CISA stopped reliably sending KEV alerts.
We didn't.
CyberComply monitors the CISA Known Exploited Vulnerabilities catalog 24/7 and alerts you the moment a new KEV drops — before the deadline clock starts ticking without you knowing.
KEV Intelligence Brief | August 19, 2026
Distribution: Federal Contractors · DevOps/MLOps Teams · Security Operations Leaders Classification: Unclassified // For Official Use
Eight vulnerabilities added to CISA's Known Exploited Vulnerabilities catalog across the past nine days span your AI/ML infrastructure, core network security appliances, virtualization fabric, and enterprise collaboration platforms. Three deadline clusters demand immediate triage. All entries carry BOD 26-04 obligations.
DEFCON NOW: Overdue and Expiring-Today Deadlines Demand Immediate Action
Four entries added August 11 have already passed or are critically overdue. Teams not yet remediated are out of compliance with BOD 26-04 and should treat these as active incidents, not patch tickets.
CVE-2026-20349 — Cisco ASA/FTD Heap Inspection (Deadline: August 14 — OVERDUE): An unauthenticated remote attacker can trigger unexpected device reloads on Cisco Secure Firewall ASA and FTD appliances, producing sustained denial-of-service conditions. For organizations whose perimeter security runs on ASA or FTD, this is not a theoretical availability concern — it is a firewall-down scenario exploitable without credentials. If patching has not occurred, isolate affected appliances from untrusted network segments immediately, engage Cisco TAC for emergency guidance, and verify whether anomalous reload events in the past 30 days constitute indicators of prior exploitation requiring forensic triage under BOD 26-04's forensics requirements.
CVE-2026-68820 — Windows AFD for WinSock Use-After-Free (Deadline: August 25): This local privilege escalation in the Windows Ancillary Function Driver for WinSock is the classic post-exploitation enabler. An authorized but low-privileged attacker — think compromised service account or phishing foothold — uses this to escalate to SYSTEM. Its August 25 deadline gives teams less than a week. Prioritize endpoints and servers where interactive or remote user sessions exist, and layer in endpoint detection rules looking for AFD driver exploitation patterns. Patch isolation is straightforward here; no architectural tradeoffs required.
August 21 Cluster: Four Critical Deadlines Across Microsoft, Apple, and Broadcom
Three vendors, four CVEs, one deadline — Friday, August 21. This cluster represents arguably the highest-density remediation sprint in recent KEV history and touches network infrastructure, virtualization, collaboration, and endpoint simultaneously.
CVE-2026-33824 — Microsoft IKE Service Extensions Double Free (RCE): A double-free memory corruption bug in the IKE Service Extensions stack enables remote code execution. IKE is foundational to IPsec VPN functionality on Windows systems. Internet-facing VPN concentrators and Windows servers with IKE enabled should be treated as unauthenticated RCE candidates until patched. Prioritize internet-exposed instances; consider temporarily disabling non-essential IKE endpoints if patching cannot be completed by Friday.
CVE-2026-55040 — Microsoft SharePoint Weak Authentication (Auth Bypass): Unauthenticated network attackers can bypass SharePoint's security controls entirely. For federal contractors operating SharePoint on-premises — still a substantial population under M365 hybrid deployments — this represents a direct data exfiltration risk. Cloud-hosted SharePoint tenants should confirm with Microsoft whether mitigations are applied at the platform level. On-premises deployments need patches applied immediately; if delayed, restrict SharePoint access to known IP ranges and enforce MFA at the network layer.
CVE-2026-59310 — Broadcom VMware vCenter Path Traversal (RCE): Network-accessible vCenter servers remain one of the most targeted assets in enterprise environments, and this path traversal allowing arbitrary code execution continues that pattern. Threat actors with even basic network access to the vCenter management plane can achieve full hypervisor-layer compromise — impacting every hosted VM simultaneously. Segment vCenter management interfaces from production networks if not already done, audit recent vCenter access logs for anomalous API calls, and apply Broadcom's patch before Friday. This is not optional maintenance.
CVE-2026-65400 — Apple macOS Improper Authentication (Screen Sharing Bypass): A network-adjacent attacker can authenticate to macOS Screen Sharing without valid credentials. In enterprise Mac fleets — common in engineering, design, and federal agency environments — this opens full graphical remote access to unpatched endpoints. Disable Screen Sharing on endpoints where it is not operationally required. For those that need it, enforce network-level firewall rules restricting VNC/Screen Sharing ports (5900/TCP) to authorized management subnets only, pending patch deployment.
AI/ML Infrastructure Under Active Threat: Developer Toolchains in the Crosshairs
The inclusion of MLflow and Ray in this KEV batch is a significant signal. These are not obscure edge tools — they are production-grade MLOps and distributed compute frameworks embedded across federal AI initiatives and commercial AI pipelines.
CVE-2026-64849 — MLflow SSRF (Deadline: September 2): This server-side request forgery in MLflow allows attackers to reach internal services and cloud metadata endpoints, receiving both response status and body content. In cloud-hosted ML environments, successful SSRF against the instance metadata service (IMDS) yields IAM credentials and can enable full account takeover. Immediately restrict MLflow server exposure to internal networks only, enforce IMDSv2 on AWS instances (blocking most SSRF-based metadata harvesting), and audit MLflow server logs for unexpected outbound requests to RFC-1918 or 169.254.169.254 addresses.
