CISA stopped reliably sending KEV alerts.
We didn't.
CyberComply monitors the CISA Known Exploited Vulnerabilities catalog 24/7 and alerts you the moment a new KEV drops — before the deadline clock starts ticking without you knowing.
KEV Intelligence Brief — August 14, 2026
Prepared for: Federal Contractors · DevOps & Platform Engineering · Security Operations Leadership Reference period: August 4–11, 2026 | Brief date: August 14, 2026
Deadline Watch: Three Entries Already Overdue, More Require Immediate Action
This week's KEV additions demand immediate triage. Several patch deadlines have already passed, meaning federal agencies and contractors operating under BOD 26-04 are formally out of compliance if remediation is incomplete as of today.
CVE-2026-8037 (Progress LoadMaster) carried a deadline of August 10 — four days ago. This unauthenticated command injection flaw allows arbitrary OS command execution against LoadMaster appliances by exploiting unsanitized input across multiple command endpoints. LoadMaster serves as a critical load balancing and ADC layer in many production environments, meaning exploitation here can pivot quickly to backend application infrastructure. If you have not already patched, isolate internet-facing LoadMaster management interfaces immediately and validate that no unauthorized commands were executed. Threat actor access to a load balancer grants traffic interception and lateral movement capability that log review alone may not catch — invoke CISA's Forensics Triage Requirements before returning affected appliances to production.
CVE-2026-63077 (JetBrains TeamCity) and CVE-2026-18556 (N-able N-central) and CVE-2026-34486 (Apache Tomcat) and CVE-2026-9198 (IBM Langflow) all carried deadlines of August 7 or August 8 — all overdue. These are addressed in detail by theme below, but the compliance posture is clear: if any of these remain unpatched in your environment, document your exception and escalate immediately.
CVE-2026-20349 (Cisco ASA/FTD) and CVE-2026-72898 (Metabase) share today's deadline of August 14. With today being the final day, treat these as emergency change requests if patches have not been applied.
CVE-2026-68820 (Microsoft Windows AFD/WinSock) carries the longest runway — August 25 — but should not be deprioritized. Its exploitation chain is likely already understood by sophisticated actors given its use-after-free mechanics in the Windows kernel networking stack.
Infrastructure and Network Fabric Under Active Threat
Three of the eight entries target foundational network and perimeter infrastructure, creating compounding risk when considered together.
CVE-2026-20349 affects Cisco Secure Firewall ASA and FTD — devices that sit at the edge of countless federal and enterprise networks. The heap inspection vulnerability enables unauthenticated remote attackers to trigger unexpected device reloads, producing a denial-of-service condition. While DoS may appear lower severity than code execution, weaponizing it against a firewall creates enforcement gaps that can be exploited in tandem with other intrusion techniques. Organizations running redundant ASA/FTD pairs should patch the standby unit first, validate failover, then patch the active node — but do not delay. Given CISA's Forensics Triage Requirements, capture device logs and memory snapshots before patching where possible.
CVE-2026-8037 (Progress LoadMaster) and CVE-2026-18556 (N-able N-central) represent a particularly dangerous pattern: both target infrastructure management platforms used to administer other systems at scale. N-central's authentication bypass (alternate path/channel) means an attacker who reaches the N-central interface can potentially authenticate without valid credentials and inherit its managed endpoint visibility — effectively a master key to any environment where N-able is deployed for remote monitoring and management. RMM platform compromises have featured prominently in supply chain intrusion campaigns in recent years. If N-central is internet-exposed, take it offline or restrict access to known management IP ranges immediately, even if patching is complete. Rotate all API keys, service account credentials, and managed endpoint credentials that N-central has touched.
Developer Toolchains and Data Platforms: Unauthenticated RCE at Scale
The remaining four CVEs converge on a high-consequence theme: unauthenticated attackers achieving administrative or code execution access against platforms that sit deep inside development pipelines and data workflows.
CVE-2026-63077 (JetBrains TeamCity) enables unauthenticated remote code execution via the agent polling protocol — the internal channel TeamCity uses to coordinate build agents. Prior TeamCity compromises have been attributed to state-sponsored actors targeting software supply chains, and this class of vulnerability is operationally ideal for that purpose: compromise the CI/CD server, poison build artifacts, propagate malware downstream. Any TeamCity instance reachable from the internet should have been patched by August 8. If that deadline was missed, assume compromise, isolate the instance, audit recent pipeline runs and build artifact integrity, and rotate all secrets stored in TeamCity (API tokens, cloud credentials, signing keys).
CVE-2026-72898 (Metabase) is an unauthenticated SQL injection flaw that escalates directly to administrator access on the Metabase instance. From that position, attackers can pivot to every connected database, exfiltrate credentials, and read any data Metabase is authorized to query. Organizations using Metabase to expose analytics against production databases face a full data breach scenario. Patch today, rotate all database credentials stored in Metabase connection configurations, and audit query logs for anomalous export activity.
CVE-2026-9198 (IBM Langflow) delivers unauthenticated full remote code execution on default Langflow deployments — a particularly sharp finding given Langflow's role as an AI workflow orchestration platform increasingly deployed in production environments. Default deployments suggest that misconfigured or rapidly stood-up instances are at highest risk. Any Langflow instance accessible without authentication controls should be considered compromised until forensics prove otherwise. Restrict access to authenticated, network-segmented deployments immediately.
