This month: 6 KEVs detected

CISA stopped reliably sending KEV alerts.
We didn't.

CyberComply monitors the CISA Known Exploited Vulnerabilities catalog 24/7 and alerts you the moment a new KEV drops — before the deadline clock starts ticking without you knowing.

CVE-2026-8037
Progress · LoadMaster
Progress LoadMaster Command Injection Vulnerability
Detected Aug 7 · 3-day patch deadline
CVE-2026-63077
JetBrains · TeamCity
JetBrains TeamCity Deserialization of Untrusted Data Vulnerability
Detected Aug 5 · 3-day patch deadline
CVE-2026-18556
N-able · N-central
N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability
Detected Aug 4 · 3-day patch deadline

KEV Intelligence Brief | August 10, 2026

Classification: TLP:CLEAR | Audience: Federal Contractors, DevOps, Security Operations Reporting Period: July 27 – August 10, 2026 | Prepared: Monday, August 10, 2026

Eight vulnerabilities added to CISA's Known Exploited Vulnerabilities catalog over the past two weeks demand immediate attention. Several patch deadlines have already passed; at least one expires today. The entries cluster into three operationally meaningful threat themes: unauthenticated access to infrastructure management platforms, exploitation of developer and AI toolchains, and persistence bypass in perimeter security appliances.

Deadline Watch: Infrastructure Management Platforms Under Active Attack

The highest-urgency cluster involves platforms that sit at the center of enterprise IT operations — load balancers, firewall management, and RMM tooling. Compromise here is rarely contained.

Progress LoadMaster (CVE-2026-8037) carries a patch deadline of today, August 10. The vulnerability is a command injection in multiple unauthenticated command endpoints — meaning no credentials are required for full appliance compromise. LoadMaster instances exposed to the internet should be treated as potentially compromised until patched and forensically triaged. Organizations running LoadMaster should immediately restrict management interface access to trusted IP ranges and apply the vendor patch before end of business today. BOD 26-04 obligations are not discretionary here; federal contractors without a documented exception are out of compliance as of this morning.

Cisco Secure Firewall Management Center (CVE-2026-20316) had its deadline pass on August 1 — making it nine days overdue for most federal and contractor environments. The hard-coded password vulnerability allows unauthenticated remote login using a low-privileged account that ships with the product. Even low-privilege access to FMC is operationally dangerous: policy visibility, network topology data, and lateral pivot opportunities are all within reach. Any organization still running an unpatched FMC must treat credential rotation on adjacent systems as mandatory, not optional, until a forensic triage confirms no unauthorized access.

N-able N-central contributes two entries that deserve joint handling. CVE-2026-18577 (deadline August 6) and CVE-2026-18556 (deadline August 7) are both authentication bypass vulnerabilities affecting alternate paths or channels — and critically, CVE-2026-18577 is the result of an incomplete patch for CVE-2026-18556. This patch bypass pattern is a red flag: if your team applied the first fix and considered the matter closed, you are almost certainly still vulnerable. N-central is a remote monitoring and management platform with deep endpoint access across managed environments. MSPs and federal contractors using N-able should treat both CVEs as a single remediation event, validate their current patch level against vendor guidance, and audit N-central administrative accounts for unauthorized additions or access since late July.

Developer and AI Toolchains as Initial Access Vectors

Threat actors increasingly pivot to CI/CD infrastructure and AI orchestration tools as high-value, low-detection entry points. Two recent KEV entries illustrate exactly that risk.

JetBrains TeamCity (CVE-2026-63077) has a deadline that passed on August 8. The deserialization vulnerability targets the agent polling protocol — a component that is often exposed broadly within build networks and not treated with the same scrutiny as external-facing services. Unauthenticated RCE in a CI/CD platform means attackers can inject malicious build artifacts, exfiltrate source code, steal signing keys, or pivot laterally through service accounts with broad internal permissions. If your TeamCity instance is internet-facing or reachable from a DMZ, patching alone is insufficient: conduct a full audit of recent build pipelines, examine agent configurations for unauthorized additions, and rotate all service account credentials associated with the platform.

IBM Langflow (CVE-2026-9198) may be the most immediately dangerous entry for AI-forward organizations. Langflow is a low-code AI workflow builder increasingly deployed in enterprise and research environments, often with significant cloud service access. The code injection vulnerability allows unauthenticated RCE on default deployments — meaning installations that have never been hardened are fully exposed out of the box. The August 7 deadline has passed. Any internet-exposed Langflow instance must be isolated immediately. Organizations that cannot patch should discontinue external access and treat the deployment as compromised pending triage.

Perimeter Appliance Persistence: Fortinet and Tomcat

Fortinet FortiOS (CVE-2025-68686) carries today's deadline and represents a qualitatively different threat than the others: it is a post-exploitation persistence mechanism bypass, not a primary intrusion vector. An attacker who has already compromised FortiOS at the filesystem level can use crafted HTTP requests to bypass the patch designed to eliminate the symbolic link persistence technique documented in prior Fortinet campaigns. This is threat actor tradecraft designed to maintain long-term access after defenders believe they have cleaned an incident. Organizations running FortiOS must not only apply the current patch but should also review filesystem integrity and validate that prior incident response efforts fully remediated any compromise.

