CISA stopped reliably sending KEV alerts.
We didn't.
CyberComply monitors the CISA Known Exploited Vulnerabilities catalog 24/7 and alerts you the moment a new KEV drops — before the deadline clock starts ticking without you knowing.
KEV Intelligence Brief — August 20, 2026
Issued by: Security Operations Intelligence | Classification: TLP:WHITE Coverage Period: August 18–20, 2026 | CVEs Covered: 8
CISA added eight vulnerabilities to the KEV catalog over the past 72 hours spanning five vendors, three architectural layers, and multiple exploitation surfaces. The entries cluster into three distinct threat narratives: a cascade of critical Microsoft and VMware infrastructure flaws demanding immediate action, an aggressive attack surface emerging across AI/ML and video conferencing developer tooling, and a credential bypass flaw targeting macOS endpoints at scale. Federal agencies and contractors operating under BOD 26-04 face hard patch deadlines as early as Friday, August 21 — some effectively overdue by the time this brief is read.
Deadline Watch: Microsoft, VMware, and Apple — Friday Is Not Optional
Three vendors account for five of this week's KEV additions, all carrying a patch deadline of August 21, 2026 — tomorrow. Organizations that have not already begun remediation are operationally behind.
CVE-2026-33824 (Microsoft IKE Service Extensions) is a double-free vulnerability enabling remote code execution within Windows VPN infrastructure. Double-free conditions in kernel-adjacent components are notoriously reliable primitives for privilege escalation chains; treat this as a potential beachhead into broader Windows environments, not merely a VPN issue. IKE services are frequently exposed at network perimeters and between network segments, amplifying blast radius.
CVE-2026-55040 (Microsoft SharePoint) describes a weak authentication bypass allowing unauthenticated network access to bypass a security feature. SharePoint is pervasive in federal contractor environments and frequently holds sensitive documents and integrated workflows. An authentication bypass here isn't a theoretical risk — it is an active credential-free path into organizational data stores. Teams running on-premises SharePoint should treat this as emergency-tier; SharePoint Online operators should verify Microsoft's service-side remediation status and consult tenant security advisories.
CVE-2026-59310 (Broadcom VMware vCenter) is a path traversal vulnerability permitting arbitrary code execution for any threat actor with network access to vCenter. VMware vCenter vulnerabilities have a documented history of rapid weaponization by nation-state and ransomware actors. Network-level access to vCenter — often assumed to be an internal-only risk — is increasingly achievable through earlier-stage footholds. If your vCenter management interface is not strictly isolated from general corporate network segments, that architectural gap is now your most urgent compensating control, independent of patching timeline.
CVE-2026-65400 (Apple macOS) enables a network-adjacent attacker to authenticate to Screen Sharing without valid credentials. This is a credential-less remote control capability. In enterprise environments where macOS endpoints are common among engineering and executive staff, this vulnerability provides an interactive foothold requiring no phishing, no malware delivery, and no password. Organizations should immediately audit Screen Sharing enablement across the fleet and disable the service where it is not operationally required, even before patch deployment. Credential rotation for accounts on affected systems is strongly advised.
All four require patching by August 21 under BOD 26-04. Contracting officers and security leads should document remediation progress now for audit purposes.
AI/ML and Developer Tooling Under Active Exploitation
Two vulnerabilities this week reinforce an accelerating pattern: the AI/ML development stack is under sustained, active attack, and the assumption that developer tools are "internal" or "low-risk" is no longer defensible.
CVE-2025-62593 (Ray-Project Ray) is a code injection vulnerability enabling remote code execution, with a notable detail: it is exploitable through Firefox and Safari in developer contexts. Ray is widely used to orchestrate distributed machine learning workloads. The browser-based exploitation vector means developers who interact with Ray dashboards — even on local or lab networks — may be exposed without running traditional server-facing services. The patch deadline is August 21, and teams using Ray in any capacity should treat browser-accessible Ray UI components as a high-priority attack surface. Network segmentation of Ray clusters and disabling browser-accessible dashboards where feasible are warranted compensating controls.
CVE-2026-64849 (MLflow) is a server-side request forgery (SSRF) vulnerability allowing attackers to pivot to internal services and cloud metadata endpoints, capturing response status and body content. In cloud-hosted ML pipeline environments, metadata service access — particularly the IMDSv1 endpoint on AWS or equivalent GCP/Azure services — can yield instance credentials sufficient for lateral movement or privilege escalation within a cloud tenant. The patch deadline is September 2, offering slightly more runway, but the cloud metadata exfiltration angle makes this a higher-urgency item than the timeline implies. MLflow instances should have outbound network access restricted via egress firewall rules, and cloud metadata service access should be blocked at the host or network level as an immediate compensating control regardless of patch status.
TrueConf Server: A Two-Stage Attack Chain to Watch
CVE-2026-72529 and CVE-2026-72530 (TrueConf Server) are distinct vulnerabilities on the same product and same attack surface — port 4307/TCP — and they appear designed to function as a two-stage compromise chain. CVE-2026-72529 is a missing authentication flaw enabling arbitrary script execution by any unauthenticated remote attacker; CVE-2026-72530 is a code injection vulnerability that breaks out of TrueConf's isolated environment to execute arbitrary code on the host operating system.
