This month: 26 KEVs detected

CISA stopped reliably sending KEV alerts.
We didn't.

CyberComply monitors the CISA Known Exploited Vulnerabilities catalog 24/7 and alerts you the moment a new KEV drops — before the deadline clock starts ticking without you knowing.

CVE-2019-1068
Microsoft · SQL Server
Microsoft SQL Server Remote Code Execution Vulnerability
Detected Aug 26 · 3-day patch deadline
CVE-2026-8452
Citrix · NetScaler ADC and NetScaler Gateway
Citrix NetScaler ADC and NetScaler Gateway Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability
Detected Aug 26 · 3-day patch deadline
CVE-2026-60004
Gitea · Gitea
Gitea Code Injection Vulnerability
Detected Aug 25 · 3-day patch deadline

KEV Intelligence Brief — August 26, 2026

Issued by: Security Operations Intelligence | Distribution: Federal Contractors, DevOps, SOC Leadership

Eight new entries hit the CISA Known Exploited Vulnerabilities catalog in the past 72 hours, spanning infrastructure middleware, developer toolchains, Linux host components, and legacy web frameworks. The batch is unusually heterogeneous in age — vulnerabilities ranging from 2015 to 2026 are actively being exploited — but it organizes cleanly around three operational concerns: critically compressed patch windows on perimeter-facing systems, a concentrated attack surface across Linux host components, and a developer toolchain threat cluster that warrants immediate supply-chain scrutiny.

Deadline Watch: Oracle, Citrix, and Gitea Demand Immediate Action

Three of the eight entries carry patch deadlines that are either already overdue or expire within days of this brief's publication. These demand same-day triage, not queue placement.

CVE-2026-21962 (Oracle HTTP Server / WebLogic Server Proxy Plug-in) carries a CISA deadline of August 27 — meaning federal agencies and contractors subject to BOD 26-04 are already in violation if patches have not been applied. This improper access control flaw is particularly dangerous given the breadth of impact: exploitation can yield unauthorized read, write, or delete access to all data accessible through Oracle HTTP Server and WebLogic Server Proxy Plug-in. For organizations running Oracle middleware behind load balancers or reverse proxies, this isn't a theoretical risk — it's a direct path to data exfiltration or integrity compromise. Apply Oracle's Critical Patch Update guidance immediately, and if Oracle middleware is internet-facing, consider temporarily restricting inbound access to known IP ranges while patching is completed. Credential rotation for service accounts tied to WebLogic is strongly advised post-remediation.

CVE-2026-8452 (Citrix NetScaler ADC and NetScaler Gateway) expires August 29 and represents a memory buffer bounds violation capable of inducing denial of service across network access control infrastructure. NetScaler ADC and Gateway are high-value chokepoints; taking them down — or destabilizing them — can blind an organization's zero-trust enforcement layer. Apply Citrix's patch immediately. For agencies running NetScaler in clustered configurations, validate that all nodes receive the update, as partial patching leaves viable attack surface.

CVE-2026-60004 (Gitea), also due August 28, is the most tactically interesting entry in this batch. A code injection flaw in Gitea's diffpatch API endpoint allows any user with repository write access to plant an executable Git hook and achieve shell code execution as the Gitea service account. In environments where Gitea hosts CI/CD pipeline configurations, internal tooling, or infrastructure-as-code repositories, this is a direct supply-chain vector — a compromised Gitea service account can poison builds, exfiltrate secrets, or laterally move into build infrastructure. Patch immediately, rotate the Gitea service account credentials, audit recent hook configurations across all repositories, and review access logs for anomalous diffpatch API calls. If patching cannot be completed before August 28, restrict write access to repositories to a minimal trust tier until remediation is confirmed.

Linux Host Integrity: A Compounding Local Privilege Escalation Cluster

Three entries target Linux host-level components with local privilege escalation or denial-of-service potential. Individually, each requires local access; together, they represent a meaningful lateral movement amplifier — an initial foothold anywhere on a Linux host becomes a path to root.

CVE-2022-0995 (Linux Kernel) is an out-of-bounds write vulnerability allowing a local user to gain privileged access or crash the system. The Linux Kernel is the foundational attack surface for every containerized workload, VM guest, and bare-metal server in your environment. This entry, with a deadline of September 9, should be prioritized in environments running container orchestration platforms where kernel exploits can escape namespace isolation.

