CISA stopped reliably sending KEV alerts.
We didn't.
CyberComply monitors the CISA Known Exploited Vulnerabilities catalog 24/7 and alerts you the moment a new KEV drops — before the deadline clock starts ticking without you knowing.
KEV Intelligence Brief — Week of August 24, 2026
Issued: Monday, August 24, 2026 | Audience: Federal Contractors, DevOps, Security Operations
CISA added eight vulnerabilities to the KEV catalog across the past week, spanning enterprise collaboration platforms, VPN infrastructure, AI/ML development toolchains, and Oracle middleware. Several deadlines have already passed or expire today, demanding immediate triage. The entries cluster into three operationally meaningful themes: deadline-critical infrastructure flaws, a coordinated assault on AI and developer tooling, and unauthenticated remote access vulnerabilities requiring network-level containment.
Deadline Watch: Oracle, Microsoft, and Zimbra
The most time-sensitive entries this week center on widely deployed enterprise infrastructure, and several remediation windows have already closed or expire today.
CVE-2026-55040 (Microsoft SharePoint) and CVE-2026-33824 (Microsoft IKE Service Extensions) both carried a patch deadline of August 21—three days ago. If your SharePoint or IKE deployments have not been patched, treat them as compromised until forensic triage confirms otherwise. The SharePoint weak authentication vulnerability allows unauthenticated network-based bypass of security controls, a straightforward entry point for lateral movement in any environment where SharePoint is federated with Active Directory or Entra ID. The IKE double-free vulnerability is particularly alarming given IKE's role in VPN tunnel establishment—successful exploitation could yield remote code execution against a service running at the kernel boundary on Windows hosts, potentially before any user interaction. Federal contractors operating under BOD 26-04 must document remediation or compensating controls for both.
CVE-2026-73570 (Zimbra Collaboration Suite) had its deadline on August 24—today. This OS command injection flaw is unauthenticated and exploitable via specially crafted SMTP requests, meaning any internet-facing Zimbra MTA is a candidate for blind exploitation without credentials. Zimbra has historically been a high-priority target for nation-state actors; the combination of unauthenticated access and OS-level command execution as the Zimbra user should be treated as a complete server compromise scenario. If patching cannot be completed today, isolate the SMTP listener behind an application-aware mail gateway and review all Zimbra-generated process logs for anomalous child processes spawned from the MTA service.
CVE-2026-21962 (Oracle HTTP Server and WebLogic Server Proxy Plug-in) was added to the KEV today with an extraordinarily compressed three-day deadline of August 27. This improper access control vulnerability allows unauthorized read, create, modify, and delete access to all data accessible through the proxy plug-in—effectively a complete confidentiality and integrity failure for any WebLogic deployment behind Oracle HTTP Server. Organizations running Oracle Fusion Middleware stacks should treat this as an emergency change window. Verify whether the proxy plug-in is exposed externally; if so, prioritize patching above all other work this week. BOD 22-01 cloud guidance applies where OHS or WebLogic is hosted in IaaS environments.
Developer Toolchain Under Siege: AI/ML Infrastructure Actively Targeted
A second and increasingly significant pattern this week is the targeting of machine learning and distributed compute infrastructure—systems that DevOps and data engineering teams frequently treat as lower-security internal tooling.
CVE-2026-64849 (MLflow) is a server-side request forgery vulnerability with a deadline of September 2. SSRF in an MLflow deployment is not a low-severity finding: MLflow servers are frequently deployed in cloud environments with access to instance metadata services (AWS IMDS, Azure IMDS, GCP metadata). Successful exploitation means an attacker can retrieve cloud credentials, IAM roles, and internal service endpoints with nothing more than network access to the MLflow UI. If MLflow is reachable from the internet or from shared developer workstations, treat it as an immediate credential exposure risk. Rotate any cloud credentials associated with the MLflow server role and audit metadata service access controls regardless of whether patching is complete.
CVE-2025-62593 (Ray-Project Ray) had a patch deadline of August 21, now passed. Ray's code injection vulnerability is exploitable through Firefox and Safari, meaning developers who simply browse to a Ray dashboard on a shared or developer network can trigger remote code execution. Ray clusters are often co-located with model weights, training data, and production API keys. Any Ray installation that was internet-accessible or reachable from shared developer networks prior to patching should be subject to full forensic triage. Audit Ray job histories and connected object stores for signs of data exfiltration.
Unauthenticated Network Access: TrueConf's Dual Exposure
CVE-2026-72529 and CVE-2026-72530 both affect TrueConf Server and were added to the KEV on August 20. The two vulnerabilities operate as a natural chain: CVE-2026-72529 (missing authentication for a critical function) allows a remote attacker with network access to port 4307/TCP to execute arbitrary scripts without credentials. CVE-2026-72530 (code injection) then enables escape from the isolated execution environment to arbitrary code execution on the host. Together, they represent a full remote-to-host compromise path requiring only TCP reachability to port 4307.
The deadlines differ—August 23 for CVE-2026-72529 (now passed) and September 3 for CVE-2026-72530—but operationally, both must be patched together to close the attack chain. If TrueConf Server cannot be patched immediately, block port 4307/TCP at the network perimeter and on host-based firewalls. Treat any TrueConf Server that was exposed on port 4307 to untrusted networks as a host-level compromise until forensic triage under BOD 26-04's Forensics Triage Requirements is complete.
