CISA stopped reliably sending KEV alerts.
We didn't.
CyberComply monitors the CISA Known Exploited Vulnerabilities catalog 24/7 and alerts you the moment a new KEV drops — before the deadline clock starts ticking without you knowing.
KEV Intelligence Brief — September 2, 2026
Prepared for: Federal Contractors · DevOps / Platform Engineering · Security Operations Leadership Reporting Window: August 26–28, 2026 KEV Additions · Brief Date: September 2, 2026
Deadline Watch: Three Patches Already Overdue or Expiring This Week
Three of the eight newly cataloged vulnerabilities carry patch deadlines that have already passed or expire within 72 hours of this brief — demanding immediate attention before any other remediation work proceeds.
CVE-2019-1068 (Microsoft SQL Server remote code execution) carried a deadline of August 29 — it is now overdue. This is a 2019-vintage vulnerability that allows an attacker to execute arbitrary code within the SQL Server Database Engine service account context, making it a direct pivot point for lateral movement across enterprise environments. The age of this CVE combined with its KEV addition signals active exploitation, likely against unpatched legacy SQL Server instances that organizations have deprioritized. SQL Server instances exposed to internal networks with broad service account permissions are the highest-risk targets. Beyond patching, operators should immediately audit SQL Server service account privileges, enforce least-privilege configurations, and verify that no instances are internet-facing without compensating controls.
CVE-2023-49105 (ownCloud improper authentication) and CVE-2026-53362 (Linux Kernel IPv6 privilege escalation) both carried deadlines of August 30 — also now overdue. The ownCloud flaw is particularly aggressive: an unauthenticated attacker who knows a victim's username can read, modify, or delete arbitrary files, provided that user has no signing-key configured. In environments where ownCloud serves as a document collaboration or file-sharing platform — common in government contractor and research settings — this is effectively unauthenticated data exfiltration at scale. Operators should verify signing-key enforcement across all user accounts as a hardening step even post-patch.
The Linux Kernel flaw (CVE-2026-53362) affecting the IPv6 networking subsystem is a cross-distribution concern touching SUSE, Red Hat, and any downstream product built on current kernel versions. Privilege escalation via a networking subsystem component is particularly dangerous in containerized and multi-tenant environments where kernel sharing amplifies blast radius. Container platform operators on Kubernetes, OpenShift, or similar stacks should treat this as a node-level emergency patch — not a routine OS update cycle item.
Print Infrastructure as an Attack Chain: PaperCut's Chained RCE Pair
The addition of CVE-2026-81578 and CVE-2026-82078 (both PaperCut NG/MF, deadline September 11) represents one of the more operationally significant entries in this batch because CISA has explicitly flagged these two CVEs as chainable into a single attack path.
CVE-2026-81578 is a missing authentication vulnerability allowing an unauthenticated remote attacker to modify system configurations. Alone, this is serious. Chained with CVE-2026-82078 — an unsafe reflection vulnerability that permits manipulation of configuration parameters to execute arbitrary Java bytecode on the application classpath — the combination yields unauthenticated remote code execution under the PaperCut server process context. PaperCut NG/MF is widely deployed in universities, government agencies, and enterprise environments, frequently with administrative interfaces accessible from internal networks or, in some deployments, exposed to the internet.
The September 11 deadline provides roughly nine days of runway, but given the unauthenticated entry point, organizations should treat internet-facing PaperCut instances as actively compromised until patched and forensically reviewed. Per BOD 26-04 and CISA's Forensics Triage Requirements, these systems require triage — not just patching. Isolate the print management server from the broader network at the firewall level, rotate any service credentials the PaperCut process touches, and review server-side logs for configuration modification events dating back at least 30 days before applying the patch.
Developer Toolchain and Legacy Linux: Supply Chain and Privilege Escalation Exposure
Three remaining entries share a common thread: they target infrastructure components embedded deep in developer workflows and Linux system management, where exploitation is harder to detect and remediation triggers broader operational disruption.
CVE-2026-66384 (JFrog Artifactory path traversal, deadline September 10) allows an authenticated user to write data outside the intended Docker cache path under specific remote-repository conditions. In a CI/CD pipeline context, this is a supply chain integrity risk — an attacker with low-privilege repository access could potentially plant malicious artifacts or overwrite trusted image layers. DevOps teams running Artifactory as a Docker registry should audit remote repository configurations immediately and enforce strict user privilege segmentation while the patch is staged.
CVE-2015-3246 and CVE-2015-5287 are both Red Hat components — Libuser and the Automatic Bug Reporting Tool (ABRT), respectively — added to the KEV on August 26 with a deadline of September 9. The age of these CVEs (over a decade old) and CISA's notation that ABRT may be end-of-life underscores a persistent problem: old local privilege escalation vulnerabilities in system utilities remain exploitable on unpatched or legacy RHEL-derivative hosts. Both flaws are local — requiring existing system access — making them ideal second-stage tools in a broader intrusion. For ABRT specifically, CISA's guidance to consider discontinuing use should be taken seriously; organizations still running it should evaluate whether any operational dependency justifies the exposure, and transition to supported alternatives where possible.