CVE-2026-34486 (Apache Tomcat) rounds out this group with a missing encryption vulnerability that allows bypass of the EncryptInterceptor. Tomcat remains one of the most widely deployed Java application servers across federal and enterprise environments. EncryptInterceptor bypass can expose session data and intra-cluster communications to interception, particularly in clustered deployments. While less dramatic than RCE, the blast radius in clustered, session-rich environments is significant.
CVE-2026-68820 (Microsoft Windows AFD/WinSock) — a local privilege escalation via use-after-free in the Ancillary Function Driver — is the logical endpoint for attackers who have already gained a foothold through any of the above vectors. Patch Windows systems on the August 25 timeline, but prioritize hosts that run any of the above affected software.
Sources: CISA KEV Catalog · CISA BOD 26-04 · Cisco Security Advisories · Microsoft Security Update Guide · JetBrains Security Bulletins · Progress LoadMaster Security Advisories · N-able Security Advisories · Apache Tomcat Security Reports · Metabase Security
Free KEV Alerts
- Real-time notification the moment a KEV drops
- Vendor and product details
- BOD 26-04 remediation deadline included
Pro Alerts Coming Soon
- Real-time notification the moment a KEV drops
- Filtered to your specific vendor watchlist
- Urgency scoring (Critical / Urgent / Standard)
- Direct patch links included
Stay ahead of CISA.
Search the KEV Catalog by Vendor or Product
Search for CVEs by vendor or product to identify known exploited vulnerabilities in your environment
Upcoming Patch Due Dates
via Binding Operational Directive 26-04
BOD 26-04 is CISA's current vulnerability remediation directive for Federal Civilian Executive Branch (FCEB) agencies, updating the KEV-driven framework introduced under BOD 22-01 with a more risk-based approach to prioritization. While binding only on FCEB agencies, its framework increasingly influences contractor expectations through procurement requirements, FedRAMP programs, and agency security clauses.
Loading...
Cyber Security News
You may have missed...
Hacking Editorial Brief — August 15, 2026
Chinese AI Model Demonstrates Advanced Hacking Capabilities
A new open-weight AI model from a Chinese laboratory has achieved hacking capabilities nearly equivalent to leading U.S. models, according to multiple reports. The development carries significant implications for both offensive and defensive cyber operations, as AI-enabled hacking tools can dramatically scale attack and defense activities. The model's open-weight nature means its capabilities could be broadly accessible, lowering barriers to entry for threat actors seeking to automate exploitation workflows. This marks a notable shift in the AI security landscape, with cyber-capable models no longer confined to closed U.S. systems.
Arrests Made in 2023 Banking Hack; Aviation Security Research Released
German and Brazilian authorities announced multiple arrests this week connected to a late 2023 banking hack that resulted in approximately €30 million in losses. The international law enforcement action follows an extended investigation into the breach. Separately, security researchers disclosed they built a coin-sized device costing under $100 capable of compromising Boeing 737 aircraft electronics, demonstrating how brief physical access to aviation systems could create serious cybersecurity risks. The research highlights vulnerabilities in aircraft systems that could be exploited by threat actors with temporary proximity to targets.
In France, hackers stole tax and revenue data belonging to 678,000 individuals and companies from French tax and land registry systems, marking a significant breach of government financial records. The Sable Squirrel cybercrime group was identified as controlling over 10,000 domains in an operation valued at approximately $7 million, with infrastructure supporting illegal streaming, gambling, and malware distribution. At least 31,000 malware samples have been observed communicating with Sable Squirrel-controlled domains.
Sources: Axios · Recorded Future News · Gizmodo · New Straits Times · The Hacker News
*
Inside a cyberattack: How hackers steal data
The truth about cybersecurity is that it's almost impossible to keep hackers outside of an organization, particularly as the cybercrime industry ...
China-Linked Hackers Use AI Agents in Autonomous Attack on Taiwan
China-linked hackers devised an autonomous attack framework using AI agents with Bayesian prioritisation to target Taiwanese government systems, exfil...
Taiwan says it was targeted last month in AI-driven hacking campaign
Taiwan's Ministry of Digital Affairs detected AI-assisted cyberattacks on government agencies in July, with hackers employing a hybrid approach combin...
'Near-autonomous' AI agents attack Taiwan's nuclear safety agency
Over the first four days of July, near-autonomous AI agents compromised government user accounts and extracted personnel records before expanding atta...
China-Linked Hackers Use AI Agents in Autonomous Attack on Taiwan
Suspected Chinese cyber operatives used publicly available AI tools to deploy up to eight autonomous AI agents that compromised 85 government user acc...
Windows Driver Zero-Day CVE-2026-68820 Under Active Exploitation by Lazarus
Microsoft patched CVE-2026-68820, a critical Windows driver zero-day under active exploitation that allows local attackers to escalate privileges to S...
What we know about the alleged Iranian hacks on US water utilities - TechCrunch
Cybersecurity experts have long believed that Iranian hackers target low-hanging fruit in opportunistic isolated attacks, so this hacking campaign ...
'Cyber privateers': Trump issues order allowing US companies to hack overseas groups ...
The US government is already doing a lot of hacking on foreign targets. The new program risks having too many cooks in the kitchen, some former ...
Millions of SoCal cars may be vulnerable to hackers. Here's what you can do - NBC 7 San Diego
A security flaw affects KARR and SWDS anti-theft devices. Here's how Southern California drivers can check their cars and install the patch.
Updated daily