CVE-2025-62593 — Ray Code Injection / RCE (Deadline: August 21 — IMMINENT): Ray's code injection vulnerability is particularly alarming because exploitation paths run through Firefox and Safari — meaning developers browsing while running local Ray clusters are plausible targets. This blurs the line between developer workstation security and infrastructure security. Patch Ray immediately across all environments; do not treat development or staging deployments as lower priority. Developers running Ray locally should update browsers as a secondary control and avoid browsing untrusted sites while Ray dashboard ports are exposed.
Taken together, these two entries suggest adversaries are actively mapping and exploiting the AI development pipeline as a lateral movement pathway into broader cloud environments. MLOps security is no longer a future concern.
Operational Reminder: All eight entries carry BOD 26-04 obligations, including forensic triage requirements for confirmed exploitation. Agencies and federal contractors must document remediation status and report to CISA per applicable timelines.
Sources: CISA KEV Catalog · CISA BOD 26-04 · Cisco Security Advisory: ASA/FTD · Microsoft Security Update Guide · Broadcom VMware Security Advisories · Apple Security Releases · MLflow Security Advisories · Ray Project Security
Free KEV Alerts
- Real-time notification the moment a KEV drops
- Vendor and product details
- BOD 26-04 remediation deadline included
Pro Alerts Coming Soon
- Real-time notification the moment a KEV drops
- Filtered to your specific vendor watchlist
- Urgency scoring (Critical / Urgent / Standard)
- Direct patch links included
Stay ahead of CISA.
Search the KEV Catalog by Vendor or Product
Search for CVEs by vendor or product to identify known exploited vulnerabilities in your environment
Upcoming Patch Due Dates
via Binding Operational Directive 26-04
BOD 26-04 is CISA's current vulnerability remediation directive for Federal Civilian Executive Branch (FCEB) agencies, updating the KEV-driven framework introduced under BOD 22-01 with a more risk-based approach to prioritization. While binding only on FCEB agencies, its framework increasingly influences contractor expectations through procurement requirements, FedRAMP programs, and agency security clauses.
Loading...
Cyber Security News
You may have missed...
Hacking Editorial Brief — August 19, 2026
DOJ Indicts 17 in Iranian State-Sponsored Hacking Campaign
The U.S. Department of Justice has charged 17 individuals linked to an Iran-backed hacking operation targeting American universities, private sector companies, and federal agencies. Prosecutors allege the group, associated with the sanctioned Tehran-based Mabna Institute, compromised 144 U.S. universities, 42 private companies, and at least five federal government entities. The campaign focused on unauthorized access to email accounts and large-scale theft of intellectual property, representing a sustained espionage effort against U.S. research and academic institutions. The indictments add to a growing body of enforcement actions targeting Iranian cyber operations, though attribution and prosecution of state-sponsored actors operating from foreign jurisdictions remain largely symbolic without extradition mechanisms.
China-Linked Actor Demonstrates Near-Autonomous AI Attack Capability
Security researchers have documented what is being described as the first "near-autonomous" nation-state cyberattack, attributed to a Chinese-language threat actor operating in the Asia-Pacific region. The campaign represents a tactical shift toward AI-enabled offensive operations, though specific technical details of the autonomous capabilities remain limited. Separately, Cisco has confirmed active exploitation of a high-severity denial-of-service vulnerability in its Secure Firewall ASA and Threat Defense software, urging immediate patching. OpenAI has announced enhanced security controls around AI model training and testing infrastructure following recent security incidents, signaling growing concern about the attack surface presented by large-scale AI development environments.
Sources: CTV News · Courthouse News · Cybersecurity Dive · Dark Reading · Bleeping Computer · CNN Business
*
Inside a cyberattack: How hackers steal data
The truth about cybersecurity is that it's almost impossible to keep hackers outside of an organization, particularly as the cybercrime industry ...
Cisco Actively Exploited Denial-of-Service Vulnerability in Secure Firewall
Cisco is warning that a high-severity denial-of-service vulnerability in Secure Firewall ASA and Threat Defense software is being actively exploited i...
Opinion | The OpenAI Hugging Face Hack, Explained - The New York Times
In July, the A.I. company Hugging Face discovered that it was hacked by an OpenAI agent. Helen Toner, a former OpenAI board member, ...
OpenAI is hardening AI testing and training in light of hacking incidents | CNN Business
OpenAI is unveiling new, stronger security safeguards around its training and testing in light of new model capabilities and a spate of incidents ...
Rules about funding and cybersecurity can shape the defense market as surely as contracts do
Summary: The Defense Department is moving toward final decisions on cybersecurity requirements for contractors while Congress continues to debate ...
Feds charge 17 in Iran-backed hacking scheme - Courthouse News
Prosecutors say members of the sanctioned Tehran-based firm the Mabna Institute compromised emails for more than 100000 college professors ...
OpenAI halts testing, slows development after rogue model hacked Hugging Face
It comes after two OpenAI models broke out of their testing environment last month and hacked into another AI firm without human direction. Chief ...
DOJ unseals new charges against 17 hackers in Iran-backed campaign | WTVB
By AJ Vicens Aug 18 (Reuters) - The U.S. Department of Justice on Tuesday unsealed new and updated charges against 17 individuals working with an ...
DOJ charges 17 people in Iran-backed hacking campaign against US | Cybersecurity Dive
Officials allege an IRGC-linked organization was behind a coordinated effort to steal research from American universities, companies and ...
Updated daily
