CISA stopped reliably sending KEV alerts.
We didn't.
CyberComply monitors the CISA Known Exploited Vulnerabilities catalog 24/7 and alerts you the moment a new KEV drops — before the deadline clock starts ticking without you knowing.
KEV Intelligence Brief — August 31, 2026
Issued: Monday, August 31, 2026 | Audience: Federal Contractors, DevOps, SecOps Leadership | Classification: Unclassified / For General Distribution
Eight vulnerabilities were added to CISA's Known Exploited Vulnerabilities catalog between August 26–28, spanning print management, cloud storage, developer artifact infrastructure, core Linux components, and legacy enterprise software. The pattern is notable: attackers are demonstrably chaining pre-auth bugs into code execution, exploiting forgotten infrastructure, and reviving decade-old local privilege escalation paths — likely because organizations still haven't addressed them. BOD 26-04 compliance obligations are active across all eight entries.
Critical Deadline: Two Entries Are Already Past Due or Overdue as of Today
Two KEV entries carry patch deadlines that either passed this weekend or expire tomorrow, demanding immediate triage over any other action item in this brief.
CVE-2019-1068 (Microsoft SQL Server RCE) had a patch deadline of August 29 — two days ago. Any SQL Server instance that has not been patched is now out of compliance with BOD 26-04 requirements. This is not a theoretical risk: the vulnerability allows remote code execution under the SQL Server Database Engine service account, meaning a successful attacker can operate with the privileges of that service — potentially accessing every database hosted on that instance, exfiltrating credentials, or pivoting laterally to Active Directory-integrated systems. If patching cannot be completed retroactively, isolate the instance from internet-facing network segments immediately, audit authentication logs for anomalous query patterns, and initiate forensic triage per CISA's requirements. Credential rotation for the SQL Server service account and any accounts with access to hosted databases is warranted regardless of patch status.
CVE-2023-49105 (ownCloud Improper Authentication) carries a deadline of August 30 — yesterday. Despite the 2023 CVE identifier, this vulnerability is actively exploited in current campaigns and was added to KEV only last Thursday. The flaw is severe: an unauthenticated attacker who knows a victim's username can access, modify, or delete any file if the victim has no signing-key configured — a default condition in many deployments. Organizations running self-hosted ownCloud instances should treat this as a critical incident response posture, not a patching task. Verify signing-key configuration across all user accounts, restrict external access to the WebDAV endpoint, and assume any internet-exposed instance without signing-keys has been compromised pending forensic review.
Chained for Code Execution: The PaperCut Two-Stage Attack and the JFrog Artifactory Path Traversal
Three vulnerabilities in this batch directly target the software delivery and document infrastructure that DevOps and enterprise operations teams depend on daily, and two of them are explicitly designed to be chained together.
CVE-2026-81578 and CVE-2026-82078 (PaperCut NG/MF) were added simultaneously on August 28 with a shared deadline of September 11, and CISA's catalog explicitly acknowledges the chaining relationship. The attack sequence is straightforward and devastating: CVE-2026-81578 provides unauthenticated access to modify system configurations — no credentials required — and CVE-2026-82078 then exploits an unsafe reflection vulnerability to execute arbitrary Java bytecode already on the application classpath under the PaperCut server process security context. Together, these constitute a full unauthenticated remote code execution chain against any internet-exposed PaperCut server. PaperCut is deeply embedded in university, government, and enterprise print environments, many of which expose the management interface externally for remote administration convenience. That convenience is now a critical liability. Until patching is complete, remove the PaperCut Application Server port (typically 9191/9192) from any internet-accessible firewall rule, enforce network segmentation between print servers and core infrastructure, and review PaperCut server process permissions to limit the blast radius of the underlying service account.
CVE-2026-66384 (JFrog Artifactory Path Traversal) carries a deadline of September 10 and represents a distinct but equally consequential risk for DevOps pipelines. The vulnerability allows an authenticated user to write data outside the intended Docker cache path under specific remote-repository conditions — a path traversal that, in a CI/CD environment, could enable artifact poisoning, configuration file overwriting, or deployment of malicious container images into downstream pipelines. Unlike the PaperCut chain, this requires authentication, but insider threat and compromised CI service accounts must be considered realistic threat actors. Audit Artifactory remote repository configurations now, restrict write permissions to Docker cache paths using Artifactory's permission target controls, and review recent artifact push activity from service accounts for anomalous paths.
Legacy Debt Coming Due: Linux Kernel, Red Hat Libuser, and ABRT
The final cluster is a cautionary tale about deferred maintenance. Three vulnerabilities from 2015 and one from 2026 reflect a spectrum of local privilege escalation risks across Linux environments.
CVE-2026-53362 (Linux Kernel) is the most urgent of this group, with a September 10 deadline and cross-distribution impact confirmed across SUSE, Red Hat, and any Linux distribution using the affected kernel version. The vulnerability enables privilege escalation via the IPv6 networking subsystem — meaning any multi-tenant or container host environment where IPv6 is enabled could allow a low-privileged process or container workload to escalate to root. Disable IPv6 where not operationally required as an immediate interim measure, and prioritize kernel patching on hosts running container workloads, hypervisors, or shared compute environments.
