CISA stopped reliably sending KEV alerts.
We didn't.
CyberComply monitors the CISA Known Exploited Vulnerabilities catalog 24/7 and alerts you the moment a new KEV drops — before the deadline clock starts ticking without you knowing.
KEV Intelligence Brief — August 7, 2026
Prepared by: Cybersecurity Intelligence | Distribution: Federal Contractors, DevOps, SecOps Leadership
This week's KEV additions paint a consistent picture: attackers are targeting the infrastructure layer beneath applications — load balancers, build systems, RMM platforms, AI tooling, and firewall management consoles. Several deadlines have already passed or expire this weekend. Teams should treat this brief as an active operational checklist, not background reading.
Network and Security Management Infrastructure: Multiple Paths to Full Compromise
The most operationally urgent cluster this week involves products that sit at the trust boundary of enterprise networks — where a single bypass can hand an adversary the keys to everything downstream.
N-able N-central is carrying two related CVEs added within 24 hours of each other. CVE-2026-18577 (added August 3, deadline August 6 — now overdue) is an authentication bypass enabling account takeover. CVE-2026-18556 (added August 4, deadline August 7 — today) is explicitly described as an incomplete patch for that first vulnerability. This is a textbook patch-bypass scenario. If your team applied the initial N-central fix and considered the matter closed, you should assume the remediation is insufficient. N-central's privileged position as a remote monitoring and management platform means compromise here translates directly to lateral movement across every managed endpoint in your environment. Isolate internet-facing N-central instances immediately, verify the latest vendor patch is applied, and audit administrative account activity for anomalous access patterns dating back at least 30 days.
Cisco Secure Firewall Management Center (FMC) (CVE-2026-20316, deadline August 1 — overdue by six days) exposes a hard-coded password that allows unauthenticated remote attackers to authenticate with a low-privileged account. On a firewall management plane, "low-privileged" is rarely the end of the story — it is reconnaissance real estate. If you have not patched, assume the credential is known to threat actors. Rotate all local FMC accounts, review policy change logs, and verify no unauthorized firewall rules were introduced. BOD 26-04 obligations for this CVE are past due; federal contractors operating unpatched FMC instances are out of compliance today.
Fortinet FortiOS (CVE-2025-68686, deadline August 10) requires a slightly different analytical frame. Exploitation requires prior filesystem-level access, making this a post-exploitation persistence mechanism rather than an initial access vector. Specifically, it bypasses the symbolic link cleanup patch Fortinet has pushed in response to earlier campaigns. If your FortiOS devices have been involved in any incident in the past 12 months, this vulnerability means previously believed-remediated persistence may still be active. Apply the patch, but also conduct forensic triage per CISA's requirements — particularly examining SSL-VPN virtual filesystem mounts and unexpected symbolic links.
Developer and Build Infrastructure: Unauthenticated RCE in the Pipeline
Attackers who can compromise the systems that build and deploy software gain access far beyond any single application. Two entries this week target exactly that surface.
JetBrains TeamCity (CVE-2026-63077, deadline August 8 — tomorrow) introduces deserialization of untrusted data exploitable through the agent polling protocol — meaning the attack surface is not just the web UI but any port TeamCity build agents use to check in. Unauthenticated RCE on a CI/CD server is a supply chain event waiting to happen. Treat an unpatched TeamCity server as a compromised build environment: review recent build artifacts, pipeline configurations, and deployment keys for signs of tampering. If TeamCity is internet-facing, take it offline until patched. This is not an acceptable tradeoff to preserve build uptime.
IBM Langflow (CVE-2026-9198, deadline August 7 — today) allows unauthenticated code injection on default deployments — a detail worth underlining. Many Langflow instances in AI development environments were stood up rapidly, often without hardened configurations, as teams moved fast on generative AI initiatives. The default attack surface is broad. Any organization running Langflow for AI workflow orchestration should audit for internet exposure immediately, apply vendor mitigations, and validate that no unauthorized flows or API keys were injected into the environment.
Deadline Watch: Application Infrastructure Under Active Exploitation
Two additional entries round out the week and require immediate attention from application and platform teams.
Progress LoadMaster (CVE-2026-8037, deadline August 10) enables command injection through unsanitized input across multiple command endpoints — with no authentication required. LoadMaster appliances are often deployed as ADCs for critical application delivery; compromise can enable traffic interception and session hijacking at scale. Notably, Progress had a difficult 2024–2025 with MOVEit and related tooling; their products have been attractive targets. Apply vendor mitigations now, restrict management interface access to trusted IP ranges, and treat this with the same urgency as prior Progress vulnerabilities that led to mass exploitation.
Apache Tomcat (CVE-2026-34486, deadline August 7 — today) allows bypass of the EncryptInterceptor, effectively stripping the encryption layer from cluster session replication traffic. In multi-node Tomcat deployments — common in Java enterprise and government application stacks — this exposure can allow a network-adjacent attacker to intercept or tamper with sensitive session data. Patch immediately and verify EncryptInterceptor configuration is functioning as intended post-update.