CVE-2015-3246 (Red Hat Libuser) involves a race condition that allows authenticated local users to corrupt /etc/passwd, enabling privilege escalation or denial of service. The age of this CVE — over a decade old — does not diminish its severity. The fact that it is being actively exploited in 2026 suggests threat actors are actively targeting unpatched legacy Red Hat deployments, particularly in government and critical infrastructure environments slow to modernize base images.

CVE-2015-5287 (Red Hat ABRT — Automatic Bug Reporting Tool) compounds the libuser concern. A symlink attack against a predictably named file allows local users to escalate privileges. CISA's advisory notes ABRT may be end-of-life, meaning no vendor patch may be forthcoming. Organizations still running ABRT should disable or uninstall the service immediately rather than waiting for a patch that may not arrive. Both Red Hat entries carry a September 9 deadline; treat them as a pair during remediation sweeps.

Developer Toolchain and Application Framework Exposure

Two entries target application-layer components embedded in web infrastructure and development pipelines, with broader organizational reach than their descriptions suggest.

CVE-2019-1068 (Microsoft SQL Server) allows remote code execution in the context of the SQL Server Database Engine service account — a highly privileged context in most enterprise deployments. The August 29 deadline makes this effectively a 72-hour window from the date of this brief. Apply the relevant cumulative update per Microsoft's guidance, and validate SQL Server service accounts operate under least-privilege configurations. Network segmentation preventing direct external access to SQL Server ports (1433/TCP) should be verified as a compensating control.

CVE-2021-23758 (Ajax.NET Professional / AjaxPro) represents a deserialization of untrusted data flaw enabling remote code execution through arbitrary .NET class instantiation — a class of vulnerability with a well-documented exploitation toolchain. AjaxPro is flagged as potentially end-of-life, and CISA is direct: discontinue use if mitigations are unavailable. Development teams maintaining legacy ASP.NET applications should audit for AjaxPro dependencies across application manifests, paying particular attention to applications with internet-facing endpoints that process user-supplied serialized data. Migration to supported .NET serialization frameworks is the only durable fix.

Summary Remediation Priorities

| Deadline | CVE(s) | Action | |---|---|---| | Aug 27 (past due) | CVE-2026-21962 | Patch Oracle HTTP Server / WebLogic now; rotate credentials | | Aug 28 | CVE-2026-60004 | Patch Gitea; audit hooks; rotate service account | | Aug 29 | CVE-2026-8452, CVE-2019-1068 | Patch Citrix NetScaler, SQL Server; verify network segmentation | | Sep 9 | CVE-2015-3246, CVE-2015-5287, CVE-2021-23758, CVE-2022-0995 | Patch or remove; prioritize ABRT removal if EoL confirmed |

All eight entries fall under BOD 26-04 obligations for federal agencies and contractors. Forensics triage documentation is required alongside remediation per current CISA guidance.

Sources: CISA KEV Catalog · CISA BOD 26-04 · Microsoft Security Update Guide — CVE-2019-1068 · Oracle Critical Patch Update Advisory · Citrix Security Bulletins · Gitea Security Advisories · Red Hat Security Advisories · Linux Kernel CVE Tracker

Free KEV Alerts

  • Real-time notification the moment a KEV drops
  • Vendor and product details
  • BOD 26-04 remediation deadline included

Pro Alerts Coming Soon

  • Real-time notification the moment a KEV drops
  • Filtered to your specific vendor watchlist
  • Urgency scoring (Critical / Urgent / Standard)
  • Direct patch links included

Stay ahead of CISA.

No spam. Unsubscribe anytime. We don't sell your data.


Upcoming Patch Due Dates

via Binding Operational Directive 26-04

BOD 26-04 is CISA's current vulnerability remediation directive for Federal Civilian Executive Branch (FCEB) agencies, updating the KEV-driven framework introduced under BOD 22-01 with a more risk-based approach to prioritization. While binding only on FCEB agencies, its framework increasingly influences contractor expectations through procurement requirements, FedRAMP programs, and agency security clauses.

Loading...

News Logo

Cyber Security News

You may have missed...


