This month: 18 KEVs detected

CISA stopped reliably sending KEV alerts.
We didn't.

CyberComply monitors the CISA Known Exploited Vulnerabilities catalog 24/7 and alerts you the moment a new KEV drops — before the deadline clock starts ticking without you knowing.

CVE-2026-73570
Synacor · Zimbra Collaboration Suite (ZCS)
Zimbra Collaboration Suite (ZCS) OS Command Injection Vulnerability
Detected Aug 21 · 3-day patch deadline
CVE-2026-72529
TrueConf · Server
TrueConf Server Missing Authentication for Critical Function Vulnerability
Detected Aug 20 · 3-day patch deadline
CVE-2025-62593
Ray-Project · Ray
Ray-Project Ray Code Injection Vulnerability
Detected Aug 18 · 3-day patch deadline

KEV Intelligence Brief — August 21, 2026

Prepared for: Federal Contractors · DevOps & Platform Engineering · Security Operations Leadership Distribution: TLP:WHITE Reporting Period: August 18–21, 2026

Eight vulnerabilities added to CISA's Known Exploited Vulnerabilities catalog over the past four days span infrastructure virtualization, enterprise collaboration, AI/ML developer tooling, and core Windows network services. The pattern is notable: threat actors are actively pivoting across the full stack, from developer workstations to hypervisor control planes. Federal civilian agencies operating under BOD 26-04 face legally binding remediation deadlines — several of which expire today. All other organizations should treat these with equivalent urgency.

Deadline Watch: Today's Expiry Cluster Demands Immediate Action

Four CVEs carry a patch deadline of August 21, 2026 — meaning remediation windows close as of this brief's publication.

CVE-2026-33824 (Microsoft IKE Service Extensions) is arguably the most structurally dangerous of the group. A double-free memory corruption vulnerability in the Internet Key Exchange service creates a remote code execution pathway in Windows environments with IPsec/VPN exposed to the network. IKE is rarely considered an attack surface by perimeter teams, yet it sits at the heart of encrypted tunnel negotiation in hybrid-cloud and zero-trust architectures. Organizations should verify that IKE endpoints are not directly reachable from untrusted networks and apply the relevant Windows security update immediately.

CVE-2026-55040 (Microsoft SharePoint) describes a weak authentication vulnerability that allows unauthenticated network attackers to bypass security controls. SharePoint is pervasive in government and federal contractor environments, frequently handling sensitive unclassified documents and serving as an identity-integrated collaboration hub. Authentication bypass on SharePoint can chain directly into credential harvesting, lateral movement, or data exfiltration — particularly dangerous in hybrid Microsoft 365 deployments where on-premise SharePoint federates with cloud identity. Teams running on-premise SharePoint servers should treat any unpatched instance as externally compromised until patched and forensically triaged per BOD 26-04 requirements.

CVE-2026-59310 (Broadcom VMware vCenter) adds a path traversal vulnerability enabling arbitrary code execution for any attacker with network-level access to vCenter. vCenter exploits consistently represent some of the highest-impact incidents in enterprise environments because successful exploitation gives adversaries hypervisor-level control over entire virtual infrastructure estates. The blast radius here is enormous. Organizations should immediately audit vCenter network exposure, enforce management-plane network segmentation if not already in place, rotate vCenter service account credentials, and apply Broadcom's patch without delay. Cloud environments managed through vCenter-compatible APIs should be evaluated per BOD 26-04 cloud service guidance.

CVE-2025-62593 (Ray-Project Ray) rounds out today's expired deadlines with a code injection vulnerability affecting the Ray distributed computing framework, exploitable through Firefox and Safari. Ray is widely used in AI/ML research and production inference pipelines. The browser-exploitable nature of this flaw is atypical and significant: developers running Ray dashboards locally or on shared development infrastructure are exposed through routine web browsing. This is a supply-chain and developer-endpoint risk, not just a server risk.

The AI/ML Attack Surface Expands: Developer Tooling in the Crosshairs

The simultaneous KEV listing of two AI/ML platform vulnerabilities — Ray (CVE-2025-62593) and MLflow (CVE-2026-64849) — signals that adversaries are actively targeting the machine learning development lifecycle, not just production deployments.