Operational Reminder: Six of these eight deadlines fall between July 27 and August 10. Three are already overdue. For federal agencies and contractors subject to BOD 26-04, compliance is not optional — document your remediation status, exceptions, and compensating controls now.
Sources: CISA KEV Catalog · CISA BOD 26-04 · Cisco Security Advisory – FMC · Fortinet PSIRT Advisory – FortiOS · Progress LoadMaster Security Advisories · JetBrains TeamCity Security Bulletin · N-able Security Advisories · Apache Tomcat Security Reports
Free KEV Alerts
- Real-time notification the moment a KEV drops
- Vendor and product details
- BOD 26-04 remediation deadline included
Pro Alerts Coming Soon
- Real-time notification the moment a KEV drops
- Filtered to your specific vendor watchlist
- Urgency scoring (Critical / Urgent / Standard)
- Direct patch links included
Stay ahead of CISA.
Search the KEV Catalog by Vendor or Product
Search for CVEs by vendor or product to identify known exploited vulnerabilities in your environment
Upcoming Patch Due Dates
via Binding Operational Directive 26-04
BOD 26-04 is CISA's current vulnerability remediation directive for Federal Civilian Executive Branch (FCEB) agencies, updating the KEV-driven framework introduced under BOD 22-01 with a more risk-based approach to prioritization. While binding only on FCEB agencies, its framework increasingly influences contractor expectations through procurement requirements, FedRAMP programs, and agency security clauses.
Loading...
Cyber Security News
You may have missed...
Hacking Editorial Brief — August 6, 2026
Supply Chain Worm Compromises Hundreds of npm Packages
A threat actor successfully compromised hundreds of npm packages, including the widely-used 'keyv' library with over 150 million weekly downloads, deploying a self-propagating backdoor worm across the JavaScript ecosystem. According to Datadog Security Labs analysis, the attack represents a significant supply chain compromise affecting numerous downstream dependencies. The worm's self-spreading mechanism allows it to automatically infect additional packages, amplifying the campaign's reach beyond the initial compromise vector. The incident underscores persistent vulnerabilities in package repository security and dependency chain integrity, with the scale of affected installations potentially reaching millions of applications relying on compromised packages.
Iranian Threat Actors Target U.S. Water Infrastructure
Multiple U.S. municipal water systems came under cyberattack over the past week in a coordinated campaign officials attribute to Iranian threat actors. The FBI and Environmental Protection Agency issued joint warnings to critical infrastructure operators following confirmed intrusions affecting facilities in New Jersey and other states. The attacks targeted operational technology systems used to manage water treatment and distribution, raising concerns about potential disruption to public utilities. The campaign follows established patterns of Iranian-linked threat activity against U.S. critical infrastructure, though authorities have not disclosed specific technical details of the intrusion methods or whether any systems experienced operational impacts. Separately, Canadian authorities disclosed that a Kitchener resident pleaded guilty to charges related to a 2021 breach of a U.S. cloud services provider that compromised data on over 165 million customers, facing up to 30 years in federal prison for participation in the international hacking conspiracy.
Sources: Datadog Security Labs · 6ABC · Philadelphia Inquirer · CityNews Kitchener
*
Inside a cyberattack: How hackers steal data
The truth about cybersecurity is that it's almost impossible to keep hackers outside of an organization, particularly as the cybercrime industry ...
CISA and Partners Release Joint Advisory on Countering Chinese State-Sponsored Actors
CISA, NSA, FBI, and international partners released a joint cybersecurity advisory detailing ongoing malicious activity by Chinese state-sponsored APT...
House Report Finds US Telecom Data Centers Exposed in Chinese Hack
A House Select Committee on China report reveals that US telecommunications companies connected their systems to data centers in ways that exposed the...
FBI says hackers altered operating instructions for water systems in some states - YouTube
At least 12 states are reporting cyberattacks on water systems that may be linked to Iran-backed hackers. CBS News homeland security correspondent ...
CISA Flags TeamCity CVE-2026-63077 RCE Flaw Under Active Exploitation in the Wild
CISA warns that attackers are actively exploiting TeamCity CVE-2026-63077, an unauthenticated RCE flaw that can expose credentials and compromise buil...
New Interrupt Injection Attack Can Bypass Spectre v2 Defenses on Intel and AMD CPUs
AMD told them it plans a kernel patch; MIT says one has since shipped and arrives in a normal operating system update. Cybersecurity. A fix is in the ...
A Security Pro Hacked North Korean Hackers. He Found They'd Breached Hundreds of ...
For nearly two years, researcher Vangelis Stykas has maintained access to North Korean hackers' servers. His work shows they pulled off intrusions ...
OpenAI Didn't Notice Its AI Agents Using a Message Board to Plan Their Hacking Spree
At the Black Hat security conference, the AI giant revealed new details about how its agents went rogue, hacked several other companies—and did it ...
At least 12 states report cyberattacks on water systems possibly linked to Iran-backed ...
Cyberattacks on U.S. water systems that officials suspect may be linked to Iran-backed hackers have been reported in at least a dozen states, ...
Updated daily
