CISA stopped reliably sending KEV alerts.
We didn't.
CyberComply monitors the CISA Known Exploited Vulnerabilities catalog 24/7 and alerts you the moment a new KEV drops — before the deadline clock starts ticking without you knowing.
KEV Intelligence Brief — August 7, 2026
Prepared by: Cybersecurity Intelligence | Distribution: Federal Contractors, DevOps, SecOps Leadership
This week's KEV additions paint a consistent picture: attackers are targeting the infrastructure layer beneath applications — load balancers, build systems, RMM platforms, AI tooling, and firewall management consoles. Several deadlines have already passed or expire this weekend. Teams should treat this brief as an active operational checklist, not background reading.
Network and Security Management Infrastructure: Multiple Paths to Full Compromise
The most operationally urgent cluster this week involves products that sit at the trust boundary of enterprise networks — where a single bypass can hand an adversary the keys to everything downstream.
N-able N-central is carrying two related CVEs added within 24 hours of each other. CVE-2026-18577 (added August 3, deadline August 6 — now overdue) is an authentication bypass enabling account takeover. CVE-2026-18556 (added August 4, deadline August 7 — today) is explicitly described as an incomplete patch for that first vulnerability. This is a textbook patch-bypass scenario. If your team applied the initial N-central fix and considered the matter closed, you should assume the remediation is insufficient. N-central's privileged position as a remote monitoring and management platform means compromise here translates directly to lateral movement across every managed endpoint in your environment. Isolate internet-facing N-central instances immediately, verify the latest vendor patch is applied, and audit administrative account activity for anomalous access patterns dating back at least 30 days.
Cisco Secure Firewall Management Center (FMC) (CVE-2026-20316, deadline August 1 — overdue by six days) exposes a hard-coded password that allows unauthenticated remote attackers to authenticate with a low-privileged account. On a firewall management plane, "low-privileged" is rarely the end of the story — it is reconnaissance real estate. If you have not patched, assume the credential is known to threat actors. Rotate all local FMC accounts, review policy change logs, and verify no unauthorized firewall rules were introduced. BOD 26-04 obligations for this CVE are past due; federal contractors operating unpatched FMC instances are out of compliance today.
Fortinet FortiOS (CVE-2025-68686, deadline August 10) requires a slightly different analytical frame. Exploitation requires prior filesystem-level access, making this a post-exploitation persistence mechanism rather than an initial access vector. Specifically, it bypasses the symbolic link cleanup patch Fortinet has pushed in response to earlier campaigns. If your FortiOS devices have been involved in any incident in the past 12 months, this vulnerability means previously believed-remediated persistence may still be active. Apply the patch, but also conduct forensic triage per CISA's requirements — particularly examining SSL-VPN virtual filesystem mounts and unexpected symbolic links.
Developer and Build Infrastructure: Unauthenticated RCE in the Pipeline
Attackers who can compromise the systems that build and deploy software gain access far beyond any single application. Two entries this week target exactly that surface.
JetBrains TeamCity (CVE-2026-63077, deadline August 8 — tomorrow) introduces deserialization of untrusted data exploitable through the agent polling protocol — meaning the attack surface is not just the web UI but any port TeamCity build agents use to check in. Unauthenticated RCE on a CI/CD server is a supply chain event waiting to happen. Treat an unpatched TeamCity server as a compromised build environment: review recent build artifacts, pipeline configurations, and deployment keys for signs of tampering. If TeamCity is internet-facing, take it offline until patched. This is not an acceptable tradeoff to preserve build uptime.
IBM Langflow (CVE-2026-9198, deadline August 7 — today) allows unauthenticated code injection on default deployments — a detail worth underlining. Many Langflow instances in AI development environments were stood up rapidly, often without hardened configurations, as teams moved fast on generative AI initiatives. The default attack surface is broad. Any organization running Langflow for AI workflow orchestration should audit for internet exposure immediately, apply vendor mitigations, and validate that no unauthorized flows or API keys were injected into the environment.
Deadline Watch: Application Infrastructure Under Active Exploitation
Two additional entries round out the week and require immediate attention from application and platform teams.
Progress LoadMaster (CVE-2026-8037, deadline August 10) enables command injection through unsanitized input across multiple command endpoints — with no authentication required. LoadMaster appliances are often deployed as ADCs for critical application delivery; compromise can enable traffic interception and session hijacking at scale. Notably, Progress had a difficult 2024–2025 with MOVEit and related tooling; their products have been attractive targets. Apply vendor mitigations now, restrict management interface access to trusted IP ranges, and treat this with the same urgency as prior Progress vulnerabilities that led to mass exploitation.
Apache Tomcat (CVE-2026-34486, deadline August 7 — today) allows bypass of the EncryptInterceptor, effectively stripping the encryption layer from cluster session replication traffic. In multi-node Tomcat deployments — common in Java enterprise and government application stacks — this exposure can allow a network-adjacent attacker to intercept or tamper with sensitive session data. Patch immediately and verify EncryptInterceptor configuration is functioning as intended post-update.
