromised hundreds of npm packages including 'keyv' with over 150 million weekly downloads to propagate a self-spreading backdoor wor...

https://www.wired.comAug 6

A Security Pro Hacked North Korean Hackers. He Found They'd Breached Hundreds of ...

For nearly two years, researcher Vangelis Stykas has maintained access to North Korean hackers' servers. His work shows they pulled off intrusions ...


Updated daily