This month: 29 KEVs detected

CISA stopped reliably sending KEV alerts.
We didn't.

CyberComply monitors the CISA Known Exploited Vulnerabilities catalog 24/7 and alerts you the moment a new KEV drops — before the deadline clock starts ticking without you knowing.

CVE-2023-49105
ownCloud · ownCloud
ownCloud Improper Authentication Vulnerability
Detected Aug 27 · 3-day patch deadline
CVE-2026-53362
Linux · Kernel
Linux Kernel Unspecified Vulnerability
Detected Aug 27 · 3-day patch deadline
CVE-2019-1068
Microsoft · SQL Server
Microsoft SQL Server Remote Code Execution Vulnerability
Detected Aug 26 · 3-day patch deadline

KEV Intelligence Brief — August 28, 2026

Issued by: Security Operations Intelligence | Classification: TLP:WHITE Reporting Period: August 26–27, 2026 | Entries Covered: 8 CVEs

Eight vulnerabilities added to CISA's KEV catalog over the past 48 hours reflect three converging threat patterns: unauthenticated file system exposure in enterprise collaboration infrastructure, privilege escalation via Linux kernel weaknesses embedded across heterogeneous environments, and a cluster of aging-but-newly-exploited vulnerabilities in development toolchains and database services that organizations have allowed to persist far too long. Federal agencies and contractors operating under BOD 26-04 must treat the deadlines below as operational ceilings, not targets.

Emergency Window: Unauthenticated File Access and Active Infrastructure Targets

Two entries carry patch deadlines this weekend, making them the immediate operational priority for any team reading this brief.

CVE-2019-1068 (Microsoft SQL Server) carries a deadline of August 29 — tomorrow. This remote code execution vulnerability allows an attacker to execute arbitrary code in the context of the SQL Server Database Engine service account, a foothold that can rapidly translate into lateral movement, credential harvesting, and data exfiltration across any environment where SQL Server runs with elevated privileges. SQL Server instances should never be directly internet-exposed, but the reality of legacy architecture and misconfigured perimeter controls means many are. If patching cannot be completed before tomorrow's deadline, network-level isolation of SQL Server instances and audit of service account privileges are non-negotiable interim steps. Verify that the Database Engine service account is not running with domain admin or local system privileges.

CVE-2023-49105 (ownCloud) carries a deadline of August 30 and presents an arguably more acute risk: an improper authentication vulnerability that permits unauthenticated file access, modification, and deletion — provided the attacker knows the victim's username and the account lacks a configured signing key. In environments where ownCloud is used for document sharing, that username condition is trivially satisfied through directory harvesting, phishing artifacts, or prior breach data. Organizations should immediately audit signing-key configuration across all user accounts, force-enable signing keys as a mandatory baseline, and treat any ownCloud instance exposed to the public internet as compromised pending forensic review. CISA's Forensics Triage Requirements apply here explicitly.

Linux Kernel Privilege Escalation: A Multi-Distribution Crisis

CISA added two Linux Kernel entries that together represent a systemic risk across virtually every Linux-dependent workload in federal and commercial environments.

CVE-2026-53362 — a newly cataloged vulnerability in the Linux Kernel's IPv6 networking subsystem — enables privilege escalation and explicitly impacts distributions including SUSE and Red Hat, with the advisory noting additional products may be affected. The deadline is August 30, giving teams this weekend to act. Because IPv6 is enabled by default on most modern Linux deployments and is often left unmonitored relative to IPv4 traffic, this attack surface is broader than many teams currently model. Organizations that cannot patch immediately should assess whether disabling IPv6 is operationally feasible as a temporary mitigation and should prioritize patching on any internet-facing or multi-tenant systems first.

CVE-2022-0995 — a Linux Kernel out-of-bounds memory write vulnerability cataloged earlier — carries a deadline of September 9. Local users can leverage this to gain privileged access or trigger denial of service. While local access is required, this class of vulnerability is routinely chained with initial access techniques in post-exploitation sequences. Treat this as a privilege escalation enabler in your threat models, not a standalone low-severity finding. Distribution-specific patches from Red Hat, SUSE, Ubuntu, and Debian are available; confirm your kernel version and apply the appropriate update.

Developer Toolchain and Legacy Software: Long-Deferred Debt Comes Due

Three entries in this cycle target the software supply chain and development infrastructure, and two of them involve software that may already be end-of-life in your environment.

