CISA stopped reliably sending KEV alerts.
We didn't.
CyberComply monitors the CISA Known Exploited Vulnerabilities catalog 24/7 and alerts you the moment a new KEV drops — before the deadline clock starts ticking without you knowing.
KEV Intelligence Brief — August 12, 2026
Prepared for: Federal Contractors · DevOps & Platform Teams · Security Operations Leadership Classification: Unclassified // For Official Use Reference Period: CVEs added to CISA KEV August 4–11, 2026
Eight new entries hit the CISA Known Exploited Vulnerabilities catalog over the past week, spanning network security appliances, developer infrastructure, AI tooling, and enterprise management platforms. Three patch deadlines have already passed. The breakdown below follows the attack surface logic that threat actors are already exploiting.
Deadline Watch: Overdue and Imminent — Act Now
Four of the eight entries carry patch deadlines that have already elapsed or expire within 48 hours of this writing. Federal agencies and covered contractors have no discretion here under BOD 26-04 — these assets must be patched or isolated immediately.
CVE-2026-9198 (IBM Langflow), CVE-2026-18556 (N-able N-central), and CVE-2026-34486 (Apache Tomcat) all carried a deadline of August 7 — five days ago. If your environment is running any of these and remediation has not been completed, treat this as an active incident posture, not a patch backlog item.
The Langflow code injection (CVE-2026-9198) is arguably the most dangerous of the three. Default deployments are exploitable by unauthenticated remote attackers for full RCE — no credentials, no prerequisites. Organizations running AI workflow pipelines on exposed Langflow instances should assume compromise, rotate all API keys and credentials accessible to those deployments, and conduct forensic triage per CISA's documented requirements before bringing patched instances back online. The surface area here extends to any downstream data source or model endpoint Langflow was connected to.
N-able N-central's authentication bypass (CVE-2026-18556) is a different class of problem: N-central is an RMM platform. An attacker who bypasses authentication on an RMM console doesn't just own one box — they own every managed endpoint beneath it. If N-central exposure is confirmed without remediation, assume lateral movement capability across the entire managed estate and initiate threat hunting immediately.
Apache Tomcat's missing EncryptInterceptor enforcement (CVE-2026-34486) is lower on the immediate severity scale but should not be deprioritized in clustered or load-balanced Tomcat deployments. Traffic that was assumed to be encrypted in transit between cluster nodes may have been observable. Audit cluster topology, review session data sensitivity, and patch.
CVE-2026-8037 (Progress LoadMaster) carried a deadline of August 10 — two days ago. This unauthenticated command injection across multiple management endpoints makes LoadMaster appliances trivially exploitable from the internet. Progress LoadMaster has a documented history of attracting sophisticated threat actor attention, and command injection on a load balancer gives adversaries a persistent, strategically positioned foothold. If internet-facing LoadMaster instances are not yet patched, isolate the management interface immediately and treat the appliance as potentially compromised.
CVE-2026-20349 (Cisco ASA/FTD) and CVE-2026-72898 (Metabase) carry a deadline of August 14 — two days out. Treat these as urgent.
Developer and CI/CD Infrastructure: The Pipeline Is the Target
Two entries this week underscore an accelerating pattern: adversaries are methodically working through developer toolchains because compromising build and analytics infrastructure yields access far upstream of production defenses.
CVE-2026-63077 (JetBrains TeamCity) — deadline August 8, now overdue — describes unauthenticated RCE via the agent polling protocol. TeamCity has now accumulated multiple KEV entries across successive years, and the pattern is consistent: nation-state actors and ransomware operators treat CI/CD compromise as a force multiplier, enabling supply chain insertion, secrets theft, and code-signing abuse. Any organization with internet-exposed TeamCity instances that has not patched should perform immediate artifact integrity verification alongside remediation. Assume any build artifacts produced during the exposure window may be suspect.
CVE-2026-72898 (Metabase) deserves special attention beyond its SQL injection classification. The attack chain here is notably complete: unauthenticated remote injection escalates directly to administrator access, which then exposes application configuration and stored database credentials for every connected data source. In environments where Metabase is fronting analytics against production databases, this is effectively an unauthenticated path to all connected data. Patch before the August 14 deadline, but also audit the Metabase MB_DB_ configuration for credential exposure, rotate all connected database credentials regardless of whether exploitation is confirmed, and review Metabase query logs for anomalous or injected SQL strings.
Endpoint and Network Perimeter: Privilege Escalation and DoS at Scale
CVE-2026-20349 affects Cisco ASA and FTD — the perimeter devices organizations depend on to enforce segmentation and VPN access. The heap inspection vulnerability enables unauthenticated remote DoS via device reload. While the described impact is availability rather than confidentiality, operationally, weaponized DoS against ASA/FTD devices can be used to force failover, disrupt enforcement, and create reconnaissance windows. Internet-exposed management interfaces should be restricted immediately; patch by August 14.
CVE-2026-68820 (Microsoft Windows Ancillary Function Driver for WinSock) carries the latest deadline in this batch — August 25 — but should not be treated as lower urgency. Use-after-free privilege escalation vulnerabilities in Windows kernel-adjacent drivers are consistently paired with initial access exploits in multi-stage attack chains. An attacker who phishes or exploits their way to a low-privileged foothold on a Windows system can chain CVE-2026-68820 to elevate to SYSTEM. Prioritize patching on internet-facing Windows servers, VDI endpoints, and any system where initial access risk is elevated. Deploy August Patch Tuesday updates immediately if not already done.