Hacking Editorial Brief — August 26, 2026

NVIDIA AI Agent Platform Vulnerable to Drive-By Model Poisoning

A critical vulnerability in NVIDIA's NemoClaw AI agent deployment wrapper (CVE-2026-65105) allows attackers to hijack and persistently poison local AI models through a single malicious website visit. The flaw stems from NemoClaw's default configuration, which binds the underlying Ollama API to 0.0.0.0, exposing it to DNS rebinding attacks. Researchers demonstrated that an attacker-controlled webpage can exploit this misconfiguration to inject malicious instructions, alter model behavior, and maintain persistent access to the AI agent without requiring user interaction beyond visiting the site. The vulnerability highlights emerging attack surfaces as AI agents gain filesystem access and operational autonomy, with security firms warning that autonomous AI systems deployed with overly permissive network configurations create novel exploitation vectors that bypass traditional security boundaries.

Iran-Linked Groups Target U.S. Water Infrastructure and Universities in Coordinated Campaigns

The Department of Justice charged 17 Iranian nationals allegedly affiliated with the Islamic Revolutionary Guard Corps in a multi-year cyber espionage campaign targeting hundreds of U.S. and international universities to exfiltrate research and intellectual property. Separately, Iranian-linked threat groups have been actively exploiting vulnerable programmable logic controllers in attacks against U.S. water treatment facilities, focusing on industrial control systems with known security weaknesses. A separate China-nexus operation dubbed QUICSILVER is targeting Myanmar government personnel and IT sectors using Virtual Hard Disk files disguised as diplomatic event invitations to deliver QUICAgent, a Go-based backdoor that tunnels command-and-control traffic through the QUIC protocol and leverages Cloudflare Workers infrastructure to obscure attacker infrastructure. Additionally, researchers disclosed 24 malicious npm packages abusing unpkg CDN mirrors to redirect developers to ClickFix-style fake CAPTCHA pages for credential theft.

Sources: The Hacker News · Cybersecurity News · Facilities Dive · Campus Reform · Seqrite · The Hacker News

📌 Pinned

*

https:betanews.comMar 5

Inside a cyberattack: How hackers steal data

The truth about cybersecurity is that it's almost impossible to keep hackers outside of an organization, particularly as the cybercrime industry ...

https://www.facilitiesdive.comAug 26

What we know about the hacking campaign against US water systems | Facilities Dive

Threat groups with suspected links to Iran have targeted vulnerable programmable logic controllers, the devices used to monitor and control ...

https://therecord.mediaAug 26

Employee benefits platform Paylogix says hackers stole financial and health data

The benefits management firm Paylogix told regulators that hackers stole sensitive information on tens of thousands of people from its systems.

https://thehackernews.comAug 26

A Malicious Webpage Could Poison Your Local AI Model Behind NVIDIA NemoClaw

"The client cannot detect or prevent this - the template is a model-level property invisible to API consumers," Oasis Security said. Cybersecurity.

https://www.forbes.comAug 25

CISA Gives Federal Agencies 72 Hours To Patch Actively Exploited Oracle Bug

CISA issued an urgent directive requiring Federal Civilian Executive Branch agencies to patch CVE-2026-21962, a critical Oracle vulnerability with a C...

https://thehackernews.comAug 26

U.S. Sanctions Iran-Linked Hackers Behind Critical Infrastructure Breaches

#1 Trusted Cybersecurity News Platform. Followed by 5.70+ million · The Hacker News Logo... Get the Latest News. Home; Newsletter ...

https://www.aljazeera.comAug 25

The Iran war is bringing cyberwarfare into critical infrastructure | Cybersecurity | Al Jazeera

These incidents mark an important shift in cybersecurity. For years, much of the public conversation around cyberthreats focused on data. People ...

https://www.nytimes.comAug 25

A Chinese A.I. Lab May Test the World's Cybersecurity With a Model - The New York Times

Lab May Test the World's Cybersecurity. In July, an unreleased OpenAI model went rogue and demonstrated remarkable hacking abilities. This week, a lab...

https://federalnewsnetwork.comAug 25

Why secure communications remain a human problem | Federal News Network

... Cybersecurity Read more. Cybersecurity best practices technology, Firewall, Cloud security protection.Endpoint security.Encryption. Secure, for no...


Updated daily