CVE-2026-66384 (JFrog Artifactory) is a path traversal vulnerability allowing authenticated users to write data outside the intended Docker cache path under specific remote-repository conditions. With a deadline of September 10, this is the furthest out in this cycle, but it demands immediate attention in any environment where Artifactory serves as a central artifact registry. A compromised artifact path in a CI/CD pipeline can propagate malicious content downstream to build systems and production deployments. Upgrade Artifactory and audit remote repository configurations for anomalous write activity.

CVE-2021-23758 (Ajax.NET Professional) exposes a critical deserialization of untrusted data vulnerability enabling remote code execution via arbitrary .NET class instantiation. AjaxPro is explicitly flagged as potentially end-of-life. The path forward here is not patching — it is removal or replacement. Any application surface still running AjaxPro should be inventoried immediately, and development teams should plan accelerated migration to supported .NET frameworks. Deadline: September 9.

The two Red Hat entries — CVE-2015-3246 (Libuser, race condition enabling /etc/passwd corruption and privilege escalation) and CVE-2015-5287 (ABRT, symlink attack enabling privilege escalation) — are over a decade old. Their addition to KEV in 2026 signals confirmed, active exploitation. ABRT is flagged as potentially end-of-life; discontinuation is the recommended path. For Libuser, apply available patches from Red Hat and assess whether the affected system configurations align with current hardening baselines. Deadline for both: September 9.

Operational Posture Summary

| CVE | Product | Deadline | Key Risk | |---|---|---|---| | CVE-2019-1068 | MS SQL Server | Aug 29 | RCE via DB Engine service account | | CVE-2023-49105 | ownCloud | Aug 30 | Unauthenticated file access/deletion | | CVE-2026-53362 | Linux Kernel | Aug 30 | Privilege escalation via IPv6 | | CVE-2015-3246 | Red Hat Libuser | Sep 9 | passwd corruption, local privesc | | CVE-2015-5287 | Red Hat ABRT | Sep 9 | Symlink-based local privesc (EoL) | | CVE-2021-23758 | Ajax.NET Pro | Sep 9 | RCE via .NET deserialization (EoL) | | CVE-2022-0995 | Linux Kernel | Sep 9 | Out-of-bounds write, local privesc | | CVE-2026-66384 | JFrog Artifactory | Sep 10 | Path traversal in artifact registry |

Federal contractors: BOD 26-04 compliance is mandatory. Document compensating controls for any asset where patch deadlines cannot be met and escalate through your authorizing official chain without delay.

Sources: CISA KEV Catalog · CISA BOD 26-04 · Microsoft SQL Server Security Advisory CVE-2019-1068 · ownCloud Security Advisory CVE-2023-49105 · JFrog Artifactory Security Bulletins · Red Hat Security Advisory: Libuser · Red Hat Security Advisory: ABRT · Linux Kernel Security · CISA Forensics Triage Guidance

Free KEV Alerts

  • Real-time notification the moment a KEV drops
  • Vendor and product details
  • BOD 26-04 remediation deadline included

Pro Alerts Coming Soon

  • Real-time notification the moment a KEV drops
  • Filtered to your specific vendor watchlist
  • Urgency scoring (Critical / Urgent / Standard)
  • Direct patch links included

Stay ahead of CISA.

No spam. Unsubscribe anytime. We don't sell your data.


Upcoming Patch Due Dates

via Binding Operational Directive 26-04

BOD 26-04 is CISA's current vulnerability remediation directive for Federal Civilian Executive Branch (FCEB) agencies, updating the KEV-driven framework introduced under BOD 22-01 with a more risk-based approach to prioritization. While binding only on FCEB agencies, its framework increasingly influences contractor expectations through procurement requirements, FedRAMP programs, and agency security clauses.

Loading...

News Logo

Cyber Security News

You may have missed...


Hacking Editorial Brief — August 28, 2026

CRPx0 Cybercrime Crew Pivots to ClickFix Ransomware, Claims Quintupled Victim Count

The CRPx0 hacking operation has rapidly evolved from a scam service into a ClickFix-delivered ransomware and cryptocurrency theft business over recent months, claiming victim counts have increased more than fivefold. The crew has adopted social engineering tactics that trick victims into executing malicious payloads through fake security prompts, shifting from low-sophistication scams to credential harvesting and file encryption campaigns. The evolution demonstrates how cybercrime groups are lowering technical barriers through automated delivery mechanisms that exploit user trust rather than software vulnerabilities.