Read together: an attacker who achieves script execution via the authentication bypass (72529) can leverage the code injection (72530) to escape containment and own the underlying host. The patch deadlines differ — August 23 for CVE-2026-72529 and September 3 for CVE-2026-72530 — but the chained exploitation risk means both should be treated as a single emergency. Port 4307 should be firewalled from any public or untrusted network segment immediately. TrueConf Server deployments that cannot be patched within this window should be taken offline or strictly access-controlled until remediation is confirmed.
Sources: CISA KEV Catalog · CISA BOD 26-04 · Microsoft Security Response Center · Broadcom VMware Security Advisories · Apple Security Updates · Ray-Project Security · MLflow Security Advisories · TrueConf Security Bulletins
Free KEV Alerts
- Real-time notification the moment a KEV drops
- Vendor and product details
- BOD 26-04 remediation deadline included
Pro Alerts Coming Soon
- Real-time notification the moment a KEV drops
- Filtered to your specific vendor watchlist
- Urgency scoring (Critical / Urgent / Standard)
- Direct patch links included
Stay ahead of CISA.
Search the KEV Catalog by Vendor or Product
Search for CVEs by vendor or product to identify known exploited vulnerabilities in your environment
Upcoming Patch Due Dates
via Binding Operational Directive 26-04
BOD 26-04 is CISA's current vulnerability remediation directive for Federal Civilian Executive Branch (FCEB) agencies, updating the KEV-driven framework introduced under BOD 22-01 with a more risk-based approach to prioritization. While binding only on FCEB agencies, its framework increasingly influences contractor expectations through procurement requirements, FedRAMP programs, and agency security clauses.
Loading...
Cyber Security News
You may have missed...
Hacking Editorial Brief — August 20, 2026
NSA and FBI Warn of AI-Generated Exploitation Tools Targeting Critical Infrastructure
The National Security Agency and Federal Bureau of Investigation have issued a joint advisory warning that threat actors are now actively using artificial intelligence to generate exploitation scripts in attacks against critical infrastructure. The campaign involves adversaries leveraging AI to produce credential theft tools and develop attack pathways into operational technology environments. This marks a documented escalation from AI-assisted reconnaissance to full script generation for exploitation, representing a meaningful reduction in the technical barrier for sophisticated attacks. The warning comes as security researchers continue to track the maturation of AI-enabled offensive capabilities, with threat actors increasingly automating portions of the attack lifecycle previously requiring manual development.
Microsoft Patches 421 Vulnerabilities Including Actively Exploited Zero-Day
Microsoft's August 2026 Patch Tuesday addresses 421 common vulnerabilities and exposures, including one actively exploited zero-day tracked as CVE-2026-68820 in the Windows Ancillary Function Driver for WinSock. The volume represents one of the largest single-month patch releases in recent history. In a separate incident, OpenAI has implemented tightened security controls following reports that AI agents successfully compromised systems on Hugging Face, a major machine learning model repository. The breach underscores ongoing concerns about the attack surface presented by AI development infrastructure and the emerging threat of autonomous or semi-autonomous exploitation by AI-powered tools.
Sources: The Record · Bleeping Computer
*
Inside a cyberattack: How hackers steal data
The truth about cybersecurity is that it's almost impossible to keep hackers outside of an organization, particularly as the cybercrime industry ...
Georgia Tech Students Claim Victory at DEF CON's Elite Hacking Competition
Year after year, some of the world's best hackers gather at DEF CON in Las Vegas to put their skills to the test. None is more prominent than the ...
Could hackers target your drinking water? Monroe County boosts cyber defenses
... hacking capabilities, "which means you have to continue to invest in your defensive capabilities.” Alongside Sens. Chuck Schumer and Kirsten ...
AI-backed campaign targeting vulnerable Siemens S7 devices, CISA and FBI warn
The FBI, the National Security Agency and the Cybersecurity and ... Cybersecurity Dive news delivered to your inbox. Get the free daily ...
Federal cybersecurity mandate stirs concern in Alaska fishing industry - National Fisherman
A cybersecurity policy change coming down from the federal government is drawing backlash from Alaska's commercial fishing industry. The concern is .....
US charges 17 Iranian hackers over 31-terabyte academic data theft - Help Net Security
The U.S. has charged 17 alleged members of Mabna Institute, an Iranian hacking-for-hire company accused of running a years-long campaign that ...
'Not a theoretical risk,' feds warn as attackers use AI-made code to hack critical infrastructure ...
National security and infosec experts last week told The Register that while there is no indication that the water-system hackers used AI in their ...
Cloudflare Workers Spectre Attack Leaks JWT From Co-Located Worker at 12 Bits/Second
Cybersecurity researchers have disclosed details of a remote Spectre attack against Cloudflare Workers that leaked a JSON Web Token (JWT) from a ...
Cisco Actively Exploited Denial-of-Service Vulnerability in Secure Firewall
Cisco is warning that a high-severity denial-of-service vulnerability in Secure Firewall ASA and Threat Defense software is being actively exploited i...
Updated daily
