CISA stopped reliably sending KEV alerts.
We didn't.
CyberComply monitors the CISA Known Exploited Vulnerabilities catalog 24/7 and alerts you the moment a new KEV drops — before the deadline clock starts ticking without you knowing.
KEV Intelligence Brief — August 21, 2026
Prepared for: Federal Contractors · DevOps / MLOps Teams · Security Operations Leaders Classification: TLP:CLEAR | Brief Date: Friday, August 21, 2026
Eight vulnerabilities added to the CISA KEV catalog this week span identity infrastructure, AI/ML developer toolchains, collaboration platforms, and core network services. Three patch deadlines have already passed or expire today. The threat picture is not random — attackers are systematically targeting unauthenticated entry points across both enterprise perimeters and the emerging AI/ML software stack.
Deadline Expired: Microsoft and AI Toolchain Patches Due Today
Three KEV entries carry a patch deadline of August 21, 2026 — meaning federal agencies are already out of compliance if mitigations are not in place, and private contractors under BOD 26-04 obligations face the same exposure.
CVE-2026-33824 (Microsoft Internet Key Exchange Service Extensions) is the most operationally dangerous of the trio. A double-free memory corruption vulnerability in the IKE service enables remote code execution on systems handling VPN and IPsec negotiation. IKE services are rarely monitored with the same fidelity as HTTP-facing endpoints, and exploitation here can directly undermine network segmentation controls. If Windows hosts running IKE services cannot be patched immediately, isolate them from untrusted networks and accelerate the Patch Tuesday cycle. Confirm the patch is applied at the OS level — not just acknowledged by a configuration management tool.
CVE-2026-55040 (Microsoft SharePoint) documents a weak authentication vulnerability permitting security feature bypass over the network. Organizations relying on SharePoint for document collaboration, intranet portals, or M365-integrated workflows should treat this as an authentication integrity failure, not merely a misconfiguration. Post-patch, audit SharePoint access logs and OAuth token grants for anomalous access patterns consistent with pre-exploitation reconnaissance.
CVE-2025-62593 (Ray-Project Ray) marks a notable inflection point: an AI/ML distributed computing framework reaching KEV status with a code injection vector exploitable through Firefox and Safari. Developers running Ray dashboards or job servers on developer workstations — often with broad internal network access — represent a lateral movement opportunity that most endpoint detection tools are not tuned to catch. Ray is frequently deployed without authentication in research and staging environments. If Ray cannot be patched today, restrict the dashboard to localhost or a secured internal VLAN, and explicitly block browser-based access from untrusted origins.
The AI/ML Attack Surface Is Expanding — MLflow and Ray Signal a Trend
Two of this week's eight entries target components of modern ML infrastructure, reinforcing what has been an emerging but under-discussed pattern: the AI/ML developer toolchain is becoming a high-value attack surface precisely because it is trusted, networked, and often deprioritized by security teams focused on traditional application stacks.
CVE-2026-64849 (MLflow) describes a server-side request forgery (SSRF) vulnerability with a patch deadline of September 2, 2026. MLflow's experiment tracking servers are routinely deployed on cloud infrastructure with access to instance metadata services (IMDS) — AWS IMDSv1, Azure IMDS, GCP metadata endpoints — making SSRF in this context synonymous with potential credential theft and cloud pivot. Organizations running MLflow in AWS should enforce IMDSv2 as an independent control regardless of patch status. Audit MLflow deployments for external accessibility; an MLflow server should never be reachable from the public internet without authentication proxying in front of it.
Paired with CVE-2025-62593 (Ray), CISA's cataloging of both vulnerabilities in a single week signals that AI/ML toolchain hardening is no longer optional. Security teams should inventory all Ray, MLflow, Kubeflow, and similar ML-adjacent services and apply network-layer controls as a minimum floor, independent of vendor patch timelines.
Collaboration Infrastructure and Identity Under Coordinated Pressure
The remaining four entries target identity, messaging, and collaboration infrastructure — systems that are both internet-exposed by design and deeply integrated into enterprise trust chains.
CVE-2026-69836 (Microsoft Entra ID) is the highest-stakes entry of the week. Deserialization of untrusted data in Entra ID — Microsoft's primary cloud identity platform — enabling unauthenticated network-based code execution represents a potential authentication backbone compromise. The patch deadline is August 24, 2026. BOD 26-04 guidance for cloud services applies; organizations that cannot confirm vendor-side mitigations are deployed should escalate to their Microsoft TAM and validate through the M365 Service Health dashboard. Post-remediation, initiate forensic triage per CISA's published requirements: review Entra sign-in logs, conditional access bypass events, and service principal activity for the preceding 30 days minimum.
CVE-2026-73570 (Zimbra Collaboration Suite) presents a textbook high-risk profile: unauthenticated OS command injection via crafted SMTP requests, executable as the Zimbra user, with a patch deadline of August 24, 2026. Zimbra instances have been consistently targeted by nation-state actors and ransomware operators throughout 2025–2026. If patching cannot be completed before Monday, consider temporarily blocking inbound SMTP from non-allowlisted IP ranges at the MTA or firewall level and enabling enhanced logging on port 25.
CVE-2026-72529 and CVE-2026-72530 (TrueConf Server) form a chained exploitation pair. CVE-2026-72529 is a missing authentication flaw on port 4307/TCP enabling arbitrary script execution — deadline August 23, 2026. CVE-2026-72530 is a code injection vulnerability on the same port allowing sandbox escape to the host — deadline September 3, 2026. The staggered deadlines should not obscure the operational reality: these two vulnerabilities are likely used in sequence. Firewall port 4307/TCP from all untrusted networks immediately, even if patching is underway. TrueConf is common in government and critical infrastructure video conferencing deployments, increasing the targeting likelihood.