Summary Action Priorities
| Priority | CVEs | Deadline | Status | |---|---|---|---| | Overdue — Act Now | CVE-2019-1068, CVE-2023-49105, CVE-2026-53362 | Aug 29–30 | PAST DUE | | Imminent | CVE-2015-3246, CVE-2015-5287 | Sep 9 | 7 days | | Upcoming | CVE-2026-66384 | Sep 10 | 8 days | | Upcoming | CVE-2026-81578, CVE-2026-82078 | Sep 11 | 9 days |
All eight CVEs are subject to BOD 26-04 obligations for federal agencies and contractors. For any asset where patching is not immediately feasible, document compensating controls, enforce network isolation, and initiate forensic triage per CISA requirements.
Sources: CISA KEV Catalog · CISA BOD 26-04 · PaperCut Security Advisories · ownCloud CVE-2023-49105 Advisory · JFrog Artifactory Security Center · Red Hat CVE Database · Microsoft MSRC CVE-2019-1068 · CISA Forensics Triage Guidance
Free KEV Alerts
- Real-time notification the moment a KEV drops
- Vendor and product details
- BOD 26-04 remediation deadline included
Pro Alerts Coming Soon
- Real-time notification the moment a KEV drops
- Filtered to your specific vendor watchlist
- Urgency scoring (Critical / Urgent / Standard)
- Direct patch links included
Stay ahead of CISA.
Search the KEV Catalog by Vendor or Product
Search for CVEs by vendor or product to identify known exploited vulnerabilities in your environment
Upcoming Patch Due Dates
via Binding Operational Directive 26-04
BOD 26-04 is CISA's current vulnerability remediation directive for Federal Civilian Executive Branch (FCEB) agencies, updating the KEV-driven framework introduced under BOD 22-01 with a more risk-based approach to prioritization. While binding only on FCEB agencies, its framework increasingly influences contractor expectations through procurement requirements, FedRAMP programs, and agency security clauses.
Loading...
Cyber Security News
You may have missed...
Hacking Editorial Brief — September 2, 2026
U.S. and CrowdStrike Move to Dismantle Two-Decade Russian Botnet
U.S. law enforcement and CrowdStrike announced coordinated action to dismantle Sality, a Russian cybercrime operation active for approximately two decades. While details of the disruption remain limited, officials characterized the infrastructure takedown as targeting one of the internet's longest-running malware campaigns. Despite being overshadowed in recent years by more disruptive ransomware and wiper operations, Sality has maintained persistent botnet infrastructure used for various criminal purposes. The dismantling effort represents sustained counter-cybercrime cooperation between federal agencies and private-sector threat intelligence, though the scope of seized infrastructure and operational impact have not been fully disclosed.
Dropbox Confirms 5,000 Account Compromises via Third-Party Authentication Bypass
Dropbox disclosed that approximately 5,000 user accounts were compromised in August through an authentication bypass involving Lenovo identity services. Attackers used victims' email addresses to create new Lenovo IDs, exploiting a third-party sign-in integration to access Dropbox accounts without requiring passwords. The campaign resulted in unauthorized viewing and downloading of stored content. The incident highlights persistent risk in federated authentication systems where credential reuse and third-party identity provider flaws enable access without traditional credential theft. Dropbox has notified affected users, though the threat actor behind the campaign and the full scope of exfiltrated data remain unconfirmed.
Sources: Reuters · Channel News Asia · Cybernews
*
Inside a cyberattack: How hackers steal data
The truth about cybersecurity is that it's almost impossible to keep hackers outside of an organization, particularly as the cybercrime industry ...
FBI takes down China-linked hacking network behind attacks on NASA, DOJ and U.S. Senate
The Justice Department and FBI seized domains tied to hacking tools QScan and QTRouter built and run by Chinese state-sponsored group QTFY that target...
NASA, Fed, Senate among Chinese hackers' targets, Justice Department says
The DOJ announced it disrupted a Chinese hacking operation by Nanjing Xinjiuwei Network Technology Company targeting NASA, the Federal Reserve, and ot...
US Says China-Linked Hackers Targeted NASA, Fed and Senate
The US Justice Department and FBI disrupted online infrastructure allegedly used by Chinese state-sponsored hackers to target American government agen...
FBI seizes China-linked hacking platforms QScan and QTRouter used to target U.S. critical infrastructure
The U.S. Department of Justice and FBI seized two platforms used by a China-linked group to hide cyberattacks and target critical infrastructure since...
Chinese state-backed hackers breached U.S. agencies' networks for years, DOJ & FBI says
The Justice Department and FBI announced the seizure of multiple domains connected to the Chinese state-sponsored hacking group QTFY that had breached...
US healthcare giant McKesson breached, ShinyHunters claims 284m patient records
ShinyHunters claimed it breached US healthcare giant McKesson and made a $55,236,150 ransom demand for 284 million patient records.
DOJ: Chinese State-Sponsored Hackers Breached Senate, Federal Reserve, Multiple Agencies
The DOJ seized internet domains tied to QTFY hacking platforms QScan and QTRouter that Chinese state-sponsored operatives used to breach the Federal R...
Fed, NASA and DOJ among victims of Chinese state-sponsored hacker group: Court documents
The Federal Reserve, U.S. Senate, Department of Justice, and NASA were victims of computer intrusion by Chinese state-sponsored hacking group QTFY, ac...
Updated daily