ATF Declares Major Incident After Ransomware Gang Claims Breach

The U.S. Bureau of Alcohol, Tobacco, Firearms and Explosives declared a cyberattack on one of its systems a "major incident," triggering formal congressional notification procedures. A ransomware gang has claimed responsibility for the breach, though ATF has not confirmed the extent of data exfiltration or operational impact. The incident adds to a growing list of federal agency compromises following this week's disclosure of Chinese state-sponsored campaigns targeting NASA, the Senate, and multiple cabinet departments.

TeamPCP Hackers Arrested in Australia for Supply Chain Attacks

Australian Federal Police, working with the FBI and Western Australia Police Force, arrested two men aged 21 and 23 over their alleged roles in TeamPCP, the cybercrime group behind the March 2026 compromise of open-source security tools Trivy, KICS, and LiteLLM. The arrests follow a months-long investigation into supply chain attacks that inserted malicious code into widely-deployed security scanning tools used by development teams globally. Meanwhile, Dark Caracal deployed previously undocumented Go-based malware called GoCaracal during an intrusion at a Venezuelan communications organization, expanding the Lebanon-linked threat group's targeting beyond its traditional Middle East focus.

Critical Infrastructure Incidents and AI-Enabled Threats

Boston Scientific disclosed a cybersecurity incident disrupting customer order processing and shipping operations, with the pro-Russian group Server Killers claiming responsibility. Separately, Iranian APT group Nimbus Manticore, affiliated with the Islamic Revolutionary Guard Corps, was tied to additional infrastructure and previously undocumented malware variants. OpenAI and Anthropic jointly warned that AI-enabled attack tools will increasingly target hospitals, water treatment facilities, and other critical infrastructure as models reduce the technical expertise required for sophisticated hacking operations.

Sources: The Register · TechCrunch · The Hacker News · The Hacker News · Security Week · The Hacker News

📌 Pinned

*

https:betanews.comMar 5

Inside a cyberattack: How hackers steal data

The truth about cybersecurity is that it's almost impossible to keep hackers outside of an organization, particularly as the cybercrime industry ...

https://thehackernews.comAug 27

QTFY Campaign Targets NASA, Federal Reserve, and Other U.S. Agencies

The Department of Justice revealed that QTFY computer intrusion activity targeted NASA, the Federal Reserve, Department of Energy, Department of Justi...

https://techcrunch.comAug 27

Medical device maker Boston Scientific says a cyberattack is causing a 'global disruption' to ...

Zack Whittaker is the security editor at TechCrunch. He also authors the weekly cybersecurity newsletter, ...

https://www.atf.govAug 27

ATF responds to cybersecurity incident

WASHINGTON - The Bureau of Alcohol, Tobacco, Firearms and Explosives is responding to a cybersecurity incident affecting a standalone system.

https://www.politico.comAug 27

DOJ blames China for string of hacks targeting federal agencies and hospitals - POLITICO

Chinese hackers carried out a yearslong coordinated campaign to worm their way into federal networks — including those at the Departments of ...

https://www.theguardian.comAug 27

UK's small power plants face continued cyber risk after Iran-linked hack - The Guardian

Government measures to improve resilience are not due until 2030 and July's hack has not altered this timeline.

https://www.aljazeera.comAug 26

US says Chinese-linked hackers attacked NASA, Senate, and gov't agencies

The U.S. disrupted a China-affiliated hacking operation that targeted the Department of Justice, NASA, the Federal Reserve, and the Senate using QScan...

https://www.cp24.comAug 26

US says Chinese hackers hit hospitals, NASA, Senate and more

U.S. officials exposed a Chinese cyber-espionage campaign that compromised federal agencies including NASA, the Federal Reserve, DOJ, DOE, and the Sen...

https://www.hngn.comAug 26

Chinese Hackers Ran Eight-Year Operation Inside DOJ, NASA, Federal Reserve and Senate

The Justice Department announced disruption of a Chinese state-sponsored hacking operation (QTFY/Nanjing Xinjiuwei) that breached multiple federal age...


Updated daily