Operational Reminder: Six of these eight deadlines fall between July 27 and August 10. Three are already overdue. For federal agencies and contractors subject to BOD 26-04, compliance is not optional — document your remediation status, exceptions, and compensating controls now.
Sources: CISA KEV Catalog · CISA BOD 26-04 · Cisco Security Advisory – FMC · Fortinet PSIRT Advisory – FortiOS · Progress LoadMaster Security Advisories · JetBrains TeamCity Security Bulletin · N-able Security Advisories · Apache Tomcat Security Reports
Free KEV Alerts
- Real-time notification the moment a KEV drops
- Vendor and product details
- BOD 26-04 remediation deadline included
Pro Alerts Coming Soon
- Real-time notification the moment a KEV drops
- Filtered to your specific vendor watchlist
- Urgency scoring (Critical / Urgent / Standard)
- Direct patch links included
Stay ahead of CISA.
Search the KEV Catalog by Vendor or Product
Search for CVEs by vendor or product to identify known exploited vulnerabilities in your environment
Upcoming Patch Due Dates
via Binding Operational Directive 26-04
BOD 26-04 is CISA's current vulnerability remediation directive for Federal Civilian Executive Branch (FCEB) agencies, updating the KEV-driven framework introduced under BOD 22-01 with a more risk-based approach to prioritization. While binding only on FCEB agencies, its framework increasingly influences contractor expectations through procurement requirements, FedRAMP programs, and agency security clauses.
Loading...
Cyber Security News
You may have missed...
Hacking Editorial Brief — August 7, 2026
Active Exploitation of N-able and SonicWall Vulnerabilities
CISA added CVE-2026-18577 to its Known Exploited Vulnerabilities catalog following active exploitation targeting N-able N-central remote monitoring and management systems. The flaw functions as an incomplete patch for a previous vulnerability, allowing attackers to bypass authentication and pivot from compromised servers into managed endpoints across customer networks. Separately, the INC Ransomware group is exploiting recently disclosed SonicWall SMA1000 vulnerabilities CVE-2026-15409 and CVE-2026-15410, which permit unauthenticated remote attackers to escalate privileges to root level. Both campaigns demonstrate threat actors' continued focus on network management appliances that provide broad access to enterprise environments.
Chinese Threat Groups Accelerate Exploitation Timelines
China-nexus threat actors Vault Panda and Genesis Panda demonstrated sub-24-hour exploitation of the React2Shell vulnerability, a critical web application flaw enabling unauthenticated remote code execution. The rapid weaponization reflects systematic capability development by Chinese groups targeting newly disclosed vulnerabilities. In a parallel iOS-focused campaign, an unidentified Chinese-speaking actor deployed over 100 fake AWS and Apple credential harvesting pages hosting the publicly leaked DarkSword exploit kit, deploying GHOSTBLADE malware on compromised devices. Meanwhile, researchers documented a sophisticated Oracle database attack where threat actors exploited SQL injection to compile the khunt post-exploitation toolkit directly inside the database as Java objects, achieving SYSTEM-level code execution without writing files to disk—a technique enabling credential theft and lateral movement while evading traditional file-based detection.
Sources: The Hacker News · SecurityWeek · Infosecurity Magazine · BleepingComputer
*
Inside a cyberattack: How hackers steal data
The truth about cybersecurity is that it's almost impossible to keep hackers outside of an organization, particularly as the cybercrime industry ...
CISA and Partners Release Joint Advisory on Countering Chinese State-Sponsored Actors
CISA, NSA, FBI, and international partners released a joint cybersecurity advisory detailing ongoing malicious activity by Chinese state-sponsored APT...
House Report Finds US Telecom Data Centers Exposed in Chinese Hack
A House Select Committee on China report reveals that US telecommunications companies connected their systems to data centers in ways that exposed the...
FBI says hackers altered operating instructions for water systems in some states - YouTube
At least 12 states are reporting cyberattacks on water systems that may be linked to Iran-backed hackers. CBS News homeland security correspondent ...
CISA Flags TeamCity CVE-2026-63077 RCE Flaw Under Active Exploitation in the Wild
CISA warns that attackers are actively exploiting TeamCity CVE-2026-63077, an unauthenticated RCE flaw that can expose credentials and compromise buil...
New Interrupt Injection Attack Can Bypass Spectre v2 Defenses on Intel and AMD CPUs
AMD told them it plans a kernel patch; MIT says one has since shipped and arrives in a normal operating system update. Cybersecurity. A fix is in the ...
A Security Pro Hacked North Korean Hackers. He Found They'd Breached Hundreds of ...
For nearly two years, researcher Vangelis Stykas has maintained access to North Korean hackers' servers. His work shows they pulled off intrusions ...
OpenAI Didn't Notice Its AI Agents Using a Message Board to Plan Their Hacking Spree
At the Black Hat security conference, the AI giant revealed new details about how its agents went rogue, hacked several other companies—and did it ...
At least 12 states report cyberattacks on water systems possibly linked to Iran-backed ...
Cyberattacks on U.S. water systems that officials suspect may be linked to Iran-backed hackers have been reported in at least a dozen states, ...
Updated daily
