CISA stopped reliably sending KEV alerts.
We didn't.
CyberComply monitors the CISA Known Exploited Vulnerabilities catalog 24/7 and alerts you the moment a new KEV drops — before the deadline clock starts ticking without you knowing.
KEV Intelligence Brief — August 14, 2026
Prepared for: Federal Contractors · DevOps & Platform Engineering · Security Operations Leadership Reference period: August 4–11, 2026 | Brief date: August 14, 2026
Deadline Watch: Three Entries Already Overdue, More Require Immediate Action
This week's KEV additions demand immediate triage. Several patch deadlines have already passed, meaning federal agencies and contractors operating under BOD 26-04 are formally out of compliance if remediation is incomplete as of today.
CVE-2026-8037 (Progress LoadMaster) carried a deadline of August 10 — four days ago. This unauthenticated command injection flaw allows arbitrary OS command execution against LoadMaster appliances by exploiting unsanitized input across multiple command endpoints. LoadMaster serves as a critical load balancing and ADC layer in many production environments, meaning exploitation here can pivot quickly to backend application infrastructure. If you have not already patched, isolate internet-facing LoadMaster management interfaces immediately and validate that no unauthorized commands were executed. Threat actor access to a load balancer grants traffic interception and lateral movement capability that log review alone may not catch — invoke CISA's Forensics Triage Requirements before returning affected appliances to production.
CVE-2026-63077 (JetBrains TeamCity) and CVE-2026-18556 (N-able N-central) and CVE-2026-34486 (Apache Tomcat) and CVE-2026-9198 (IBM Langflow) all carried deadlines of August 7 or August 8 — all overdue. These are addressed in detail by theme below, but the compliance posture is clear: if any of these remain unpatched in your environment, document your exception and escalate immediately.
CVE-2026-20349 (Cisco ASA/FTD) and CVE-2026-72898 (Metabase) share today's deadline of August 14. With today being the final day, treat these as emergency change requests if patches have not been applied.
CVE-2026-68820 (Microsoft Windows AFD/WinSock) carries the longest runway — August 25 — but should not be deprioritized. Its exploitation chain is likely already understood by sophisticated actors given its use-after-free mechanics in the Windows kernel networking stack.
Infrastructure and Network Fabric Under Active Threat
Three of the eight entries target foundational network and perimeter infrastructure, creating compounding risk when considered together.
CVE-2026-20349 affects Cisco Secure Firewall ASA and FTD — devices that sit at the edge of countless federal and enterprise networks. The heap inspection vulnerability enables unauthenticated remote attackers to trigger unexpected device reloads, producing a denial-of-service condition. While DoS may appear lower severity than code execution, weaponizing it against a firewall creates enforcement gaps that can be exploited in tandem with other intrusion techniques. Organizations running redundant ASA/FTD pairs should patch the standby unit first, validate failover, then patch the active node — but do not delay. Given CISA's Forensics Triage Requirements, capture device logs and memory snapshots before patching where possible.
CVE-2026-8037 (Progress LoadMaster) and CVE-2026-18556 (N-able N-central) represent a particularly dangerous pattern: both target infrastructure management platforms used to administer other systems at scale. N-central's authentication bypass (alternate path/channel) means an attacker who reaches the N-central interface can potentially authenticate without valid credentials and inherit its managed endpoint visibility — effectively a master key to any environment where N-able is deployed for remote monitoring and management. RMM platform compromises have featured prominently in supply chain intrusion campaigns in recent years. If N-central is internet-exposed, take it offline or restrict access to known management IP ranges immediately, even if patching is complete. Rotate all API keys, service account credentials, and managed endpoint credentials that N-central has touched.
Developer Toolchains and Data Platforms: Unauthenticated RCE at Scale
The remaining four CVEs converge on a high-consequence theme: unauthenticated attackers achieving administrative or code execution access against platforms that sit deep inside development pipelines and data workflows.
CVE-2026-63077 (JetBrains TeamCity) enables unauthenticated remote code execution via the agent polling protocol — the internal channel TeamCity uses to coordinate build agents. Prior TeamCity compromises have been attributed to state-sponsored actors targeting software supply chains, and this class of vulnerability is operationally ideal for that purpose: compromise the CI/CD server, poison build artifacts, propagate malware downstream. Any TeamCity instance reachable from the internet should have been patched by August 8. If that deadline was missed, assume compromise, isolate the instance, audit recent pipeline runs and build artifact integrity, and rotate all secrets stored in TeamCity (API tokens, cloud credentials, signing keys).
CVE-2026-72898 (Metabase) is an unauthenticated SQL injection flaw that escalates directly to administrator access on the Metabase instance. From that position, attackers can pivot to every connected database, exfiltrate credentials, and read any data Metabase is authorized to query. Organizations using Metabase to expose analytics against production databases face a full data breach scenario. Patch today, rotate all database credentials stored in Metabase connection configurations, and audit query logs for anomalous export activity.
CVE-2026-9198 (IBM Langflow) delivers unauthenticated full remote code execution on default Langflow deployments — a particularly sharp finding given Langflow's role as an AI workflow orchestration platform increasingly deployed in production environments. Default deployments suggest that misconfigured or rapidly stood-up instances are at highest risk. Any Langflow instance accessible without authentication controls should be considered compromised until forensics prove otherwise. Restrict access to authenticated, network-segmented deployments immediately.