Operational Posture Guidance
Organizations subject to BOD 26-04 must document remediation status, apply CISA's Forensics Triage Requirements where exploitation cannot be ruled out, and escalate unresolved overdue items through their ISSO chain. For all unauthenticated RCE entries — Langflow, LoadMaster, TeamCity, and Metabase — the forensics step is not optional hygiene; it is a compliance requirement.
Sources: CISA KEV Catalog · CISA BOD 26-04 · Cisco Security Advisories · Microsoft Security Update Guide · JetBrains TeamCity Security Advisories · Progress LoadMaster Security Advisories · N-able Security Advisories · Apache Tomcat Security Reports · Metabase Security Advisories
Free KEV Alerts
- Real-time notification the moment a KEV drops
- Vendor and product details
- BOD 26-04 remediation deadline included
Pro Alerts Coming Soon
- Real-time notification the moment a KEV drops
- Filtered to your specific vendor watchlist
- Urgency scoring (Critical / Urgent / Standard)
- Direct patch links included
Stay ahead of CISA.
Search the KEV Catalog by Vendor or Product
Search for CVEs by vendor or product to identify known exploited vulnerabilities in your environment
Upcoming Patch Due Dates
via Binding Operational Directive 26-04
BOD 26-04 is CISA's current vulnerability remediation directive for Federal Civilian Executive Branch (FCEB) agencies, updating the KEV-driven framework introduced under BOD 22-01 with a more risk-based approach to prioritization. While binding only on FCEB agencies, its framework increasingly influences contractor expectations through procurement requirements, FedRAMP programs, and agency security clauses.
Loading...
Cyber Security News
You may have missed...
Hacking Editorial Brief — August 13, 2026
Taiwan Targeted in First Fully Autonomous AI-Driven Cyberattack
Taiwan's government confirmed it was targeted in July by what security researchers characterize as the first end-to-end autonomous AI-powered cyberattack, attributed to suspected China-linked threat actors. According to Israeli cybersecurity firm assessments, attackers deployed an AI tool built from open-source components that autonomously devised and executed effective attack strategies in real-time without human intervention. Taiwan's investigation determined the attacks displayed clear characteristics of an overseas source, employing a hybrid approach that combined AI-driven reconnaissance, exploitation, and lateral movement. The incident represents a significant escalation in autonomous offensive AI capabilities, moving beyond the AI-augmented vulnerability research disclosed yesterday to fully automated attack execution.
Supply Chain and Infrastructure Targeting Continues
Nearly 800 malicious packages were published to the npm registry, delivering cross-platform remote access trojans and infostealers targeting Windows, macOS, and Linux systems in what appears to be a coordinated supply chain attack campaign. The cluster of packages demonstrates continued threat actor focus on software supply chains as a distribution mechanism. Iran-backed threat actors continued targeting U.S. water infrastructure, with officials confirming additional intrusions in New Jersey facilities. A hacker claims to have stolen data belonging to 15 million Kazakhstanis from the country's eGov service; Kazakhstan authorities are investigating the alleged breach. Separately, security researchers are investigating an unauthorized Wi-Fi network that appeared on a Delta flight following a hacker convention, suspected to be a rogue access point designed for man-in-the-middle attacks.
Sources: Yahoo · Tom's Hardware · Financial Times · The Hacker News · CBS News · The Diplomat
*
Inside a cyberattack: How hackers steal data
The truth about cybersecurity is that it's almost impossible to keep hackers outside of an organization, particularly as the cybercrime industry ...
It May Be Time to Panic About AI - The Atlantic
OpenAI, Anthropic, and Meta each reported that their models then hacked into other companies. Humans didn't notice until after the fact. In some cases...
Lazarus hackers pair fake job offers with Windows zero-day exploit - Help Net Security
Lazarus hackers pair fake job offers with Windows zero-day exploit. The North Korea-linked Lazarus group is using fake job offers, trojanized PDF ...
Microsoft-vendetta hacker has a new zero day that gives system privileges on fully patched Windows
According to at least one other researcher, the exploit works. “I've tried it, it works on latest Windows 11,” former Microsoft employee and security ...
August 2026 Patch Tuesday: Microsoft Fixes 421 CVEs, One Exploited Zero-Day
Microsoft released its August 2026 security update addressing 421 vulnerabilities including 62 critical issues, with one elevation of privilege flaw a...
Lazarus Exploits Windows Zero-Day to Gain SYSTEM Access and Deploy Backdoor
The end goal of these intrusions is to seize complete control of infected computers and bypass security controls. Cybersecurity. The use of a ...
Ransomware Attacks on U.S. Educational Institutions Decline 44% in First Half of 2026
Comparitech reports ransomware attacks against U.S. schools fell to 34 incidents in the first half of 2026, down 44% from 61 in the second half of 202...
AI agents' 'alarming' hacking skills creates rush to spend on cybersecurity - CNBC
A string of recent AI hacking incidents has pushed cybersecurity to the forefront of the conversation, as labs race to develop agentic AI from ...
Iran-Linked Hackers Target More US Water Infrastructure in New Jersey and Alabama
Iran-linked hackers targeted Water Infrastructure in New Jersey and Alabama, bringing confirmed attacks to at least 12 states.
Updated daily