MLflow's server-side request forgery vulnerability (CVE-2026-64849, deadline September 2) is particularly high-value in cloud-native ML environments. An SSRF in MLflow can be weaponized to reach AWS Instance Metadata Service (IMDS), Azure IMDS, or GCP metadata endpoints, harvesting cloud credentials and enabling lateral movement far beyond the ML platform itself. Organizations running MLflow on cloud infrastructure should immediately enforce IMDSv2 with hop-limit restrictions, block MLflow's egress to internal metadata IP ranges (169.254.169.254, fd00:ec2::254), and evaluate whether MLflow instances are inadvertently internet-exposed. Credential rotation for any cloud roles accessible from MLflow hosts is strongly advised regardless of confirmed exploitation.

For Ray (CVE-2025-62593), teams should audit all Ray cluster dashboard ports for external exposure, restrict dashboard binding to loopback or internal-only interfaces, and ensure developer machines are not running unpatched Ray versions while using affected browsers. Given Ray's prevalence in both research and production AI inference, security teams should treat any Ray deployment as potentially affected until patched.

Collaboration Infrastructure Under Pressure: TrueConf and Zimbra

Three CVEs target enterprise communication and collaboration platforms, and together they form an alarming chain for organizations running unified communications infrastructure.

The two TrueConf Server vulnerabilities — CVE-2026-72529 (missing authentication, deadline August 23) and CVE-2026-72530 (code injection, deadline September 3) — both operate through port 4307/TCP and require no authentication to reach. CVE-2026-72529 allows unauthenticated script execution; CVE-2026-72530 allows sandbox breakout and host-level code execution. Chained together, these two flaws constitute a complete unauthenticated RCE path to the underlying host. Any organization with TrueConf Server exposed — even on internal networks — should immediately firewall port 4307 from all but explicitly required sources, apply available patches, and conduct forensic triage for signs of prior exploitation consistent with BOD 26-04 requirements. Discontinue use if vendor patches are unavailable.

CVE-2026-73570 (Zimbra Collaboration Suite, deadline August 24) enables OS command injection via unauthenticated SMTP requests, with commands executing as the Zimbra service user. Zimbra has been a recurring KEV target due to its prevalence in government and international organizational deployments. Unauthenticated SMTP injection is particularly severe because SMTP is an operationally required open port; organizations cannot simply firewall it away. Apply the vendor patch on an emergency basis, review Zimbra process execution logs for anomalous child processes, and ensure outbound SMTP relay rules do not permit lateral pivot.

Summary Remediation Priorities

| CVE | Product | Deadline | Priority | |---|---|---|---| | CVE-2026-33824 | Microsoft IKE | Aug 21 — TODAY | Critical | | CVE-2026-55040 | Microsoft SharePoint | Aug 21 — TODAY | Critical | | CVE-2026-59310 | VMware vCenter | Aug 21 — TODAY | Critical | | CVE-2025-62593 | Ray | Aug 21 — TODAY | High | | CVE-2026-72529 | TrueConf Server | Aug 23 | Critical | | CVE-2026-73570 | Zimbra ZCS | Aug 24 | Critical | | CVE-2026-64849 | MLflow | Sep 2 | High | | CVE-2026-72530 | TrueConf Server | Sep 3 | High |

All deadlines are binding for federal civilian agencies under BOD 26-04. Non-federal organizations should apply equivalent urgency to any internet-facing or internally critical instances.

Sources: CISA KEV Catalog · CISA BOD 26-04 · Broadcom VMware Security Advisories · Microsoft Security Response Center · Synacor Zimbra Security Advisories · MLflow Security Disclosures · Ray-Project Security Advisories

Free KEV Alerts

  • Real-time notification the moment a KEV drops
  • Vendor and product details
  • BOD 26-04 remediation deadline included

Pro Alerts Coming Soon

  • Real-time notification the moment a KEV drops
  • Filtered to your specific vendor watchlist
  • Urgency scoring (Critical / Urgent / Standard)
  • Direct patch links included

Stay ahead of CISA.

No spam. Unsubscribe anytime. We don't sell your data.