Apache Tomcat (CVE-2026-34486), with a deadline of August 7, rounds out the cluster. The EncryptInterceptor bypass allows sensitive data to traverse cluster communications without encryption protections the administrator believes are in place. While this is not a direct RCE vulnerability, it enables credential and session data interception in multi-node deployments. Any Tomcat cluster using EncryptInterceptor should be patched immediately and network traffic should be reviewed for anomalous interception attempts.

Recommended Priorities for Today

  1. Patch or isolate LoadMaster and FortiOS — both deadlines expire today; BOD 26-04 compliance is at risk.
  2. Treat N-central as a double-patch event — validate CVE-2026-18577 remediation independently of CVE-2026-18556.
  3. Audit TeamCity pipelines and Langflow deployments — post-patch forensics are warranted, not optional.
  4. Initiate credential rotation on any system adjacent to FMC, N-central, or TeamCity regardless of patch status.

Sources: CISA KEV Catalog · CISA BOD 26-04 · Progress LoadMaster Security Advisory · JetBrains TeamCity Security Bulletin · N-able Security Advisories · Apache Tomcat Security Reports · Cisco Security Advisory Portal · Fortinet PSIRT Advisories

Free KEV Alerts

  • Real-time notification the moment a KEV drops
  • Vendor and product details
  • BOD 26-04 remediation deadline included

Pro Alerts Coming Soon

  • Real-time notification the moment a KEV drops
  • Filtered to your specific vendor watchlist
  • Urgency scoring (Critical / Urgent / Standard)
  • Direct patch links included

Stay ahead of CISA.

No spam. Unsubscribe anytime. We don't sell your data.


Upcoming Patch Due Dates

via Binding Operational Directive 26-04

BOD 26-04 is CISA's current vulnerability remediation directive for Federal Civilian Executive Branch (FCEB) agencies, updating the KEV-driven framework introduced under BOD 22-01 with a more risk-based approach to prioritization. While binding only on FCEB agencies, its framework increasingly influences contractor expectations through procurement requirements, FedRAMP programs, and agency security clauses.

Loading...

News Logo

Cyber Security News

You may have missed...


Hacking Editorial Brief — August 11, 2026

China-Linked Group Deploys New Ransomware via N-able Exploit

Microsoft has attributed a new ransomware campaign to Storm-1175, a China-linked threat actor, deploying StormEncryptor ransomware against organizations after likely exploiting CVE-2026-18577 in N-able N-central remote monitoring and management software. The campaign represents a notable shift as Chinese state-nexus actors have historically focused on espionage rather than ransomware deployment. Separately, a new ransomware variant called DeadLock has been observed systematically disabling Windows Defender, backup systems, and event logs before file encryption, demonstrating increasingly sophisticated anti-detection and anti-recovery capabilities.

Zero-Day Exploitation and Critical Infrastructure Targeting

Metabase confirmed active exploitation of a critical zero-day vulnerability allowing unauthenticated attackers to gain full administrator access to the business intelligence platform. The company has not disclosed the scope of exploitation or whether the flaw was used in targeted attacks. Meanwhile, officials from the Maine Water Utilities Association reported that water infrastructure systems across the state face constant probing attempts from threat actors using AI-driven scanning tools and phishing campaigns, highlighting persistent targeting of U.S. critical infrastructure.

Sources: The Hacker News · IT Security News · Cybersecurity News · Portland Press Herald

📌 Pinned

*

https:betanews.comMar 5

Inside a cyberattack: How hackers steal data

The truth about cybersecurity is that it's almost impossible to keep hackers outside of an organization, particularly as the cybercrime industry ...

https://techcrunch.comAug 11

Tech industry is buzzing after a Claude agent hacked into a gym | TechCrunch

... hacking case in the country, the actual hack took place months ago. The OpenClaw owner, Andrew Bird, published a now-deleted blog post about it on...

https://www.bankinfosecurity.comAug 11

AI Moves From Cheating in Theory to Hacking the Real World - BankInfoSecurity

Among the many lessons learned from the OpenAI sandbox escape/Hugging Face hack and the more recent Claude "accidental" escape is that artificial ...

https://www.publicpower.orgAug 11

Bipartisan Bill Introduced to Reauthorize the Rural and Municipal Cybersecurity Grant Program

Legislation recently introduced in the U.S. Senate would reauthorize the Rural and Municipal Utility Advanced Cybersecurity (RMUC) Grant and ...

https://thehackernews.comAug 11

China-Linked Hackers Deploy New StormEncryptor Ransomware, Likely via N-central Flaw

The vulnerabilities have since been flagged by the U.S. Cybersecurity and Infrastructure Security Agency (CISA) as actively exploited in the wild.

https://federalnewsnetwork.comAug 11

FBI investigating North Korean remote IT staffer working for US agency

Justin Doubleday covers cybersecurity, homeland security and the intelligence community for Federal News Network. ... Cybersecurity Read more.

https://www.hcamag.comAug 10

Employee computers hacked in Levi cyberattack - HRD America

Clothing company Levi Strauss & Co. has disclosed that it experienced a cybersecurity incident that led to the access and extraction of certain ...

https://www.theregister.comAug 10

Demoralized developer's desperate hack came back to haunt him on LinkedIn

A script that shouldn't have worked, on a project that never ended, for a company that hardly cared.

https://www.aljazeera.comAug 10

North Korea's hackers using AI for attacks, cybersecurity firm says - Al Jazeera

Hacking group Kimsuky using AI-generated documents in spear-phishing attacks, South Korean cybersecurity firm says.


Updated daily