CVE-2015-3246 (Red Hat Libuser) and CVE-2015-5287 (Red Hat ABRT) — both with deadlines of September 9 — are eleven-year-old vulnerabilities now confirmed exploited in the wild. The libuser race condition allows /etc/passwd corruption for denial of service or privilege escalation; the ABRT symlink attack enables privilege escalation for local users with specific permissions. ABRT is explicitly noted as potentially end-of-life. Organizations still running affected Red Hat versions should assess whether those systems can be upgraded or decommissioned. If neither is immediately feasible, restrict local user permissions aggressively, audit sudoers configurations, and treat any local account on these systems as a potential escalation vector.
Sources: CISA KEV Catalog · CISA BOD 26-04 · PaperCut Security Advisories · ownCloud Security Advisories · JFrog Security Center · Red Hat Security Advisories · Microsoft Security Response Center — CVE-2019-1068
Free KEV Alerts
- Real-time notification the moment a KEV drops
- Vendor and product details
- BOD 26-04 remediation deadline included
Pro Alerts Coming Soon
- Real-time notification the moment a KEV drops
- Filtered to your specific vendor watchlist
- Urgency scoring (Critical / Urgent / Standard)
- Direct patch links included
Stay ahead of CISA.
Search the KEV Catalog by Vendor or Product
Search for CVEs by vendor or product to identify known exploited vulnerabilities in your environment
Upcoming Patch Due Dates
via Binding Operational Directive 26-04
BOD 26-04 is CISA's current vulnerability remediation directive for Federal Civilian Executive Branch (FCEB) agencies, updating the KEV-driven framework introduced under BOD 22-01 with a more risk-based approach to prioritization. While binding only on FCEB agencies, its framework increasingly influences contractor expectations through procurement requirements, FedRAMP programs, and agency security clauses.
Loading...
Cyber Security News
You may have missed...
Hacking Editorial Brief — August 31, 2026
Department of Justice Retracts China Hacking Victim Claims
The U.S. Department of Justice issued a revised statement correcting its initial announcement regarding a China-linked hacking campaign identified as QTFY. The original release claimed Chinese threat actors had successfully compromised multiple high-value U.S. government entities including the Senate, Federal Reserve, and NASA. Two days later, DOJ walked back those claims, clarifying that these agencies were targeted but not confirmed victims of the intrusion campaign. The unusual correction raises questions about attribution verification processes and the accuracy of threat intelligence being released for public disclosure.
Cronos Blockchain Halted After $75M DeFi Exploit; University Breach Confirmed
Cronos blockchain operators suspended network operations following a $75 million exploit targeting the Tectonic lending application. The attacker allegedly manipulated the thinly traded TONIC token—inflating its price approximately 100-fold—then used the artificially inflated collateral to borrow legitimate assets before withdrawing funds. The incident follows familiar DeFi attack patterns exploiting oracle manipulation and liquidity vulnerabilities. Separately, the University of Nottingham confirmed a June 2026 data breach after ShinyHunters leaked approximately 455,000 unique email addresses along with associated personal, academic, and financial records. The disclosure adds to ShinyHunters' active 2026 campaign following its claimed Abbott Laboratories breach earlier this week. Pro-Russian hacktivist group Server Killers also claimed responsibility for attacks on Norwegian government services, allegedly causing budget data leakage.
Sources: TheHackerNews · The Next Web · CoinDesk · Bright Defense · Tech Insider
*
Inside a cyberattack: How hackers steal data
The truth about cybersecurity is that it's almost impossible to keep hackers outside of an organization, particularly as the cybercrime industry ...
DOJ: Chinese State-Sponsored Hackers Breached Senate, Federal Reserve, Multiple Agencies
The DOJ seized internet domains tied to QTFY hacking platforms QScan and QTRouter that Chinese state-sponsored operatives used to breach the Federal R...
Fed, NASA and DOJ among victims of Chinese state-sponsored hacker group: Court documents
The Federal Reserve, U.S. Senate, Department of Justice, and NASA were victims of computer intrusion by Chinese state-sponsored hacking group QTFY, ac...
U.S. Says Chinese Hackers Targeted Senate, NASA, Hospitals, and More
Federal officials announced disruption of a yearslong Chinese hacking campaign (QTFY) that compromised or targeted U.S. institutions including NASA, t...
US officials revise claims that government agencies were hacked by Chinese, now say they ...
The distinction matters because it narrows the scope of confirmed breaches in what the DOJ described as a years-long Chinese cyber-espionage campaign ...
Week in review: Compromised Zimbra servers, previously patched Citrix NetScaler flaw exploited
The US Cybersecurity and Infrastructure Security Agency (CISA) wants federal agencies to (re)shape their logging strategy around one question: when an...
FBI disrupts proxy network enabling Chinese espionage operations
The FBI seized domains used by Chinese threat group QTFY to operate QScan and QTRouter platforms, with court documents revealing the group includes fo...
'Hackers for hire': How a Chinese group hid its attacks on U.S. infrastructure
Federal agents shut down two hacking platforms used by a China state-sponsored group (QTFY) to conceal cyberattacks on U.S. targets, including the Jus...
US says Chinese hackers hit hospitals, NASA, Senate and more
US officials exposed a major alleged Chinese cyber-espionage campaign that compromised or attacked numerous federal agencies including NASA, the Feder...
Updated daily