Upcoming Patch Due Dates

via Binding Operational Directive 26-04

BOD 26-04 is CISA's current vulnerability remediation directive for Federal Civilian Executive Branch (FCEB) agencies, updating the KEV-driven framework introduced under BOD 22-01 with a more risk-based approach to prioritization. While binding only on FCEB agencies, its framework increasingly influences contractor expectations through procurement requirements, FedRAMP programs, and agency security clauses.

Loading...

News Logo

Cyber Security News

You may have missed...


Hacking Editorial Brief — August 24, 2026

Federal Agencies Issue Alert on AI-Assisted Attacks Targeting Industrial Control Systems

Five federal agencies released a joint cybersecurity advisory warning that unspecified threat actors are conducting AI-assisted attacks against Siemens S7 Series programmable logic controllers at critical infrastructure facilities across the United States. The advisory represents the first confirmed government acknowledgment of artificial intelligence being weaponized to target industrial control systems in active campaigns. The attacks focus on PLCs widely deployed in energy, manufacturing, and water treatment facilities, suggesting sophisticated threat actors are leveraging AI capabilities to automate reconnaissance, vulnerability discovery, or exploitation of operational technology environments. The warning comes as the UAE separately reports defending against approximately 800,000 daily hacking attempts—four times pre-conflict levels—using its own AI-powered defensive systems.

Novel FTP Banner Technique Delivers Malware in Ongoing Campaign

Threat actors are exploiting File Transfer Protocol server banners to hide malware commands and infect Windows systems in a campaign active since early July. The technique abuses FTP banner messages—typically used to display server information—to inject and execute malicious payloads, representing a creative evasion method that bypasses traditional detection focused on file transfers or standard command-and-control channels. The campaign continues to target Windows environments with no identified attribution. Separately, a hacker group identifying itself as "Madarx" claims to be selling six million Bangladeshi job seeker CVs on dark web marketplaces, while Apollo Global reportedly suffered a data breach exposing names, addresses, and Social Security numbers after attackers accessed the firm's cloud infrastructure.

Sources: SC World · Rest of World · Techzine Global · New Age · IDN Financials

📌 Pinned

*

https:betanews.comMar 5

Inside a cyberattack: How hackers steal data

The truth about cybersecurity is that it's almost impossible to keep hackers outside of an organization, particularly as the cybercrime industry ...

https://cardinalnews.orgAug 24

Canvas is back in the classroom despite security concerns following hack - Cardinal News

In April, hackers breached Instructure, the company behind Canvas, which schools use to manage assignments, track grades and deliver course content, ....

https://www.energylivenews.comAug 24

Iran-linked hackers blamed for power pant shut down - Energy Live News

Iran-linked hackers have been blamed for a cyber-attack that temporarily shut down a small UK power plant, reports the Guardian.

https://www.calcalistech.comAug 24

After raising $51 million, Minimus shuts down as Twistlock founders return remaining | Ctech

The cybersecurity startup failed to gain enough commercial momentum to continue operating. Customers will have 60 days to migrate before the ...

https://thehackernews.comAug 21

Lazarus Group Exploits Windows Zero-Day to Target Defense and Aerospace

The North Korean Lazarus Group exploited a newly patched Windows zero-day to deliver a never-before-seen backdoor targeting defense and aerospace comp...

https://cyberrecaps.comAug 22

Microsoft Patches Critical Entra ID Remote Code Execution Vulnerability CVE-2026-69836

Microsoft patched a critical remote code execution vulnerability in Entra ID (CVSS 10.0) that allows unauthorized attackers to execute code over a net...

https://thehackernews.comAug 24

UAT-10147 Uses AI to Scale Server Attacks, Deploys SPECTRE With EDR Bypass and Linux Rootkit

Cybersecurity researchers have disclosed details of a Chinese-speaking cybercrime group dubbed UAT-10147 that's targeting Windows and Linux web ...

https://www.the-independent.comAug 23

Iranian hackers carry out unprecedented attack on UK's power network - The Independent

Iranian hackers carry out unprecedented attack on UK's power network · The generator was forced to shut down for four days following the cyber ...

https://www.thetimes.comAug 23

Iranian hackers forced UK energy facility to shut for four days - The Times

Iranian hackers shut down a British energy facility for four days last month in what is believed to be the first attack of its kind in this ...


Updated daily