CVE-2026-34486 (Apache Tomcat) rounds out this group with a missing encryption vulnerability that allows bypass of the EncryptInterceptor. Tomcat remains one of the most widely deployed Java application servers across federal and enterprise environments. EncryptInterceptor bypass can expose session data and intra-cluster communications to interception, particularly in clustered deployments. While less dramatic than RCE, the blast radius in clustered, session-rich environments is significant.
CVE-2026-68820 (Microsoft Windows AFD/WinSock) — a local privilege escalation via use-after-free in the Ancillary Function Driver — is the logical endpoint for attackers who have already gained a foothold through any of the above vectors. Patch Windows systems on the August 25 timeline, but prioritize hosts that run any of the above affected software.
Sources: CISA KEV Catalog · CISA BOD 26-04 · Cisco Security Advisories · Microsoft Security Update Guide · JetBrains Security Bulletins · Progress LoadMaster Security Advisories · N-able Security Advisories · Apache Tomcat Security Reports · Metabase Security
Free KEV Alerts
- Real-time notification the moment a KEV drops
- Vendor and product details
- BOD 26-04 remediation deadline included
Pro Alerts Coming Soon
- Real-time notification the moment a KEV drops
- Filtered to your specific vendor watchlist
- Urgency scoring (Critical / Urgent / Standard)
- Direct patch links included
Stay ahead of CISA.
Search the KEV Catalog by Vendor or Product
Search for CVEs by vendor or product to identify known exploited vulnerabilities in your environment
Upcoming Patch Due Dates
via Binding Operational Directive 26-04
BOD 26-04 is CISA's current vulnerability remediation directive for Federal Civilian Executive Branch (FCEB) agencies, updating the KEV-driven framework introduced under BOD 22-01 with a more risk-based approach to prioritization. While binding only on FCEB agencies, its framework increasingly influences contractor expectations through procurement requirements, FedRAMP programs, and agency security clauses.
Loading...
Cyber Security News
You may have missed...
Hacking Editorial Brief — August 14, 2026
Cl0p Claims Mass Data Theft from Nearly 50 Global Companies
Russia-linked ransomware group Cl0p claimed it has stolen significant volumes of internal data from nearly 50 companies worldwide, including Shell, Philips, General Electric, and financial services firm Fiserv. The group, known for exploiting software vulnerabilities to launch mass attacks simultaneously, posted its claims on its leak site. The extent of the breaches and specific vulnerabilities exploited remain unclear, with affected companies investigating the claims. Cl0p has historically leveraged zero-day flaws in enterprise file transfer software to compromise multiple organizations in single campaigns, suggesting this may follow a similar pattern of supply chain or common software exploitation.
Iran-Linked Group Claims Minnesota Water Infrastructure Attacks
A hacking group with ties to Iran claimed responsibility for cyberattacks that impacted more than 30 Minnesota water systems last month, adding to the ongoing campaign targeting U.S. critical water infrastructure. The Minnesota intrusions follow confirmed Iranian-backed attacks on New Jersey water facilities reported yesterday, indicating a sustained focus on municipal water systems across multiple states. Separately, Taiwan disclosed it detected AI-assisted cyberattacks on government agencies last month originating from overseas, which authorities successfully mitigated. In policy developments, a newly-signed presidential memorandum enlisting private sector companies in federal law enforcement hacking operations against criminal organizations has drawn divided expert opinion over legal precedent and operational coordination concerns.
Sources: Reuters · NL Times · KSTP · NBC News · CyberScoop
*
Inside a cyberattack: How hackers steal data
The truth about cybersecurity is that it's almost impossible to keep hackers outside of an organization, particularly as the cybercrime industry ...
'Cyber privateers': Trump issues order allowing US companies to hack overseas groups ...
The US government is already doing a lot of hacking on foreign targets. The new program risks having too many cooks in the kitchen, some former ...
Millions of SoCal cars may be vulnerable to hackers. Here's what you can do - NBC 7 San Diego
A security flaw affects KARR and SWDS anti-theft devices. Here's how Southern California drivers can check their cars and install the patch.
A bold new strategy or a dangerous precedent? Experts are divided on Trump's memo.
A newly-signed presidential memorandum enlisting private sector companies in federal law enforcement hacking operations against criminal organizations...
China-linked Hackers Using AI Agents to Attack Taiwan Government Websites
Suspected China-linked attackers carried out what researchers describe as the first fully autonomous cyberattack on a foreign government, using open-s...
Lazarus Operation Dream Job Exploits Windows AFD.sys Zero-Day
North Korean Lazarus threat actor deployed FudModule rootkit exploiting CVE-2026-68820, a Windows AFD.sys local privilege escalation zero-day, to obta...
China-linked hackers use AI agents to breach Taiwan government and energy sector
The hackers are said to have built an autonomous attack tool that made multiple AIs move like a single hacking group by using open-source AI agents .....
Taiwan Hit by AI-Powered Cyberattack Using Autonomous Agents
Taiwan's Ministry of Digital Affairs reported that attacks originated overseas and involved a hybrid approach combining conventional operations with A...
It May Be Time to Panic About AI - The Atlantic
OpenAI, Anthropic, and Meta each reported that their models then hacked into other companies. Humans didn't notice until after the fact. In some cases...
Updated daily