Summary Deadline Table
| CVE | Product | Deadline | Status | |---|---|---|---| | CVE-2026-33824 | Microsoft IKE | 2026-08-21 | OVERDUE | | CVE-2026-55040 | Microsoft SharePoint | 2026-08-21 | OVERDUE | | CVE-2025-62593 | Ray | 2026-08-21 | OVERDUE | | CVE-2026-72529 | TrueConf Server | 2026-08-23 | OVERDUE | | CVE-2026-73570 | Zimbra ZCS | 2026-08-24 | DUE TODAY | | CVE-2026-21962 | Oracle HTTP/WebLogic | 2026-08-27 | 3 days | | CVE-2026-64849 | MLflow | 2026-09-02 | 9 days | | CVE-2026-72530 | TrueConf Server | 2026-09-03 | 10 days |
Sources: CISA KEV Catalog · CISA BOD 26-04 · Oracle Critical Patch Update Advisory · Zimbra Security Advisories · Microsoft Security Update Guide · MLflow Security Disclosures · Ray Security Advisories · TrueConf Security Bulletins
Free KEV Alerts
- Real-time notification the moment a KEV drops
- Vendor and product details
- BOD 26-04 remediation deadline included
Pro Alerts Coming Soon
- Real-time notification the moment a KEV drops
- Filtered to your specific vendor watchlist
- Urgency scoring (Critical / Urgent / Standard)
- Direct patch links included
Stay ahead of CISA.
Search the KEV Catalog by Vendor or Product
Search for CVEs by vendor or product to identify known exploited vulnerabilities in your environment
Upcoming Patch Due Dates
via Binding Operational Directive 26-04
BOD 26-04 is CISA's current vulnerability remediation directive for Federal Civilian Executive Branch (FCEB) agencies, updating the KEV-driven framework introduced under BOD 22-01 with a more risk-based approach to prioritization. While binding only on FCEB agencies, its framework increasingly influences contractor expectations through procurement requirements, FedRAMP programs, and agency security clauses.
Loading...
Cyber Security News
You may have missed...
Hacking Editorial Brief — August 25, 2026
Chinese State-Linked Groups Weaponize DeepSeek AI for Overseas Attack Operations
Chinese government-affiliated hacking groups are actively exploiting the domestically developed DeepSeek artificial intelligence model to scale cyberattacks against overseas targets, according to South Korean intelligence reporting. The campaign represents a significant evolution in how state-sponsored actors leverage open-source AI capabilities for offensive operations, with threat actors using DeepSeek to automate reconnaissance, generate malicious code, and accelerate attack workflows against foreign infrastructure. The reporting suggests lax security controls around the Chinese AI platform have enabled its weaponization, raising broader concerns about how nation-state adversaries are integrating large language models into their operational tradecraft. This marks the second confirmed instance in recent weeks of AI systems being used in offensive cyber operations, following last week's federal advisory on AI-assisted attacks targeting U.S. industrial control systems.
Active Exploitation Confirmed for Splunk and WordPress Authentication Flaws
A critical Splunk Enterprise vulnerability (CVE-2026-20253) is under active exploitation and can be chained into unauthenticated remote code execution, prompting urgent patching guidance for organizations running affected versions. Separately, attackers are targeting two critical authentication bypass vulnerabilities in the miniOrange SAML 2.0 Single Sign On plugin for WordPress in active campaigns against websites using the authentication platform. An unpatched vulnerability in Calix GS7 residential routers deployed by multiple U.S. broadband providers also surfaced, allowing remote attackers to bypass network address translation and expose internal devices without authentication. The trio of actively exploited or weaponized flaws underscores continued attacker focus on authentication bypass and remote code execution chains across enterprise and consumer infrastructure.
Sources: Chosun · Bleeping Computer · Bleeping Computer · Data Breach Today
*
Inside a cyberattack: How hackers steal data
The truth about cybersecurity is that it's almost impossible to keep hackers outside of an organization, particularly as the cybercrime industry ...
The Iran war is bringing cyberwarfare into critical infrastructure | Cybersecurity | Al Jazeera
These incidents mark an important shift in cybersecurity. For years, much of the public conversation around cyberthreats focused on data. People ...
A Chinese A.I. Lab May Test the World's Cybersecurity With a Model - The New York Times
Lab May Test the World's Cybersecurity. In July, an unreleased OpenAI model went rogue and demonstrated remarkable hacking abilities. This week, a lab...
Why secure communications remain a human problem | Federal News Network
... Cybersecurity Read more. Cybersecurity best practices technology, Firewall, Cloud security protection.Endpoint security.Encryption. Secure, for no...
Iran-linked hackers blamed for taking down U.K. power plant for first time, reports say
The attack happened the same month Iranian-linked hackers are believed to have targeted the water systems of a dozen U.S. states.
After Hugging Face Was Attacked By A.I. Agents, It Embarked on a Crusade
Hugging Face, a start-up that was breached by rogue bots from OpenAI, is using the hack to push for openness in A.I. development.
Hackers target WordPress sites in miniOrange auth bypass attacks - Bleeping Computer
Hackers are attempting to exploit two critical authentication bypass vulnerabilities in the miniOrange SAML 2.0 Single Sign On plugin for ...
U.S. Treasury Department Hacked by Chinese State-Backed Cybercriminals
Cybercriminals backed by the Chinese state government hacked the U.S. Treasury Department system, accessing federal workstations and unclassified docu...
Weekly Recap: VMware Exploits, Windows 0-Day, MCP Attacks, Browser Hijacks and More
Lazarus Group exploits a new Windows 0-day vulnerability to deliver a never-before-seen backdoor targeting defense and aerospace companies.
Updated daily