Remediation Priority Summary
| CVE | Product | Deadline | Status | |---|---|---|---| | CVE-2026-33824 | Microsoft IKE | Aug 21 | Expires today | | CVE-2026-55040 | Microsoft SharePoint | Aug 21 | Expires today | | CVE-2025-62593 | Ray-Project Ray | Aug 21 | Expires today | | CVE-2026-72529 | TrueConf Server | Aug 23 | 2 days | | CVE-2026-69836 | Microsoft Entra ID | Aug 24 | 3 days | | CVE-2026-73570 | Zimbra ZCS | Aug 24 | 3 days | | CVE-2026-64849 | MLflow | Sep 2 | 12 days | | CVE-2026-72530 | TrueConf Server | Sep 3 | 13 days |
Sources: CISA KEV Catalog · CISA BOD 26-04 · Microsoft Security Response Center · Zimbra Security Advisories · MLflow Security · Ray-Project Security · CISA Forensics Triage Guidance
Free KEV Alerts
- Real-time notification the moment a KEV drops
- Vendor and product details
- BOD 26-04 remediation deadline included
Pro Alerts Coming Soon
- Real-time notification the moment a KEV drops
- Filtered to your specific vendor watchlist
- Urgency scoring (Critical / Urgent / Standard)
- Direct patch links included
Stay ahead of CISA.
Search the KEV Catalog by Vendor or Product
Search for CVEs by vendor or product to identify known exploited vulnerabilities in your environment
Upcoming Patch Due Dates
via Binding Operational Directive 26-04
BOD 26-04 is CISA's current vulnerability remediation directive for Federal Civilian Executive Branch (FCEB) agencies, updating the KEV-driven framework introduced under BOD 22-01 with a more risk-based approach to prioritization. While binding only on FCEB agencies, its framework increasingly influences contractor expectations through procurement requirements, FedRAMP programs, and agency security clauses.
Loading...
Cyber Security News
You may have missed...
Hacking Editorial Brief — August 21, 2026
Active SharePoint Exploitation and PLM Attacks Target Enterprise Infrastructure
CISA has confirmed active exploitation of CVE-2026-45659, a recently patched remote code execution vulnerability in Microsoft SharePoint. The agency's warning indicates threat actors are moving quickly to weaponize the flaw against unpatched enterprise deployments. Separately, the ransomware group Clop has exploited vulnerabilities in product lifecycle management (PLM) software to compromise manufacturing giants including Shell, GE, and Philips. The campaign demonstrates continued threat actor focus on supply chain and enterprise management platforms as high-value targets for data exfiltration and ransomware deployment.
Multi-Agent AI Attack Confirmed Against Asia-Pacific Government
A Chinese-language threat actor has successfully executed what security researchers are describing as a multi-agent AI attack against government agencies in the Asia-Pacific region. The incident represents documented evidence of near-autonomous AI-enabled offensive operations moving from theoretical capability to active deployment. In related AI-enabled threat activity, unknown attackers attempted to compromise security researchers using a fabricated cryptocurrency conference as a lure, underscoring threat actor interest in targeting security professionals directly. Meanwhile, a Trezor hardware wallet vulnerability (CVE-2026-20685) exposed customer data across multiple countries between May and August 2026, affecting users of the cryptocurrency storage platform.
Sources: Security Week · Smart Industry · Cadre · TechCrunch · The Hacker News
*
Inside a cyberattack: How hackers steal data
The truth about cybersecurity is that it's almost impossible to keep hackers outside of an organization, particularly as the cybercrime industry ...
Will AI Replace Detection Roles in Cybersecurity? - CISO Series
Will AI eliminate detection engineering jobs, or just the busywork? Security leaders weigh in on where automation actually stops.
Someone targeted security researchers using a fake crypto conference as a lure
If you are a malicious hacker, cybersecurity professionals may very well be the worst people in the world to try to hack, as there is a very good ...
How a Texas student blew the whistle on a rogue AI hacking attempt: Reuters exclusive
The 24-year-old native of Turkiye figured he had caught a wily hacker red-handed. So he said he was shocked when Britain's AI Security Institute (AISI...
DOJ charges 17 in Iran-backed hacking campaign against US colleges, others
Officials allege the Mabna Institute was behind an effort to steal research from American universities, companies and government agencies.
T-Mobile Cyber Team Physically Cuts Cable to Remove Chinese Hackers From Network
T-Mobile's security team physically severed a network cable at a Seattle data center to expel Chinese state-backed hackers from Salt Typhoon, part of ...
SilkParasite Espionage Campaign Targets Central Asian Governments with Five New RATs
A previously unreported China-nexus cyber espionage operation dubbed SilkParasite is actively targeting government organizations across Central Asia u...
AI-Generated Exploit Scripts Target Siemens S7 PLCs in U.S. Critical Infrastructure
... Cybersecurity and Infrastructure Security Agency (CISA), Federal Bureau of Investigation (FBI), Department of Energy (DOE), and Environmental ...
Georgia Tech Students Claim Victory at DEF CON's Elite Hacking Competition
Year after year, some of the world's best hackers gather at DEF CON in Las Vegas to put their skills to the test. None is more prominent than the ...
Updated daily
